LeakProof Privacy Policy
Effective Date: August 28, 2026
Entity: Bellcrest Technologies Inc., a corporation continued/incorporated under the Canada Business Corporations Act (CBCA), registered extra-provincially in New Brunswick, Canada ("LeakProof," "Company," "we," "us," or "our").
1. Introduction
This Privacy Policy explains how LeakProof collects, uses, discloses, and safeguards information in connection with the LeakProof web application and related services (the "Service"), a B2B software platform used by field service businesses ("Customer," "you") and their authorized personnel. This Policy applies to information collected through our website (useleakproof.com), the Service itself, and related communications.
This Policy should be read together with our Terms of Service.
Scope note: The Service is offered to businesses for business use, not to individual consumers. Where the Service processes personal information about a Customer's own technicians or end-clients ("Customer Personal Data"), LeakProof generally acts as a service provider/processor on the Customer's behalf, and the Customer remains the data controller for that information. Section 3 addresses legal bases relevant to that role split.
This Policy governs LeakProof's own collection, use, and disclosure of information once a Customer authorizes LeakProof to connect to its Jobber account. It does not govern, and LeakProof does not control Jobber's own collection or use of information through the Jobber platform itself, which is addressed by Jobber's own privacy policy. Similarly, this Policy does not apply to the privacy practices of any other third party we do not own or control.
Where LeakProof processes de-identified feedback data for the purpose of improving the accuracy of its own detection technology (as described in Sections 4 and 8), LeakProof determines the purpose of that specific processing and acts as a controller (or "business" under the CCPA/CPRA) for it, distinct from its role as a service provider/processor for all other processing described in this Policy. This controller role is narrow in scope and limited to the point of extraction and de-identification; once data has been de-identified in a manner that meets applicable legal standards (irreversibly, with no reasonable means of re-identification), it generally ceases to constitute personal information under most applicable frameworks, and ongoing retention of that de-identified data falls outside the scope of personal-information obligations.
2. Information We Collect
2.1 Information You Provide Directly
Account information: name, business email, business name, and password (or OAuth credential) when you register;
Billing information: processed directly by Stripe; LeakProof receives limited billing metadata (e.g., plan, last four card digits, billing address) but not full payment card numbers;
Communications: information you provide when contacting support@useleakproof.com or otherwise corresponding with us.
2.2 Information Collected Automatically
Usage data: pages visited, features used, timestamps, and similar diagnostic data collected via our application and error-monitoring tooling;
Device/log data: IP address, browser type, and device identifiers collected automatically when you access the Service or website;
Cookies and similar technologies, as described in Section 6.
2.3 Information Processed Through the Service ("Job Content")
When a Customer connects its Jobber account, the Service retrieves and processes the following job-related content from Jobber to identify margin leaks:
Jobs: job identifier, job number, title, status, total value, job instructions, up to the ten most recent job notes (text), and job line items (name, quantity, price).
Visits associated with a job: visit title, visit instructions, and visit line item name/description.
Invoices: invoice identifiers, invoice number, status, subject and message (where read for sync purposes), line item name/description/quantity/price, linked product or service, and the invoice's Jobber web link.
Client information: the client's name, and the client's identifier when creating an invoice on the Customer's behalf. LeakProof does not collect the client's email address, phone number, or physical address through this process.
This content may incidentally include personal information about a Customer's technicians (for example, a technician's name appearing in a job note) or about a Customer's clients (whose name is read as described above).
LeakProof does not currently collect or process photographs, image attachments, audio recordings, or voice transcriptions from Jobber. If this changes in the future, this Policy will be updated before any such collection begins.
In addition to Job Content, the Service reads a Customer's Jobber team member ("Users") records for the specific purpose of calculating the Customer's subscription tier, which is based on the number of distinct field staff dispatched to jobs in a trailing period. This is a deliberate, structured data pull — not incidental — and includes, for each team member on the connected Jobber account: name, email address, phone number, mailing address, timezone, and administrative/ownership role. This data is used solely for subscription tier calculation and is not used for marketing, profiling, or any purpose unrelated to billing. See Section 4 for the specific purpose and Section 11 for the rights of individuals whose information is collected this way despite not being LeakProof account holders themselves.
3. Legal Bases for Processing (GDPR)
Where the UK or EU General Data Protection Regulation applies to our processing of personal information, LeakProof relies on the following legal bases:
Performance of a contract: processing account and billing information necessary to provide the Service under our agreement with the Customer.
Legitimate interests: processing usage and diagnostic data to secure, maintain, and improve the Service, balanced against individual privacy interests.
Consent: where required, for optional marketing communications or non-essential cookies.
Legal obligation: where processing is necessary to comply with applicable law.
Where LeakProof processes Customer Personal Data (technician or end-client information within Job Content, including Users-scope data described in Section 2.3) as a service provider/processor on behalf of a Customer, the Customer is responsible for establishing the applicable legal basis with its own technicians and clients, and LeakProof processes that data solely under the Customer's instructions, as further described in Section 7.
Where LeakProof acts as a controller for the narrow purpose described in Section 1 (improving detection accuracy using de-identified feedback data), LeakProof relies on legitimate interests as its legal basis — specifically, its interest in improving the accuracy and reliability of the Service for all Customers — balanced against individual privacy interests through the de-identification safeguards described in Section 8, which are designed to remove any reasonable possibility of re-identifying the individual, business, or job the data originated from.
4. How We Use Information
To provide, operate, and maintain the Service, including generating margin-leak findings and facilitating draft invoice creation in Jobber;
To calculate a Customer's subscription tier and billing based on the number of active field staff, using team member data obtained via the Jobber Users scope described in Section 2.3;
To process subscription payments via Stripe and manage billing;
To send transactional communications (e.g., account, billing, and product notices) via Resend, including scheduled operational digest emails a Customer may opt into or out of at any time (see Section 11.4);
To monitor, diagnose, and fix errors via Sentry;
To collect anonymized product usage analytics to understand feature usage and improve the Service (see Section 7);
To improve the accuracy of our AI-based detection and margin-leak identification rules over time, using de-identified feedback data generated when a Customer's team approves or dismisses a flagged item — this data is stripped of any information identifying the Customer, technician, client, or specific job before it is used for this purpose (see Section 8);
To generate de-identified, aggregated insights and statistics (for example, total revenue identified or recovered across our customer base), which may be retained indefinitely and used for business reporting or in marketing materials, without exposing any individual Customer's underlying data;
To respond to support requests;
To comply with legal obligations and enforce our Terms of Service.
5. AI Processing Disclosure
The Service uses a third-party artificial intelligence provider, Anthropic, PBC ("Anthropic"), to analyze Job Content and generate margin-leak findings. Job Content submitted for analysis is transmitted to Anthropic's API for processing and is subject to Anthropic's own data handling terms for API customers. LeakProof does not use Customer Job Content to train AI models operated by LeakProof, and Anthropic does not use content submitted through its commercial API to train its models, consistent with Anthropic's commercial terms.
As of the date this Policy was last reviewed, Anthropic's standard commercial API data retention policy is to automatically delete API inputs and outputs from its systems within 30 days of receipt or generation, except where longer retention is required to enforce Anthropic's usage policy or comply with law. Current details are published at Anthropic's data retention documentation (support.claude.com). This is a third-party policy outside LeakProof's control and may change; this section should be re-verified against Anthropic's current published terms at each review of this Policy, not treated as a one-time confirmation.
6. Cookies, Tracking Technologies & Advertising Disclosure
Our marketing website may use cookies and similar technologies for analytics and, if enabled, advertising measurement (for example, conversion tracking for Google Ads, Meta Ads, or LinkedIn Ads campaigns).
Where required by applicable law, we will provide a cookie consent mechanism allowing you to accept or reject non-essential cookies before they are set.
7. Data Sharing & Third-Party Subprocessors
We share information with categories of service providers, each engaged under contractual confidentiality and data protection obligations, solely to operate the Service. These categories include: cloud application hosting; database hosting and authentication; AI-based content analysis to generate margin-leak findings; payment processing and billing; error monitoring and diagnostics; transactional email delivery; anonymized product analytics; and business email and internal collaboration tools.
A current list of our specific subprocessors, including what each provider does and the categories of data each may access, is maintained separately at useleakproof.com/subprocessors and is updated from time to time as our vendors change. We will provide reasonable advance notice before adding a new subprocessor with access to Job Content, consistent with Section 14.
We do not sell personal information, as that term is defined under the CCPA/CPRA, and we do not share personal information for cross-context behavioral advertising, except to the extent standard advertising cookies described in Section 6 are later enabled on our marketing website.
We may disclose information where we reasonably believe it is necessary to satisfy applicable law, regulation, legal process, or a valid governmental request, including subpoenas, search warrants, civil investigative demands, or court orders; to enforce our Terms of Service, including investigating potential violations; and to detect, prevent, or address fraud, security, or technical issues. We may also disclose information in connection with a merger, acquisition, financing, or sale of assets, or due diligence for any such transaction, subject in all cases to the information remaining protected under materially equivalent terms.
8. Data Retention
We retain account and billing information for as long as the Customer maintains an active subscription. Retention periods after a Customer's subscription is canceled depend on the type of information, as follows:
General account data and Job Content (audit findings, flagged items, connection records): retained for 12 months following cancellation, after which it is deleted or, where described below, de-identified and retained only in aggregate or de-identified form. Disconnecting a Jobber account alone (without canceling the subscription) does not begin this period — see below.
Records evidencing actions LeakProof took on a Customer's behalf in Jobber (for example, creating a supplemental invoice or adding a line item to an invoice), and associated seat-based billing ledger records: retained for 6 years following the later of cancellation or the date of the relevant action, consistent with standard business record retention practice in Canada and comparable practice in the United States.
Feedback data generated when a Customer's team approves or dismisses a flagged item is, upon a Customer's cancellation, extracted into a de-identified form (stripped of any Customer, technician, client, or job identifiers) and retained indefinitely to improve the accuracy of our detection and rules over time, as described in Section 4. Once de-identified, this data is no longer associated with any individual or Customer.
De-identified, aggregate statistics about revenue identified or recovered across our customer base are retained indefinitely, as described in Section 4.
Note on what starts this clock: only cancellation of a Customer's subscription starts the retention periods above. Disconnecting a Jobber connection without canceling the subscription clears stored access credentials but does not trigger deletion of previously collected data, since the Customer may reconnect.
9. Data Security
We implement administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, or destruction, including access controls enforced through row-level security on our database, encrypted connections, and monitored error/alerting infrastructure. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. International & Cross-Border Data Transfers
LeakProof is based in Canada, and our service providers may process information in Canada, the United States, and other countries. Where personal information originating in the EU/UK is transferred outside those regions, we rely on appropriate safeguards, such as Standard Contractual Clauses, to the extent required by applicable law.
11. Your Rights and Choices
11.1 GDPR (EU/UK) Data Subject Rights
Where applicable, individuals may have the right to access, correct, delete, restrict, or port their personal information, and to object to certain processing. Requests relating to Customer Personal Data within Job Content should generally be directed to the relevant Customer (as data controller); LeakProof will assist Customers in responding to such requests as required by our processing agreement.
11.2 CCPA/CPRA (California) Rights
California residents may have the right to know, delete, correct, and opt out of the sale or sharing of personal information (noting that we do not currently sell or share personal information as described in Section 7), and the right to non-discrimination for exercising these rights.
11.3 PIPEDA (Canada) Rights
Canadian individuals may have the right to access and request correction of their personal information held by us, consistent with the Personal Information Protection and Electronic Documents Act.
11.4 Individuals Whose Data We Receive Without a Direct Account (e.g. Customer Team Members)
Some individuals' information — such as a Customer's field staff whose name, email, phone, and address are read via the Jobber Users scope described in Section 2.3 — is collected by LeakProof without that individual holding a LeakProof account or having interacted with LeakProof directly. Such individuals may contact us using the details in Section 15 to inquire about or request correction or deletion of their information; we will verify the request and either respond directly or route it to the relevant Customer, consistent with our role as a service provider under Section 3.
Where LeakProof operates opt-in features that send periodic communications on a Customer's behalf (such as the scheduled operations digest email), each such communication includes a direct, one-click opt-out mechanism that does not require logging into the Service.
To exercise any applicable right, contact us using the details in Section 15. We may need to verify your identity and, where the request concerns Job Content, may direct you to the relevant Customer. If we receive a request regarding information we process on a Customer's behalf and for which the Customer is accountable, we will direct the request to the relevant Customer and assist the Customer in responding, where possible.
12. Children's Privacy
The Service is intended for business use by individuals 18 years of age or older and is not directed to children. We do not knowingly collect personal information from individuals under 18. If we become aware that we have inadvertently collected such information, we will take steps to delete it.
13. Data Breach Notification
In the event of a security incident that results in unauthorized access to, or acquisition, disclosure, alteration, or destruction of personal information we hold, LeakProof will assess the incident's nature and scope and take reasonable steps to investigate and contain it. Where the incident poses a real risk of significant harm to affected individuals, or otherwise triggers a legal notification obligation, we will notify affected individuals and, where required, the applicable regulatory authority or authorities, without unreasonable delay and in the manner and within any timeframe required by applicable law.
For Canadian individuals, this includes our obligations under the Personal Information Protection and Electronic Documents Act (PIPEDA), including notification to the Office of the Privacy Commissioner of Canada and to affected individuals where the breach creates a real risk of significant harm, and maintaining records of all breaches of security safeguards regardless of whether that threshold is met.
For individuals in the United States, we will comply with applicable state data breach notification laws, which vary by state in their triggering thresholds, required timelines, and notification content, and may separately require notification to state regulators or credit reporting agencies depending on the nature and scale of the incident.
Where a Customer's own Job Content or Customer Personal Data (as described in Section 3) is affected, we will notify the affected Customer without unreasonable delay and provide the Customer with information reasonably necessary for the Customer to meet its own notification obligations to its technicians, clients, or regulators, consistent with our role as a service provider under this Policy.
14. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will provide notice (such as by email or in-product notice) before the changes take effect. The "Effective Date" above reflects the date of the most recent revision. We encourage you to review this Policy periodically.
15. Contact Us
If you have questions, comments, or requests regarding this Policy or your personal information, please contact us:
Inquiries: support@useleakproof.com
Mail address: Bellcrest Technologies Inc. #1094 201-1065 Canadian Place, Mississauga, ON L4W 0C2, Canada