Last updated July 22, 2026
Privacy Policy
Green Leaf Labs collects only the information needed to understand and respond to service requests, operate the website safely, and improve the customer journey.
Information we collect and why
When you submit our intake form, we collect your name, email address, phone number, organization name, selected service, project details and message, plus limited technical and consent information. We use this information to review your request, determine whether the project is a fit, communicate with you, prepare a quote or invoice, deliver agreed services, keep business records, prevent abuse, and meet legal obligations. Please do not send passwords, payment-card details, government identifiers, or other unnecessary sensitive information through the form.
How we use and share information
We do not sell client data. We use intake information only for the purposes described above and do not use it for unrelated advertising. We share it only with service providers that help us run the intake and payment process, or where disclosure is required or permitted by law.
Analytics and security
When enabled, our first-party analytics record limited events such as page views, calls-to-action, and successful form submissions. These events do not include your name, email, message, or full IP address and do not use advertising cookies. Security services such as Cloudflare Turnstile may process technical information needed to distinguish people from automated abuse.
Supabase, Stripe, and cross-border processing
We store intake information and related payment-status records in Supabase, a third-party cloud database provider. We use Stripe, a third-party payment processor, to issue and process invoices. Stripe receives payment information needed to process an invoice; Green Leaf Labs does not collect or store full payment-card numbers through its website. Supabase and Stripe may transfer, store, or process personal information in the United States or other jurisdictions outside Canada. Information processed in another country may be subject to that country’s laws and may be accessible to government, law-enforcement, or national-security authorities where legally required.
Green Leaf Labs remains responsible for personal information in its custody or control when we use these service providers. We use contractual and other safeguards intended to require a level of protection comparable to the protection we provide, and we limit each provider’s use of personal information to providing its services to us.
Retention and protection
We retain intake information for [DATA RETENTION PERIOD], unless a longer period is needed for an active project, accounting, dispute resolution, backup recovery, or legal compliance. We use access controls, encrypted connections, restricted server credentials, monitoring, and backups appropriate to the sensitivity of the information.
Access, correction, and complaints
Where PIPEDA applies, you can ask to access the personal information we hold about you, learn how we have used or disclosed it, or ask us to correct information that is incomplete or inaccurate. To make a request, contact [PRIVACY CONTACT — NAME/ROLE AND EMAIL] and include enough information for us to verify your identity and find the relevant record. We will respond as required by applicable law. If you have a privacy concern, please contact us first so we can try to resolve it. You may also file a complaint with the Office of the Privacy Commissioner of Canada.
Privacy contact
Our designated person accountable for privacy matters is [PRIVACY CONTACT — NAME/ROLE AND EMAIL].
Changes
We may update this policy as our services or providers change. The current version and revision date will remain available on this page.
