Varc Privacy Policy
How Latticewell Labs Ltd handles personal data in connection with Varc.
Last updated: 15 September 2026
This Privacy Policy explains how Latticewell Labs Ltd (“Latticewell”, “we”, “us” or “our”) collects, uses and protects personal data when you use https://varc.dev, the Varc application, contact us, purchase Varc or otherwise interact with our services.
1. Who is responsible for your data
Latticewell Labs Ltd is the controller of personal data covered by this policy, except where another organisation acts as an independent controller for its own purposes. For example, Paddle acts as an independent controller for personal data it processes as Merchant of Record for Varc transactions.
2. What this policy covers
This policy covers personal data we process through the Varc website, software, licensing and support channels. It does not govern data processed independently by third-party services that you choose to use with Varc.
3. Data we may collect
3.1 Account, contact and support information
When you contact us, request support, join a mailing list, create an account where applicable, or otherwise communicate with us, we may collect your name, email address, organisation, the content of your messages and information you choose to provide.
3.2 Purchase and update renewal information
When you purchase Varc or an optional update renewal through Paddle, Paddle processes the payment as Merchant of Record. We may receive transaction and licence information needed to provide the product, such as customer identifiers, email address, product or plan, transaction status, update coverage dates, country or tax-related information made available to us, and refund or chargeback status. We do not receive or store your full payment-card details from Paddle.
3.3 Licence and device information
Where needed to activate, secure or manage Varc licences, we may process information such as licence identifiers, app version, operating-system information, device characteristics and device or installation identifiers. We use this information to deliver entitlements, prevent misuse and support compatible software releases.
3.4 Website and technical information
When you visit our website or online services, standard technical data may be generated, such as IP address, browser or device type, requested pages, timestamps, referring page and server-security logs. We use this information to operate, secure and understand our services.
3.5 Diagnostics and product telemetry
Varc may offer diagnostics, crash reporting or usage telemetry. Where these features are enabled, the data may include app version, operating system, error information, performance information, feature interactions and technical identifiers. We aim to avoid collecting database contents, credentials or secrets through diagnostics and will provide controls or consent where required by law.
3.6 Redis, Valkey and other database content
Varc is primarily a local desktop application. Merely connecting Varc to a Redis or Valkey server does not mean that Latticewell receives the server’s database contents or your connection credentials. Database data is ordinarily processed on your device.
If you deliberately use a feature that sends information to a remote service, export information, attach diagnostic material to a support request, or connect Varc to a third-party provider, the information you choose to send may be processed by that service for the requested purpose. Varc will identify remote features where reasonably necessary.
3.7 Cookies and similar technologies
Our website may use cookies or similar technologies that are necessary for security, preferences or core functionality. If we use non-essential analytics or marketing technologies, we will provide any consent mechanism required by applicable law.
4. How we use personal data and our legal bases
We process personal data for the following purposes:
- to provide Varc, licence entitlements, account functions and customer support — generally because processing is necessary to perform a contract or take steps at your request;
- to operate, secure, maintain and improve our software, website and infrastructure — generally based on our legitimate interests in running and protecting our business and services;
- to prevent fraud, abuse, licence misuse and security incidents — generally based on our legitimate interests and, where applicable, legal obligations;
- to manage purchases, optional update renewals, refunds, accounting, tax and business records — because this is necessary to perform contracts and comply with legal obligations;
- to send service communications, security notices and important product information — to perform our contract or pursue legitimate interests; and
- to send optional marketing communications where permitted — based on consent where consent is required, or another lawful basis where applicable.
5. Paddle and payment processing
Paddle is the Merchant of Record for Varc purchases processed through Paddle. Paddle determines how it processes payment, fraud-prevention, tax, invoicing and transaction data for its own purposes, and Paddle and Latticewell act as independent controllers for the buyer data each holds.
You can read Paddle’s privacy notice at paddle.com/legal/privacy.
6. Who we share personal data with
We may share personal data where reasonably necessary with:
- Paddle and other transaction or commerce partners involved in fulfilling purchases;
- hosting, infrastructure, email, support, security, diagnostics or analytics providers that help us operate Varc;
- professional advisers such as accountants, insurers, auditors and legal advisers;
- law-enforcement, regulators, courts or other authorities where disclosure is legally required or reasonably necessary to protect rights, users or systems; and
- a buyer, investor or successor in connection with a proposed or completed merger, financing, reorganisation, sale or transfer of all or part of our business, subject to appropriate confidentiality and data-protection safeguards.
We do not sell personal data.
7. International transfers
Some service providers may process personal data outside the United Kingdom. Where a transfer requires safeguards under applicable data-protection law, we use an available lawful transfer mechanism, such as an adequacy regulation or appropriate contractual safeguards.
8. How long we keep personal data
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including to provide the service, maintain security, resolve disputes and meet legal, tax and accounting obligations. Retention periods vary by data type. Transaction and business records may be retained for several years where required by law; support and technical data are generally kept for shorter periods unless needed for an ongoing issue, security investigation or legal claim.
9. Security
We use technical and organisational measures intended to protect personal data against unauthorised access, alteration, loss or disclosure. No system can be guaranteed completely secure, so you should also protect your devices, credentials and API keys.
10. Your data-protection rights
Depending on where you live and the circumstances of our processing, you may have rights to request access to your personal data, correction, deletion, restriction, objection, and data portability. Where we rely on consent, you may withdraw that consent at any time without affecting processing that was lawful before withdrawal.
Some rights are subject to legal conditions or exemptions. We may need to verify your identity before acting on a request.
11. Right to object
Where we process personal data on the basis of legitimate interests, you have the right to object in circumstances provided by data-protection law. You also have the right to object at any time to processing for direct marketing.
12. Complaints
We would appreciate the opportunity to resolve privacy concerns directly. You also have the right to complain to a data-protection authority. In the United Kingdom, the supervisory authority is the Information Commissioner’s Office (ICO).
ICO information is available at ico.org.uk.
13. Children
Varc is a professional developer tool and is not directed to children. We do not knowingly collect personal data from children where doing so would require parental consent.
14. Changes to this policy
We may update this Privacy Policy when our products, providers or legal obligations change. The latest version will be published on our website with its updated date. Where a change is material, we will provide additional notice where appropriate.
Contact details
Company: Latticewell Labs Ltd
Company number: 17420726
Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
Email: support@varc.dev
Website: https://varc.dev