Legal

Privacy Policy

This overview describes the processing currently visible in the Leonety architecture. It must be legally reviewed and completed with the controller’s verified details before launch.

Controller and contact

The controller is the service operator listed below. Privacy requests can be sent using the verified contact details: Ahmed Sultanline · [REQUIRED BUSINESS ADDRESS] · [REQUIRED CONTACT EMAIL]

Hosting

Leonety is hosted on Vercel. Technical request, security and deployment logs may be processed to deliver and protect the service.

Registration and authentication

Supabase provides authentication, database and storage services. Account identifiers, profile data, session metadata and security events are processed to create and protect accounts.

Google and Meta login

When a user chooses Google or Facebook login, the selected provider and Supabase process the OAuth data needed for sign-in. Social login is optional.

Workspace and business data

Leonety processes workspace, client, invoice, contract, product, inventory, time and transaction data entered by users to provide the requested SaaS functions.

Billing

Paddle processes checkout, payment and subscription data when a paid plan is used. Leonety stores only the identifiers and status data needed to provide access and support billing.

AI assistants

When an AI feature is used, the prompt and limited relevant context are sent server-side to the configured AI provider. The public assistant receives no private workspace data.

Connected services

Optional WooCommerce, WhatsApp and other configured integrations process only the data needed for the selected connection or sync. Provider access and scope depend on each workspace’s setup.

Support and contact

Messages sent to support are processed to answer requests, troubleshoot issues and document necessary follow-up.

Logs and security

Limited technical data such as IP address, request time, route, device information and errors may be processed for security, abuse prevention and reliable operation.

Cookies and local storage

Leonety currently uses browser storage required for authentication, locale, workspace preference, PWA and core UI state. No optional analytics or marketing tracker was found in the audited source.

Purposes and legal bases

Processing serves contract performance and pre-contract steps, legitimate interests in security and operation, legal obligations, and consent where an optional provider connection requires it. Applicability must be verified for the operator’s situation.

Recipients and international transfers

Data may be received by hosting, authentication, billing, AI and integration providers used for the requested function. Provider locations and transfer safeguards must be checked against the final contracts and account regions.

Retention and deletion

Data is kept while the account or legal purpose requires it and is then deleted or anonymized where permitted. Statutory retention duties for business records may apply.

Your rights

Depending on applicable law, data subjects may request access, correction, deletion, restriction, portability or object to processing, and may complain to the competent supervisory authority.

Last updated: September 2026