ForeLeaf Back Office Privacy Policy
Introduction
ForeLeaf LLC, a Missouri limited liability company (“ForeLeaf,” “we,” “our,” or “us”), provides ForeLeaf Back Office, our multi-tenant software-as-a-service product for merchant businesses, including point-of-sale, CRM, invoicing, payroll calculation, purchasing, telephony, analytics, and related modules (the “Back Office Service”). This Privacy Policy explains how we handle personal information in connection with the Back Office Service.
This Privacy Policy covers the Back Office Service only. ForeLeaf’s separate consumer-facing product, the ForeLeaf Marketplace, is governed by a separate Marketplace Privacy Policy.
There are two different data relationships in the Back Office Service, and it is important to understand which one applies to any given piece of data.
From time to time, we may change this Privacy Policy. If we do, we will post an amended version on this webpage with a new “last updated” date. If we make material changes, we will provide notice, for example, by email to the account contact or an in-product notice, at least 14 days before the change takes effect, unless a shorter period is required by law or to address a security or legal issue.
1. Scope and the Controller/Processor Distinction
Data ForeLeaf Processes on the Merchant’s Behalf (ForeLeaf as Processor)
When a merchant business (the “Merchant,” “you,” for purposes of the account relationship) uses ForeLeaf Back Office to run its business, the Merchant loads and generates business data, for example, records about its own employees, its own customers, payroll and direct-deposit details, invoices, purchase records, call recordings, and analytics about the Merchant’s own operations (“Merchant-Controlled Data”). For Merchant-Controlled Data, the Merchant is the controller (or “business”) and ForeLeaf acts as a processor (or “service provider” under U.S. state privacy laws), handling the data only on the Merchant’s documented instructions.
This Privacy Policy is not the governing document for Merchant-Controlled Data. That processing is governed by the Data Processing Addendum (“DPA”), which forms part of the ForeLeaf Back Office Terms of Service. See “Merchant-Controlled Data We Process” below.
Data ForeLeaf Collects and Uses for Its Own Purposes (ForeLeaf as Controller)
Separately, ForeLeaf collects a limited set of data for which ForeLeaf itself is the controller (or “business”), meaning we decide why and how it is used. This includes the Merchant’s account and administrative contact information, billing information, and product-usage, device, and analytics data about how the Back Office Service is accessed and used, plus support communications with us (“Controller Data”). This Privacy Policy addresses Controller Data: what we collect, how we use it, who we share it with, and the choices and rights available to the Merchant’s account contacts.
2. Personal Data We Collect
Information We Collect as a Controller
We collect the following categories of Controller Data for our own purposes:
- Account and Administrative Contact Information. Name, business email address, phone number, job title/role, username, and authentication credentials of the individuals a Merchant designates to create, administer, or use the Back Office account (for example, the account owner and admin users), plus the Merchant’s business name and business address.
- Billing Information. Subscription plan and enabled module add-ons; billing contact details; the Merchant’s business tax/EIN or similar identifiers where applicable; and transaction/invoice history for the Merchant’s subscription to ForeLeaf. Payment-card and bank details for subscription billing are collected and stored by our payment processor, Stripe.
- Device, Log, and Product-Usage Data. IP address, browser and device type, operating system, device identifiers, pages/screens viewed, features used, clicks, session times, referring URLs, crash and error reports, and similar telemetry, used to operate, secure, and improve the service and understand product adoption.
- Support and Other Communications. Records of your communications with us, e.g., support tickets, emails, chat messages, and phone calls, and their contents.
- Marketing and Preference Information. Communication and marketing preferences, event/webinar registrations, and survey responses, where applicable.
We do not intentionally collect sensitive personal information about Merchant account contacts through this controller relationship. Sensitive data belonging to the Merchant’s own employees or customers (for example, payroll/SSN, biometric, or similar data) is Merchant-Controlled Data processed under the DPA.
Merchant-Controlled Data We Process
When a Merchant uses ForeLeaf Back Office, it inputs and generates business data, including its employees’ payroll and personal information (which may include direct-deposit bank details and government tax identifiers), its customers’ contact and transaction records, invoices, purchasing/accounts-payable records for the Merchant’s vendors, telephony call recordings (and transcripts, if that feature is offered and enabled), and operational analytics. For all of that data: the Merchant is the controller and ForeLeaf is the processor/service provider; ForeLeaf processes that data only on the Merchant’s documented instructions, for the purpose of providing the service, and does not use it for its own independent purposes except as permitted by the DPA; and the terms governing that processing, including security measures, subprocessors, international-transfer mechanisms, breach notification, and data return/deletion, are set out in the DPA, incorporated into the Back Office Terms of Service.
If you are an employee, customer, or other individual whose data appears in a Merchant’s Back Office account, ForeLeaf handles that data on the Merchant’s behalf. To exercise privacy rights over that data, contact the Merchant (the business) directly; ForeLeaf will support the Merchant in responding as required by the DPA and applicable law.
3. How We Use Controller Data
We use Controller Data to:
- Provide, maintain, and administer the ForeLeaf Back Office Service, including creating and securing accounts and authenticating users;
- Bill and collect subscription and add-on fees, prevent payment fraud, and keep financial records;
- Communicate with you about your account, service changes, security and technical notices, and support requests;
- Operate, secure, troubleshoot, and improve the Service, including diagnostics, analytics, and product development;
- Provide customer support, including (where authorized under the Back Office Terms of Service) accessing or impersonating Merchant accounts to diagnose and resolve issues, solely to the extent reasonably necessary and subject to the access limits, confidentiality, and audit-logging obligations described in that agreement and the DPA;
- Send marketing communications about ForeLeaf products and features, where permitted and subject to your right to opt out; and
- Comply with law, enforce our agreements, and protect the rights, safety, and property of ForeLeaf, our Merchants, and others.
We do not use Controller Data to build advertising profiles for third parties, and we do not sell it. See “Sharing and Sale of Personal Information” below.
Use of Artificial Intelligence
ForeLeaf uses a third-party large-language-model provider (Anthropic) to support certain Back Office features, including the chat assistant on a Merchant’s customer portal (which processes messages from the Merchant’s customers), and features for contracts, photos, and data imports. A Merchant may instead choose to connect its own account with OpenAI, xAI, or OpenRouter; for that Merchant, the selected provider processes the data those features send.
4. Subprocessors and Service Providers
We use trusted third parties to help operate ForeLeaf Back Office. Depending on the feature, these providers may process Controller Data and/or Merchant-Controlled Data (processed under the DPA). The current list includes:
- Core providers: Stripe (including Stripe Connect) for subscription billing and payment processing; Amazon Web Services for cloud hosting and infrastructure; Cloudflare for content delivery, network security, and edge services; Postmark for transactional and notification email; Twilio for SMS and voice/telephony, including recording of calls forwarded through the Service (callers hear a recording notice before the call connects); Anthropic for AI features; and Sentry for application error and performance monitoring.
- AI providers a Merchant selects: OpenAI, xAI, and OpenRouter, only for a Merchant that connects its own account with one of them.
- Integrations a Merchant turns on: QuickBooks, Gusto, Samsara, ShipStation, DocuSign, Mailchimp, GoHighLevel, and Slack, only for a Merchant that connects them.
- Resources loaded by your browser: Google Fonts and OpenStreetMap/Esri map tiles, which receive your IP address when your browser loads them.
We require our providers by contract to protect the data they handle and to use it only to provide services to us (or to the Merchant, in the case of processor data). The current list of subprocessors for Merchant-Controlled Data is the list above, and it will also be maintained under the DPA.
5. Sharing and Sale of Personal Information
Beyond the service providers/subprocessors described above, we may share Controller Data: with the Merchant organization, for example, an account owner or admin can see other users’ account and usage activity within their organization; for legal reasons, to comply with law, legal process, or lawful government requests, to enforce our terms, and to protect the rights, safety, and property of ForeLeaf, our Merchants, or others; in a business transfer, in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy or a successor policy; and with your consent, for any other purpose disclosed at the time.
We do not sell your personal information, and we do not “share” it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), and comparable state laws.
6. Security
We maintain administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit and at rest, access controls, least-privilege and role-based access, audit logging, network security, and monitoring. Bank account and tax identifiers within Merchant-Controlled Data are encrypted at rest. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Data Retention
We retain Controller Data for as long as the Merchant’s account is active and as needed to provide the Service, and afterward as required for legitimate business and legal purposes, for example, we retain financial and transaction records as long as needed for the purposes above and as required by law (tax and payment records for at least 7 years) to meet tax and accounting obligations.
ForeLeaf Back Office provides data export and account deletion, which a Merchant can request through support@tryforeleaf.com. When a Merchant requests deletion of its account, the account enters a 30-day pending-deletion period during which the request can be cancelled, after which it is deleted or de-identified in accordance with our standard cycles and any legal retention requirements.
8. Cookies and Similar Technologies
We and our providers use cookies and similar technologies on office.tryforeleaf.com and related sites to keep you signed in, remember preferences, secure the Service, and understand usage. Some are strictly necessary for the Service to function; others support analytics and product improvement.
You can control cookies through your browser settings.
9. Notice to Nevada Residents
Nevada law allows Nevada residents to opt out of the sale of certain types of personal information. We do not currently sell personal information as defined under Nevada law. If you are a Nevada resident, you may still submit a verified request to opt out of sales, and we will record your instructions and incorporate them in the future if our policy changes. You may send opt-out requests to privacy@tryforeleaf.com.
10. Your State Privacy Rights and Additional Disclosures
Depending on where you live, you may have rights under U.S. state privacy laws, including the CCPA and the comprehensive privacy laws of Virginia, Colorado, Connecticut, and Utah, and of other states as their laws take effect. These rights, to the extent they apply to Controller Data described in this Policy, may include the right to know or access the personal information we hold about you and how we use and disclose it; the right to correct inaccurate personal information; the right to delete your personal information; the right to receive a copy of your personal information in a portable format; the right to opt out of any sale or sharing of personal information and of certain targeted advertising or profiling (we state above that we do not sell or share); and the right to non-discrimination for exercising your rights.
To exercise these rights over Controller Data, contact us at privacy@tryforeleaf.com. We will verify your request as required by law and may ask for information to confirm your identity. You may designate an authorized agent where the law allows. If we deny a request, you may appeal by emailing privacy@tryforeleaf.com with the subject line “Privacy Appeal.”
Data-Subject Requests About Merchant-Controlled Data. If your request concerns data that a Merchant controls, for example, you are an employee or customer of a business that uses ForeLeaf Back Office, that business is the controller. Please direct your request to the Merchant. ForeLeaf, as processor, will assist the Merchant in fulfilling verified requests as required by the DPA and applicable law, and will refer such requests to the relevant Merchant.
11. Notice to California Residents
This section is intended solely for, and applicable only to, California residents, and supplements the disclosures above with respect to Controller Data.
Notice at Collection of Personal Information
In the preceding 12 months, we have collected the following categories of personal information for our controller purposes: identifiers (name, business email, phone number); personal information described in California’s Customer Records statute (billing and payment-related information); internet or electronic network activity information (device, log, and usage data); professional or employment-related information (job title/role); and commercial information (subscription and billing history).
Sale, Sharing, and Disclosure of Personal Information
We have not sold or shared personal information, as those terms are defined by the CCPA, in the twelve (12) months preceding the effective date of this Privacy Policy. We do not use sensitive personal information for purposes other than those permitted by the CCPA and its regulations.
Your Rights
If you are a California resident, you have the right to know what personal information we have collected about you, the right to delete personal information we collected from you (subject to certain exceptions), the right to correct inaccurate personal information, and the right not to receive discriminatory treatment for exercising these rights. You may submit a request by emailing privacy@tryforeleaf.com or by contacting us as described in “How to Contact Us” below.
12. Accessibility
We are committed to ensuring this Privacy Policy is accessible to individuals with disabilities. If you wish to access this Privacy Policy in an alternative format, please contact us as described below.
13. How to Contact Us
ForeLeaf LLC. Privacy inquiries: privacy@tryforeleaf.com. Legal notices: legal@tryforeleaf.com. Support: support@tryforeleaf.com. Mailing address: 211 NW Executive Way, Suite H, Lee’s Summit, MO 64064.