This overview expands on the safeguards described in the Privacy Policy and Data Processing Addendum.
1. Security approach
Leafine applies defense-in-depth measures to prevent, detect, and respond to incidents. No system is completely secure, but we work to protect the confidentiality, integrity, and availability of the Services and the data they process.
2. Encryption
Leafine uses encryption in transit and at rest to protect personal data during transmission and storage.
Connected Platform data is accessed through approved APIs and protected with technical measures during international transfer.
3. Access controls
Leafine applies access controls and least-privilege principles. Personnel and service providers receive access only as needed to operate and support the Services and are subject to confidentiality obligations.
Merchants are responsible for safeguarding account credentials and API keys, managing Authorized User access, and notifying Leafine immediately of unauthorized use.
4. Logging and monitoring
Leafine uses audit logging and continuous monitoring to secure accounts, prevent fraud, investigate incidents, diagnose reliability issues, and monitor application performance.
PostHog EU Cloud receives consented analytics, masked replay, errors, logs, AI performance metadata, and operational form submissions. Chat prompts and responses are excluded. Sensitive form and chat regions are blocked from replay, and telemetry payloads are sanitized before delivery. New Relic receives request handler names and timing only and does not receive message content.
5. Data minimization and AI processing
Subprocessors receive only the data described on the Subprocessors page for the stated purpose.
OpenAI is Leafine's only AI subprocessor. Google Workspace data is never used to train or improve an AI or machine learning model, including by subprocessors. No other third-party AI provider receives Gmail data.
6. Platform security
Leafine connects to Shopify, TikTok, Meta, Google, and other Platforms through approved APIs and processes their data according to applicable developer and data policies.
For Gmail, Leafine requests only the https://www.googleapis.com/auth/gmail.modify scope and does not delete messages, create drafts, or change account settings.
7. Incident response
Leafine works to prevent, detect, investigate, and respond to incidents quickly. We may suspend activity where necessary to address a security, legal, reputational, or Platform risk.
We provide reasonable assistance for personal-data breach investigation and notifications required by applicable law.
To report suspected misuse or a security issue, contact security@leafine and include “Security” in the subject line.
8. Merchant responsibilities
Merchants must protect their credentials, review permissions granted to Authorized Users and connected Platforms, maintain appropriate human oversight of automated actions, and ensure Merchant Data is processed lawfully.
The Acceptable Use Policy describes prohibited conduct and enforcement measures.