Privacy Policy
Last Updated: July 15, 2026
•Effective Date: June 28, 2026
•Entity: leaex parlourmates private limited
Privacy Commitment Summary
This Privacy Policy applies to leaex parlourmates private limited ("Leaex", "We", "Us", or "Our") and governs the collection, processing, storage, and transfer of personal data across our websites (leaex.com, app.leaex.com, partner.leaex.com), Progressive Web Applications (PWA), mobile interfaces, APIs, customer portals, communication integrations, and AI services. We do not sell personal data. We comply with the Indian Digital Personal Data Protection Act (DPDP Act 2023), Information Technology Act 2000, General Data Protection Regulation (GDPR), California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and CalOPPA.
1. Corporate Identity & Introduction
Welcome to Leaex. This Privacy Policy describes how leaex parlourmates private limited (CIN / Registration details maintained under Indian Companies Act; Registered Address: Rest House, Near Water Tank, Banda, Banda Nagar, Sagar, Sagar- 470335, Madhya Pradesh, India) collects, uses, protects, and discloses personal data when you visit our website, register for an account, subscribe to our software services, access our applications, or interact with our automated intelligence systems.
By accessing or using the Service, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree with our policies and practices, your choice is not to use our Services.
2. Interpretation and Definitions
Interpretation
Capitalized terms have specific meanings defined below. Singular definitions apply equally to plural forms and vice-versa.
Definitions
- Account: A unique authenticated account created for a User, Merchant, Partner, or Organization to access our Service or designated platform tiers.
- Affiliate: Any entity that directly or indirectly controls, is controlled by, or is under common control with the Company (where "control" means ownership of 50% or more of voting securities or management authority).
- Business Customer / Partner: Any commercial salon, spa, retail outlet, enterprise, or merchant that licenses Leaex software to manage appointments, operational floor queues, inventory, staffing, payments, or client engagement.
- End User / Client: An individual consumer or patron who books appointments, receives messaging, or engages with a Business Customer powered by the Leaex platform.
- Company ("We", "Us", "Our"): Refers to leaex parlourmates private limited, Rest House, Near Water Tank, Banda, Banda Nagar, Sagar, Sagar- 470335, Madhya Pradesh, India.
- Cookies & Web Beacons: Small data files, browser storage items, tracking pixels, scripts, or identifier tokens placed on your device to ensure security, authenticate sessions, remember preferences, and analyze system performance.
- Country / Primary Jurisdiction: Madhya Pradesh, India, subject to applicable Indian union and federal laws.
- Device: Any internet-connected hardware including desktop workstations, tablets, POS terminals, smartphones, and mobile devices used to access the Service.
- Personal Data (Personal Information): Any information that relates to an identified or identifiable natural person.
- Platform / Service: All software products, websites (leaex.com, app.leaex.com), APIs, dashboards, Progressive Web Applications, and automated communication tools operated by the Company.
- Service Provider / Subprocessor: Any third-party natural or legal entity engaged by the Company to process data, provide cloud infrastructure, facilitate transactions, deliver messaging, or deliver analytics on our behalf.
- Usage Data: Telemetry, log entries, diagnostic metrics, and access data collected automatically through user interaction with the Service infrastructure.
- You / User: The individual accessing or using the Service, or the company or legal entity on behalf of which such individual accesses the Service.
3. Categories of Information We Collect
We collect information across several distinct categories based on your relationship with Leaex (as a website visitor, registered business partner, staff member, or end consumer):
A. Personal Identification Data
- Full legal name and preferred name
- Email address (business and personal)
- Mobile telephone numbers (including WhatsApp ID)
- Physical address, city, state/province, ZIP/PIN code, country
- Profile avatars, language preference, time zone
B. Social Media & Federated Logins
- OAuth tokens from Google, Facebook, Twitter/X, Apple
- Public profile identifiers, verified emails, display names
- Authentication timestamps and federated account IDs
C. Business & Merchant Data
- Trade name, business category, business address
- Goods and Services Tax Identification Number (GSTIN) / PAN
- Bank payout details, UPI IDs, merchant billing records
- Employee rosters, role assignments, shift schedules, commissions
- Service catalogs, pricing menus, inventory stock levels
D. End-Customer Records
- Client names, telephone numbers, and email addresses
- Appointment histories, chair time, service records
- Loyalty points, credit balances, voucher redemptions
- Treatment notes, stylist preferences, allergy cautions
- Customer feedback, ratings, and reviews
E. Device, Telemetry & Diagnostics
- IP address, geolocation city/country estimates
- Browser user agent, browser version, operating system
- Hardware screen dimensions, viewport resolution, color depth
- PWA installation state, service worker sync status
- Core Web Vitals, crash logs, error traces, latency metrics
F. Billing & Payment Records
- Payment gateway transaction IDs, reference numbers
- Subscription tier, billing cycle, renewal status
- Tax invoices, credit notes, payment receipt vouchers
- Note: Full credit/debit card numbers and CVV codes are processed directly by certified PCI-DSS Level 1 gateways (Razorpay/Stripe) and are never stored on Leaex origin servers.
G. Communications, Messaging & AI Data
- Messages transmitted via Meta WhatsApp Cloud API, SMS gateways, and transactional emails
- Delivery receipts, message open flags, opt-in/opt-out consent timestamps
- Customer support tickets, live chat transcripts, grievance records
- Prompts, context parameters, workflow inputs, and output summaries generated when utilizing Leaex AI tools
4. Tracking Technologies, Cookies & Web Beacons
We use Cookies, local storage, session storage, and web beacons to maintain active user sessions, enhance platform performance, protect against unauthorized access, and analyze traffic patterns.
1. Strictly Necessary / Essential Cookies
Required for core authentication, session management, CSRF token validation, load balancing, and security verification. The platform cannot function properly without these cookies.
2. Functionality & Preference Storage
Stores user interface preferences, active theme (dark/light/warm/cool), language selections, workspace layout state, and offline local-first sync caches.
3. Performance & Analytics Cookies
Employed through privacy-focused telemetry (PostHog, Google Analytics, Sentry) to understand user navigation, feature adoption, application rendering speeds, and crash diagnostics.
4. Web Beacons & Pixel Tags
Small electronic transparent markers embedded in service pages and notification emails to verify delivery, count page views, and monitor system health.
You can configure your browser to reject cookies or notify you when cookies are placed. However, disabling essential cookies will disable access to authenticated portals (app.leaex.com).
5. Purposes and Lawful Basis of Processing
We process personal data under the following lawful bases and for the specific purposes enumerated below:
- Performance of a Contract: To provision user accounts, authenticate logins, operate the real-time floor queue, process client bookings, calculate billing/subscriptions, and provide customer support.
- Legitimate Business Interests: To monitor system reliability, deploy security patches, prevent fraudulent bookings or abusive API requests, enhance UI/UX workflows, train and refine internal operational models, and conduct anonymized business analytics.
- Compliance with Legal Obligations: To adhere to applicable statutory regulations, tax documentation laws (GST/TDS in India), accounting audits, court orders, and law enforcement requests under the Indian IT Act and DPDP Act.
- With Explicit Consent: To send marketing communications, promotional newsletters, product announcements, and remarketing advertisements where you have opted in. You may withdraw consent at any time without affecting past lawful processing.
6. Third-Party Service Providers & Subprocessors
We engage vetted third-party vendors to support our platform infrastructure under strict data protection agreements that prohibit unauthorized data usage:
| Vendor / Service | Function / Processing Role | Data Categories | Location |
|---|---|---|---|
| Supabase / AWS | Database Hosting, Auth, Realtime Sync | Account, Business, Client, Booking Data | India / Global Edge |
| Cloudflare / Vercel | Edge CDN, DDoS Mitigation, Application Delivery | IP Address, Routing Telemetry, SSL Data | Global Edge Network |
| Razorpay / Stripe | Payment Processing & Merchant Settlement | Billing Info, Transaction Tokens, Invoices | India / USA / EU |
| Meta (WhatsApp Cloud API) | WhatsApp Customer Communications | Phone Numbers, Booking Reminders, Messages | Global / USA |
| Google (Google Places API) | Address Autocomplete & Geocoding | Location search queries, device IP | Global |
| PostHog / Sentry | Telemetry, Crash Reporting, Performance Monitoring | Diagnostic logs, browser stack traces, session telemetry | EU / USA |
| AI Engine Providers (Anthropic, OpenAI, Google) | Automated Intelligence & Workflow Suggestions | Prompts, structured operational context, output text | USA / Global |
7. Merchant (Partner) Responsibilities as Data Fiduciaries
When a Business Customer uses Leaex to manage their establishment, the Business Customer acts as the primary Data Fiduciary (Data Controller) regarding their end-client records, while Leaex acts as a Data Processor.
Business Customers agree and warrant that:
- They have obtained all necessary consents from their patrons to store contact information and send transactional and promotional messaging.
- They will promptly honor client requests for data correction, access, or erasure.
- They will not upload sensitive personal data (such as health biometric records or financial credentials) into unauthorized free-text notes fields.
- They maintain independent privacy policies governing their in-store and direct customer interactions.
8. Artificial Intelligence (AI) Features & Data Governance
Leaex incorporates automated intelligence features to help businesses analyze schedules, draft communication templates, predict peak hours, and streamline workflows.
- No Training on Proprietary Data: Customer personal data and proprietary salon records are not used to train public foundation models without explicit agreement.
- Ephemeral Processing: Prompts sent to authorized AI model endpoints are processed securely via enterprise APIs with zero data retention for training.
- Human Review: AI outputs are advisory tools. Users remain responsible for validating recommendations before taking commercial or operational actions.
9. Communications & WhatsApp Messaging Policy
Leaex provides automated communication tools integrated with the Meta WhatsApp Business API, SMS, and email.
- Opt-In Compliance: Businesses may only send messages to recipients who have explicitly opted in to receive communications.
- Opt-Out Mechanism: All automated promotional campaigns include standard unsubscribe mechanisms (e.g., replying "STOP" on WhatsApp or clicking "Unsubscribe" in emails).
- Zero Tolerance for Spam: Transmission of unsolicited bulk spam, deceptive phishing content, or messaging promoting restricted items is strictly prohibited and results in immediate account termination.
10. Data Retention, Archival & Anonymization
We retain personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy:
- Active User Accounts: Retained for the duration of the active business relationship, plus up to 24 months post-account closure to resolve potential post-termination reconciliation or disputes.
- Customer Support & Chat Records: Retained for up to 24 months from ticket resolution for quality assurance, staff training, and audit defense.
- System Logs & Telemetry: Stored for up to 24 months for network security audits, anomaly detection, and fraud prevention before automated purge.
- Statutory Tax & Financial Invoices: Retained for 7 to 8 years as required by Indian taxation statutes (GST Act, Income Tax Act) and corporate regulatory standards.
- Encrypted Backups: Automated rolling disaster-recovery backups are encrypted and retained on a 30-to-90 day cyclic purge schedule.
11. Data Security & Technical Safeguards
We deploy multi-layered administrative, physical, and technical controls designed to protect personal data against accidental loss, unauthorized access, alteration, and disclosure:
- Encryption in Transit: All web and API traffic is strictly enforced over TLS 1.3 / HTTPS with automated HSTS headers.
- Encryption at Rest: Core database volumes, file storage buckets, and server backups are encrypted using AES-256 standards.
- Isolation & Row-Level Security (RLS): Database architecture utilizes strict PostgreSQL Row-Level Security to prevent cross-tenant data access.
- Role-Based Access Control (RBAC): Employee access to production infrastructure is governed by least-privilege principles, multi-factor authentication (MFA), and audit logging.
12. International Data Transfers
Your information may be processed and stored on servers located outside of your state, province, or country where data protection laws may differ. When transferring data internationally, we implement Standard Contractual Clauses (SCCs), Data Transfer Impact Assessments, and technical encryption safeguards to ensure your data receives equivalent protection.
13. Global Privacy Rights & Jurisdiction Disclosures
A. India — Digital Personal Data Protection Act (DPDP Act 2023)
If you reside in India, you enjoy statutory rights under the DPDP Act 2023 and Information Technology Act 2000:
- Right to Access Summary: Request a summary of personal data being processed and identities of data fiduciaries/processors.
- Right to Correction and Erasure: Request correction of inaccurate data and erasure of data no longer necessary for the original purpose.
- Right of Grievance Redressal: Access our Grievance Officer for prompt resolution of data disputes before escalating to the Data Protection Board of India.
- Right to Nominate: Nominate another individual to exercise your rights in the event of death or incapacity.
B. European Union & United Kingdom (GDPR / UK GDPR)
Users located in the European Economic Area (EEA) or UK have the following rights under GDPR:
- Right of Access (Art. 15): Obtain confirmation of processing and a copy of your personal data.
- Right to Rectification (Art. 16): Correct inaccurate or incomplete personal records.
- Right to Erasure / "To Be Forgotten" (Art. 17): Request deletion of personal data under statutory grounds.
- Right to Restriction (Art. 18) & Data Portability (Art. 20): Receive your structured data in a machine-readable format.
- Right to Object (Art. 21): Object to processing based on legitimate interests or direct marketing.
- Right to Lodge a Complaint: File a grievance with your local Data Protection Supervisory Authority.
C. United States — California Privacy Rights (CCPA / CPRA & CalOPPA)
Under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CPRA):
- Right to Know & Access: Request the specific pieces of personal information collected over the preceding 12 months.
- Right to Delete: Request deletion of personal information, subject to statutory exemptions.
- Right to Correct: Request correction of inaccurate personal records.
- No Sale / Sharing of Personal Information: We do NOT sell personal information or share personal data for cross-context behavioral advertising.
- Right to Limit Sensitive Data Use: We only collect sensitive personal data strictly necessary to provide requested services.
- Non-Discrimination: We will not discriminate against you (via pricing, quality, or service level) for exercising your privacy rights.
- CalOPPA "Do Not Track" Signals: We honor Do-Not-Track (DNT) and Global Privacy Control (GPC) signals transmitted by compatible browser headers.
14. Protection of Children's Privacy
Our Service is not directed to children under the age of 16 (or under the age of 18 in jurisdictions where higher thresholds apply for commercial contracts). We do not knowingly collect personal data from minors. If we learn that we have collected personal data from a child without verified parental or legal guardian consent, we will promptly delete that information from our active databases. Parents or guardians who believe their child has provided us with personal data may contact us at support@leaex.com.
15. Account Deletion & Self-Service Data Erasure
You have the absolute right to terminate your account and request permanent deletion of your personal records.
Self-Service Deletion Portal
Submit an automated deletion request directly through our dedicated erasure portal.
16. Amendments to this Privacy Policy
We may update our Privacy Policy periodically to reflect technological innovations, regulatory modifications, or platform enhancements. When material changes occur, we will notify registered users via email notification and update the "Last Updated" date at the top of this document. Continued use of the platform after effective dates constitutes acceptance of updated terms.
17. Grievance Officer & Official Contact Information
In accordance with the Indian Information Technology Act 2000 and the Digital Personal Data Protection Act 2023, the details of the designated Grievance Officer and Data Protection Contact are provided below:
Company Legal Entity:
leaex parlourmates private limited
Registered Corporate Address:
Rest House, Near Water Tank, Banda, Banda Nagar, Sagar, Sagar- 470335, Madhya Pradesh, India
Grievance & Data Protection Inquiries:
Official Web Portals: