Lazlo
Legal

Privacy Policy

Last updated: 10 June 2026

This Privacy Policy explains how Oshi Group Ltd (“Oshi Group”, “we”, “us”, “our”) collects, uses, shares and protects personal data when you use Lazlo (the “Service”) and our website. We are committed to handling your data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who we are

The data controller is Oshi Group Ltd, a company registered in England and Wales (Companies House No. 16129680), with registered office at Nightingale House, 46–48 East Street, Epsom, Surrey KT17 1HQ, United Kingdom. Oshi Group is VAT registered. For any privacy question, or to exercise your data-protection rights, contact us at support@oshigroup.co.uk.

2. The data we process

Lazlo is a unified analytics platform. To provide it, we process the following categories of data:

  • Account & authentication data — your name, business name, email address and the credentials and access tokens needed to sign you in and to maintain your authorised connections. Access tokens for connected channels are encrypted at rest.
  • E-commerce & advertising data — when you connect a channel, we access (on a read-only basis, via that platform's authorised OAuth flow) order, product, fee, cost, inventory, payout and ad-spend data from your connected accounts. We do not place orders, move stock or initiate payouts.
  • Usage & technical data — log data, device/browser information and basic analytics needed to operate and secure the Service.
  • Communications — the content of messages you send us by email, phone or our contact form.

3. Connected platforms (data sources)

With your authorisation, we connect to the following third-party platforms via their official OAuth / API authorisation flows to retrieve the data described above:

  • Shopify — orders, products and store data.
  • Amazon Selling Partner (SP-API) — orders, settlements, fees and inventory.
  • Amazon Ads — advertising spend and campaign metrics.
  • Google Ads — advertising spend and campaign metrics.
  • Meta Ads — advertising spend and campaign metrics.
  • Klaviyo — email marketing metrics and attributed revenue.
  • Not On The High Street (NOTHS) — marketplace orders and fees.
  • ShipHero — fulfilment and inventory data.

Connections are read-only and can be revoked by you at any time, either from within Lazlo or from the connected platform's own settings. Each platform's own privacy terms continue to govern your relationship with it.

4. How and why we use it (lawful bases)

  • To provide the Service — to deliver per-tenant analytics, profit reporting, forecasting and recommendations to you: performance of a contract (UK GDPR Art. 6(1)(b)).
  • To respond to enquiries and set up trials — to take steps at your request prior to entering a contract (Art. 6(1)(b)).
  • To secure, maintain and improve the Service — our legitimate interests in running a reliable, secure product (Art. 6(1)(f)).
  • To meet legal and accounting obligations — compliance with a legal obligation (Art. 6(1)(c)).

Your data is processed on a strictly per-tenant basis: one customer's data is never shared with, or used to serve, another customer.

5. Sharing & sub-processors

We do not sell your data. We share it only with service providers who process it on our behalf under contract, to operate the Service:

  • Supabase — managed database and authentication (hosted in the EU, eu-west-2 / London region).
  • Fly.io — application hosting and compute.
  • Anthropic — large-language-model processing used to generate written insights and recommendations. Only the minimum data needed for a given insight is sent, and it is not used to train third-party models.
  • Resend — transactional email delivery.

A current list of sub-processors is available on request.

6. Where your data is held & international transfers

We host and store data within the United Kingdom and the European Union. Where any data is transferred outside the UK (for example to a sub-processor), we rely on appropriate safeguards such as UK adequacy regulations or the International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses.

7. Retention

We keep personal data only for as long as necessary for the purposes above, to comply with legal and accounting obligations, and to resolve disputes. When you close your account, you may ask us to export or delete your data — see our Data Deletion page.

8. Security

We use appropriate technical and organisational measures — including encryption in transit and at rest, encrypted storage of connection tokens, and tenant-level access controls — to protect personal data against unauthorised access, loss or disclosure.

9. Your rights

Under UK GDPR you have the right to access, rectify, erase, restrict or object to the processing of your personal data, and the right to data portability. To exercise any of these rights, email support@oshigroup.co.uk and we will respond within one month. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk, though we would welcome the chance to address your concern first.

10. Data deletion

You can request deletion of your account and associated data at any time. Full instructions, including what is deleted and the timeframe, are on our Data Deletion page.

11. Cookies

This website uses only cookies and similar technologies that are strictly necessary to operate the site and keep you signed in. If we introduce analytics or marketing cookies, we will request your consent and update this policy.

12. Children

The Service is intended for businesses and is not directed at children under 16.

13. Changes

We may update this policy from time to time. We will post the revised version here and update the “last updated” date above.

14. Contact

Oshi Group Ltd, Nightingale House, 46–48 East Street, Epsom, Surrey KT17 1HQ, United Kingdom · support@oshigroup.co.uk