Privacy Policy
Effective date: [EFFECTIVE_DATE] · Last updated: [EFFECTIVE_DATE]
1. Introduction and Scope
This policy explains how LancerLoadout, operated by Pushkar Kumar Mishra (“we”, “us”), handles personal data. It covers two different groups of people:
- Users — freelancers and businesses who create a LancerLoadout account.
- Viewers — people (typically a User's clients) who open a public proposal, scope agreement, or client guide link. Viewers do not need an account, and we deliberately collect very little about them — see Sections 3 and 4.
This policy is written to be read in one pass, item by item. If anything is unclear, email [SUPPORT_EMAIL] and we will explain in plain language.
2. Our Roles
- For account data, usage data, and page engagement analytics, we decide how and why the data is processed — we are the data controller (GDPR) / data fiduciary (DPDP Act 2023).
- For Client Content — the details Users enter about their own clients inside proposals, agreements, and guides — the User decides what to collect and why. We process that content only to provide the Service, acting in a processor-like role. Users are responsible for their own obligations to their clients.
- For international payments, Lemon Squeezy is the Merchant of Record and an independent controller of the payment transaction data it collects at checkout, under its own privacy policy. For payments in India, Razorpay processes payment data under its own privacy policy.
3. Information We Collect
| Category | Data | Source | Purpose |
|---|---|---|---|
| Account | Name, email address, profile image | Google sign-in (OAuth) | Create and secure your account; send transactional email |
| Profile & branding | Brand name, brand logo, brand color, timezone | You | Display your branding on your pages; schedule reminders in your timezone |
| Client Content | Proposals, agreements, guides — including client names, project details, and pricing you enter | You | Provide the Service: store, render, and share your documents at your direction |
| Usage & plan | Plan status, credit balance and transactions, feature usage counts, page creation activity | Generated by the Service | Operate free limits, credits, and fair-use caps; billing state |
| Payment confirmation | Order/subscription identifiers, plan purchased, transaction status, billing country | Razorpay / Lemon Squeezy webhooks | Activate what you paid for. We never receive or store card or bank details. |
| Viewer analytics (public pages) | Timestamp of visit, browser user-agent, device type (parsed from user-agent), referrer domain, time on page, per-section reading time, acceptance events | Viewer's browser | Show Users how their documents are engaged with; hot-lead detection; reminder timing |
| Support | Emails you send us and our replies | You | Answer questions; resolve grievances |
4. What We Deliberately Do Not Collect
Our viewer tracking is privacy-conscious by design. On public pages we do not collect, store, or derive:
- IP addresses (our analytics database contains no IP data for viewers);
- geolocation of any kind;
- device fingerprints or persistent identifiers;
- the Viewer's name, email, or identity — a visit is not linked to a person;
- tracking or advertising cookies (public pages set no tracking cookies at all).
One honest caveat: like every website, our infrastructure providers (hosting and networking) transiently process IP addresses as a technical necessity of serving web traffic, including short-lived security logs. Those infrastructure logs are not linked to viewer analytics, are not used to identify Viewers, and are retained only briefly under the providers' standard practices. We also do not use any third-party analytics or advertising SDKs anywhere in the Service.
5. How We Use Information
- Provide, maintain, and secure the Service and your account;
- render your public pages and show you engagement analytics for them;
- operate plans, free limits, credits, and fair-use caps;
- send transactional email (for example, sign-in related messages and proposal expiry reminders) via our email provider;
- generate AI drafts when you explicitly request one (Section 6);
- respond to support requests and grievances;
- comply with law, prevent abuse, and enforce our Terms.
We do not sell personal data. We do not share personal data with advertisers. We do not use Client Content or Viewer analytics for advertising.
6. AI Processing Disclosure
When you click to generate an AI draft (for example, a follow-up message for a proposal), we send the relevant proposal content and its engagement summary to a third-party AI provider to produce the draft. This happens only when you invoke the feature — never automatically in the background.
- Current provider: Google (Gemini API), used under Google's paid API terms, under which inputs and outputs are not used to train Google's models. The provider may retain data briefly for abuse monitoring under its terms.
- We may add or switch providers (for example, Anthropic) to maintain quality and availability; this section will always name the current provider(s).
- Generated drafts are ephemeral: we do not store them after they are shown to you, unless you paste the text into your own content.
- If you prefer that a given proposal's content never be sent to an AI provider, simply do not use the AI features on it — nothing is sent unless you invoke them.
7. Who Sees Viewer Analytics
Engagement analytics for a public page (visit times, device type, referrer, reading time, section engagement) are shown to the User who owns that page, so they can follow up appropriately. Every public page displays a short privacy notice to Viewers disclosing this. Analytics are not public and are not shared with other users.
8. Legal Bases for Processing
Where the GDPR or UK GDPR applies: we rely on contract (account, plan, and billing data — needed to provide what you signed up for); legitimate interests (viewer engagement analytics in a B2B document-negotiation context, service security, and abuse prevention — balanced against rights by our no-IP, no-identity design); consent (where we ask for it explicitly); and legal obligation (financial records).
Where India's DPDP Act 2023 applies: we process personal data with consent given at sign-up after notice, and for legitimate uses recognized by the Act (including voluntary provision of data for a specified purpose, and compliance with law). You may withdraw consent at any time as easily as it was given — by deleting your account in Settings or emailing [SUPPORT_EMAIL] — after which we stop processing and delete data per Section 11, subject to legal retention duties.
California (CCPA/CPRA): we do not sell or share personal information as those terms are defined in the CCPA, and we do not use sensitive personal information beyond providing the Service. California residents may exercise access, deletion, and correction rights via [SUPPORT_EMAIL]; we do not discriminate for exercising rights.
9. Processors and Third Parties We Use
| Provider | Role | Data involved | Location |
|---|---|---|---|
| Supabase | Database and file storage | All Service data (account, content, analytics) | ap-south-1 (Mumbai, India) |
| Cloudflare | Application hosting and delivery | Traffic to the app and public pages (transient) | Global edge network |
| Sign-in (OAuth); AI drafting (Gemini API, paid tier) | Name, email, profile image (sign-in); proposal content + engagement summary (only when you invoke AI) | Global | |
| Resend | Transactional email delivery | Your email address and message content (e.g., expiry reminders) | Global |
| Lemon Squeezy | Merchant of Record for international purchases (independent controller) | Checkout and payment data it collects; we receive order status only | USA/Global |
| Razorpay | Payment gateway for purchases in India | Payment data it collects; we receive transaction status only | India |
We share personal data only with the providers above (to run the Service), when required by law or valid legal process, to protect rights and safety, or with your direction/consent. If the business is reorganized (for example, incorporated as a company), data may transfer to the successor under this same policy, with notice.
10. Cookies
The logged-in application uses essential cookies only: session/authentication cookies required for sign-in to work, and security tokens. We do not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies anywhere. Public pages set no tracking cookies. Because we use only strictly necessary cookies, no cookie-consent banner is required; if we ever introduce non-essential cookies, we will ask for consent first.
11. Data Retention
| Data | Retained | Then |
|---|---|---|
| Account and profile data | While your account exists | Deleted within 30 days of account deletion |
| Client Content (your documents) | Until you delete the page, or your account is deleted | Deleted within 30 days; residual copies in encrypted backups age out within 35 days after that |
| Viewer analytics for a page | While that page exists | Deleted with the page (and with account deletion) |
| Credit ledger and usage counters | While your account exists | Deleted within 30 days of account deletion, except records needed for financial compliance |
| Payment/transaction records | As required by Indian tax and accounting law | Up to 8 years, then deleted |
| Support correspondence | Up to 24 months after resolution | Deleted |
| Infrastructure security logs (providers) | Short-lived, per provider standards | Rotated automatically (typically well under 12 months) |
We erase personal data once its purpose is served or consent is withdrawn, whichever is earlier, unless a legal duty requires longer retention. Bracketed values are our current retention settings and may be tightened; the published policy will always reflect current practice.
12. Your Rights
Depending on where you live, you have some or all of the following rights, and we honor them for all Users regardless of location wherever feasible:
- Access — obtain a copy of the personal data we hold about you and a summary of processing;
- Correction — fix inaccurate or incomplete data (most account data is editable directly in Settings);
- Erasure — delete your account and data (Settings, or email us);
- Portability — receive your Client Content in a usable export;
- Objection / restriction — object to or restrict processing based on legitimate interests;
- Withdraw consent — at any time, as easily as it was given, without affecting prior lawful processing;
- Grievance redressal — raise a complaint and receive a timely response (Section 13);
- Nomination (DPDP) — nominate a person to exercise your rights in the event of death or incapacity, by writing to [SUPPORT_EMAIL].
To exercise any right, use Settings where available or email [SUPPORT_EMAIL] from your account email. We may verify your identity via that email. We respond within the timelines in Section 13. Viewers can also contact us with questions, though by design we hold no data that identifies a Viewer personally.
13. Grievance Redressal
Grievance contact: Pushkar Kumar Mishra, Grievance Officer, email [SUPPORT_EMAIL], Chainpur, PO Mittanchak, PS Sampatchak, Patna District, Bihar 804453, India. We acknowledge grievances within 48 hours and aim to resolve them within 30 days — in all cases within the timelines required by applicable law (the Consumer Protection (E-Commerce) Rules, 2020 require acknowledgement within forty-eight hours and redressal within one month; the DPDP Rules 2025 require response within a period not exceeding 90 days). If you are in India and are not satisfied with our resolution, you may escalate to the Data Protection Board of India. If you are in the EU/UK, you may lodge a complaint with your local supervisory authority.
14. International Data Transfers
Our providers store and process data in the locations listed in Section 9, which may be outside your country. India's DPDP framework permits cross-border transfer except to territories restricted by the Central Government; we monitor those notifications. Where GDPR applies to a transfer outside the EEA/UK, we rely on our providers' safeguards, including Standard Contractual Clauses and equivalent mechanisms in their data processing agreements.
15. Security
We use reasonable technical and organizational safeguards appropriate to a service of our size: encryption in transit (HTTPS everywhere), encryption at rest by our database provider, row-level access controls so accounts can only reach their own data, scoped API keys, least-privilege access, and no storage of payment credentials at all. No internet service can guarantee absolute security; keep your Google account protected (we recommend two-factor authentication).
16. Data Breach Notification
If a personal data breach occurs that affects you, we will inform affected Users without undue delay in plain language — what happened, what data was involved, what we are doing, what you can do, and how to reach us — and will notify the Indian Computer Emergency Response Team (CERT-In) within six hours of becoming aware of a reportable cyber incident, and the Data Protection Board of India and/or other supervisory authorities within the timelines required by applicable law (including the 72-hour reporting requirements under the DPDP Rules 2025 and GDPR where they apply).
17. Children
The Service is for adults (18+) and is not directed at children. We do not knowingly collect children's data. If you believe a child has created an account, contact [SUPPORT_EMAIL] and we will delete it.
18. Changes to This Policy
We may update this policy as the Service or the law evolves. For material changes we will notify Users by email or in-product notice before the change takes effect. The “Last updated” date reflects the current version.
19. Contact
LancerLoadout · operated by Pushkar Kumar Mishra · Chainpur, PO Mittanchak, PS Sampatchak, Patna District, Bihar 804453, India · [SUPPORT_EMAIL].