Legal

Privacy Policy

Last updated: July 19, 2026

This Privacy Policy explains how PayLeaf ("PayLeaf," "we," "us," or "our") collects, uses, discloses, and protects personal information. PayLeaf is operated by Nishan Singh, an individual based in British Columbia, Canada. PayLeaf is a payment tool that lets Canadian small-business vendors accept payments by QR code and send invoices that customers can pay online (and, in the future, Tap to Pay on iPhone).

We are committed to protecting your privacy in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and British Columbia's Personal Information Protection Act (PIPA).

The most important thing to know: PayLeaf is powered by Stripe. All card processing, banking, and identity verification are handled directly and securely by Stripe. PayLeaf never sees or stores card numbers, CVV codes, bank account details, Social Insurance Numbers (SIN), or government ID documents.

1. Who this policy covers

  • Vendors — business owners who create a PayLeaf account to accept payments.
  • Customers— people who pay a vendor through PayLeaf. We process limited customer information on the vendor's behalf (see Section 3).

2. Information we collect from vendors

Account information

  • Email address (from email signup or Sign in with Apple)
  • Name, where provided (e.g. by Apple on first sign-in)
  • Password — stored only as a secure hash by our authentication provider; we never see or store your plaintext password

Business profile

  • Business name, business type, and public payment slug (your payment link)
  • Business address (street, city, province, postal code)
  • Tax settings (province and GST/PST/HST/QST configuration)
  • Logo and invoice branding details you choose to add, such as your GST/HST number and payment terms, which appear on the invoices and receipts you send

Transaction records

  • Amounts, taxes, dates, payment status, invoice numbers, and optional notes or table numbers for sales you process
  • Stripe reference identifiers (such as payment and account IDs) used to reconcile payments — references only, not financial credentials

Invoices

  • The content of invoices you create: line-item descriptions, quantities and prices, taxes, invoice number, due date, and any notes you add
  • The customer details you enter for an invoice — customer name, and customer email address where you provide one so the customer can be sent a receipt
  • Invoice status (draft, unpaid, paid, or void) and the generated invoice PDF

You control what goes into an invoice. Please only enter customer information you are entitled to use for billing that customer.

Device and technical information

  • A push notification token for your device, so we can send payment alerts you've enabled
  • Login session tokens, stored securely on your device
  • If you enable biometric quick unlock (Face ID / Touch ID), we store only your on/off preference. Biometric data itself never leaves your device and is never accessible to PayLeaf — it is handled entirely by iOS.

What we deliberately do NOT collect from vendors

  • Bank account numbers, transit numbers, or banking credentials
  • Government ID, SIN, or date-of-birth verification documents
  • These are collected directly by Stripeduring payout onboarding and never pass through PayLeaf's systems. We store only Stripe's account reference and status (for example, whether payouts are enabled).

3. Information we process about customers

  • Card details go directly to Stripe.Customers enter their card information on Stripe's secure, hosted payment page. Card numbers never touch PayLeaf's servers, and we never store them. Stripe is certified to the highest industry standard (PCI DSS Level 1).
  • If the customer (or vendor) provides an email address or phone number to receive a receipt, we store it with the transaction and use it only to deliver that receipt.
  • For invoices, we store the customer name and — where the vendor provides one — the customer email address, so the invoice can be addressed and a receipt sent when it is paid.
  • We record the amount, taxes, date, and payment status of the transaction.
  • Digital receipts are viewable at a private link protected by an unguessable identifier; receipt pages are excluded from search engines.
  • An invoice payment page is likewise reachable only through its unguessable link and is excluded from search engines. That page deliberately shows only what is needed to pay — the business name, invoice number, line items, taxes and amount due. It does notexpose the customer's email address, your private invoice notes, or any Stripe identifiers.

We process this information on the vendor's behalf. Vendors are responsible for handling their customers' information appropriately.

4. AI invoice drafting

PayLeaf offers an optional feature that drafts invoice line items from a plain-language description of the work. This section explains exactly what happens when you use it.

The feature runs only when you ask it to. Nothing is sent for drafting unless you type a description and request a draft.

What is sent. When you request a draft, we send the following to our AI provider, Anthropic, to generate the suggestion:

  • The description of the work that you typed
  • Your business name and business type
  • The line items (descriptions and prices) from your three most recent invoices, so the suggested wording and pricing match your own

What is not sent.We do not send your customers' names, their email addresses or phone numbers, any card or banking information, or your account credentials. The past-invoice context is limited to line items — it does not include the customer those invoices were addressed to.

Nothing is saved until you save it. A draft is returned to your device for you to review and edit. The drafting step does not create or change any invoice on its own — an invoice is stored only when you save it through the normal invoice flow. AI drafts; you approve.

Anthropic processes this information as our service provider in order to return the draft, under its own terms and privacy policy — see anthropic.com/legal/privacy. Suggested prices and wording are drafting aids, not professional advice; you are responsible for the content of any invoice you send.

5. Why we collect and use information

We use personal information only to:

  • Create and operate vendor accounts
  • Enable payment acceptance through Stripe and route payouts to the vendor's own account
  • Calculate applicable Canadian sales taxes and generate receipts, invoices, and reports
  • Create, deliver and track invoices, including generating invoice PDFs and marking an invoice paid when payment settles
  • Draft invoice line items when you use the AI drafting feature (Section 4)
  • Send payment notifications and account alerts the vendor has enabled
  • Deliver receipts to customers by email (or SMS, where available)
  • Maintain security, prevent fraud and abuse, and enforce rate limits
  • Meet legal, tax, and accounting obligations
  • Provide customer support

We do not use your information for any other purpose without your consent.

6. What we do NOT do

  • We do not sell or rent personal information — to anyone, ever.
  • We do not show ads or share data with advertisers.
  • We do not use third-party analytics or tracking SDKs in the app.
  • We do not store card numbers, CVVs, bank credentials, SIN, or ID documents.
  • We do not track your location. (If Tap to Pay on iPhone launches in a future update, Apple requires location access at the time of an in-person transaction; it would be used only to process that payment and never to track you. We will update this policy when that feature becomes available.)

7. Service providers we share information with

We share information only with the service providers necessary to run PayLeaf, each bound by their own privacy and security obligations:

  • Stripe — payment processing, identity/bank verification, and payouts. Processes card data, banking and identity information (collected directly by Stripe) and transaction data. See stripe.com/privacy. Vendors also agree to the Stripe Connected Account Agreement during onboarding.
  • Supabase — database and authentication hosting. Processes account, business, invoice, and transaction records.
  • Anthropic — AI invoice drafting. Processes the work description you type, your business name and type, and line items from your recent invoices, only when you request a draft (see Section 4). See anthropic.com/legal/privacy.
  • Resend — email delivery. Processes email addresses and receipt, invoice, and verification email content.
  • Expo — push notification delivery. Processes device push tokens and notification content.
  • Apple — Sign in with Apple; App Store; and, in the future, Tap to Pay. Processes sign-in identity where you choose Apple sign-in.
  • Vercel — application hosting. Processes data transiting our servers and standard server logs.
  • Upstash — abuse prevention (rate limiting). Processes IP addresses and request counts.

We may also disclose information if required by law, regulation, or legal process, or to protect the rights, safety, and security of PayLeaf, our users, or the public.

8. Where your data is stored (cross-border transfer)

Our service providers store data on secure cloud infrastructure that may be located in the United States or other countries outside Canada. This means your information may be subject to the laws of those jurisdictions while stored there. We choose reputable providers with strong security practices, and we protect data in transit and at rest regardless of location.

9. How we protect your information

  • Encryption — data is encrypted in transit (TLS/HTTPS) and at rest.
  • No sensitive financial storage— card and bank data are handled exclusively by Stripe, keeping them out of PayLeaf's systems entirely.
  • Access controls — vendors can only access their own data; every data request is checked against the authenticated account. Privileged operations run only on our servers, never in the app.
  • Secure sessions— login sessions are stored in your device's secure storage, with optional biometric unlock.
  • Abuse protection — sensitive endpoints are rate-limited; webhooks are cryptographically verified; security headers and hardened configurations are applied.
  • Accountability — administrative and security-relevant actions are logged.

No system is perfectly secure, but we design so that the most sensitive data (cards, banking, identity) never enters our systems in the first place.

10. Data retention and deletion

  • We retain your information while your account is active.
  • You can delete your account in the app (Settings → Account → Delete Account). When you do, we remove or de-identify your personal information, including your business profile details.
  • Exception — financial records: transaction and invoice records are retained even after account deletion, in de-identified or minimal form, because Canadian tax and financial law requires businesses to keep transaction records (generally for six to seven years).
  • Residual copies may persist in encrypted backups for a limited period before being overwritten.

11. Your rights

Under PIPEDA and BC PIPA, you may:

  • Access the personal information we hold about you
  • Correct inaccurate or incomplete information
  • Withdraw consent or delete your account (this may end your ability to use PayLeaf)
  • Complain — first to us, and if unsatisfied, to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or the Office of the Information and Privacy Commissioner for British Columbia

To exercise any of these rights, contact support@payleafpayments.ca. We respond within a reasonable time as required by law.

12. Children's privacy

PayLeaf is a business tool for adults operating a business. It is not directed at children, and we do not knowingly collect personal information from anyone under the age of majority.

13. Changes to this policy

We may update this policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes, notify you in the app. Continued use of PayLeaf after changes take effect constitutes acceptance.

14. Contact

Nishan Singh (PayLeaf)
Email: support@payleafpayments.ca
British Columbia, Canada

This policy reflects PayLeaf's actual data practices as of the date above. It should be reviewed by a qualified Canadian privacy lawyer before being relied upon as a binding legal document.