Privacy Policy
Last updated August 18, 2026
This policy explains the information Leaster processes to provide accounts, rental-search tools, billing, support, security, and live-provider usage.
Information Leaster Stores
- Account information such as email address, display name, password hash, verification status, role, and account status.
- Authentication and security records such as hashed session or one-time tokens, CSRF values, rate-limit records, and security audit events.
- Customer content such as search rules, preferences, search runs, listing results, saved listings, and export records.
- Billing records such as Stripe customer and subscription identifiers, subscription state and dates, webhook event records, Top-Up purchases, grants, refunds, and credit-ledger entries.
- Guest Pass records, live-provider usage and reservation records, ZIP codes submitted for live searches, provider result data, and safe provider error categories.
- Bug reports, support details you choose to submit, outbound email metadata, request identifiers, page paths, browser user-agent strings, and operational logs.
How Information Is Used
Leaster uses this information to authenticate accounts, deliver requested searches, calculate credits and entitlements, process and reconcile billing, provide saved features, prevent abuse, diagnose problems, respond to support requests, and maintain financial and security records.
Service Providers
Stripe processes payment details and may provide Leaster with customer, subscription, invoice, Checkout, payment, and refund identifiers. Leaster does not store complete payment-card numbers. Render hosts the application and database, the configured email provider delivers account messages, and RentCast is the current external listing provider when live access is enabled. These providers process information under their own terms and privacy practices.
Cookies and Security
Leaster uses a necessary HttpOnly, SameSite session cookie to keep signed-in customers authenticated. It does not use this cookie for advertising. Passwords and one-time tokens are stored as cryptographic hashes; production email records do not retain one-time-link bodies or raw tokens.
Retention and Deletion
Expired sessions and one-time-token records are removed after a short operational grace period. Old outbound account-email records and stale rate-limit records are also removed. Customer search history and saved listings remain until you delete them or an approved retention policy changes. Billing, credit, provider-accounting, Stripe event, and security-audit records may be retained as needed for reconciliation, fraud prevention, disputes, accounting, and legal obligations.
You may request correction or deletion of eligible account information through Support. Some financial, security, or legal records may need to remain even after an account-related request.
Children and Changes
Leaster is not directed to children under 13, and customers must be at least 18 to create a paid account. Material changes to this policy should be posted here with an updated date.
Contact
Privacy questions may be sent to support@shwatkins.com.