Leakeo ("we", "our", "us") operates the Leakeo platform — a personal calendar and reminders app that helps you remember the dates that matter. This policy explains what personal data we collect, why we collect it, how we use it, and your rights under applicable data protection law.
By using Leakeo, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the platform.
Leakeo is an independent software product. For all data protection enquiries, use the in-app support form within your Leakeo dashboard or the contact form.
We do not collect analytics, tracking, or any personal data from visitors to the leakeo.com marketing website. If you browse leakeo.com without signing up, nothing about your visit is recorded or stored by us.
Our data collection applies only to:
We collect two distinct categories of data:
When you create and use a Leakeo account, we collect:
Leakeo processes behavioural and transactional event data from your store on your behalf. The tracking script (v5) collects the following categories of data from your store visitors:
_lk_vid (first-party cookie, 2-year expiry): a randomly generated UUID used to recognise returning visitors across sessions. This cookie is only set when consent is given. If your tracking script includes the data-consent="false" attribute, a session-only visitor ID is stored in sessionStorage instead (see GDPR consent support below). This identifier is not derived from personal information and cannot identify a specific individual._lk_uid (localStorage): a user identifier set via the window.leakeo.identify() API, used for cross-device user linking. Only present when explicitly set by your store's code.The following keys are stored in sessionStorage and do not persist beyond the browser session:
_lk_sid — session ID_lk_sent — event deduplication set_lk_pc — page count within the session_lk_ss — session start timestamp_lk_utm — UTM parameters, referrer hostname, screen dimensions, viewport dimensions, language, and connection type_lk_type — detected site type (ecom, saas, or unknown)_lk_vid_nc — no-consent visitor ID (only present when data-consent="false" is set)The tracking script collects the following event types from your store visitors. Full page URLs (including query parameters) are transmitted as part of each event.
window.leakeo.identify()).The following data points are derived server-side from request headers and are not sent by the visitor's browser:
If you connect Stripe or Shopify integrations, we receive revenue and subscription data directly from those platforms via signed webhooks:
You are the data controller for this data. We process it solely to provide you with the Leakeo service. The _lk_vid cookie is classified as an analytics cookie and requires consent from your store visitors under GDPR and the ePrivacy Directive. See our Cookie Policy for guidance on your disclosure obligations and our Data Processing Addendum for processing details.
| Purpose | Legal basis |
|---|---|
| Providing the Leakeo service (monitoring, incidents, alerts) | Contract performance |
| Account management and authentication | Contract performance |
| Billing and subscription management | Contract performance and legal obligation |
| Product analytics and service improvement | Legitimate interests (improving our platform) |
| Security monitoring and fraud prevention | Legitimate interests |
| Responding to support requests | Contract performance / legitimate interests |
| Compliance with legal obligations | Legal obligation |
We do not sell your personal data. We share data only with the following parties:
A full list of our subprocessors is available at leakeo.com/legal/subprocessors.
Our subprocessors (Google Firebase, Vercel, Stripe) may process data outside your country. Where they do, they rely on Standard Contractual Clauses or other recognised transfer mechanisms. Google Cloud and Stripe maintain GDPR-compliant data processing agreements.
You may request details of the specific safeguards in place via the in-app support form.
| Data type | Retention period |
|---|---|
| Raw event data (your store visitors) | 30 days from collection |
| Daily aggregated summaries (counters only, no personal data) | Retained indefinitely |
| Monthly rollup summaries | Retained indefinitely |
| Revenue events (hashed IDs and amounts only) | Retained indefinitely |
| Subscription events | Retained indefinitely |
| Billing and subscription records | 7 years (legal obligation) |
| Account profile data | Duration of account + 30 days after deletion |
| Usage analytics (internal) | 12 months rolling |
| Support tickets | 2 years |
| Security and access logs | 90 days |
Depending on applicable law, you may have the following rights regarding your personal data:
To exercise any of these rights, submit a request via the in-app support form. We will respond within 30 days.
We use a minimal set of cookies. The only cookie set by the Leakeo tracking script is _lk_vid, a first-party analytics cookie with a 2-year expiry. No third-party cookies, advertising cookies, or marketing cookies are used.
GDPR consent support: the tracking script supports a consent-aware mode. When you add the data-consent="false" attribute to the script tag, all cookie creation is deferred until your store visitor grants consent via window.leakeo.consent(). Until consent is given, a session-only visitor ID (stored in sessionStorage) is used instead of the persistent cookie, and up to 50 events are queued in memory and flushed only when consent is provided. If consent is never given during the session, no persistent identifiers are written.
See our Cookie Policy for full details.
We implement technical and organisational measures to protect your data, including HTTPS encryption in transit, Firebase authentication, Firebase App Check for request verification, server-side token validation, and signed webhooks. See our Security & Trust page for details.
No transmission over the internet is 100% secure. While we take reasonable steps to protect your data, we cannot guarantee absolute security.
Leakeo is a consumer service and is not directed at individuals under 16. We do not knowingly collect personal data from children.
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page. Continued use of the platform after changes constitutes acceptance of the revised policy. We recommend reviewing this page periodically.
For any questions about this policy or to exercise your data rights, use the in-app support form within your Leakeo dashboard, or the contact form on our website.