Skip to main content
Platform Review
PricingSign in
Lovable assessment

Lovable procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for Lovable
TopicPlan or tierRiskTheir wordsSource
DPA, audit rights & data residencyAll applicable tierslow Swiss Addendum: Adapts the SCCs to the revised Swiss FADP, naming the Swiss Federal Data Protection and Information Commissioner (FDPIC) as the competent authority.Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Physical Security: Data is hosted in SOC 2- and ISO 27001-certified data centers with 24/7 guards, biometric access, CCTV, and environmental safeguards. Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow UK International Data Transfer Addendum: Version B1.0, issued by the UK ICO under s119A DPA 2018. Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Security Monitoring: Real-time monitoring, centralized logging with one-year retention, and annual SOC 2 Type II audits. Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow a. " Data Protection Laws ": Collectively, (i) Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (the " GDPR "), UK GDPR and any implementing or supplementary legislation, and (ii) all U.S. federal or state privacy statutes in force during the Term together with other national laws governing the Processing of Personal Data. If the Customer is a UK entity, any reference to the "GDPR" shall be interpreted to include a reference to the UK GDPR.Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow For customers in the EEA, UK, or Switzerland, we may transfer Personal Data to the United States or other jurisdictions whose privacy laws have not been deemed "adequate" by European or Swiss authorities. Lovable safeguards these transfers through the following legally recognized mechanisms:Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslowEU Standard Contractual Clauses (SCCs): Module 2 (Controller-to-Processor) per Commission Decision 2021/914. UK International Data Transfer Addendum: Version B1.0, issued by the UK ICO under s119A DPA 2018. Swiss Addendum: Adapts the SCCs to the revised Swiss FADP, naming the Swiss Federal Data Protection and Information Commissioner (FDPIC) as the competent authoritCaptured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow EU Standard Contractual Clauses (SCCs): Module 2 (Controller-to-Processor) per Commission Decision 2021/914. Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslowWe have appointed a Data Protection Officer (DPO) that you can contact at: a. Email: dpo@lovable.dev b. Representative name: Assenteo Ltd c. EU Address: Lovable Labs AB, Regeringsgatan 25, 111 53 Stockholm, SwedenCaptured 2026-06-07Open source →Finding permalink →
Data retentionAll applicable tiersmedium We may retain indefinitely Customer Data in an anonymized and aggregated form for the purposes set out in the "Rights in Customer Data" section.Captured 2026-06-07Open source →Finding permalink →
Data retentionAll applicable tiersmedium We may also retain specific PII, after account closure or deletion requests, for fraud prevention, legal defense, or to comply with our legal obligations.Captured 2026-06-07Open source →Finding permalink →
Data retentionAll applicable tierslow System Resilience: Continuous backups with industry-standard recovery objectives designed to minimize downtime and data loss. Captured 2026-06-07Open source →Finding permalink →
Data retentionAll applicable tiersmedium We can retain PII as long as reasonably necessary to provide the Services.Captured 2026-06-07Open source →Finding permalink →
Data retentionAll applicable tiersmedium Deleted data may persist in backups for a limited time before being permanently removed.Captured 2026-06-07Open source →Finding permalink →
Data retentionAll applicable tierslow The provisions of these Terms relating to intellectual property, data rights, disclaimers, limitations of liability, indemnification, governing law, and any other terms that by their nature should survive, will continue in effect after termination of your account or these Terms.Captured 2026-06-07Open source →Finding permalink →
Data retentionAll applicable tierslowCookie-derived identifiers are retained only for the period necessary to fulfil the purposes above and never longer than thirteen (13) months for analytics cookies after which they are deleted or irreversibly anonymized.Captured 2026-06-07Open source →Finding permalink →
Data retentionAll applicable tierslowLog data is retained for up to ninety (90) days, unless required by law, to monitor performance, troubleshoot issues, and improve user experience.Captured 2026-06-07Open source →Finding permalink →
Data retentionAll applicable tierslow to meet record-keeping, accounting, and audit requirements.Captured 2026-06-07Open source →Finding permalink →
Data retentionAll applicable tierslow Resolving disputes or enforcing agreements. Customer data is retained for up to ninety (90) days, unless required by law, after which it is deleted or isolated. To cancel your account or request data deletion, contact us as outlined in the Policy. Upon account termination or expiration (including forfeiture of unused Credits as per the Terms), we will delete your Personal Data within 30 days, except for data required for fraud prevention, legal compliance, or legal defense purposes. Backups may retain data for up to 90 days. To request deletion, contact us at privacy@lovable.dev ; we comply with Data Protection Laws (e.g., GDPR erasure rights). We retain Customer Data only as needed to provide the Services, with deletion available upon request (subject to backups and legal holds).Captured 2026-06-07Open source →Finding permalink →
Data retentionAll applicable tiersmedium Usage Data and anonymized or aggregated information may be retained indefinitely.Captured 2026-06-07Open source →Finding permalink →
Data retentionAll applicable tiersmedium We retain Personal Data only as long as necessary to fulfill the purposes outlined in this Policy or as required by applicable law, including:Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslowOpt-out of sales, sharing, or targeted advertising: Opt out of the sale or sharing of personal information. Lovable does not sell or share personal information as defined under U.S. privacy laws.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow All sub-processors are bound by contractual obligations equivalent to those in our DPAs, ensuring compliance with Data Protection Laws. We provide notice of sub-processor changes, allowing customers to object within ten (10) business days. The current list of authorized sub-processors is available at https://trust.lovable.dev and includes the sub-processor's name, location, and processing purpose. We do not sell your Personal Data.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium If an Integration is connected via MCP Server to permit data to be accessed, Lovable may receive information that the Integration makes available through the API to facilitate the integration. Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Necessary to protect our rights, reputation, property, or those of our users, affiliates, or the public.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow The Personal Data required to fulfil the domain purchase will be clearly indicated to you during the purchase flow. Any additional data fields not marked as required are voluntary. Your Personal Data may be shared with:Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmediumYour Personal Data may be shared with: The applicable registry operator; ICANN; Any ICANN-authorised escrow service provider; and Other third parties as required or permitted by applicable ICANN policies or lawCaptured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Certain Infrastructure Providers may have the right under their own terms to use aggregated or anonymized usage data derived from your activity for their own business purposes. By using the Services, you acknowledge and agree to those providers’ rights.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Data Handling For Domain Name Registrars : Lovable provides domain registrations through cooperation with domain name registrars subject to the Domain Name Registration Terms. To provide domain registrations Lovable may process your Personal Data to: Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Data Handling In Integrations and App Connectors : Our Services allow users to send and receive Personal Data from third-party services (which we refer to as ' Integrations '). Integrations are applications or platforms that integrate with Lovable via API Connectors or using a Model Context Protocol for chat connectors (' MCP Server '). Once an API connection is enabled, the provider of an Integration may share certain information with Lovable. For example: Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium the AI Gateway (via Third-Party AI Providers such as OpenAI, Google, or OpenRouter); orCaptured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow Your interactions with Third-Party Services are governed by their own privacy policies and terms. We encourage you to review those policies before providing Personal Data, as Lovable is not responsible for the privacy or security practices of external sites or integrations.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow"Infrastructure Provider(s)" means third-party providers of hosting, database, storage, networking, or related infrastructure services we use to provide Lovable Cloud (for example, Supabase). "Lovable Cloud" means our optional cloud hosting and back-end environment, which may include database hosting, authentication, file and object storage, and API endpoints. Lovable Cloud is provisioned on third-party infrastructure (currently Supabase)Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmediumBy using Lovable Cloud, you consent to the transfer, storage, and processing of your Customer Data by Supabase under their privacy policy (available at supabase.com/privacy ).Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslowWe engage third-party sub-processors to support our Services, such as: Hosting and maintaining our platform, website, and databases. Processing payments through secure third-party payment processors. Providing technical support, customer service, and analytics. Storing and securing data, including integrations with Supabase and GitHub. All sub-processors are bound by contractual obligations equivalent to those in our DPAs, ensuring compliance with Data Protection Laws. We provide notice of sub-processor changes, allowing customers to object within ten (10) business days. The current list of authorized sub-processors is available at https://trust.lovable.dev and includes the sub-processor's name, location, and processing purpose. We do not sell your Personal Data.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow "Lovable Cloud" means our optional cloud hosting and back-end environment, which may include database hosting, authentication, file and object storage, and API endpoints. Lovable Cloud is provisioned on third-party infrastructure (currently Supabase).Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow"Third-Party AI Provider(s)" means external providers of artificial intelligence models or related services that you can access through the AI Gateway (for example, OpenAI, Google, or OpenRouter).Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow As a data processor, Lovable processes Personal Data on behalf of our customers in accordance with their instructions and applicable DPAs. We engage third-party sub-processors to support our Services, such as:Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow Disclosures will comply with Data Protection Laws and be limited to what is necessary.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Legal Obligations: We retain and disclose information as necessary to comply with bookkeeping rules, export-control and sanctions regulations, court orders, or other legal duties. Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Necessary to comply with a valid legal process or governmental request (e.g., subpoena, court order, or law-enforcement demand) and, unless legally prohibited, Lovable will notify the affected customer before producing data. Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium You consent to certain data being transferred to ICANN (as described in the ICANN Privacy Policy ) and to other third parties as described; and, Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium When an Integration is enabled via API, Lovable is authorised to connect and access data made available to it in accordance with our agreement with the provider of the Third-Party Service and any permission(s) granted by the Customer. Lovable may receive whether you successfully authenticated with an Integration and your usage of the functionality.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Lovable may investigate and disclose information, as permitted by law, if we believe in good faith that such action is:Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Other third parties as required or permitted by applicable ICANN policies or law.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow "Infrastructure Provider(s)" means third-party providers of hosting, database, storage, networking, or related infrastructure services we use to provide Lovable Cloud (for example, Supabase).Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow Staff & Vendor Oversight : All employees pass background checks, sign confidentiality agreements, and receive yearly security training; sub-processors are vetted and contractually bound to equivalent protections. Captured 2026-06-07Open source →Finding permalink →
Tier differencesAll applicable tierslow Free Credits: We may grant Free Credits (for example, $25/month for Lovable Cloud and $1/month for the AI Gateway).Captured 2026-06-07Open source →Finding permalink →
Tier differencesAll applicable tierslow "Paid Cloud Credits" means Lovable Cloud Service Credits you purchase through the Site or otherwise and use for running your applications with Lovable Cloud feature enabled.Captured 2026-06-07Open source →Finding permalink →
Tier differencesAll applicable tierslow Paid Cloud Credits: You can buy Paid Cloud Credits anytime. Paid Cloud Credits don't earn interest and have no cash or stored-value equivalent.Captured 2026-06-07Open source →Finding permalink →
Tier differencesAll applicable tierslow "Paid Credits" means Lovable Application Credits you purchase through the Site or otherwise and use for your requests in Lovable chat. Captured 2026-06-07Open source →Finding permalink →
Tier differencesAll applicable tierslow Free Credits: Daily Free Credits are granted to users daily or on a specific schedule according to their plan and agreement automatically. Daily Free Credits expire at the end of the day and do not roll over. Promotional Free Credits expire at the end of each monthly billing cycle and do not roll over.Captured 2026-06-07Open source →Finding permalink →
Tier differencesAll applicable tiersmedium may be limited to specific Services (for example, only the AI Gateway);Captured 2026-06-07Open source →Finding permalink →
Tier differencesAll applicable tierslow Lovable Cloud and the AI Gateway run on Cloud Credits. You have two separate balances - one for Lovable Cloud and one for the AI Gateway. Cloud Credits are consumed as you use those Services and are in addition to any Platform subscription fees.Captured 2026-06-07Open source →Finding permalink →
Tier differencesAll applicable tierslow "Free Credits" means promotional or trial credits we grant you (for example, $25 per month for Lovable Cloud and $1 per month for the AI Gateway).Captured 2026-06-07Open source →Finding permalink →
Tier differencesAll applicable tierslow "Credits" means the prepaid, non-refundable, non-redeemable units you purchase or receive to use the Services. Credits are consumed as you use the Platform, Lovable Cloud, the AI Gateway, or other usage-based features.Captured 2026-06-07Open source →Finding permalink →
Tier differencesFreemediumPlease note: This Privacy Policy applies to Free and Pro plans. This does not include Business and Enterprise plans which are governed by our terms and Data Processing Agreement found here .Captured 2026-06-07Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.