Privacy Policy
Effective Date: January 1, 2026 · Last Updated: August 27, 2026
1. Overview & Data Minimization Philosophy
LMCProtocol.com ("LMCProtocol", "we", "us", or "our") provides sub-second local business telemetry, technical flaw detection (Meta Pixel, GA4, review velocity), and Model Context Protocol (MCP) integrations for autonomous AI agents, SDR workflows, and developers.
We operate under strict data minimization principles. Our engine inspects publicly accessible spatial listings, open DNS MX routing records, and public commercial website DOM structures in real time. We do not harvest, broker, or trade consumer personal data or private end-user conversations.
2. Information We Collect
When you use LMCProtocol services, we collect only the minimum telemetry necessary to operate and secure the API:
- Account & Billing Information: Your email address and subscription identifier when creating an account or subscribing to a paid tier. Payment processing is managed via Stripe (or on-chain micro-settlement via Subcent402) and card details never touch our application servers.
- API Usage Telemetry: Request timestamps, API key hashes, queried niches/locations, diagnostic vector sizes, and monthly lookup quotas.
- Security Logs: Request IP addresses and client user agents accessing our endpoints for DDoS mitigation and SSRF protection.
3. How We Process Spatial & Web Telemetry
When an API client queries local business data (e.g. POST /v1/search), our gateway parses public business registries and audits public website markup for technical flaws (missing conversion pixels, absent GA4 measurement tags, stalled review velocity).
- Zero Private Context Storage: We do not log, retain, or train on any private system prompts, agent instructions, or cold outreach email drafts passed through our endpoints.
- Episodic Caching: Public technical telemetry is cached for up to 7 days to eliminate unnecessary load on target business web servers.
4. GDPR, UK DPA, CCPA & 1-Click Domain Suppression
Under the UK Data Protection Act, EU GDPR, and California Consumer Privacy Act (CCPA), domain owners have the absolute right to have their business domain suppressed from automated indexing.
We provide an instant self-serve suppression tool: 1-Click Domain Opt-Out. Any domain submitted is permanently blacklisted from all future diagnostic searches and telemetry exports across our platform.
5. Sub-Processors & Infrastructure
We share data exclusively with critical infrastructure providers:
- Stripe, Inc. — Subscription billing and payment processing.
- Cloudflare, Inc. — Edge routing, SSL termination, and DDoS protection.
- DigitalOcean, LLC — Cloud computing and sovereign API hosting.
6. Contact & Data Protection Officer
For privacy questions, security reports, or data inquiries:
Email: [email protected]
Platform: LMCProtocol.com