LensLlama

LensLlama Privacy Policy

Last updated: July 29, 2026

LensLlama is operated by Foundry Lane LLC (dba LensLlama), a U.S. limited liability company based in California. We operate the LensLlama platform at lensllama.net. If you have any privacy questions, contact us at contact@lensllama.net.

Plain-language summary. LensLlama is a marketplace for independent Eyecare Professionals (ECPs) and independent optical labs. Our architecture is built on a simple rule: we do not collect, store, or transmit patient information. Not patient names, not dates of birth, not medical records, not insurance details. Orders move through our system using a LensLlama-generated order number and the technical specifications of the eyewear being made — never anything that identifies a patient. This policy describes the data we do collect from our business users, how we use it, who we share it with, and your rights.

1. What we collect

From ECPs: account information (name, professional title, email, phone); practice information (practice name, business address, business contact details); payment information for your subscription (processed by Stripe — we do not see or store your card number, only a Stripe reference); and the order data you create (prescription values, frame and lens specifications, the lab you select) — all identified by our order number, never by patient identity.

From Labs: lab account information (name, role, email, phone); lab business information (name, ship-from address, turnaround, services and capabilities); pricing data you provide; and a Stripe Connect identifier when you connect your payout account (not your banking details, which live with Stripe).

From all users: basic technical data needed to operate the platform — IP address (security and rate-limiting), browser/device type, pages visited and actions taken (product improvement), and cookies as described in our cookie banner.

Phone number. If you provide your phone number and opt in during account onboarding, we use it solely to send transactional order status text messages via our SMS provider, Twilio Inc. Your phone number is not shared with any other third party and is not used for marketing. We do not sell, rent or share mobile numbers or SMS consent with third parties or affiliates for any purpose. Message frequency varies based on your order volume. Message and data rates may apply. You can revoke consent at any time by replying STOP to any SMS, or reply HELP for support, or update your notification preferences in your account settings. This number is not monitored for replies other than STOP and HELP — for anything else, email contact@lensllama.net. The complete SMS program terms are in our SMS Terms of Use. SMS is sent to optical laboratory accounts only — see the SMS notifications disclosure for the full terms.

2. What we don't collect

By design, LensLlama never collects:

  • Patient names, dates of birth, ages, or any other patient identifiers
  • Patient medical records, examination notes, or clinical history
  • Patient insurance information (carrier, member ID, policy number)
  • Patient contact information (address, phone, email)
  • Patient SSNs, driver’s license numbers, or government IDs
  • Any data that could re-identify a specific patient

If you accidentally include patient information in a free-text field (we minimize these), we will work to remove it. Do not paste or type patient identifiers into any LensLlama form. Our forms are structured (dropdowns, enums) precisely to prevent this.

3. How we use what we collect

We use the data we collect to:

  • Provide the platform: route orders, calculate prices, generate shipping labels, process payments, deliver email notifications
  • Communicate with you: order status, billing notices, support replies, occasional product announcements
  • Improve the product (in aggregate; we do not target individuals)
  • Protect the platform: detect fraud, prevent abuse, enforce Terms
  • Comply with legal obligations

We do not sell your data. We do not use your data for advertising. We do not share your data with third parties for their marketing purposes.

4. Who we share data with

We share data only with the service providers we need to operate the platform, and only the minimum each provider needs:

ProviderWhat we sharePurpose
Stripe, Inc.Subscription billing data, payout account references, payment transaction dataPayment processing
ResendEmail content (transactional emails to ECP/lab business addresses only — never to patients)Transactional email delivery
Fly.ioApplication hosting; database is encrypted at restHosting infrastructure
ShippoECP practice address, lab business address, order number — never patient informationShipping label generation, carrier integration
SentryError logs scrubbed of personal dataApplication error monitoring
Twilio Inc.Lab business phone number and transactional message content (order number and status only — never patient information, and never to ECPs)Transactional SMS delivery to opted-in laboratory accounts

We may also disclose information to comply with legal obligations (court orders, subpoenas) or to protect the rights, property, or safety of LensLlama, our users, or the public.

5. How long we keep your data

  • Active accounts: as long as your account is active
  • Closed accounts and order records: retained 7 years after closure for tax, accounting, and legal-defense purposes, then deleted
  • Server logs: retained 90 days, then deleted

If applicable law requires longer retention (or earlier deletion), we follow the law.

6. Your rights

Depending on where you live, you may have rights to access, correct, delete, or port your data, to opt out of marketing emails (every email has an unsubscribe link), and to lodge a complaint with your data protection authority. Email contact@lensllama.net to exercise these rights; we may retain data we are legally required to keep. We honor requests within the time required by applicable law (typically 30 days).

7. Security

  • Encryption in transit: all connections use HTTPS (TLS 1.2+)
  • Encryption at rest: our database is encrypted at rest
  • Access controls: internal access is role-based and audit-logged
  • Authentication: link-based sign-in (no passwords to compromise)
  • Sessions expire after 8 hours of inactivity, with a maximum lifetime of 8 hours on a shared device or 30 days when you choose “Remember this device”
  • Rate limiting and audit logging
  • PCI: we never see or store card numbers — Stripe handles them
  • No PHI architecture: we do not collect Protected Health Information, eliminating a major class of risk

No system is perfectly secure. If we discover a security incident that affects your data, we will notify you as required by applicable law.

8. Cookies

We use minimal cookies, all described in our cookie banner: essential cookies (required for the platform to function, e.g. remembering you’re signed in) and functional cookies (remembering your preferences). We do not use advertising cookies, and we do not use third-party analytics that share data with advertisers. We never sell your cookie data.

9. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated policy here with a new “Last updated” date. Significant changes will be communicated by email.

10. Contact us

Privacy questions, data requests, or concerns: contact@lensllama.net · Foundry Lane LLC (mailing address available on request). We respond to privacy inquiries within 5 business days.

HIPAA. LensLlama does not collect, store, or transmit patient information. We are not a HIPAA Covered Entity, nor (by architectural design) a HIPAA Business Associate. If your practice handles patient PHI through other tools, those tools — not LensLlama — are governed by HIPAA.

California residents.The CCPA/CPRA provide additional rights, including the right to know, the right to delete, and the right to opt out of “sale” (which we don’t do). Email us to exercise these rights.

EU/UK residents. The GDPR and UK GDPR may apply to certain processing. Email us for GDPR/UK GDPR requests.

This is Version 1.0 of the LensLlama Privacy Policy, pending attorney review. See also our Trust page.