Privacy Policy

Last updated: February 23, 2026 · Effective date: February 23, 2026

This Privacy Policy ("Policy") describes how Leaf Software Studio LLC ("Company," "we," "us," or "our"), operating the Leaf Software platform ("Platform," "Service"), collects, uses, discloses, and protects your personal information. This Policy applies to all users of the Platform, including visitors, free-tier users, and paid subscribers. By accessing or using Leaf Software, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree, please discontinue use of the Service immediately.

1. Definitions

"Personal Data" means any information relating to an identified or identifiable natural person, including but not limited to name, email address, IP address, device identifiers, and location data. "Processing" means any operation performed on Personal Data, whether by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, alignment, combination, restriction, erasure, or destruction. "Data Controller" means Leaf Software Studio LLC, which determines the purposes and means of processing Personal Data. "Data Processor" means any third party that processes Personal Data on behalf of the Data Controller. "Data Subject" means the identified or identifiable natural person to whom Personal Data relates. "Consent" means any freely given, specific, informed, and unambiguous indication of the Data Subject's wishes. "Cookies" means small text files placed on your device by web servers to store preferences and usage information.

2. Information We Collect

We collect the following categories of information: (a) Account & Identity Data: Name, email address, phone number, business name, job title, mailing address, username, and password hash when you register for an account. (b) Payment & Billing Data: Credit or debit card number (processed and stored by our PCI-DSS compliant payment processor, Stripe), billing address, transaction history, invoice records, subscription tier, and renewal dates. We do not store full card numbers on our servers. (c) Usage & Behavioral Data: Pages visited, features used, click patterns, search queries, session duration, frequency of use, in-app actions, and interaction with notifications and emails. (d) Device & Technical Data: IP address, browser type and version, operating system, device type and model, unique device identifiers, screen resolution, language preferences, time zone setting, and referring URLs. (e) Communications Data: Content of support tickets, chat messages, emails sent to us, feedback submissions, and survey responses. (f) User-Generated Content: Any data, files, text, images, or other content you upload to or create within the Platform. (g) Third-Party Data: Information received from third-party integrations you authorize (e.g., CRM systems, marketing platforms, social media accounts), including contact lists, engagement metrics, and profile data from those services. (h) Location Data: Approximate geographic location derived from your IP address, and precise location only if you explicitly grant permission through your device settings. (i) Cookie & Tracking Data: Information collected through cookies, web beacons, pixel tags, and similar technologies as described in Section 11.

3. How We Collect Information

We collect information through the following methods: (a) Directly from you: When you create an account, fill out forms, make a purchase, contact support, participate in surveys, or otherwise voluntarily provide information. (b) Automatically: Through cookies, server logs, web beacons, SDKs, and similar technologies when you access or use the Platform. (c) From third parties: From payment processors (Stripe), authentication providers (Google, Microsoft, GitHub OAuth), analytics services (Google Analytics, Mixpanel), advertising networks, and partner integrations you connect to your account. (d) From publicly available sources: Business directories, public social media profiles, and government records, only to the extent permitted by applicable law.

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, we process your Personal Data under the following legal bases as defined by the General Data Protection Regulation (GDPR): (a) Contractual Necessity (Article 6(1)(b)): Processing necessary to perform our contract with you, including providing the Service, processing payments, and managing your account. (b) Legitimate Interests (Article 6(1)(f)): Processing necessary for our legitimate interests, including improving the Service, preventing fraud, ensuring security, conducting analytics, and sending non-promotional service communications. We balance our interests against your rights and freedoms. (c) Consent (Article 6(1)(a)): Processing based on your explicit consent, including sending marketing communications, placing non-essential cookies, and processing special categories of data. You may withdraw consent at any time. (d) Legal Obligation (Article 6(1)(c)): Processing necessary to comply with applicable laws, regulations, legal processes, or governmental requests, including tax, accounting, and anti-money laundering obligations. (e) Vital Interests (Article 6(1)(d)): In rare circumstances, processing necessary to protect your vital interests or those of another natural person.

5. How We Use Your Information

We use the information we collect for the following purposes: (a) Service Delivery: To create and manage your account, provide access to features, process transactions, deliver customer support, and fulfill our contractual obligations to you. (b) Service Improvement: To analyze usage patterns, conduct A/B testing, diagnose technical issues, develop new features, and optimize the Platform's performance, usability, and reliability. (c) Communications: To send transactional emails (account confirmations, password resets, billing receipts), service announcements (maintenance notices, security alerts, feature updates), and — with your consent — marketing communications (newsletters, promotional offers, product recommendations). (d) Security & Fraud Prevention: To detect, investigate, and prevent fraudulent, unauthorized, or illegal activity; enforce our Terms & Conditions; protect the rights, property, and safety of our users and the Company. (e) Legal Compliance: To comply with applicable laws, regulations, legal processes, or enforceable governmental requests; to establish, exercise, or defend legal claims. (f) Analytics & Research: To conduct aggregate, anonymized, or pseudonymized analysis of usage trends, prepare internal reports, and conduct market research to better understand our user base. (g) Personalization: To customize your experience, including content recommendations, interface preferences, and targeted feature suggestions based on your usage history and preferences. (h) Billing & Financial Operations: To process subscription payments, issue invoices and receipts, manage refunds, detect payment fraud, and comply with tax and accounting obligations.

6. Information Sharing & Disclosure

We do not sell your Personal Data. We may share information in the following circumstances: (a) Service Providers: We share data with trusted third-party vendors who assist us in operating the Platform, including cloud hosting providers (AWS, Vercel), payment processors (Stripe), email delivery services (SendGrid, Resend), analytics platforms (Google Analytics, Mixpanel), customer support tools, and monitoring services (Sentry). All service providers are bound by Data Processing Agreements (DPAs) and are contractually obligated to use your data solely for the purposes we specify. (b) Business Transfers: In connection with a merger, acquisition, reorganization, bankruptcy, asset sale, or similar transaction, your data may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on the Platform of any change in ownership or uses of your Personal Data. (c) Legal Requirements: We may disclose information if required by law, regulation, subpoena, court order, or other legal process, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, the safety of others, investigate fraud, or respond to a government request. (d) With Your Consent: We may share information with third parties when you have given us explicit consent to do so, such as when connecting third-party integrations or participating in co-branded promotions. (e) Aggregated & De-identified Data: We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you, for research, analytics, benchmarking, or marketing purposes. (f) Professional Advisors: We may share information with our attorneys, accountants, auditors, and insurers as necessary for professional advice, litigation, audit, or insurance purposes.

7. International Data Transfers

Leaf Software Studio is headquartered in Miami, Florida, United States. Your Personal Data may be transferred to, stored in, and processed in the United States and other countries where our service providers maintain facilities. For transfers of Personal Data from the EEA, UK, or Switzerland to the United States or other countries not deemed to provide an adequate level of data protection, we rely on the following safeguards: (a) Standard Contractual Clauses (SCCs): We enter into European Commission-approved Standard Contractual Clauses with our data processors located outside the EEA/UK. (b) Data Privacy Framework: Where applicable, we rely on certifications under the EU-U.S. Data Privacy Framework, the UK Extension, and the Swiss-U.S. Data Privacy Framework. (c) Supplementary Measures: Where required, we implement additional technical and organizational measures, such as encryption in transit and at rest, pseudonymization, and access controls, to ensure an essentially equivalent level of protection. By using the Platform, you acknowledge and consent to the transfer of your data to the United States and other jurisdictions as described herein.

8. Data Retention

We retain your Personal Data only for as long as reasonably necessary to fulfill the purposes for which it was collected, including: (a) Active Account Data: Retained for the duration of your account and for 30 days after account deletion to allow for reactivation. (b) Billing & Transaction Records: Retained for 7 years after the last transaction to comply with tax, accounting, and financial regulatory requirements. (c) Usage & Analytics Data: Retained in identifiable form for up to 26 months, after which it is aggregated and anonymized for long-term trend analysis. (d) Communications & Support Data: Retained for 3 years after the last interaction, or longer if required for legal proceedings. (e) Security & Fraud Logs: Retained for up to 5 years for security investigation and legal compliance purposes. (f) Marketing Preferences: Retained until you withdraw consent or unsubscribe, plus a suppression record to honor your opt-out indefinitely. When data is no longer needed, we securely delete or irreversibly anonymize it using industry-standard methods. You may request earlier deletion of your data as described in Section 9.

9. Data Security

We implement comprehensive technical and organizational measures to protect your Personal Data, including: (a) Encryption: All data in transit is protected using TLS 1.2 or higher. Sensitive data at rest is encrypted using AES-256 encryption. (b) Access Controls: Role-based access controls (RBAC) limit employee access to Personal Data on a need-to-know basis. Multi-factor authentication (MFA) is required for administrative access. (c) Infrastructure Security: Our infrastructure is hosted on SOC 2 Type II certified cloud platforms with redundant data centers, DDoS protection, and automated threat detection. (d) Application Security: We conduct regular penetration testing, vulnerability assessments, and code reviews. Our development practices follow OWASP Top 10 guidelines. (e) Incident Response: We maintain a documented incident response plan. In the event of a data breach affecting your Personal Data, we will notify you and the appropriate supervisory authorities within 72 hours as required by applicable law. (f) Employee Training: All employees with access to Personal Data undergo mandatory security and privacy training upon hire and annually thereafter. (g) Vendor Security: Third-party service providers are assessed for security compliance before engagement and are required to maintain appropriate security measures. While we strive to protect your Personal Data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

10. Your Privacy Rights

Depending on your location, you may have the following rights regarding your Personal Data: (a) Right of Access: You may request confirmation of whether we process your Personal Data and obtain a copy of the data we hold about you. (b) Right to Rectification: You may request correction of inaccurate or incomplete Personal Data. (c) Right to Erasure ("Right to Be Forgotten"): You may request deletion of your Personal Data, subject to certain legal exceptions (e.g., compliance with legal obligations, defense of legal claims). (d) Right to Restriction of Processing: You may request that we limit the processing of your Personal Data under certain circumstances. (e) Right to Data Portability: You may request your Personal Data in a structured, commonly used, machine-readable format (e.g., JSON or CSV) and transmit it to another controller. (f) Right to Object: You may object to processing based on legitimate interests or for direct marketing purposes at any time. (g) Right to Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing performed before withdrawal. (h) Right to Lodge a Complaint: You have the right to file a complaint with a supervisory authority in your jurisdiction (e.g., your local Data Protection Authority in the EEA/UK). (i) Right Not to Be Subject to Automated Decision-Making: You may request not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. To exercise any of these rights, contact us at privacy@leafsw.com. We will respond to verified requests within 30 days (or as required by applicable law). We may need to verify your identity before fulfilling your request.

11. Cookies & Tracking Technologies

We use cookies and similar tracking technologies to collect and store information when you use the Platform. (a) Strictly Necessary Cookies: Required for the Platform to function properly (e.g., session management, authentication, security). These cannot be disabled. (b) Functional Cookies: Remember your preferences and settings (e.g., language, theme, layout) to provide a personalized experience. (c) Analytics Cookies: Help us understand how users interact with the Platform, measure performance, and identify areas for improvement. We use Google Analytics (with IP anonymization enabled) and Mixpanel. (d) Marketing Cookies: Used to deliver relevant advertisements and track the effectiveness of marketing campaigns across platforms. These are only placed with your explicit consent. (e) Web Beacons & Pixel Tags: Small transparent images embedded in emails and pages to track open rates, click-through rates, and conversions. You can manage cookie preferences through your browser settings or our cookie consent banner. Disabling certain cookies may affect the functionality of the Platform. For more details, see our Cookie Policy page.

12. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides you with additional privacy rights: (a) Right to Know: You may request details about the categories and specific pieces of Personal Data we have collected about you in the past 12 months, the sources of collection, the business or commercial purpose, and the categories of third parties with whom we shared it. (b) Right to Delete: You may request deletion of your Personal Data, subject to certain exceptions. (c) Right to Correct: You may request correction of inaccurate Personal Data. (d) Right to Opt Out of Sale/Sharing: We do not sell your Personal Data. We do not share your Personal Data for cross-context behavioral advertising. If this changes, we will provide a "Do Not Sell or Share My Personal Information" link. (e) Right to Limit Use of Sensitive Personal Information: If we collect sensitive personal information, you may limit its use to what is necessary to provide the Service. (f) Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights. To submit a verifiable consumer request, contact us at privacy@leafsw.com. We will verify your identity using a two-step verification process and respond within 45 days. You may designate an authorized agent to submit requests on your behalf with proper written authorization. Categories of Personal Data collected in the preceding 12 months: Identifiers, commercial information, internet or electronic network activity, geolocation data, professional or employment information, and inferences drawn from the above.

13. Additional State Privacy Rights

We comply with applicable state privacy laws, including: (a) Virginia Consumer Data Protection Act (VCDPA): Virginia residents may exercise rights to access, correct, delete, obtain a copy of, and opt out of targeted advertising, sale of personal data, and profiling. (b) Colorado Privacy Act (CPA): Colorado residents may exercise similar rights, including opting out via a universal opt-out mechanism such as Global Privacy Control (GPC). (c) Connecticut Data Privacy Act (CTDPA): Connecticut residents have rights to access, correct, delete, obtain a copy, and opt out of targeted advertising, sale, and profiling. (d) Texas Data Privacy and Security Act (TDPSA): Texas residents may exercise rights to access, correct, delete, and opt out. We honor the Global Privacy Control (GPC) signal as a valid opt-out request. (e) Utah Consumer Privacy Act (UCPA): Utah residents may exercise rights to access, delete, and opt out of targeted advertising and sale of personal data. To exercise rights under any state law, contact us at privacy@leafsw.com.

14. European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the rights outlined in Section 10 of this Policy, plus: (a) Data Protection Officer: For privacy inquiries specific to GDPR compliance, contact our designated privacy contact at privacy@leafsw.com. (b) Supervisory Authority: You have the right to lodge a complaint with your local Data Protection Authority. A list of EEA DPAs can be found at https://edpb.europa.eu/about-edpb/about-edpb/members_en. (c) Cross-Border Transfers: See Section 7 for our transfer mechanisms. (d) Data Processing Agreements: We enter into GDPR-compliant Data Processing Agreements with all processors and sub-processors. (e) Records of Processing: We maintain records of processing activities in accordance with Article 30 of the GDPR and will make these available to supervisory authorities upon request.

15. Children's Privacy

The Platform is not intended for use by children under the age of 16 (or 13 in jurisdictions where COPPA applies with parental consent). We do not knowingly collect Personal Data from children under these ages. If we become aware that we have inadvertently collected Personal Data from a child under the applicable age, we will take immediate steps to delete such data. If you are a parent or guardian and believe your child has provided us with Personal Data, please contact us at privacy@leafsw.com and we will promptly delete the information.

16. Third-Party Links & Services

The Platform may contain links to third-party websites, applications, or services that are not operated by us. This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party service you access through the Platform. We are not responsible for the privacy practices, content, or security of third-party websites or services. The inclusion of a link does not imply endorsement of the linked site by Leaf Software Studio.

17. Do Not Track Signals

Some web browsers transmit "Do Not Track" (DNT) signals. There is currently no industry standard for how companies should respond to DNT signals. We honor the Global Privacy Control (GPC) signal as a valid opt-out request in jurisdictions that recognize it (including California, Colorado, Connecticut, and Texas). For other DNT signals, our current practices are described in this Privacy Policy and our Cookie Policy.

18. Automated Decision-Making & Profiling

We may use automated processing, including algorithms and machine learning models, to analyze usage patterns, detect fraud, personalize content, and improve the Service. We do not use solely automated decision-making that produces legal or similarly significant effects on you without human intervention. If automated processing is used in ways that significantly affect you, you have the right to request human review, express your point of view, and contest the decision by contacting privacy@leafsw.com.

19. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will: (a) Notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by the GDPR (Article 33). (b) Notify affected individuals without undue delay when the breach is likely to result in a high risk to their rights and freedoms (GDPR Article 34). (c) Comply with state breach notification laws in all applicable U.S. jurisdictions, which generally require notification within 30-60 days. (d) Provide details about the nature of the breach, the data affected, the likely consequences, and the measures taken or proposed to address it. (e) Maintain an internal breach register documenting all incidents regardless of severity.

20. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. When we make material changes: (a) We will post the revised Policy on this page and update the "Last updated" date at the top. (b) For material changes, we will provide at least 30 days' advance notice via email to the address associated with your account and/or a prominent banner on the Platform. (c) Your continued use of the Platform after the effective date of the revised Policy constitutes your acceptance of the changes. (d) If you do not agree to the revised Policy, you must discontinue use of the Platform and delete your account. We encourage you to review this Policy periodically to stay informed about how we protect your information.

21. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us: Leaf Software Studio LLC Miami, Florida, United States Email: privacy@leafsw.com General inquiries: hello@leafsw.com Website: https://leafsw.com For GDPR-related inquiries, please direct your correspondence to our privacy team at privacy@leafsw.com with the subject line "GDPR Request." We aim to respond to all legitimate inquiries within 30 days. If you feel that your inquiry has not been adequately addressed, you have the right to lodge a complaint with your local data protection authority.