Legal

Privacy Policy

Last updated September 4, 2026

1. What we collect

From you (the account holder), we collect your email address, the website and backup URLs you configure, and billing information processed by our payment provider. We do not store full card numbers — those are handled directly by our payment processor.

2. What the script collects from your visitors

The LastRedirect service worker sets no cookies on your website and does not follow anyone between sites. It does report two kinds of event to us: a check-in when it installs or starts up, and a record of each failover redirect. Each of those carries the entry path of the page involved — query strings and fragments are stripped before it is stored — and from the request itself we derive a truncated IP address, a coarse location (country and city), the network operator, and the browser, operating system and device type. Full IP addresses are used only to perform the location lookup and are never stored.

This is what the per-site statistics on your dashboard are built from. These event records are deleted automatically 30 days after they are created. We do not use them for advertising, do not sell them, and do not combine them with data from other websites.

This is separate from lastredirect.com itself, which does set a few cookies of its own — see our Cookie Policy.

3. How we use account data

We use your email to send login links, billing receipts, and service notices (such as a failover being triggered on your site, if you've enabled notifications). We use your configured URLs solely to generate your install script and service worker.

4. Sharing

We share billing details with our payment processor to process subscription charges. We do not sell your data or share it with advertisers. We may disclose information if required by law.

5. Data retention

We retain account data for as long as your account is active. When you delete your account, we remove your configured websites and personal information within 30 days, except billing records we're required to retain for tax purposes.

6. Security

Nothing routes through our infrastructure during normal operation — traffic goes directly between visitors, your origin, and your backup. Account data is encrypted in transit and at rest. The script you install is downloaded once and served from your own domain: we do not host a script on your pages, so there is no third-party origin serving code to your visitors. Its filename is content-addressed and the install snippet carries a Subresource Integrity hash, so your visitors' browsers verify the file before executing it and refuse anything that does not match.

7. Your rights

You can review and update your account details from your Profile page, and delete your account and all associated data at any time from the same page. If you are in the EEA or UK, see our GDPR Policy for the full set of rights the GDPR gives you and how to exercise them.

8. Changes to this policy

We may update this policy from time to time. Material changes will be communicated by email or an in-product notice.

9. Contact

Questions about this policy can be sent to privacy@lastredirect.com.