Back to LegoTechApps

Privacy Policy

Last updated: August 8, 2026

Information we collect

When you contact us or request an estimate, we collect the details you submit, including your name, phone number, email, company, project description, and estimate answers.

How we use it

We use this information to respond to your request, prepare and discuss a project estimate, provide requested services, and maintain necessary business records.

Newsletter

Newsletter signup is optional and disabled by default. You may unsubscribe from marketing messages at any time.

Sharing and retention

We do not sell your personal information. We share it only with service providers required to operate our systems or when legally required. We retain it only as long as reasonably necessary.

External services and links

Some links, such as shipment-status tracking, open third-party services. When you follow them, that provider's privacy policy and terms apply. LegoTechApps does not send your contact-form information to those services through these links.

QR codes & scan analytics

Businesses using LegoTechApps can create QR codes and short links. When you scan such a code or open such a link, we log the event for that business's analytics: the date and time; your IP address; information derived from that IP address by a third-party geolocation provider (ip-api.com), to which your IP address is sent — approximate location (continent, country, region, city, postal code and approximate coordinates), time zone and local currency, the network you are on (internet provider, organisation and network operator name), and whether the connection appears to be mobile data, a VPN or proxy, or a data centre; and your device and browser information (user-agent) together with the referring page. The location is estimated from your IP address and is not GPS: it usually identifies a city or region, not a street address, and it can be wrong.

This is used to measure engagement with that business's codes. The business can see these entries, including your IP address, and can permanently delete a code's scan history at any time. We do not use this information to personally identify you, and we do not track you across unrelated websites. Requests a business makes to test its own code are not recorded. The business can also see when the same IP address has scanned its codes before, so a returning visitor is recognisable as the same device even though we do not know who you are. If a business retires a code and leaves it retired, the page shown to anyone who later scans it displays how many times that code was scanned, so it can be offered to a new owner; no location or device detail from those scans is shown publicly.

Clients club & review sign-up

If you choose to join a business's "clients club" or leave feedback through a page we host, we collect the details you provide (such as name, phone number and email) and store them for that business, with your consent, so they can contact you with offers and updates. You can ask the business to remove your details at any time.

Lead agent

Businesses using LegoTechApps can run a "lead agent" that reads public messages to find people asking for what that business sells. If you have posted publicly in a Telegram group that a business has added its own bot to, this may apply to you.

What is stored. The text of your message, the date, your public display name and username, a link to your public profile and to the message, the name of the group it was posted in, and any phone number or email address you yourself wrote inside the message. An AI then adds a score from 0 to 100 estimating how likely you are to be looking to buy, one line explaining that score, and a few keywords. We do not read private chats, we do not collect anything you have not published, and we do not combine this with data from anywhere else or build a profile of you across businesses.

Where it comes from. Only sources the platform permits: Telegram groups where a member or administrator has deliberately added that business's own bot, and — where the business has connected its account — comments left on that business's own posts. We do not scrape Instagram, Facebook or TikTok, and the agent never signs in to anyone's account.

Why. So a business can answer a public question about the kind of service it provides. We rely on our customers' legitimate interest in responding to a public request for what they sell. The record is visible only to that one business, never to others.

How long. Until the business deletes the lead, or 30 days after it deletes its account, whichever comes first. A lead is never sold or shared, and is not used to train any AI model.

Your choices. You can ask the business to delete a lead, or contact us and we will have it removed. If you would rather not be found this way at all, tell the group's administrator: the bot is in the group at their invitation, and removing it stops any further messages from that group being read.

Deleting your account

If you have a LegoTechApps account, you can delete it at any time from Settings → Delete account. You do not need to contact us and you do not need a reason.

When you ask, your account is closed immediately: your QR codes and short links stop resolving, your clients-club and review pages stop accepting sign-ups, automatic emails and scheduled reports stop, and your session ends. Any paid subscription is cancelled at that moment, so nothing further is charged.

Your data is then held, unused and inaccessible, for 30 days. Logging in during that period and pressing Restore reverses everything, including unused token credits. We email you when the deletion is scheduled, again seven days before the deadline, and once when it is done. You can also choose to have your accountant, or other addresses you enter, notified.

After 30 days everything is permanently deleted and cannot be recovered by you or by us: your businesses, orders, clients and client groups, buildings and residents, expenses and receipts, messages, QR codes and their scan history, review requests and feedback, generated articles and videos, notifications, settings and your login itself.

The first exception is invoices you issued. An invoice is a tax document, and the law in most countries where we operate requires it to be kept for several years — typically six to ten in the EU, six in the UK, seven in Israel, three to seven in the United States. We keep the invoice record (its number, date, amounts, tax and currency) and permanently overwrite everything personal on it: the customer name, email address and postal address, any notes, and the link to your account. The shared invoice link stops working. What remains cannot be traced back to you or to your customer, so it is no longer personal data.

The second exception is a fraud-prevention record. Every new account receives a free welcome balance. To stop the same person collecting it over and over by deleting an account and signing up again, we keep a one-way cryptographic fingerprint of the email address that received one, together with a count and the dates. It is not the address, and it cannot be turned back into the address: it is never used to contact you, to advertise to you, or to build any profile, and on its own it can answer exactly one question — whether a welcome balance has already been claimed. We keep it for as long as we offer a welcome balance, on the basis of our legitimate interest in preventing abuse of a free offer.

Deleting your LegoTechApps account also deletes the personal details your own clients gave you through pages we host. If you are a client of a business rather than an account holder, you can ask that business to remove your details at any time, or contact us.

Contact

For privacy requests, contact LegoTechApps through the website contact form or WhatsApp.