Privacy notice
Last updated 2026-10-01
This notice explains what happens to your details when you join the Lantern waitlist on lantern.living or lantern.fitness, and when you set up a business in the Lantern business portal.
Who we are
Lantern is run by Britannic AI Limited, registered in England and Wales with company number 16879653. Registered office: 71-75 Shelton Street, Covent Garden, London WC2H 9JQ. We are the data controller: we decide what is collected and why.
For any question or request about your data, email [email protected].
What we collect
- Your email address.
- The language of the page you signed up on (English or Thai), so we write to you in that language.
- A record of your consent: the exact wording you agreed to (version v1) and when you ticked the box.
- A scrambled (hashed) form of your IP address. We keep the hash, not the address, and use it only to spot abuse such as mass sign-ups.
When you visit the site, Cloudflare, which hosts and protects it, processes your IP address and technical details about your browser to deliver the pages and block attacks. The waitlist form and the business portal's email sign-in use Cloudflare Turnstile to check that a person, not a bot, is filling them in. Turnstile uses signals from your browser for that check only. It is not used for advertising or to track you across other sites.
Why we use it, and our legal basis
- To email you when Lantern memberships open. Legal basis: your consent (UK GDPR Article 6(1)(a); PDPA section 19). We send nothing else unless you agree to it separately.
- To keep the sign-up form free of abuse, using the hashed IP address, rate limits and Turnstile. Legal basis: our legitimate interest in keeping the service secure (UK GDPR Article 6(1)(f); PDPA section 24(5)).
- To answer requests you send to [email protected] about your data, and keep a record that we did. Legal basis: our legal obligation to answer them (UK GDPR Article 6(1)(c); PDPA section 24(6)).
We don't sell your data, use it for advertising, or make automated decisions about you.
If you set up a business on Lantern
Business owners and managers use the Lantern business portal to put their business on Lantern. For that we collect:
- Your email address and how you sign in (Google, Apple or email), to create your account and keep you signed in. WorkOS handles sign-in; we never see or store your password.
- What you type to search for your business. It is sent to Google, with the page language, to find the business's Google listing. Your account details are not sent to Google.
- The business's details from its Google listing, as you confirm or correct them: name, address, opening hours, phone number, category, website and Google's ID for the listing. Also the position of your business on the map: the pin you confirm, which is your own data, not Google's.
- What our server finds on the business's public website: its logo, and links to its Instagram, menu, booking page, LINE, WhatsApp and phone number. These are only suggestions; you choose what to use.
- What you add when you set up the listing: your business's Instagram username, its logo (a photo or file you upload, or the one we found, stored as two small images), a link to your booking page or timetable, and where members should send enquiries (a LINE ID, WhatsApp number, Instagram username or phone number). These are shown on your listing.
- A record of the business terms and the data consent you agreed to at the Agree step: which wording, in which language, and when.
- When you sign in, we pass your IP address and the name of your browser to WorkOS for its checks against abuse. We do not store them.
- Your prices: the items, prices and notes you type, and what we read from the menu or price list on the business's website. You can also send a photo or PDF of your menu or price board, from your computer or by scanning a code with your phone; we remove the location data a photo may carry, check the file for viruses, and keep it until you replace it or your business is removed. To read the menu and to translate each item into English and Thai, we send the photo or PDF, or the item's words, to an AI service (Anthropic, below); we do not send your name or your business's name, address or contact details with it, and Anthropic handles it for us under its data processing terms. If you choose to show members a link to your menu instead, we keep that link.
- Which setup steps you open and finish, how long you spend on each, and any error a step shows, so we can see where people get stuck. These are recorded against an internal ID number for your account and business, never your name, email address or phone number, and without cookies. They are sent to PostHog. We do not record your screen. Legal basis: our legitimate interest in making setup easier (UK GDPR Article 6(1)(f); PDPA section 24(5)). You can ask us to delete them.
Legal basis: your consent, which you give at the Agree step when you register (UK GDPR Article 6(1)(a); PDPA section 19). Rate limits and Turnstile protect sign-in on the same legitimate-interest basis as the waitlist form.
We keep your account and your business's details while the business is on Lantern, and delete them 6 months after it stops having an active listing, or sooner if you ask. What the website scan found is deleted 30 days after the scan. Translations of price list wording are kept for 365 days with no link to your business, so the same words are not translated twice.
How long we keep it
- Your waitlist entry and consent record are deleted 12 months after you signed up, or sooner if you unsubscribe.
- If you unsubscribe or withdraw your consent, we delete your entry within 7 days.
- Emails you send to [email protected] about your data are kept for 2 years after we close your request, as a record that we dealt with it, then deleted.
- The hashed IP address is deleted with your entry. Rate-limit counters are deleted automatically once their time window has passed.
- Deleted data can remain in our database backups for a short time, until those backups expire.
Who handles it for us
These companies handle data on our behalf, under contracts that only let them use it to provide their service to us.
| Company | What they do for us | Where |
|---|---|---|
| Cloudflare, Inc. | Hosting for these pages, security and bot protection (including Turnstile), and storage for our database backups and business logos (R2) | Global network; backups and logos in Asia Pacific |
| Vultr (The Constant Company, LLC) | The server that runs our database and API | Singapore |
| Coolify Cloud (coolLabs Technologies Bt.) | The tool we use to deploy and manage that server. It can access the server. | European Union |
| WorkOS, Inc. | Sign-in to the business portal (Google, Apple and email accounts). We never see your password. | United States |
| Google LLC | Business search in the business portal (Google Places): receives what you type and the listing you pick | Global network |
| PostHog, Inc. | Usage statistics for the business portal (PostHog Cloud): which setup steps are opened and finished, and where people stop. It receives internal ids only, no names, emails or phone numbers. | European Union |
| Anthropic, PBC | Reads menu photos and PDFs and translates price wording for the business portal (Anthropic API): receives the menu file or the item's words only, with nothing that names you or your business | United States |
Your data is stored on a server in Singapore. Backups are kept on that server, in our hosting provider's backups of it, and in Cloudflare R2 in Asia Pacific.
International transfers
We are a UK company. Our server is in Singapore, and some of the companies in the table above are in the European Union and the United States, so your data leaves the UK and Thailand. Each transfer is covered by the data protection terms we have with that provider. For personal data from Thailand, those terms are how we meet the PDPA's rules on sending data abroad. Email [email protected] for a copy.
Your rights
Under UK GDPR and Thailand's Personal Data Protection Act (PDPA) you can ask us to:
- give you a copy of your data;
- correct it;
- delete it;
- restrict or object to how we use it;
- send it to you in a portable format;
- stop using it, by withdrawing your consent at any time. Withdrawing doesn't affect what we did before you withdrew.
Email [email protected]. We reply within one month under UK GDPR and within 30 days under the PDPA. We may ask you to confirm the request from the address you signed up with.
How to unsubscribe or withdraw consent
Use the unsubscribe link in any email we send, or email [email protected] from the address you signed up with. Either way, we delete your waitlist entry within 7 days.
Complaints
Please tell us first at [email protected] and we will try to put it right. You can also complain to a regulator:
- UK: Information Commissioner's Office (ICO), https://ico.org.uk/make-a-complaint/
- Thailand: Office of the Personal Data Protection Committee (PDPC), https://www.pdpc.or.th/
Age
The waitlist is for adults. If you are under 20, please don't sign up.
Changes to this notice
If we change this notice, we update the date at the top. If a change affects what you agreed to, we will email you before it takes effect.