Privacy Policy
This Privacy Policy explains how Leavefly, a sole proprietorship (“Leavefly”, “we”) collects, uses, and shares personal data when you use Leavefly (the “Service”).
1. Who is responsible
For personal data of people who visit our site and sign up, Leavefly is the controller. For personal data that a customer’s workspace processes about its own members (“Customer Data”), the customer organisation is the controller and Leavefly acts as processor on its behalf.
2. Data we collect
- Account data: name, work email, hashed password (or Google sign-in identifier), organisation name, role.
- Leave & workspace data: leave requests, dates, leave types, balances, approvals, comments/reasons, teams, holidays, approver/delegate relationships.
- Usage & technical data: log data, IP address, device/browser information, and cookies necessary for authentication and security.
- Payment data: handled by our Merchant of Record (see §5). We do not store full card details.
3. How we use data
To provide and operate the Service; authenticate users; send transactional emails (e.g. invitations, approval notifications, verification); provide optional integrations you enable; maintain security and prevent abuse; comply with legal obligations; and improve the Service.
We rely on the following legal bases (where GDPR/UK-GDPR applies): performance of a contract, legitimate interests (security, service improvement), consent (where required, e.g. non-essential cookies), and legal obligation.
4. Cookies and analytics
We use strictly necessary cookies for login sessions and security (via our authentication provider). We do not use advertising cookies. We use a privacy-friendly, cookieless analytics tool (Umami) that collects aggregate, non-identifying usage statistics and does not track you across sites.
5. Sub-processors and sharing
We share data with service providers who process it on our behalf:
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Application & API hosting (compute) | Germany (EU) |
| Neon | Database (PostgreSQL) | Germany (EU) — Frankfurt |
| Cloudflare | Marketing-site hosting, CDN, DNS, and security (WAF/DDoS) | Global edge network |
| Brevo (Sendinblue) | Transactional email delivery | European Union |
| Umami Analytics | Privacy-friendly, cookieless website analytics (marketing site only) | European Union |
| Creem | Payment processing & tax (Merchant of Record) | EU / US |
| Slack, ClickUp | Only when you connect them; data is exchanged to provide the integration | United States |
We do not sell personal data. We may disclose data if required by law or to protect rights and safety.
6. International transfers
Your data may be processed in countries other than your own. Where required, we use appropriate safeguards (e.g. standard contractual clauses) for such transfers.
7. Retention
We keep Customer Data for as long as your workspace is active. When an admin deletes a workspace, all Customer Data — including every member’s account — is permanently and irreversibly deleted immediately. There is no grace period or recovery window. Export your data first if you need a copy; you can export at any time while the workspace is active.
8. Your rights
Depending on your location, you may have rights to access, correct, delete, export, or restrict processing of your personal data, and to object or withdraw consent. The Service includes self-service data export and workspace deletion. For other requests, contact us at [email protected]. You may also complain to your local data-protection authority.
9. Security
We use industry-standard measures including encryption in transit, hashed passwords, scoped access controls, and signed tokens for calendar feeds and integrations. No system is perfectly secure; we cannot guarantee absolute security.
10. Children
The Service is for workplace use and not directed to children under 16.
11. Changes
We may update this Policy and will notify you of material changes.
12. Contact
[email protected] — Leavefly, a sole proprietorship.