LMT Connect Privacy Policy

LASER MARKING TECHNOLOGIES

LMT Connect Privacy Policy

Effective date: July 17, 2026
Last updated: July 17, 2026

Laser Marking Technologies, LLC (“LMT,” “we,” “us,” or “our”) provides the LMT Connect mobile application, its related machine-telemetry services, customer support features, application programming interfaces, and backend systems (collectively, “LMT Connect” or the “Service”). This Privacy Policy explains how LMT collects, uses, discloses, retains, and protects information when customers, their authorized personnel, LMT staff, machine controllers, or other approved devices use the Service.

This Privacy Policy applies to LMT Connect for Android and iOS and to the LMT Connect services operated by LMT. It does not replace the privacy terms of a customer organization that provides an account to its employees, and it does not govern an unrelated third-party website or service merely because LMT Connect links to it.

Plain-language summary

  • LMT Connect is a business and industrial support application. LMT does not sell personal information and does not use LMT Connect data for targeted or cross-context behavioral advertising.
  • The Service collects account, organization, machine, support, device, security, and machine-telemetry information needed to operate the product.
  • Machine telemetry is designed to accumulate as a lasting historical record for the customer organization and may be retained on an ongoing basis even when an individual user’s account is removed.
  • AI support requests may be processed by an AI service provider using the user’s message, recent support conversation, relevant authorized machine details, and selected image attachments.
  • Users can request account deletion in the app or through the public LMT Connect Account Deletion page.

1. Who is responsible for the information

LMT operates LMT Connect and is responsible for the information it processes for its own business purposes, such as account administration, security, customer support, warranty administration, product improvement, and legal compliance.

When an employer, customer, or other organization provides or manages an LMT Connect account, that organization may also control information associated with its users, machines, tickets, samples, and operations. Organization administrators may manage team access and may be able to view organization-owned information. In those circumstances, LMT may process information on the organization’s behalf and according to its instructions, contractual terms, and applicable law.

2. Information we collect

Account, identity, and profile information

We may collect or receive:

  • name, business email address, telephone number, physical or business address, profile image, company name, job or access role, and organization membership;
  • authentication identifiers and account status, including the identity maintained by our authentication provider, password-reset activity, approval status, and sign-in session information;
  • team invitations, machine-access grants, administrator permissions, notification preferences, appearance preferences, and offline-sync settings; and
  • account-deletion requests, request status, verification information, and any optional reason submitted with a request.

Passwords are processed through our authentication provider. LMT personnel do not need to know and should never ask a user to send a password by email or support message.

Customer organization and machine information

We may collect information supplied by the customer organization, LMT personnel, a machine builder, a connected controller, or an authorized integration, including:

  • organization name, facilities, addresses, contacts, account roles, and access relationships;
  • machine identifiers and serial numbers, model and SKU, wattage, laser source, lens size, firmware and software versions, manufacture, shipment and installation dates, machine status, notes, and configuration;
  • production-stage, shipment, service-history, warranty, maintenance, document, and machine-ownership records;
  • sample numbers, materials, applications, status, tracking information, notes, due dates, and associated machine or organization; and
  • subscription or entitlement status that controls access to historical telemetry or other paid features.

Machine telemetry and diagnostic information

Authorized machine controllers and clients may transmit telemetry to LMT Connect. Telemetry can include a machine or telemetry-device identifier, reading identifier, measurement timestamp, receipt timestamp, metric name or type, decimal or other metric value, unit, sensor channel, voltage, temperature, vibration, barometric pressure, power state, operating status, diagnostic information, and alert or threshold information.

Telemetry is primarily industrial and operational data. It may nevertheless be associated with a customer organization, facility, machine, account, support event, or authorized user and may therefore be treated as personal information where required by applicable law. LMT Connect accepts current and older readings, including out-of-order backfill, so the historical record can be complete.

Live telemetry may be available to authorized users without a historical-data subscription. A subscription or other entitlement may control a customer’s ability to view, graph, or export historical telemetry. That entitlement affects feature access; it does not necessarily stop the collection or retention of telemetry generated by an authorized machine.

Support, chat, and user-provided content

When a user requests support or communicates through LMT Connect, we may collect ticket titles and descriptions, issue type, priority, ticket status, chat messages, troubleshooting history, callback or escalation requests, staff responses, AI responses, citations, feedback, and related machine context.

Users may choose to upload photographs, screenshots, videos, PDFs, documents, or other files from a device or camera. Uploaded content may contain personal, confidential, proprietary, or sensitive information selected by the user. Users should upload only information that they and their organization are authorized to provide and that is relevant to the support request.

Device, application, usage, and security information

We may automatically receive or generate:

  • device push-notification token, device identifier used for notification registration, operating system or platform, application version, notification-delivery status, and token last-seen or revocation information;
  • Internet Protocol address, user-agent information, request time, route or action, authentication and authorization events, rate-limit events, errors, and security or audit logs;
  • resource views, feature interactions, support-session metadata, activity events, and timestamps needed to provide, secure, diagnose, and improve the Service; and
  • locally stored settings and cached data when a user enables offline access.

LMT Connect does not include a third-party advertising SDK and does not intentionally collect an advertising identifier for advertising. The app is not designed to collect precise geolocation, address-book contacts, SMS messages, call logs, health information, or microphone recordings. If a user voluntarily includes such information in a support message or uploaded file, it will be processed as user-provided content.

Information from other sources

We may receive information from the customer’s organization, LMT sales and service staff, machine builders, authorized distributors, connected machines, Pipedrive or another customer-relationship-management system, shipping or service records, and other integrations authorized by LMT or the customer. We may combine that information with information already maintained in LMT Connect to administer access, machines, samples, support, warranty, and customer relationships.

3. Device permissions and local features

  • Camera, photos, and files: LMT Connect accesses a camera, photo, or file only when the user chooses to take or select an attachment or profile image. The selected content is uploaded only after the user takes an action that submits it.
  • Notifications: With permission, LMT Connect uses the operating system and Firebase Cloud Messaging to deliver machine, support, sample, account, or service notifications. Notification permission and individual notification categories can be changed in the app or device settings.
  • Biometric unlock: If enabled, Face ID, Touch ID, fingerprint, or another device biometric can unlock a saved LMT Connect session. Biometric templates remain under the control of the device and operating-system provider. LMT Connect receives only the result needed to determine whether the local unlock succeeded.
  • Offline access: If enabled, LMT Connect stores selected machine, ticket, sample, account, telemetry, and resource information on the device so it can be viewed without a network connection. Users can disable an offline category to clear that category’s cache. Signing out clears LMT Connect offline caches managed by the app. Device backups or operating-system behavior may be controlled separately by the platform provider.

4. How we use information

We use information to:

  • create, authenticate, approve, administer, secure, and delete accounts;
  • verify organization membership and enforce role-based and machine-specific access;
  • receive, validate, normalize, deduplicate, store, display, analyze, graph, and export machine telemetry;
  • provide live machine status, historical telemetry, alerts, predictive-maintenance features, warranty information, machine documents, and sample tracking;
  • create and manage tickets, chat sessions, uploads, escalations, service history, and customer support;
  • send requested or operational notifications and communications;
  • operate AI-assisted support, search LMT resources, suggest troubleshooting steps, and route an issue to LMT staff;
  • maintain business records, CRM synchronization, subscriptions, entitlements, customer relationships, and contractual obligations;
  • detect misuse, protect accounts and infrastructure, investigate incidents, prevent fraud, maintain audit trails, and enforce terms;
  • debug, monitor, measure, maintain, and improve the reliability, accessibility, safety, and usability of LMT Connect and LMT machines; and
  • comply with law, legal process, tax or accounting rules, and valid government requests, and establish, exercise, or defend legal claims.

Legal bases for processing

Where a legal basis is required, LMT processes information as necessary to perform a contract or provide the Service requested by the user or customer organization; for LMT’s legitimate interests in operating, securing, supporting, and improving its products and business; with consent when applicable, such as for optional device permissions; and to comply with legal obligations or protect vital and legal interests. A user may withdraw consent for an optional feature through the app or device settings, but withdrawal does not affect processing already completed and may prevent that feature from working.

5. AI-assisted support

LMT Connect may offer an AI Support Assistant. When a user chooses AI support, LMT may send the AI service provider the user’s current message, a limited recent support transcript, relevant LMT knowledge content, authorized machine identifiers and specifications, ticket context, attachment names and metadata, and up to four selected image attachments. The system is designed to exclude other customers’ private information and internal-only CRM information from customer-facing responses.

AI responses may be inaccurate or incomplete and are not a substitute for qualified LMT technical support, machine documentation, or required laser-safety procedures. LMT may retain the conversation as part of the support record and may make it available to authorized LMT staff. AI output is not used to make legal, employment, credit, insurance, or similarly significant decisions about users. Safety concerns and unresolved issues may be escalated to an LMT technician or converted into a support ticket.

6. How we disclose information

We may disclose information in the following circumstances:

Within the customer organization and LMT

Authorized organization administrators, team members, and users may access organization-owned information according to their roles and machine permissions. Authorized LMT sales, service, engineering, support, security, operations, and administrative personnel may access information when needed to operate LMT Connect, assist the customer, administer machines or warranties, investigate security issues, or perform other legitimate duties. LMT staff access is not limited by a customer’s historical-telemetry subscription when access is needed for authorized LMT work.

Service providers and integrations

We may use vendors and subprocessors to perform services for us, including:

  • Supabase for authentication, databases, real-time updates, and private file storage;
  • Railway for backend application hosting, networking, and operational logs;
  • Google Firebase for push-notification registration and delivery;
  • OpenAI for AI-assisted support and, when enabled, web search used to provide public background information;
  • Pipedrive for customer, machine, deal, sample, and service workflow synchronization;
  • email-delivery providers for invitations, password-reset messages, notifications, and requested telemetry exports;
  • Amazon Web Services or Supabase Storage for private attachments and documents, depending on the configured storage service; and
  • Apple, Google, WordPress, YouTube, and other platform or content providers when necessary to distribute the app, operate device features, or open an external resource selected by a user.

These providers may process information only as needed to provide their services to LMT, subject to their contracts, security controls, and applicable law. Some providers may independently process limited device, account, or usage information under their own privacy policies when a user interacts directly with their platform.

External billing

The current LMT Connect app does not process card payments inside the app. If LMT offers an external subscription or billing link, payment information may be collected directly by a payment processor such as Stripe. LMT would not need to receive a user’s full payment-card number, but may receive billing contact information, transaction identifiers, subscription status, and payment status needed to administer the purchased service.

Legal, safety, and business transfers

We may disclose information when we reasonably believe disclosure is required by law or legal process; necessary to protect users, LMT, a customer, or the public; needed to investigate fraud, misuse, or a security incident; or appropriate to enforce an agreement. Information may also be disclosed as part of a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of LMT’s business, subject to appropriate confidentiality and legal requirements.

7. No sale of personal information or targeted advertising

LMT does not sell personal information collected through LMT Connect. LMT does not share personal information from LMT Connect for cross-context behavioral advertising and does not use LMT Connect information to serve third-party targeted advertisements. If these practices change, we will update this Privacy Policy and provide any notice or opt-out required by applicable law before the changed practice begins.

8. Data retention

We retain information for the period reasonably necessary for the purposes described in this Privacy Policy, including to provide the Service, maintain the customer’s machine and service history, satisfy contracts, protect security, resolve disputes, and comply with legal obligations.

  • Account and profile information is generally retained while the account is active and until an authorized deletion request is completed, subject to the exceptions below.
  • Machine telemetry and related operational records are designed to accumulate from the first accepted reading and may be retained on an ongoing or permanent basis as organization-owned machine history. They are not automatically deleted merely because an individual user leaves the organization or deletes an individual account.
  • Machine configuration, warranty, service, sample, support, ticket, chat, attachment, and other business records may be retained for the customer relationship, the useful life or support life of a machine, and a reasonable period afterward.
  • Push tokens are retained while needed for notifications and are revoked or removed when invalid, disabled, signed out, or deleted through the account-deletion process.
  • Security, audit, fraud-prevention, contract, warranty, tax, accounting, and legal records may be retained for up to seven years, or longer when a specific law, dispute, litigation hold, or contractual obligation requires it.
  • Backups may retain information for a limited additional period until overwritten through the applicable backup cycle. Information retained only in backup is protected from ordinary use and restored only for continuity, disaster recovery, security, or legal needs.

When a retention period ends, LMT deletes, anonymizes, de-identifies, or aggregates information when reasonably practicable. De-identified or aggregated information that can no longer reasonably identify an individual may be retained and used for legitimate business purposes.

9. Account and data deletion

A user can request deletion in LMT Connect by opening Account, selecting Privacy & Security, and selecting Request Account Deletion. A user who cannot access the app can follow the instructions on the public LMT Connect Account Deletion page.

LMT verifies the request and targets completion within 30 days. The process deletes or de-identifies the authentication identity, profile identifiers, profile image, personal notification tokens and preferences, personal machine-access grants, organization-membership access, and other account-specific personal information not subject to a valid retention requirement.

Organization-owned machine telemetry, configuration, warranty, service, sample, support, and similar business records may remain after the individual account is removed. LMT removes or de-identifies the deleted user’s direct identifiers from those records where practicable. Records that LMT must retain for security, fraud prevention, warranty, contract, tax, accounting, or legal purposes remain access restricted and are deleted or de-identified when the applicable retention requirement ends.

LMT Connect does not currently offer a separate self-service request to delete only selected server-side data while keeping the account active. Users may still contact LMT to ask whether a specific privacy right or correction is available under applicable law.

10. Security

LMT uses administrative, technical, and physical safeguards designed to protect information. These include encrypted network transmission using HTTPS/TLS, authenticated APIs, role- and machine-based authorization, database row-level security, private storage buckets, time-limited signed file links, rate limiting, input validation, idempotency controls for telemetry, audit logging, access restrictions, and secure credential management.

No system can guarantee absolute security. Users must protect their credentials, use an appropriately secured device, avoid sharing passwords, promptly report suspected unauthorized access, and review an organization’s team access when personnel or responsibilities change.

11. User choices and privacy controls

  • Users can review and update supported profile fields within LMT Connect.
  • Organization administrators can manage team access where their role permits.
  • Users can change notification categories in the app and notification permission in device settings.
  • Users can enable or disable biometric unlock without providing biometric templates to LMT.
  • Users can enable, disable, and clear categories of offline data through the app.
  • Users can choose whether to take a photograph or select a file for upload and can deny camera or photo access in device settings.
  • Users can sign out to end the local session and clear app-managed offline caches.
  • Users can request account deletion as described above.

12. Privacy rights

Depending on where a user lives and the law that applies, the user may have the right to request access to personal information, correction of inaccurate information, deletion, a portable copy, restriction of processing, objection to certain processing, withdrawal of consent, or an explanation of the categories of information collected and disclosed. Some jurisdictions also provide rights to opt out of the sale or sharing of personal information, targeted advertising, or certain profiling. LMT does not currently engage in those sale, sharing, or targeted-advertising activities through LMT Connect.

To submit a privacy request, email sales@lmtgrp.com with the subject LMT Connect privacy request. Include the account email, company name, state or country of residence, and the specific request. Do not include a password, full payment-card number, government identification number, or other unnecessary sensitive information.

LMT may need to verify identity, authority, account ownership, and organization relationship before completing a request. An authorized agent may submit a request where permitted by law, but LMT may require proof of authorization and direct verification with the user. We will respond within the time required by applicable law and will explain if an exception applies. Users may appeal a denied request by replying to LMT’s decision and stating that they wish to appeal. LMT will not discriminate against a user for exercising an applicable privacy right.

If information is controlled by the user’s employer or customer organization, LMT may refer the request to that organization or require its instructions. Users in the European Economic Area or United Kingdom may also lodge a complaint with their local data-protection authority. Users elsewhere may contact the privacy regulator or attorney general applicable to their location.

13. International processing

LMT is based in the United States, and LMT Connect information may be processed in the United States or another country where LMT or its service providers operate. Those countries may have privacy laws different from the user’s home jurisdiction. Where required, LMT uses contractual or other lawful safeguards intended to protect information transferred across borders.

14. Children’s privacy

LMT Connect is a business application for authorized personnel who work with customer organizations and industrial equipment. It is not directed to children under 18, and LMT does not knowingly collect personal information from children through LMT Connect. If a parent, guardian, or organization believes a child has provided personal information, contact LMT so we can investigate and take appropriate action.

15. Third-party services and links

LMT Connect may open manuals, videos, websites, payment pages, email applications, telephone applications, app-store pages, or other third-party resources. A third party’s collection and use of information is governed by that third party’s privacy policy and settings. LMT is not responsible for the privacy practices of an unrelated third party.

16. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in LMT Connect, service providers, legal requirements, or business practices. The revised policy will be posted at this URL with a new “Last updated” date. If a change materially affects how we use personal information, we will provide additional notice when required by law, such as through LMT Connect, email, or an account notification.

17. Contact LMT

Questions, concerns, complaints, and privacy requests may be directed to:

Laser Marking Technologies, LLC
Attn: LMT Connect Privacy
1101 W. Sanilac Rd.
Caro, MI 48723
United States

Email: sales@lmtgrp.com
Telephone: +1 (989) 673-6690
Account deletion: LMT Connect Account Deletion