We believe privacy isn't a passive legal checklist — it's an engineering constraint. LeapCrew AI orchestrates message relays, multi-tenant databases, and external webhooks under rigid isolation protocols.
Click through our dynamic visual engine to explore the physical logical borders, HMAC validation signatures, database segregation structures, and Meta edge node dispatches.
Incoming requests (e.g., from Shopify, WooCommerce, or your bespoke webhooks) are encrypted using TLS 1.2+ and validated using dynamic SHA-256 HMAC headers. Payloads are checked and routed entirely in-memory with zero temporary disk writes.
LeapCrew AI collects the following categories of information when you use our platform:
Your name, email address, organization name, and billing details (processed by Razorpay) when you register or manage your workspace.
Phone numbers, names, tags, and message history of your CRM contacts — imported by you or synced from external systems (Shopify/WooCommerce). You are the data controller for this data.
Feature interactions, API call counts, campaign delivery statistics, chatbot node usage, and system log activity within your workspace.
Browser type, IP address, and session identifiers collected via authentication cookies for security and session management purposes.
Information collected is used exclusively for the following purposes:
LeapCrew AI implements industry-standard security measures across all data storage layers:
| Layer | Method | Standard |
|---|---|---|
| Data at Rest | PostgreSQL encrypted storage | AES-256-GCM |
| Data in Transit | All API and web traffic | TLS 1.2+ |
| Secrets & Tokens | Meta tokens, webhook keys | AES-256-GCM encrypted fields |
| Access Control | Multi-tenant isolation | Org-scoped queries + JWT session validation |
Data is stored in cloud infrastructure with physical and logical access controls. Only authorized personnel with a documented business need can access production systems.
We share your data only with the following third parties, solely to the extent necessary to deliver our service:
WhatsApp Business Platform — to deliver messages via the WhatsApp Cloud API on your behalf.
Payment processing for wallet top-ups and subscription billing.
Infrastructure and database hosting for platform operations.
We do NOT sell, rent, or trade your personal data or your customers' data to any third party for advertising or commercial purposes.
Depending on your jurisdiction, you have the following rights over your personal data:
Request a copy of all personal data we hold about you.
Correct inaccurate or incomplete personal data.
Request permanent erasure of your data. Fulfilled within 48 hours of confirmed request.
Export your data in structured JSON/CSV formats from the platform dashboard.
Object to processing based on legitimate interests or direct marketing.
Withdraw consent at any time where processing is consent-based.
Users in India have rights under the Information Technology Act 2000 and the Digital Personal Data Protection Act 2023 (DPDP Act). This includes rights to access, correction, and erasure of your personal data. Our designated Grievance Officer for India can be reached at grievance@leapcrew.in.
LeapCrew AI processes WhatsApp contact data (phone numbers, names, message content) on behalf of you — the Organization — to deliver our platform services.
You (the Organization) are the Data Controller for your contacts' data. You are solely responsible for ensuring that all contacts in your CRM have explicitly opted in to receive WhatsApp communications from your business before importing or messaging them.
LeapCrew AI acts as a Data Processor. We store and route contact data only as instructed by your workspace configuration. We do not use your contacts' data for any purpose other than delivering the LeapCrew AI service to you. See our Data Processing Agreement for full details.
LeapCrew AI uses a minimal set of cookies essential to operate the platform. We do not use behavioral tracking cookies or third-party advertising cookies.
| Cookie | Purpose | Lifespan |
|---|---|---|
| next-auth.session-token | Authenticated session management | Session |
| next-auth.csrf-token | CSRF protection | Session |
| leapcrew_theme | UI preference storage | 30 days |
See our full Cookie Policy for details on how to manage cookie preferences.
We retain your data for as long as your account is active and as required to deliver our services:
LeapCrew AI is a business-to-business SaaS platform intended exclusively for organizations and individuals aged 18 and above. We do not knowingly collect or process personal data of anyone under the age of 18.
If we become aware that we have inadvertently collected data from a minor, we will delete such data immediately. If you believe we may have collected data from a minor, please contact us at hello@leapcrew.in.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements.
For material changes — those that significantly affect your rights or how we process your data — we will notify you via:
Continued use of LeapCrew AI after the effective date of any update constitutes acceptance of the revised policy.
For privacy inquiries, data subject requests, or concerns about how we handle your data, please contact: