Privacy policy
PRIVACY POLICY
THAT LAB™ / SOFTWARE, SAAS, AND THAT FLEXCIRCUIT
Last Updated: July 29, 2026
Website, Store, Membership, Company Software, SaaS, and Licensing Revision
DIGITLIGHT IT LLC, doing business as THAT LAB and THAT LAB™ (“THAT LAB,” “Company,” “we,” “us,” or “our”), operates the THAT LAB website and store, THAT LAB Maker Club, related customer and community services, That FlexCircuit, and other current or future Company downloadable software, installed software, cloud-connected software, hosted software, software-as-a-service offerings (“SaaS”), online tools, platforms, and related account, licensing, activation, validation, hosting, storage, synchronization, security, support, and update services.
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you:
• visit or interact with https://thatlabzone.com/ or any Company-operated or authorized page, subdomain, store, customer-account area, payment page, support portal, or community feature;
• purchase, renew, cancel, or otherwise manage a product, subscription, or THAT LAB Maker Club membership;
• download, install, activate, validate, update, or use That FlexCircuit or other Company Software;
• create an account for, subscribe to, access, or use a Company SaaS Service, cloud-hosted application, online tool, platform, API, storage, synchronization, or related software feature;
• communicate with us, request support, participate in a community, or otherwise interact with our products or services.
Together, these activities and offerings are referred to as the “Services.” Our store is powered by Shopify. Our software, SaaS, account, licensing, and support systems may be operated by us using third-party cloud infrastructure, currently including DigitalOcean for the That FlexCircuit licensing service. Those and other service providers may process information on our behalf as described below. Product-specific notices or Product Terms may provide additional details for a particular Software or SaaS Service, but they may not materially reduce privacy rights stated here unless permitted by law.
If there is a conflict between this Privacy Policy and our Terms of Service or product-specific terms concerning the collection, use, retention, or disclosure of personal information, this Privacy Policy controls on those privacy matters. Applicable Product Terms control the license to and authorized use of particular Software or a SaaS Service, while this Privacy Policy controls the processing of personal information associated with that product. The That FlexCircuit End User License Agreement (“EULA”) controls That FlexCircuit-specific license matters. An applicable third-party or open-source license controls the rights granted for the component governed by that license.
Please read this Privacy Policy carefully. By using the Services, you acknowledge that you have read and understand the practices described here. Where applicable law requires consent, we will request consent separately and will not treat this acknowledgment alone as consent.
1. NOTICE AT COLLECTION
Depending on how you interact with us, we may collect the following categories of personal information:
• identifiers and contact information, such as name, email address, telephone number, billing or shipping address, account identifier, customer identifier, and IP address;
• commercial and subscription information, such as products, plans, memberships, orders, transaction records, billing interval, subscription status, original enrollment and continuity information, protected-price eligibility, renewals, cancellations, refunds, payment confirmations, chargebacks, and device or user entitlements;
• account and authentication information, such as account credentials managed by the applicable account provider, purchase email, license or entitlement identifier, device authorization, and hashed activation-token information;
• device, network, and software information, such as device identifier or hash, device name, operating-system information, application version, limited device information, network address, request endpoint, and timestamps;
• licensing, validation, security, and diagnostic information, such as activation and validation results, first- and last-seen times, offline-authorization metadata, license status, rate-limit events, failed requests, integrity or suspected-tampering event codes, and time-consistency information;
• website and store activity, such as pages viewed, cart activity, cookie identifiers, browser information, and interactions with marketing or advertising features;
• communications and support information, such as support requests, messages, attachments you choose to provide, administrative messages sent to you, message-delivery or read status, and related records;
• User Content only when you intentionally send it to us or use a feature that clearly transmits it, such as providing a project, screenshot, log, or code file for support.
We use these categories to provide and secure the Services, process transactions, create and maintain subscriptions, memberships, accounts, hosted access, and license entitlements, operate Software and SaaS Services, activate and validate licensed products, issue limited offline authorization where offered, enforce plans, users, devices, storage, usage, or other disclosed limits, prevent fraud and abuse, provide support, communicate with you, comply with law, and, where permitted, improve and market our Services.
We retain information according to the criteria in Section 10. We do not retain personal information longer than reasonably necessary for the disclosed purposes, legal obligations, security, dispute resolution, and enforcement of our agreements.
We do not sell personal information for money. Certain disclosures of website or store identifiers and online activity through Shopify features, cookies, or advertising partners may be considered a “sale,” “sharing,” or use for targeted advertising under some U.S. state privacy laws. You may opt out as described in Sections 8 and 12. We do not sell Software-license data, SaaS account or operational data, security data, support data, or That FlexCircuit license-server data, and we do not use those categories for cross-context behavioral advertising.
2. PERSONAL INFORMATION WE COLLECT OR PROCESS
“Personal information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or can reasonably be linked to an individual or household. It does not include information that is lawfully treated as public information or information that has been de-identified or aggregated so that it cannot reasonably be linked to an individual.
We may collect or process the following categories, depending on your interaction with us, the features you use, your location, and applicable law.
2.1 Contact and Customer Information
This may include your name, email address, telephone number, billing address, shipping address, customer or account identifier, and other information you provide when creating an account, placing an order, subscribing, communicating with us, or requesting support.
2.2 Account and Authentication Information
This may include usernames, account preferences, security or authentication records, customer-account identifiers, purchase email, membership credentials, and other access information. Passwords for Shopify or another third-party account service are generally processed by that provider rather than stored in our license database.
2.3 Payment and Transaction Information
This may include items purchased, product and variant information, plan, quantity, billing interval, order and transaction identifiers, payment status, payment confirmation, tax information, renewal status, cancellation status, refund status, chargeback or reversal status, and transaction dates.
Full payment-card numbers and card-security codes are generally collected and processed directly by Shopify or another payment processor. We do not intentionally store full payment-card numbers or card-security codes in Company software-licensing or SaaS operational databases, including the That FlexCircuit licensing database.
2.4 Subscription, Membership, and Entitlement Information
This may include whether you have a THAT LAB Maker Club membership, a standalone That FlexCircuit Basic, Maker, or Ultimate subscription, or another Company Software or SaaS Subscription; the current product, plan, hosted service, account tier, subscription or membership status, current term, billing interval, Protected Subscription Price eligibility, continuity status, expiration or renewal information, device, user, storage, usage, or feature limits, additional quantities, and whether an entitlement is active, suspended, disabled, revoked, expired, refunded, reversed, or otherwise not in good standing.
2.5 Software, SaaS, Licensing, Account, and Activation Information
Other Company Software or SaaS Services may process product, account, entitlement, authentication, plan, user, device, hosted-access, storage, synchronization, usage, diagnostic, or security information reasonably necessary to provide the selected service. The exact categories depend on the product and features used. Before materially different personal-information collection begins, we will update this Policy or provide a product-specific notice at or before collection as required by law.
The current That FlexCircuit licensing service may process and store the following information:
• the purchase, account, or membership email used to identify an entitlement;
• an internal customer, license, product, plan, subscription, membership, or activation identifier;
• product name and internal product mapping used to match a store product to the corresponding software license;
• license status, plan, device limit, offline-access setting, expiration, creation time, and update time;
• a device identifier in hashed or otherwise protected form;
• device name, operating-system name, limited device information, and application version;
• a server-side hash of the locally stored activation token rather than the plaintext activation token;
• activation status and first- and last-seen timestamps;
• activation, validation, refresh, logout, and device-release events;
• server-signed offline-authorization metadata, including the authorized product, plan, device, issue time, permitted offline period, and applicable license expiration;
• records reasonably necessary to verify that protected local license data and server-issued authorization remain authentic and current.
That FlexCircuit may store protected licensing information locally on your computer, which may include the purchase email, activation token, device-binding information, plan, product, recent validation state, signed offline authorization, time-integrity checkpoints, and related security information. This local information is used to allow authorized operation and limited offline continuity and is not a replacement for an active qualifying subscription.
2.6 Network, Security, and Fraud-Prevention Information
The licensing and support systems may process and store:
• IP address and request-source information;
• request endpoint, date, time, and response status;
• attempted activation or validation information;
• success or failure status and neutral or internal reason codes;
• rate-limit, cooldown, request-frequency, and unusually frequent-request information;
• suspected credential sharing, token misuse, unauthorized device use, circumvention, cracking, tampering, protected-data modification, or automated-request information;
• device, operating-system, application-version, integrity, certificate, signature, and time-consistency information associated with a security event;
• observed, expected, local, server, or checkpoint time values reasonably necessary to investigate time manipulation or a false-positive time mismatch;
• support-review, reset, exception, and resolution records.
A temporary technical restriction may be associated with an account, email address, license, SaaS account, device, activation record, IP address, or request source. The purpose is to secure the applicable software, SaaS, licensing, or support service and investigate abuse or technical errors, not to use operational or license data for advertising.
2.7 Support, Messaging, and Communications
We collect information you provide when you email, call, or otherwise communicate with us. If the Software includes a support-messaging feature, we may process message content, title, time, license or device identifiers, message direction, delivery or read acknowledgment, and reset history. The support-message database may use license and device identifiers rather than repeating your email in every message record, but the message may still be linkable to your customer or license record through our internal systems.
Do not send passwords, full payment-card numbers, private cryptographic keys, government identification numbers, health information, or other highly sensitive information through ordinary support messages unless we specifically request an appropriate secure method.
2.8 Website, Store, Cookie, and Usage Information
We and our providers may collect information about how you access and use the website and store, including browser type, device type, IP address, cookie or similar identifiers, referring pages, pages viewed, links clicked, cart activity, purchases, and interactions with account, advertising, or marketing features.
For desktop Software, ordinary license checks are intended to collect entitlement, device, network, security, validation, and limited operational information described in this Policy and applicable product notice. For That FlexCircuit, we do not intentionally collect the content of your locally stored circuit projects, source code, block programs, generated executables, or other local User Content through an ordinary activation or license-validation request. For a future SaaS Service, content you intentionally create, upload, store, synchronize, or process through the hosted service may necessarily be transmitted to and stored by that service as described at or before collection.
2.9 Aggregate and De-Identified Information
We may create aggregate or de-identified information for security, reliability, capacity planning, and business analytics. For example, the licensing system may maintain a rolling history of aggregate online-user counts sampled over approximately twenty-four hours. That aggregate count is not intended to identify a particular user and is maintained separately from ordinary license and support records.
Where we maintain de-identified information, we will take reasonable measures to prevent it from being re-associated with an individual, except where permitted by law to test de-identification methods or security.
2.10 Information We Do Not Intentionally Require
We do not intentionally require biometric identifiers, precise geolocation, health information, information about sexual orientation, religion, race or ethnicity, or government identification numbers to purchase, activate, or use ordinary Company Software or SaaS Services, including That FlexCircuit. Please do not provide such information unless it is genuinely necessary for a request and we have provided an appropriate method.
3. SOURCES OF PERSONAL INFORMATION
We may collect personal information from:
• you directly, including when you create an account, place an order, enter your purchase email in Software, create or upload content to a SaaS Service, send a support message, submit User Content for troubleshooting, or otherwise communicate with us;
• the website, store, Software, SaaS Service, account system, licensing service, cloud infrastructure, and your device automatically when you use relevant features;
• Shopify and payment, subscription, membership, or authorized sales channels, including through authenticated order, payment, subscription, refund, or other event notifications;
• cloud hosting, security, email, support, analytics, and other service providers acting on our behalf;
• business or marketing partners, subject to their notices and applicable law;
• public or legally available sources where reasonably necessary for security, fraud prevention, legal compliance, or dispute resolution.
4. HOW COMMERCE, SOFTWARE, AND SAAS ENTITLEMENT PROCESSES WORK
When you purchase, renew, change, cancel, refund, or otherwise manage an eligible Company Software or SaaS Subscription or qualifying THAT LAB Maker Club membership through Shopify or another authorized channel, the commerce platform may transmit an authenticated event to the applicable account, entitlement, SaaS, or licensing service. For That FlexCircuit, this event is transmitted to the licensing service described below. The event may include the customer or purchase email, order or transaction identifier, product and variant information, plan, quantity, subscription or payment status, and relevant dates.
We use that information to create, update, merge, or disable the corresponding customer account, Software license, SaaS access, membership benefit, or other entitlement; apply the correct internal product mapping; determine the applicable plan and authorized users, devices, storage, usage, features, or quantities; preserve qualifying price-protection and continuity information; and respond to later renewal, cancellation, refund, payment-failure, or chargeback events.
The applicable account, entitlement, SaaS, or licensing service does not need your full payment-card number to perform these functions. Payment authorization and storage of full card details are handled by Shopify or the applicable payment processor under its own privacy and security terms.
5. HOW THAT FLEXCIRCUIT ACTIVATION AND VALIDATION WORK
When you activate That FlexCircuit, the Software transmits the purchase or membership email and limited device and application information to our licensing service over the configured network connection. The service checks whether an eligible entitlement exists, whether the applicable plan and subscription are active and in good standing, and whether the device limit permits activation.
The client creates or stores a local activation token. The licensing server stores a cryptographic hash of that token rather than the plaintext token. The server also stores a protected or hashed device identifier and may store a human-readable device name, operating-system information, limited device information, application version, activation status, and first- and last-seen times.
During successful validation, the service may issue a digitally signed offline authorization tied to the applicable license, plan, device, activation record, token hash, issue time, subscription expiration, and authorized offline period. The Software verifies that authorization locally. Periodic validation may occur at startup, while the Software is running, when you request a refresh, or when reasonably necessary to confirm entitlement or security state.
Following a successful authenticated online validation, the current That FlexCircuit licensing model normally permits authorized offline use for up to thirty (30) consecutive days, but no later than the end of the applicable paid subscription term or another authoritative loss of entitlement. Merely reconnecting to the internet does not refresh that period; the Software must successfully complete a new authenticated validation while the applicable subscription remains active and in good standing.
The Software may use server time, system time, monotonic timing information, and protected local checkpoints to detect possible attempts to extend access by moving time backward. Ordinary travel, daylight-saving-time changes, and legitimate automatic time-zone changes are not intended violations. Material inconsistencies may produce a warning, temporary restriction, or support review.
6. HOW WE USE PERSONAL INFORMATION
We may use personal information for the following purposes.
6.1 Provide, Administer, and Fulfill the Services
This includes operating the website and store; processing orders and payments; delivering digital products; creating and maintaining accounts; administering subscriptions, memberships, plans, billing intervals, protected subscription prices, subscription continuity, device quantities, and entitlements; enabling account and customer-service features; and performing our contractual obligations.
6.2 License Creation, Activation, Validation, and Offline Continuity
This includes matching a purchase or membership to the correct That FlexCircuit plan; creating or updating a license; authorizing devices; enforcing plan, user, and device limits; validating subscription status; issuing and verifying signed offline authorization; processing logout or device release; and helping restore legitimate access after a supported technical issue.
6.3 Security, Integrity, Abuse Prevention, and Fraud Detection
This includes authenticating requests, verifying webhook signatures, protecting administrative endpoints, detecting credential sharing or circumvention, applying cooldowns and rate limits, investigating suspicious events, detecting time or protected-data manipulation, preserving evidence of security events, preventing unauthorized access, and protecting our users, systems, and rights.
6.4 Support and Communications
This includes responding to questions, troubleshooting activation and device problems, processing support resets, sending account, license, renewal, billing, download, security, and service messages, maintaining support history, and communicating changes to the Services or policies.
6.5 Business Operations and Improvement
This includes maintaining backups, measuring aggregate service availability and online capacity, debugging, improving reliability and compatibility, auditing records, training personnel, preventing repeated errors, and planning products and services. We do not use the content of local circuit projects or source code for these purposes unless you intentionally provide that content to us.
6.6 Marketing and Advertising
Subject to your choices and applicable law, we may send promotional communications and use website or store activity to measure or personalize marketing. You may unsubscribe from promotional email at any time. We may still send non-promotional communications necessary for an order, subscription, account, license, security event, or support request.
That FlexCircuit license-server data is not used for cross-context behavioral advertising and is not sold to advertisers.
6.7 Legal, Compliance, and Protection Purposes
This includes complying with tax, accounting, consumer-protection, privacy, export-control, sanctions, court, law-enforcement, and other legal obligations; responding to valid legal process; resolving disputes; enforcing the Terms, EULA, Orders, and policies; and establishing, exercising, or defending legal claims.
6.8 Legal Bases Where Required
Where laws such as the GDPR or UK GDPR apply, our legal bases may include performing a contract, taking steps at your request before entering a contract, complying with legal obligations, pursuing legitimate interests such as service security and fraud prevention, and consent where consent is required. You may withdraw consent for consent-based processing, but withdrawal does not affect prior lawful processing.
7. HOW WE DISCLOSE PERSONAL INFORMATION
We may disclose personal information only as reasonably necessary for the purposes described in this Policy, including to the following categories of recipients.
7.1 Shopify and Commerce Providers
Our store is hosted by Shopify. Shopify and connected payment, subscription, tax, fraud-prevention, customer-account, and commerce providers may process information to host the store, process transactions, manage subscriptions, prevent fraud, provide enhanced commerce features, and support customer privacy choices.
7.2 Cloud Hosting and Technical Service Providers
We use third-party infrastructure providers, currently including DigitalOcean, to host and operate the licensing service, databases, encrypted network services, and related server functions. We may also use providers for domain, content-delivery, security, backup, monitoring, email, support, and software-distribution services. These providers process information on our behalf under applicable contracts and their own legal obligations.
7.3 Professional and Business Service Providers
We may disclose information to accountants, legal advisors, insurers, auditors, consultants, and similar professionals where reasonably necessary to operate the business, comply with law, or protect legal rights.
7.4 Marketing and Advertising Partners
We may disclose website or store identifiers and online activity to Shopify features or marketing and advertising partners to measure or personalize advertising, subject to your choices and applicable law. These recipients may use information according to their own privacy notices.
We do not disclose That FlexCircuit license-server data to advertising partners for cross-context behavioral advertising.
7.5 At Your Direction or With Your Consent
We may disclose information when you direct us to do so, request an integration, authorize an agent, use a social or third-party login feature, or otherwise provide valid consent.
7.6 Affiliates and Business Transactions
We may disclose information within our corporate group or in connection with a proposed or completed merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, subject to appropriate confidentiality and legal requirements.
7.7 Legal and Safety Disclosures
We may disclose information to comply with law, regulation, subpoena, court order, warrant, or other valid legal process; protect users or the public; investigate fraud or abuse; enforce our agreements; and protect the rights, property, security, and safety of the Company, our users, service providers, or others.
We do not publicly publish customer emails, device identifiers, activation records, support messages, or license-security events as part of normal licensing operations.
8. RELATIONSHIP WITH SHOPIFY; SALE, SHARING, AND TARGETED ADVERTISING
Shopify collects and processes personal information about access to and use of the store in order to provide and improve Shopify-powered commerce services. Information submitted to the store is transmitted to Shopify and may be processed by Shopify and its providers in countries other than your country of residence.
We may use Shopify enhanced services that combine information from interactions with our store and other merchants or services. In those circumstances, Shopify may independently determine certain processing purposes and is responsible for that processing as described in Shopify’s Privacy Policy and privacy controls. Shopify’s current privacy materials and consumer controls are available at https://www.shopify.com/legal/privacy and https://privacy.shopify.com/en/.
We do not sell personal information for monetary payment. However, disclosures of online identifiers or website activity through cookies, Shopify enhanced services, or advertising partners may be considered “sale,” “sharing,” or targeted advertising under certain state laws even when no money is exchanged for the information.
Where applicable, you may opt out by using the privacy choices, cookie choices, or “Do Not Sell or Share My Personal Information” mechanism displayed on the Services, by enabling a legally recognized browser-based universal opt-out mechanism such as Global Privacy Control (https://globalprivacycontrol.org/), or by contacting us at hi@thatlabzone.com. Where required by law and technically capable of being associated with an account, we will apply a valid opt-out signal to that account as well as the browser or device that sent it.
Other than legally recognized opt-out preference signals, we do not respond to general “Do Not Track” browser signals.
The license-server categories described in Sections 2.4 through 2.7 are used for commerce fulfillment, licensing, security, support, and compliance. We do not sell those licensing records or share them for targeted advertising.
9. USER CONTENT AND LOCAL PROJECTS
As between you and the Company, you retain ownership of your circuit projects, source code, block programs, text, settings, files, and generated output, subject to third-party rights and licenses.
That FlexCircuit is designed so that ordinary project files and code are stored locally unless you choose another storage location. Ordinary licensing and validation requests do not intentionally upload the contents of those files to us.
If you intentionally send User Content to support, upload it through a feature, or otherwise transmit it to us, we may copy, process, store, and review it only as reasonably necessary to provide the requested feature, troubleshoot, secure, or support the Services, comply with law, or as otherwise disclosed at the time. We do not obtain ownership of User Content merely because you provide it for support.
You are responsible for maintaining your own backups. Do not submit another person’s personal information unless you have authority to do so.
10. RETENTION OF PERSONAL INFORMATION
We retain each category only for as long as reasonably necessary for the purpose for which it was collected, the context of our relationship, and applicable legal requirements. Retention criteria include:
• account, subscription, membership, order, refund, chargeback, tax, and transaction records may be retained for the duration of the relationship and for the period reasonably necessary for accounting, tax, consumer-protection, dispute, fraud, and legal obligations;
• customer, license, plan, entitlement, device, and activation records may be retained while the applicable account or entitlement is active and for a reasonable period afterward to support reactivation, prevent unauthorized reuse, resolve disputes, process refunds, investigate fraud or security issues, and enforce license terms;
• activation-token hashes, device hashes, security events, rate-limit records, suspicious-activity records, network addresses, and related logs may be retained according to operational and security risk, limitation periods, and legal requirements;
• support messages and attachments may be retained for as long as reasonably necessary to provide support, maintain service history, resolve disputes, improve support quality, and comply with legal obligations;
• evidence of electronic acceptance of an EULA or other agreement may be retained for contract administration, security, and evidentiary purposes;
• aggregate online-user samples used for short-term operational monitoring are currently maintained in an approximately twenty-four-hour rolling window and are excluded from ordinary customer/license backups;
• rotated backups may retain information until the applicable backup is overwritten or securely deleted under our backup schedule. A deletion request may not immediately remove information from isolated backups, but we will not restore deleted information for ordinary use and will continue to protect it until the backup expires, unless retention is legally required;
• de-identified or aggregated information may be retained longer where it is not reasonably linkable to an individual.
When information is no longer reasonably necessary, we may delete, aggregate, de-identify, or securely isolate it, subject to technical limitations and legal obligations.
Deleting or materially restricting the email, account, entitlement, device, activation, hosted-content, or operational information associated with an active Software or SaaS Subscription may make account access, hosted operation, activation, validation, synchronization, storage, offline authorization, support, or continued licensed access impossible. For That FlexCircuit, this includes the licensing functions described above. If a privacy request conflicts with an active service that requires the information, we will explain the effect and any available alternatives.
11. SECURITY
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. Depending on the system, these measures may include HTTPS or equivalent encrypted transport, cryptographic hashing of activation tokens and device identifiers, digitally signed offline authorization, access controls, administrative IP restrictions, request-size limits, rate limits, security logging, backups, key rotation procedures, and separation of certain databases or operational records.
No system is perfectly secure. We cannot guarantee that unauthorized access, loss, misuse, alteration, or disclosure will never occur. You are responsible for using accurate system time where required, keeping your account and device secure, protecting local activation data, installing security updates, and notifying us promptly of suspected compromise.
Do not send sensitive information through an insecure channel. If we become aware of a security incident requiring notice, we will provide notice and make required reports in accordance with applicable law.
12. YOUR PRIVACY RIGHTS AND CHOICES
Depending on where you reside and subject to applicable exceptions, you may have some or all of the following rights:
• Access or Know: request confirmation of whether we process your personal information and request access to categories or specific information, sources, purposes, and recipients;
• Correct: request correction of inaccurate personal information;
• Delete: request deletion of personal information, subject to legal and operational exceptions;
• Portability: request a portable copy of certain information you provided or information processed by automated means;
• Opt Out: opt out of sale, sharing, targeted advertising, or certain profiling where applicable;
• Limit: request limitation of certain uses or disclosures of sensitive personal information where applicable;
• Withdraw Consent: withdraw consent for processing based on consent;
• Appeal: appeal a decision we make concerning a qualifying privacy request where applicable;
• Non-Discrimination: receive service without unlawful discrimination for exercising a privacy right.
You may submit a request through a privacy-request or privacy-choices mechanism displayed on the Services or by emailing hi@thatlabzone.com with “Privacy Request” in the subject line. Please identify the right you wish to exercise and the email or account associated with the request.
We may verify your identity and authority before completing a request. Verification may require confirming access to the relevant email account, providing transaction information, or supplying other information reasonably necessary to prevent unauthorized access or deletion. We will not request more information than reasonably necessary for verification.
You may designate an authorized agent where permitted by law. We may require proof of the agent’s authority and may ask you to verify your identity directly.
If we deny a request in whole or in part, we will provide the reason and any available appeal instructions as required by law. To appeal, reply to our decision or email hi@thatlabzone.com with “Privacy Appeal” in the subject line.
We may retain information needed to document and honor an opt-out, prevent fraud, comply with law, complete a transaction, provide a requested service, maintain security, exercise legal rights, or satisfy another legal exception.
13. COMMUNICATION PREFERENCES
You may opt out of promotional email by using the unsubscribe link in the message or contacting us. Opting out of marketing does not prevent us from sending non-promotional communications concerning purchases, subscriptions, renewals, cancellations, refunds, account security, licenses, activation, support, policy updates, or other service matters.
You are responsible for keeping the email associated with your order, subscription, membership, and software entitlement current where the applicable service permits updates.
14. CHILDREN’S DATA
The Services are not directed to children under thirteen (13), and we do not offer direct purchases or independent software-license accounts to children under thirteen.
A minor may use the Services only through a parent, legal guardian, school, or organization that is legally authorized to provide required permissions, accept applicable agreements, and take responsibility for the use. Schools and organizations are responsible for obtaining any notices, consents, and authorizations required for their users.
We do not knowingly sell or share for targeted advertising the personal information of individuals under sixteen (16). If we learn that we collected personal information online from a child under thirteen without legally sufficient authorization, we will take reasonable steps to delete it or obtain legally required parental authorization. A parent or guardian may contact us at hi@thatlabzone.com.
15. THIRD-PARTY WEBSITES, TOOLS, PACKAGES, AND LINKS
The Services may link to or integrate with third-party websites, social platforms, software packages, Python modules, payment systems, or other tools that we do not control. This Privacy Policy does not govern a third party’s independent practices. Review the third party’s privacy and security policies before providing information or using its services.
The embedded IDE or builder tools may allow you to install or execute third-party code. Such code may access files, devices, networks, or personal information according to your computer permissions and the code’s behavior. We do not control information independently collected by a package you choose to install or code you choose to execute.
16. INTERNATIONAL DATA TRANSFERS
We and our service providers may process and store personal information in the United States and other countries. Those countries may have data-protection laws different from those in your country.
Where applicable law requires a transfer mechanism for personal information transferred from the European Economic Area, United Kingdom, Switzerland, or another jurisdiction, we will rely on an applicable adequacy decision, Standard Contractual Clauses, United Kingdom addendum or equivalent terms, consent where valid, or another legally recognized mechanism.
17. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy to reflect changes to the Services, licensing architecture, service providers, legal requirements, or our practices. We will post the revised Policy, update the “Last Updated” date, and provide additional notice where required by law.
Material changes normally apply prospectively. If a change materially affects information already collected, we will handle that information in accordance with applicable law and any additional notice or consent requirements.
18. CONTACT INFORMATION
DIGITLIGHT IT LLC
doing business as THAT LAB and THAT LAB™
110 North Akard Street, #1057
Dallas, Texas 75201
United States
Website: https://thatlabzone.com/
Email: hi@thatlabzone.com
Phone: +1 765-274-9313
For a privacy request, use the subject line “Privacy Request.”
For an appeal of a privacy-request decision, use the subject line “Privacy Appeal.”
For a security concern, use the subject line “Security Notice.”