Privacy Policy for LEAFIO Shelf Efficiency
Summary. LEAFIO Shelf Efficiency is a business application used by authorized employees, contractors, and suppliers of LEAFIO customers to receive and complete merchandising tasks, view and execute planograms, scan product barcodes, submit shelf and product images, and communicate execution results to the relevant customer organization.
We do not sell personal data, and the App is not used to provide third-party behavioral advertising.
1. Scope of this Privacy Policy
This Privacy Policy explains how Leafio Inc. and its applicable affiliates (“LEAFIO,” “we,” “us,” or “our”) access, collect, use, disclose, retain, and protect information in connection with the LEAFIO Shelf Efficiency mobile application (the “App”).
This Privacy Policy applies only to the App and related mobile services. It does not replace the privacy notice or internal policies of the retailer, supplier, employer, or other organization that provides a user with access to the App (the “Customer Organization”).
The App is intended for business use. User accounts are normally created, authorized, or managed by a Customer Organization rather than by individual consumers.
2. Roles and Responsibility for Data
Depending on the circumstances:
- The Customer Organization generally determines why and how business-user data and merchandising data are processed and may act as the data controller or business.
- LEAFIO generally processes such data on behalf of the Customer Organization as a processor or service provider under the applicable agreement.
- LEAFIO may act as an independent controller for limited information used for account security, service administration, legal compliance, support, and protection of the App.
Questions concerning work assignments, store data, planograms, uploaded shelf images, or account access should normally be directed first to the relevant Customer Organization.
3. Information We May Process
The categories of information processed depend on the App configuration, the Customer Organization, the user’s role, and the features used.
| Category | Examples | Primary purpose |
|---|---|---|
| Account and business identity information | Name, business email address, employee or supplier identifier, organization, role, assigned store or location, language, and account status. | Authentication, authorization, account administration, task assignment, and support. |
| Authentication information | Login identifiers, authentication tokens, session information, and single sign-on identifiers. LEAFIO does not intentionally store a user’s identity-provider password when SSO is used. | Secure sign-in, session management, and prevention of unauthorized access. |
| User-generated and operational content | Task completion records, comments, timestamps, planogram execution results, product or fixture measurements, product availability information, and other merchandising information entered or submitted through the App. | Delivering Shelf Efficiency functions, monitoring planogram execution, reporting, audit trails, and operational analysis. |
| Photos and images | Shelf photographs, realograms, product images, fixture images, and images selected from the device or captured with the camera. | Documenting shelf execution, comparing actual layouts with planograms, image-based recognition or validation, and reporting to the Customer Organization. |
| Barcode and scanner data | Product barcodes or other codes scanned by the user. | Identifying products, navigating planograms, updating product-related records, and completing merchandising tasks. |
| Device and technical information | Device model, operating system, App version, IP address, language, time zone, device or application identifiers, network information, and push-notification token. | Operating the App, maintaining compatibility, delivering notifications, securing sessions, troubleshooting, and service administration. |
| Usage, diagnostics, and security information | Feature interactions, login events, synchronization events, error logs, crash information, performance data, and security events. | Reliability, troubleshooting, fraud and abuse prevention, security monitoring, and product improvement. |
| Support communications | Messages, screenshots, attachments, contact details, and other information submitted in connection with a support request. | Responding to requests, resolving incidents, and improving support quality. |
Camera and Photo Access
The App may request access to the device camera or selected photos when a user chooses to scan a barcode, capture a shelf or product image, or upload an existing image. The App should request the relevant device permission before accessing these features. Images submitted through the App may be transmitted to and stored in the Customer Organization’s LEAFIO environment.
Location Data
The standard App functionality does not require precise background GPS tracking. IP addresses and other technical information may indicate an approximate region. If a Customer Organization enables a feature that requires device location, the App will provide an appropriate in-app disclosure and request the required permission before accessing location data.
4. How We Use Information
We may use information processed through the App to:
- authenticate users and manage access rights;
- provide, synchronize, maintain, and improve App functionality;
- deliver planograms, tasks, notifications, and operational instructions;
- allow users to scan barcodes, submit images, and report task completion;
- compare shelf images or execution results with approved planograms, including through image-recognition functionality where enabled;
- provide reporting, audit trails, analytics, and service administration to the Customer Organization;
- respond to support requests and diagnose technical problems;
- protect the App, users, customers, and LEAFIO against unauthorized access, fraud, abuse, and security threats;
- comply with contractual, legal, accounting, regulatory, and law-enforcement obligations; and
- establish, exercise, or defend legal claims.
5. Legal Bases for Processing
Where applicable data-protection law requires a legal basis, processing may be based on one or more of the following:
- performance of a contract or steps necessary to provide the App and related services;
- the legitimate interests of LEAFIO or the Customer Organization, such as service security, administration, support, and improvement;
- compliance with a legal obligation;
- consent, where consent is required for a specific permission or processing activity; or
- another legal basis available under applicable law.
6. How Information Is Shared
We may disclose information only as reasonably necessary for the purposes described in this Privacy Policy, including to:
- the Customer Organization, including its administrators, managers, and other authorized users;
- authorized suppliers or business partners where the Customer Organization has enabled a controlled supplier or partner workflow;
- LEAFIO affiliates and personnel who need access to operate, secure, support, or maintain the service;
- service providers that provide hosting, infrastructure, authentication, push notifications, diagnostics, security, customer support, or similar services under contractual obligations;
- professional advisers and authorities where reasonably necessary to comply with law, enforce agreements, investigate security issues, or protect legal rights; and
- a successor organization in connection with a merger, acquisition, restructuring, financing, or sale of all or part of the business, subject to appropriate safeguards and notice where required.
LEAFIO does not sell personal data obtained through the App and does not disclose it for third-party cross-context behavioral advertising.
7. Third-Party Services and SDKs
The App may use third-party software development kits or services for functions such as authentication, push notifications, application diagnostics, hosting, and security. These providers may process limited data on LEAFIO’s behalf only to provide the relevant service, subject to applicable contracts and legal requirements.
The specific providers may vary by deployment, region, operating system, and Customer Organization configuration. LEAFIO reviews relevant providers and limits their access to information reasonably necessary for the service they provide.
8. Data Retention
LEAFIO retains information only for as long as reasonably necessary for the purposes described in this Privacy Policy, as required by the Customer Organization’s instructions and the applicable service agreement, or as required by law.
Retention periods may vary by data category:
- Customer operational data, task history, and uploaded images are generally retained according to the Customer Organization’s configuration, contract, and documented instructions.
- Account information is generally retained while the account is active and for a limited period afterward where necessary for security, audit, contractual, or legal purposes.
- Logs, diagnostics, and security records are retained for a limited period appropriate to troubleshooting, security, and legal requirements.
- Backup copies may remain for a limited backup-retention period before being overwritten or securely deleted.
Information may be retained longer where necessary to comply with law, resolve disputes, enforce agreements, or protect legal rights.
9. Account and Data Deletion
The App does not normally provide self-service consumer account creation. Accounts are typically created and managed by a Customer Organization.
A user who wants to deactivate or delete an account, or request deletion of personal data associated with the account, may:
- contact the administrator or privacy contact of the relevant Customer Organization; or
- contact LEAFIO at [email protected].
LEAFIO will verify the request and, where LEAFIO processes the data on behalf of a Customer Organization, may refer the request to that organization or act on its documented instructions. Data that LEAFIO is legally required or permitted to retain may be excluded from immediate deletion.
10. Data Security
LEAFIO uses reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, loss, or destruction. These measures may include:
- encrypted transmission using modern transport encryption;
- role-based access controls and authentication mechanisms;
- logging, monitoring, and security-event management;
- restricted personnel access based on business need;
- backup and recovery processes; and
- security and confidentiality obligations for relevant service providers and personnel.
No method of transmission or storage is completely secure. Accordingly, LEAFIO cannot guarantee absolute security.
11. International Data Transfers
LEAFIO and its service providers may process information in countries other than the user’s country of residence. The applicable hosting region may depend on the Customer Organization’s contract and deployment configuration.
Where required, LEAFIO uses appropriate safeguards for international transfers, such as contractual data-protection terms, adequacy mechanisms, or other lawful transfer methods.
12. User Privacy Rights
Depending on the user’s jurisdiction and subject to applicable exceptions, a user may have the right to:
- request access to personal data;
- request correction of inaccurate or incomplete personal data;
- request deletion of personal data;
- request restriction of processing;
- object to certain processing;
- request portability of eligible personal data;
- withdraw consent where processing is based on consent; and
- submit a complaint to an applicable data-protection authority.
Because LEAFIO often processes App data on behalf of a Customer Organization, users should normally submit requests first to that organization. LEAFIO will assist the Customer Organization as required by applicable law and contract.
13. Children’s Privacy
The App is a business tool and is not directed to children. LEAFIO does not knowingly use the App to collect personal data from children under 13, or under a higher minimum age where required by local law. If LEAFIO learns that such data has been processed without appropriate authorization, it will take reasonable steps to delete or otherwise address the data.
14. Notifications
If enabled, the App may use a device push-notification token to send task assignments, planogram updates, reminders, service notices, or security messages. Users may manage notification permissions through the device settings, although disabling notifications may limit certain operational features.
15. Changes to this Privacy Policy
LEAFIO may update this Privacy Policy to reflect changes in the App, legal requirements, or data-processing practices. The updated version will be posted at a publicly accessible location and will show a revised effective date. Where required, LEAFIO or the Customer Organization will provide additional notice.
16. Contact Us
Questions, requests, or concerns about this Privacy Policy or the App’s handling of personal data may be sent to:
Leafio Inc.Email: [email protected]
Website: https://www.leafio.ai/
Mailing address: 16192 Coastal Highway, Lewes, Delaware 19958, USA