LEO CRM, Inc. (doing business as Leo Innovate)
Last Updated: [August 14, 2026] Effective Date: [August 14, 2026]
LEO CRM, Inc. (“Leo Innovate,” “we,” “us,” or “our”) values your trust and is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and protect information when you visit our websites, use our mobile applications, interact with our platform, communicate with us, or otherwise engage with our services (collectively, the “Services”).
This Privacy Policy applies to the websites, mobile applications, products, and services we operate under the Leo Innovate brand, including business management software, online booking and walk-in management tools, marketing and AI-assisted tools, branded app services, websites, customer support, payment and merchant-service functionality, hardware-related services, and related business solutions for beauty and wellness businesses.
Leo Innovate operates a platform used by beauty and wellness businesses (“Business Customers”) to serve their own clients and staff. Our privacy responsibilities depend on whose data is involved:
Company Name: LEO CRM, Inc.
Brand Name: Leo Innovate
Mailing Address: 5717 Red Bug Lake Rd, Suite 304, Winter Springs, FL 32708
Email: [email protected]
Phone: 1-800-701-0104
If you enable location features on a mobile device, we may collect precise geolocation with your permission. You can disable this in your device settings.
If you make a purchase or use payment functionality, we may collect or receive billing contact details, transaction details, payment status, and partial payment-related metadata. We do not store full payment card numbers. Payment card data is processed by PCI-compliant third-party payment processors and merchant-service providers.
Certain information we handle may be considered “sensitive” under applicable law, such as precise geolocation, login credentials, and financial account information. We process sensitive personal information only as needed to provide the Services, and we do not use or disclose it for purposes to which the right to limit applies without providing the choices described in Section 10. We do not sell sensitive personal information.
We share information with vendors and service providers that help us operate, including providers of cloud hosting, data storage, analytics, customer support, email delivery, SMS delivery, payment processing, merchant services, security and fraud prevention, and app hosting. These providers are bound by contract to use the information only to perform services for us.
We may allow certain advertising and analytics partners to collect information through cookies and similar technologies to measure and improve our marketing. Under some state laws, this activity may be considered a “sale” of personal information or “sharing” for cross-context behavioral advertising, even when no money changes hands. You can opt out as described in Section 10 and by using an opt-out preference signal such as Global Privacy Control (see Section 8).
If you use features that send messages, invite users, publish content, enable bookings, or share information with customers, staff, or third parties, we process and transmit that information as part of providing the Services.
We may disclose information in connection with a merger, acquisition, financing, reorganization, sale of assets, or similar transaction. We will require the recipient to honor this Policy or provide notice of material changes.
We may disclose information if required by law, subpoena, court order, or other legal process, or where we believe disclosure is necessary to comply with applicable law, enforce our agreements, protect rights, property, or safety, or investigate fraud, abuse, or security issues.
We may use and disclose aggregated or de-identified information that does not identify you. We maintain and use such information in de-identified form and do not attempt to re-identify it except as permitted by law.
Some Services include AI-assisted and marketing tools that analyze usage and content to generate suggestions, insights, or communications. Where we engage in profiling that produces legal or similarly significant effects about an individual, residents of certain states may opt out. To exercise this choice, contact us using the details in Section 2. We do not use your content to train third-party foundation models except as disclosed to you or as permitted by our agreement with your Business Customer.
We use cookies, pixels, local storage, and similar technologies to keep users logged in, remember preferences, improve performance and functionality, analyze traffic and usage, support security and fraud prevention, and measure marketing effectiveness.
You can adjust your browser settings to refuse or limit cookies, and where required we provide a cookie preference tool. Some features may not function properly if cookies are disabled. For advertising-related cookies, see Sections 8 and 10.
Global Privacy Control (GPC) and similar opt-out preference signals let you communicate a choice to opt out of sale or sharing of your personal information at the browser or device level. Where required by law, we treat a detected GPC signal as a valid request to opt out of the sale and sharing of personal information for that browser or device, and, where applicable, we display a confirmation that your signal has been honored.
Do Not Track (DNT) is an older browser setting. Because there is no consistent industry standard for interpreting DNT signals, we do not respond to DNT, but we do honor GPC as described above.
We may send transactional or service-related communications such as account notices, booking confirmations, appointment reminders, verification messages, billing notices, support updates, and security alerts. We may also send marketing or promotional messages where permitted by law and with any consent required.
You can opt out of marketing emails using the unsubscribe link. You can opt out of marketing text messages by replying STOP where applicable; reply HELP for help. Message and data rates may apply. Opting out of marketing does not stop service-related or transactional communications. Our SMS practices are further described in our Text Message Policy.
Depending on where you live and subject to legal exceptions, you may have some or all of the following rights regarding personal information for which we are the controller:
Submit a request by email to [email protected] or by phone at 1-800-701-0104. To opt out of sale/sharing and targeted advertising, use the same channels or enable Global Privacy Control (Section 8). We will not discriminate against you for exercising your rights.
You may use an authorized agent to submit a request on your behalf. We may require the agent to provide proof of authorization and may require you to verify your identity directly.
We may need to verify your identity before processing certain requests and will only use information provided for verification for that purpose.
If we decline your request, you may appeal by replying to our decision or by contacting [email protected] with the subject line “Privacy Appeal.” We will respond within the timeframe required by applicable law. If your appeal is denied, you may contact your state attorney general.
If your request concerns data held by a beauty or wellness business that uses our platform (a Business Customer), we will refer your request to that business as the controller, or act on their documented instructions, as required by law.
In the preceding twelve months, we have collected the categories of personal information described below. Sources, purposes, and recipients are described in Sections 3 through 5.
| Category of Personal Information | Examples |
|---|---|
| Identifiers | Name, business name, email, phone, address, IP address, account identifiers |
| Customer records | Billing details, transaction and payment metadata |
| Commercial information | Products or services purchased, subscription and usage history |
| Internet/network activity | Browsing and usage data, log data, interactions with our sites and apps |
| Geolocation | Approximate location from IP; precise location only with permission |
| Audio/visual/content | Images, uploads, notes, and messages you submit |
| Professional/business | Business role, staff information entered by Business Customers |
| Sensitive personal information | Login credentials, financial account information, precise geolocation (where applicable) |
| Inferences | Preferences and characteristics derived from the above to personalize the Services |
Business or commercial purposes for collection are described in Section 4. Categories of third parties and service providers are described in Section 5. California residents have the rights to know, delete, correct, opt out of sale/sharing, limit sensitive personal information, and non-discrimination, and may appeal as described in Section 10. We will not retaliate for the exercise of these rights.
If you are a resident of a state with a comprehensive privacy law, you have the rights described in Section 10, including access, correction, deletion, portability, opt-out of targeted advertising, sale, and certain profiling, and the right to appeal. Contact us using the details in Section 2 to exercise these rights.
Nevada residents may direct us not to make certain sales of covered information. Submit a request to [email protected].
We retain personal information for as long as reasonably necessary to provide the Services, maintain business and financial records, resolve disputes, enforce agreements, and meet legal, tax, accounting, compliance, and security obligations. Retention periods vary by the type of information and the purpose for which it was collected. When information is no longer needed, we delete, de-identify, or securely store it.
We use reasonable administrative, technical, and physical safeguards designed to protect personal information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a security incident affecting your personal information, we will notify you and regulators as required by applicable law.
Our Services are intended for businesses and are not directed to children under 13, and we do not knowingly collect personal information directly from children under 13. Where a Business Customer collects information about minors through the platform, the Business Customer is responsible for obtaining any required consent. We provide additional protections for the personal data of minors where required by law and do not sell or use the personal data of known minors for targeted advertising without any required consent. If you believe a child has provided personal information to us improperly, contact us and we will take appropriate steps.
Our Services may contain links to third-party websites, services, integrations, or platforms. We are not responsible for their privacy practices. We encourage you to review their privacy policies before providing information to them.
Our Services are primarily intended for users in the United States. If you access the Services from outside the United States, you understand that your information may be transferred to, stored in, and processed in the United States or other jurisdictions where our service providers operate, which may have different data protection laws than your jurisdiction.
We aim to make this Policy accessible. If you need this Policy in an alternative format, contact us at [email protected].
We may update this Privacy Policy from time to time. If we make material changes, we will update the “Last Updated” date, and, where required by law, provide additional notice. Your continued use of the Services after an update becomes effective means you accept the revised Policy. Prior versions are available on request.
LEO CRM, Inc.
5717 Red Bug Lake Rd, Suite 304, Winter Springs, FL 32708
Email: [email protected] Phone: 1-800-701-0104