Layer7 Technologies Inc.
Layer7 Privacy Policy
Last updated 2 September 2026
This Privacy Policy explains how Layer7 Technologies Inc. ("Layer7", "we", "us", "our") handles personal data. It covers the Layer7 service at l7.gg and the dashboard at dash.l7.gg.
We have tried to write this plainly, because a privacy policy is not much use if you cannot tell what it actually says.
Two different roles
There are two kinds of data involved when you use Layer7, and we play a different role for each.
For your account data, the information about you as a Layer7 customer, we are the controller. This policy describes what we do with it.
For the traffic that flows through us to reach your sites, which includes information about your own visitors, you are the controller and we are your processor. We handle that data to give you the filtering you signed up for, under our Data Processing Addendum. If you are a visitor to a site protected by Layer7 and you have a question about your data, the right people to ask are the operators of that site, because they decide why your data is collected. We describe visitor data below so you can see what passes through us, but we act on the site operator's instructions, not our own.
What we collect, and why
Information you give us when you sign up
To create an account you give us your email address, your first and last name, and a password. We store your password only as a salted hash (PBKDF2-SHA256), never in plain text, so we cannot see or recover it. We record when you registered.
We do not collect a postal address or phone number at signup, and although older fields for those exist in our database, they are left empty.
Fraud screening at signup
When you sign up, we send your email address and the IP address of the signup to FraudLabs Pro, a fraud-screening service, and we store the risk score and status it returns. We do this to keep abusive and fraudulent signups off the platform. We do not store the signup IP address ourselves; it is sent to FraudLabs for the check.
Billing information
When you buy a paid plan, payment is handled by Stripe. We create a customer record with Stripe using your name, email, and an internal account id, and we keep the resulting Stripe customer id, your balance, your invoices, and your transaction history. Your card details are entered directly into Stripe's own checkout and never pass through or get stored by Layer7.
Support tickets
If you contact support, we keep your messages, the subject and body of your tickets, and any files you attach. To help us respond faster, the subject and body of a ticket may be passed to an AI model, run by Cloudflare, that suggests a category or a draft reply. That processing is for triage only.
Security and account activity
We keep a tamper-evident audit log of security-relevant and configuration actions on your account, such as changing a setting, enrolling or removing a second factor, or editing a rule. Those log entries include the IP address and country the action came from. This log exists to protect your account and to let us investigate abuse, and because its integrity matters, it is kept on a long-term basis and is not edited or deleted in the normal course. We do not keep a separate log of ordinary logins, and we do not store your browser's user-agent in the dashboard.
Traffic that passes through Layer7 (visitor data)
When a visitor loads a site you protect, their request reaches our edge first. To decide whether it is legitimate, we look at signals such as the visitor's IP address, the requested URL and headers, the user-agent and client-hint headers, a TLS or JA4-style connection fingerprint, and the approximate country of the connection. Most of this is used in the moment, in memory, to make a filtering decision, and is not written down.
Some of it is recorded so you can see what is happening to your site and so we can investigate attacks. We keep a sample of individual requests in our analytics, which can include the visitor's IP address, user-agent, URL path, and country, for up to 90 days. The dashboard shows a shorter window by default, seven days, and that view is adjustable per service. We also keep aggregated statistics about traffic and attacks, such as counts by country, network, and outcome, which are not tied to any one visitor. Separately, when a visitor is convicted during an attack, their IP address is added to a block list on your site's account for about 15 minutes and is then removed. Because you are the operator of your own sites, you can view the sampled request data for your domains, including visitor IP addresses, through the dashboard.
When a visitor is challenged and passes, we set a short-lived clearance cookie so they are not challenged again and again. That cookie and the browser storage used during a challenge are described in the next section.
The Layer7 website and dashboard
When you use the dashboard, we load Cloudflare's privacy-focused Web Analytics to understand aggregate usage. It does not use cookies to track you across sites. Web fonts on our site are served from our own domain through Cloudflare, so loading the site does not send your data to Google or other font hosts.
Cookies and local storage
The dashboard does not use cookies. It keeps your session token and, if you use the API page, an API key in your browser's local storage, so you stay signed in. It also stores small preferences there, such as which announcements you have dismissed and whether you have snoozed the two-factor reminder. None of this is shared with third parties.
On sites protected by Layer7, we may set one cookie on your visitors and use a little browser storage, purely to run the security check:
l7_auth: a short-lived, signed clearance cookie that tells our edge a visitor has already passed a check, so they are not challenged repeatedly. It is bound to a network range and to the specific protected service, is marked Secure and HttpOnly, and expires within 30 minutes. It contains no name, email, or account information.- A small amount of temporary storage used only while a challenge is being solved, which is cleared or expires on its own.
These are strictly necessary for the security service to work. They are not advertising or tracking cookies.
How we use personal data
We use personal data to provide and operate the Service, to filter attacks away from your sites, to secure and protect the platform and your account, to bill you and keep financial records, to send you service messages such as verification, security alerts, invoices, and notifications about attacks on your sites, to respond to your support requests, and to comply with the law.
We do not sell personal data. We do not share it for cross-context behavioural advertising. We do not use the traffic that passes through us to build advertising profiles.
Legal bases (for people in the EU, EEA, and UK)
Where the GDPR applies, we rely on these legal bases: performing our contract with you, to give you the Service you signed up for; our legitimate interests, mainly keeping the platform and our customers secure and preventing fraud and abuse, balanced against your rights; complying with legal obligations, such as keeping financial records; and your consent, where we specifically ask for it.
Who we share it with
We share personal data with the subprocessors we use to run the Service. The current list, with what each one does and what data it handles, is on our subprocessors page. In short, they are Cloudflare (the platform everything runs on), Stripe (payments), FraudLabs Pro (signup fraud screening), MXroute (sending our email), Backblaze (encrypted backups), and DeftForm (application forms), together with Cloudflare's Workers AI for ticket triage.
We may also disclose personal data if the law requires it, or to respond to valid legal process, to enforce our Terms and Acceptable Use Policy, or to protect the rights, safety, and property of Layer7, our customers, or the public. We require a proper legal basis before handing over customer data, and we tell affected customers where we are allowed to.
If Layer7 is ever involved in a merger, acquisition, or sale of assets, personal data may transfer as part of that, and we will make sure it stays subject to protections consistent with this policy.
How long we keep it
We keep your account data for as long as your account is open. Financial records, such as invoices and transactions, are kept for as long as tax and accounting law requires. Security audit logs are kept on a long-term basis for integrity and investigation, as described above. Sessions expire within 14 days. Sampled visitor request records in analytics, which can include IP addresses, are kept for up to 90 days, with the dashboard defaulting to a seven-day view; block-list entries created during an attack last about 15 minutes. When data is no longer needed for these purposes, we remove it, and our encrypted backups cycle out on their normal rotation.
There is currently no self-serve "delete my account" button. If you want your account and its personal data deleted, email support@l7.gg and we will handle it, subject to any records we are legally required to keep.
Your rights
Depending on where you live, you have some or all of these rights over your personal data: to access it, to correct it, to delete it, to restrict or object to how we use it, to receive a copy in a portable form, and to withdraw consent where we relied on consent. If the GDPR applies to you, you also have the right to complain to your local data protection authority, though we would appreciate the chance to sort things out first.
If you are in California, you have the right to know what personal information we collect and how we use and share it, to delete it, to correct it, and to not be discriminated against for exercising these rights. We do not sell personal information or share it for cross-context behavioural advertising, so there is nothing to opt out of on that front.
To exercise any of these rights, email support@l7.gg. We will verify who you are before acting, and we will respond within the time the law allows. If your request is about data we process on behalf of one of our customers (visitor traffic), we will pass it to that customer, who is the controller.
Security
We protect personal data with measures appropriate to the risk. Traffic and cookies are served over HTTPS. The clearance token is cryptographically signed so it cannot be forged or altered. Signing keys and service credentials are stored as platform secrets, not in our code. Access to systems is limited to authorized staff, customer accounts support two-factor authentication, and sensitive account actions require you to re-authenticate. Backups are encrypted before they leave our systems. No system is perfectly secure, but we work to keep the level of protection high and to improve it over time.
International transfers
We are based in the United States, and the Service runs mainly on infrastructure there. If you are outside the United States, your personal data will be processed in the United States and in other countries where our subprocessors operate. Where the law restricts these transfers, we rely on a lawful transfer mechanism, such as the Standard Contractual Clauses.
Children
Layer7 is a product for website and application operators. It is not directed at children, and we do not knowingly collect personal data from children under 16. If you believe a child has given us personal data, contact us and we will delete it.
Changes to this policy
We may update this policy from time to time. The "last updated" date at the top shows the current version, and if we make a significant change we will give reasonable notice, for example by email or in the dashboard.
Contact
If you have any question about this policy or your personal data, contact us:
Layer7 Technologies Inc. 1500 North Grant Street, Suite 429 Denver, CO 80302, USA
Email: support@l7.gg