LeaseDraftsStart · $49

Privacy Policy

Last updated: May 28, 2026 Effective date: May 28, 2026

This Privacy Policy describes how LeaseDrafts ("we," "us," or "our"), operated by Crowditory LTD (a company registered in the Republic of Cyprus, registration number HE 470687, registered office: Boumpoulinas St 26, Athienou 7600, Cyprus; corporate website: crowditory.com), collects, uses, and shares information when you use our website at leasedrafts.com (the "Service").

By using the Service, you agree to the practices described in this Privacy Policy.


1. Information we collect

1.1 Information you provide

When you use the Service to generate a residential lease, we collect the information you enter into the form, which may include:

  • Property details (address, type, bedrooms, bathrooms, square footage)
  • Landlord legal name and mailing address
  • Tenant name(s)
  • Lease term, rent amount, security deposit, late fee policy
  • Pet policy and utility arrangements
  • Any special clauses or notes you provide
  • Your email address (for delivery of the generated lease)

1.2 Payment information

When you purchase a lease, payment is processed by Stripe, Inc. We do not store full credit card or banking details on our servers. Stripe provides us with limited transaction metadata (payment confirmation, last four digits of card, billing country) which we retain for accounting and refund purposes.

1.3 Technical information

When you visit the Service, we automatically collect:

  • IP address
  • Browser type and version
  • Device type and operating system
  • Pages visited and time spent on each page
  • Referring website
  • Cookies and similar tracking technologies (see Section 6)

1.4 Information from third parties

We do not purchase or receive personal information from data brokers.


2. How we use information

We use the information we collect to:

  • Generate the lease document you requested
  • Deliver the generated lease to your email address
  • Process payments and provide receipts
  • Respond to support requests
  • Detect and prevent fraud or abuse
  • Comply with legal obligations
  • Improve the Service (in aggregate or anonymized form)
  • Send transactional emails related to your purchase (we do NOT send marketing emails unless you explicitly opt in)

We do not sell your personal information to third parties.


3. Legal bases for processing (for users in the EEA/UK)

If you are located in the European Economic Area or the United Kingdom, we process your personal data under the following legal bases:

  • Contract performance: To provide the lease generation service you purchased
  • Legal obligation: To comply with tax, accounting, and legal record-keeping requirements
  • Legitimate interests: To prevent fraud, improve the Service, and respond to inquiries
  • Consent: Where you have given explicit consent (e.g., for non-essential cookies)

4. Information sharing

We share your information only with the third-party service providers necessary to operate the Service:

Provider Purpose Data shared Location
Stripe, Inc. Payment processing Name, email, billing country, card data (handled directly by Stripe) USA
Anthropic, PBC AI-powered lease drafting Form data (property details, names, lease terms) USA
Resend, Inc. Email delivery Email address, lease PDF USA
Hetzner Online GmbH Server hosting and object storage All form data, generated PDFs Germany
Cloudflare, Inc. DNS and DDoS protection IP address, request metadata USA
Discord, Inc. Internal operational alerts (a webhook used to notify our team of paid orders, refunds, and failures) Submission ID, status, error message, redacted form summary USA
Google LLC (only if you opt in to Analytics cookies) Aggregate usage analytics via Google Analytics 4 Page-view events, anonymized IP, browser, device class USA
Meta Platforms, Inc. (only if you opt in to Advertising cookies) Future Facebook/Instagram ad-campaign attribution. Not currently active. Hashed email, IP, transaction event (not lease content) USA

Each provider is contractually required to maintain the confidentiality and security of your data.

We may also disclose information when required by law, court order, or to protect our legal rights or the safety of others.


5. International data transfers

Crowditory LTD is established in Cyprus. The Service is hosted on infrastructure located in Germany (Hetzner). Some of our service providers are located in the United States. When personal data is transferred outside the European Economic Area, we rely on the European Commission's adequacy decisions, Standard Contractual Clauses, or other lawful transfer mechanisms.


6. Cookies and tracking

The Service uses the following categories of cookies and similar technologies. A complete, itemized list of every cookie we set (name, purpose, retention) is published at /cookies, and your preferences can be changed at any time from the consent banner or that page.

6.1 Strictly necessary

Required for the Service to function: form autosave (lease-draft-{id} in localStorage), consent record (ld_consent), and staff sign-in (ld_admin, ld_oauth_state, ld_oauth_next). These cannot be disabled because the Service does not work without them.

6.2 Analytics (opt-in)

If you opt in to analytics on the consent banner, two services run:

  1. First-party funnel tracking (ld_session cookie) — identifies your browser across pages so we can see at which step of the form people drop off. The data is stored in our own database, is not sold or shared.
  2. Google Analytics 4 (cookies _ga, _ga_H43WR3JRBL, _gid) — measurement ID G-H43WR3JRBL, provided by Google LLC. We send Google anonymized usage events (page views, scroll depth). IP addresses are truncated server-side by Google (anonymize_ip=true). Google may combine this data with other data it holds about you across the web; we do not control that. See Google's privacy policy and Google Analytics terms.

If you decline analytics on our consent banner, neither service runs. No cookies are set, no Google script is loaded, and no events are recorded.

6.3 Advertising (opt-in, not active today)

We do not currently run any third-party advertising scripts (no Meta Pixel, no Google Ads tag). The consent banner includes an "Advertising" toggle so that when we eventually add one to measure ad-campaign effectiveness, it will only fire for users who have explicitly opted in. When this changes, /cookies will be updated and you will be re-prompted.


7. Data retention

We retain personal data for the following periods:

  • Form drafts (incomplete submissions): 14 days, then automatically deleted
  • Completed transactions: 7 years (for tax and accounting compliance), then deleted
  • Generated lease PDFs: 90 days in active storage; available on request thereafter for 7 years from secure backup
  • Email logs (transactional): 12 months
  • IP addresses and technical logs: 90 days

You may request earlier deletion of your data as described in Section 8.


8. Your rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your data (subject to legal retention obligations)
  • Restriction: Request restriction of processing in certain circumstances
  • Portability: Receive your data in a portable, machine-readable format
  • Objection: Object to certain types of processing, including direct marketing
  • Withdraw consent: Withdraw consent where processing is based on consent

To exercise these rights, email privacy@leasedrafts.com. We will respond within 30 days (or as required by applicable law).

8.1 California residents (CCPA/CPRA)

California residents have additional rights, including the right to:

  • Know what categories of personal information are collected
  • Request deletion of personal information
  • Opt out of "sales" or "sharing" of personal information (we do not sell personal information)
  • Non-discrimination for exercising privacy rights

To exercise California-specific rights, contact us at privacy@leasedrafts.com.

8.2 EU/UK residents (GDPR/UK GDPR)

You have the right to lodge a complaint with your local data protection authority. In Cyprus, this is the Office of the Commissioner for Personal Data Protection: www.dataprotection.gov.cy.


9. Children's privacy

The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected such information, we will delete it promptly.


10. Security

We implement reasonable technical and organizational measures to protect your data, including:

  • TLS encryption for all data in transit
  • Encrypted storage of personal data at rest
  • Restricted internal access on a need-to-know basis
  • Regular security reviews of our infrastructure

No system is fully secure, and we cannot guarantee absolute security. You are responsible for the security of your account credentials (where applicable) and the device you use to access the Service.


11. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify users by:

  • Posting a notice on the Service
  • Updating the "Last updated" date at the top of this policy
  • Where required by law, sending email notice to users with active transactions

Your continued use of the Service after changes constitutes acceptance of the updated policy.


12. Contact us

For questions about this Privacy Policy or our data practices:

Crowditory LTD (Cyprus company registration number HE 470687) Boumpoulinas St 26 Athienou 7600 Cyprus

Corporate website: crowditory.com Email: privacy@leasedrafts.com Data Protection Officer (if applicable): dpo@leasedrafts.com


End of Privacy Policy.