Skip to main contentSkip to navigation
Back to Home

Security at LemCall

Last updated: June 24, 2026

This page is maintained by LemCall to answer common security and privacy questions about the product. It describes controls that are enabled today and is not an independent certification.

Authentication

  • Email + password and Google OAuth sign-in.
  • Optional multi-factor authentication (TOTP) that organization owners can require for all members.
  • Session timeout, IP allowlists (CIDR), and personal API key controls configurable per organization under Security settings.
  • Password reset and email change flows use one-time links delivered via our transactional email provider.

Access management

  • Role-based access control with five tiers: Owner, Admin, Editor, Contributor, Customer. Permissions are scoped per organization.
  • Granular permission catalogue covering team management, billing, bookings, integrations, and audit access.
  • Admin actions and permission changes are written to an audit log that owners and admins can review and export.

Data & hosting

  • LemCall is built on Supabase (Postgres) with row-level security policies isolating each organization's data.
  • Data in transit is encrypted with TLS 1.2 or above. Data at rest is encrypted by the underlying cloud provider.
  • You can export your data at any time from your dashboard (Settings → Data export) or request deletion by contacting support.
  • Calendar integrations (Google, Microsoft) use OAuth scopes limited to the calendars you connect. Tokens are stored encrypted and can be revoked from the Integrations page.

Subprocessors

LemCall relies on the following subprocessors to operate the service:

  • Supabase — database, authentication, and edge functions.
  • Resend — transactional email delivery.
  • Google & Microsoft — only when you connect a calendar account.
  • Stripe / Paddle — only when you enable paid bookings or subscriptions.

Reporting a vulnerability

If you believe you have found a security issue, please email security@lemcall.co. Please include reproduction steps and avoid testing against other users' data. We acknowledge reports within two business days.

Shared responsibility

LemCall provides the platform controls described above. You are responsible for using them correctly — enabling MFA, scoping team permissions, reviewing integrations, and keeping account credentials confidential. See our Privacy Policy and Terms of Service for the full picture.

Encrypted in transit

TLS on every request

Unlimited team members

Flat rate, no per-seat fees

Two-way calendar sync

Google and Outlook

Timezone accurate

DST-safe slots worldwide

Live status page

Real service health

LemCall

The modern scheduling platform with flat-rate pricing. Stop paying per seat, start saving.

Built with by LemStudio

Use Cases

© 2026 LemCall by LemStudio. All rights reserved.

v2026-09-09System status