Legal · GHL apps
Privacy Policy for the GHL apps
Effective September 8, 2026
The short version
These apps are steps that run inside your automation platform. Most of them are pure computation: they receive the values you map into them, work on those values, return a result, and keep nothing. There is no server of ours in the path, no analytics, no tracking, and no third party receiving your data. Where an app connects to an outside service, it does so with a credential you create and it talks to your account at that service directly — never through us.
Who is responsible
The apps listed below are developed and published by Builds By Luke, based in Canada. For the purposes of Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and the EU/UK General Data Protection Regulation (GDPR), Builds By Luke is accountable for the handling described in this policy.
The person accountable for this policy is the Privacy Contact at Builds By Luke. Questions, access requests and complaints all go to one place:
Which apps this covers
This policy covers the following workflow-automation apps:
- Chronos Date and Time Tools — Five timezone-accurate date and time steps for workflows: format, add or subtract time, measure a gap, count business days, and find the next occurrence.
- Lexicon Text and Number Tools — Seven text and number steps for workflows: change case, clean, split names, find and replace, extract, spin, and format numbers.
- Agora Store Tools for Shopify — Nine Shopify steps for workflows: look up customers and orders, recover abandoned carts, check stock and price, sync customers, and create discount codes.
- Fulcrum Data and Logic Tools — Data shaping and real conditional branching for workflows: read JSON, work with lists, compare values, and send each contact down the right path.
- Bedrock Backup and Restore — Scheduled backup and one-click restore across every sub-account, installed once at the parent level — the one place every competing app leaves open.
It covers these apps only. The buildsbyluke.com website itself, including its contact form and chat, is covered by the site privacy policy, which is separate and unchanged.
Two roles, stated plainly
If you are the operator who installs one of these apps and builds the workflow, you decide which values the app receives and what it does with them. The contact data flowing through your workflows is yours, held in your automation platform account, and you remain responsible to your own contacts for it. The app processes only what you explicitly map into its fields, to do the job you added it for.
If you are a contact of a business that uses one of these apps, that business is your point of contact for anything about its automations. We do not receive your personal information from these apps; see the next section for why.
What every app has in common
- The apps run as code executed by the automation platform itself. There is no server operated by Builds By Luke in the request path for any app currently published.
- An app sees only the values you explicitly map into its fields. None of them reads your contact list, your conversations, your calendars or your account settings. The single permission each one requests exists solely so its steps appear in the action list.
- Values are processed in memory for the duration of one step and are not written to disk, cached, logged, or retained afterwards.
- The apps set no cookies and do not fingerprint or track anyone.
- As at the effective date above, no analytics, advertising, telemetry or usage-measurement tool is embedded in any of these apps. If that ever changes, this policy will be updated to describe it before it is switched on.
- The marketplace handles all billing. We never see card numbers or payment details.
Self-contained apps
These apps perform computation only. They connect to nothing, require no credential, and transmit nothing anywhere:
- Chronos Date and Time Tools — None. The code runs inside the automation platform.
- Lexicon Text and Number Tools — None. The code runs inside the automation platform.
- Fulcrum Data and Logic Tools — None. The code runs inside the automation platform.
For these apps the honest summary is that there is no data flow to describe. Text or a date goes into a step, a result comes out, and nothing survives the run.
Apps that connect to an outside service
Some apps exist to talk to a service you already use. These work on a bring-your-own-credential basis, and the distinction matters:
- Agora Store Tools for Shopify connects to Shopify using an admin api access token from a custom app you create inside your own shopify admin.
How a credential is handled:
- You create it, in your own account at that service, and you can revoke it there at any moment without involving us.
- It is stored in your automation platform — in the step’s configuration or in a Custom Value you control — not by us. We have no database that could hold it.
- It is transmitted only to that service’s own domain, over HTTPS, at the moment the step runs. It is not sent anywhere else, and it is never logged.
- Data returned by that service is used to populate the step’s outputs for that one run and is then discarded.
- We grant ourselves no access to your account at that service, and receive no copy of anything it returns.
Your relationship with that service is governed by their privacy policy and terms, not ours. Grant the narrowest set of permissions the steps you actually use require; each app’s page lists exactly which permission each step needs and why.
Apps that will store data outside the platform
One planned app is different in kind, and it would be misleading to bury that:
- Bedrock Backup and Restore — planned. Required. Roughly $5 a month of managed infrastructure, stated openly because a scheduled backup cannot run without a server.
A backup that lives only inside the system it is protecting is not a backup, so this app will necessarily hold a copy of data outside the automation platform. It is not built, not released, and not installable today. Before it is submitted for review, this policy will be updated to state exactly what it stores, where it is stored, how it is encrypted, how long it is kept, how it is deleted, and who can reach it. Nothing about it is in operation as at the effective date above.
What we receive automatically
The only information that reaches us without you sending it is what the marketplace gives any developer about an installation: that an install happened, which account it belongs to, and the subscription status used to grant or withdraw access to a paid plan. We do not receive your contacts, your messages, your workflow contents, or any credential you configure inside a step.
Support correspondence
If you email [email protected] we keep that correspondence for as long as it takes to resolve your question and for a reasonable period afterwards in case you write again about the same thing. Please do not send us a credential, an access token or a password — we never need one, and we will ask you to revoke anything that arrives by mistake.
Your rights
You may ask what personal information we hold about you, ask for a copy, ask for it to be corrected, or ask for it to be deleted. Write to the Privacy Contact above and you will get a reply within thirty days. In practice, for the apps described here, the honest answer to “what do you hold about me” is usually “nothing beyond the install record and any email you have sent us”.
If you are in the EU or UK you also have the right to complain to your local supervisory authority. If you are in Canada you may complain to the Office of the Privacy Commissioner. We would rather you told us first, so we can fix it.
Children
These are business tools. They are not directed at children and we do not knowingly collect information from anyone under sixteen.
Changes to this policy
If this policy changes in substance, the effective date above changes with it, and the change is described here rather than applied quietly. A change that widens what an app collects will be published before that behaviour ships, not after.
Contact
Privacy Contact, Builds By Luke, Canada — [email protected]