Privacy Policy
Last updated: May 29, 2026
Overview
This Privacy Policy explains how Bag of Holding, Inc. d/b/a Lark (“Lark,” “we,” “us,” “our”) collects, uses, and shares information when you use our website, APIs, SDKs, and services (collectively, the “Services”).
Important distinction: This policy covers two types of data:
1. Account Data — Information about you as a Lark customer
2. Customer Data — Data you and your End Users store in Lark databases
We treat these differently, as explained below.
1. Account Data We Collect
When you sign up for Lark or use our website, we collect:
Information You Provide
- Account information: Name, email address, company name, and account metadata entered on the Dashboard (such as names of projects and databases, project rules, etc.)
- Payment information: Payment is processed by Polar. We do not directly store your credit card number or payment credentials. See Polar’s Privacy Policy.
- Communications: Messages you send to our support team
Information Collected Automatically
- Usage data: API calls, feature usage, error logs
- Device information: Browser type, operating system, IP address
- Cookies and similar technologies: Session cookies, analytics (see Cookie section below)
2. Customer Data
What is Customer Data?
Customer Data is any data you or your End Users store in your Lark databases. This may include personal information about your End Users.
Our Role
You are the data controller for Customer Data. You determine what data to collect and how to use it.
We are the data processor. We only process Customer Data as necessary to provide the Services to you, in accordance with your instructions.
What We Don’t Do With Customer Data
We do not:
- Access Customer Data except as necessary to provide the Services, respond to support requests, or comply with law
- Sell Customer Data to third parties
- Use Customer Data for advertising
- Mine Customer Data for insights unrelated to providing the Services
Your Responsibilities
As the data controller, you are responsible for:
- Providing privacy notices to your End Users
- Obtaining necessary consents for data collection
- Responding to End User data subject requests
- Ensuring your use of the Services complies with applicable privacy laws
3. How We Use Account Data
We use Account Data to:
- Provide, maintain, and improve the Services
- Process payments and send billing communications
- Send service-related communications (e.g., maintenance notices, security alerts)
- Respond to your support requests
- Analyze usage to improve the Services
- Detect and prevent fraud or abuse
- Comply with legal obligations
We will not send you marketing emails unless you opt in.
4. How We Share Information
Service Providers
We share information with third parties who help us provide the Services:
| Provider | Purpose | Location |
|---|---|---|
| DataBank | Infrastructure | United States |
| Google Cloud | Infrastructure | United States |
| Cloudflare | Infrastructure | United States |
| Polar | Payment processing | United States |
| BetterStack | Usage analysis and logging | United States |
| Resend | Transactional email | United States |
We require service providers to protect your information and use it only for the purposes we specify.
Legal Requirements
We may disclose information if required by law, legal process, or government request, or to protect the rights, property, or safety of Lark, our users, or others.
Business Transfers
If Lark is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
With Your Consent
We may share information with your consent or at your direction.
5. Data Location and Transfers
Where Data is Stored
Customer Data is stored in the United States. We may add additional regions in the future.
Account Data is processed in the United States.
International Transfers
If you are located outside the United States, your information will be transferred to and processed in the United States. By using the Services, you consent to this transfer.
For users in the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on Standard Contractual Clauses or other lawful transfer mechanisms.
6. Data Retention
Account Data
We retain Account Data for as long as your account is active, plus a reasonable period afterward for legal and business purposes (typically 2 years after account closure).
Customer Data
We retain Customer Data for as long as your account is active. Upon account termination or data deletion, we will delete Customer Data from our production systems. Customer Data may persist in our backups for up to 30 days after deletion.
Deletion Requests
You can delete your data at any time through the dashboard or by contacting [email protected].
7. Data Security
We implement appropriate technical and organizational measures to protect your information, including:
- Encryption in transit (TLS) and at rest
- Access controls and authentication
- Regular security assessments
- Incident response procedures
No system is perfectly secure. If we become aware of a security breach affecting your data, we will notify you in accordance with applicable law.
8. Your Rights
Depending on your location, you may have certain rights regarding your personal information:
All Users
- Access: Request a copy of your Account Data
- Correction: Update inaccurate information
- Deletion: Request deletion of your account and associated data
- Export: Export your data in a portable format
EEA, UK, and Swiss Users (GDPR)
You also have the right to:
- Object to processing based on legitimate interests
- Restrict processing in certain circumstances
- Withdraw consent (where processing is based on consent)
- Lodge a complaint with a supervisory authority
California Users (CCPA)
You have the right to:
- Know what personal information we collect and how we use it
- Request deletion of your personal information
- Opt out of the sale of personal information (we do not sell personal information)
- Non-discrimination for exercising your rights
To exercise these rights, contact us at [email protected], subject line “CCPA Request”.
9. Cookies and Tracking
What We Use
| Type | Purpose | Duration |
|---|---|---|
| Session cookies | Authentication, security | Session |
| Preference cookies | Your settings | 1 year |
| Analytics | Usage analysis | Up to 2 years |
Analytics
We use analytics tools to understand how the Services are used. This helps us improve the product. We currently use:
- BetterStack — Product analytics and logging (Privacy Policy)
We do not use advertising trackers or sell data to advertisers.
Your Choices
Most browsers allow you to block or delete cookies. Note that blocking cookies may affect the functionality of the Services.
10. Children’s Privacy
The Services are not intended for children under 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected such information, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on our website
- Updating the “Last updated” date at the top
- Sending you an email (for material changes)
Your continued use of the Services after the effective date constitutes acceptance of the updated policy.
12. Contact Us
For questions about this Privacy Policy or to exercise your privacy rights:
Email: [email protected]
For data protection inquiries in the EEA, you may also contact:
Data Protection Officer: [email protected]
