Privacy Policy

Effective Date: April 4, 2026

LeaseStract ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our lease abstraction service at www.leasestract.com (the "Service").

1. Information We Collect

A. Information You Provide to Us

  • Account Information: Name, email address, company name, and billing information.
  • Customer Data: Lease documents and related files you upload for processing.
  • Reviews: If you choose to submit a review, we collect your name, company, role, and review content.
  • Communications: Information you provide when you contact customer support or communicate with us.

B. Information Collected Automatically

  • Usage Data: IP address, browser type, operating system, pages visited, time spent, and referring URLs.
  • Cookies and Tracking: We use essential cookies for authentication and session management. We do not use advertising cookies or third-party tracking.

2. How We Use Your Information

We use the information we collect to: provide, operate, and maintain the Service; process your lease documents and deliver abstraction results; process payments and manage billing through Stripe; send administrative information, including updates and security alerts; respond to customer service requests and provide support; monitor and analyze usage trends to improve the Service; detect, prevent, and address technical issues and security vulnerabilities; and comply with legal obligations and enforce our Terms of Service.

3. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances: Service Providers — We share information with Stripe for payment processing and Supabase/AWS for cloud hosting. These providers are contractually obligated to protect your information. Legal Requirements — We may disclose information if required by law, court order, or government request, or to protect our rights, property, or safety. Business Transfers — In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. With Your Consent — We may share information with third parties when you explicitly consent.

4. Data Retention

We retain your personal information for as long as necessary to provide the Service and fulfill the purposes described in this Privacy Policy. Uploaded documents and generated abstracts are retained in your account until you delete them or close your account. After account termination, we provide a 30-day period for data download, after which Customer Data may be permanently deleted.

5. Data Security

We implement the following security measures to protect your information: Encryption — All data is encrypted at rest using AES-256 encryption and in transit using TLS 1.2 or higher. Infrastructure — Customer Data is hosted on Supabase, which runs on Amazon Web Services (AWS) infrastructure. Supabase maintains SOC 2 Type 2 certification. Database Security — We use PostgreSQL with Row Level Security (RLS) policies to isolate customer data. Authentication — User authentication is managed through secure token-based authentication. Backups — All data is automatically backed up daily with encrypted storage. However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials.

6. Your Rights and Choices

You have the following rights regarding your personal information: Access — Request access to the personal information we hold about you. Correction — Request correction of inaccurate or incomplete information. Deletion — Request deletion of your personal information, subject to legal obligations. Data Portability — Request a copy of your data in a structured, machine-readable format. To exercise these rights, please contact us at support@leasestract.com.

7. Cookies

We use essential cookies required for authentication and session management. We do not use advertising cookies or third-party tracking. You can control cookies through your browser settings. Note that disabling cookies may affect Service functionality.

8. Third-Party Links

The Service may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.

9. Children's Privacy

The Service is not intended for individuals under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately and we will take steps to delete such information.

10. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. We implement appropriate safeguards to protect your data in accordance with this Privacy Policy and applicable laws.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website with a new effective date. Your continued use of the Service after changes constitutes acceptance of the updated policy.

12. State Privacy Rights

A. California Privacy Rights (CCPA/CPRA)

  • Right to Know: Request disclosure of personal information we collect, use, disclose, and sell.
  • Right to Delete: Request deletion of your personal information, subject to certain exceptions.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt-Out: Opt-out of the sale or sharing of personal information. We do not sell or share personal information.
  • Right to Non-Discrimination: You will not receive discriminatory treatment for exercising your CCPA rights.

B. Other State Privacy Rights

  • If you are a resident of Virginia, Colorado, Connecticut, Utah, Montana, Oregon, or Texas, you have similar rights under your state's privacy law, including the right to access, correct, delete, and obtain a copy of your personal data, and the right to opt-out of the sale of personal data (we do not sell personal data).

C. How to Exercise Your Rights

  • To exercise any of these privacy rights, please contact us at support@leasestract.com. We will respond to your request within 45 days, or up to 90 days if an extension is needed as permitted by applicable law. We will not discriminate against you for exercising your privacy rights.

13. Data Breach Notification

In the event of a data breach that compromises your personal information, we will notify you and any applicable regulatory authorities as required by law. Notification will be made without unreasonable delay and in accordance with applicable state and federal breach notification requirements.

Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:

LeaseStract

Operated by Utility Basics Holding, LLC

1309 Coffeen Avenue, Suite 9434

Sheridan, WY 82801, United States

Email: support@leasestract.com

Website: www.leasestract.com