How it worksPricingTradesResourcesFor contractorsSign inPost a project
Post a project

Lehvel / Legal

Privacy policy

What we collect, who processes it, and what you can ask us to do about it — including the part where a description of your job is read by a model.

In effect August 16, 2026

Contents · 10 sections+
  1. What we collect
  2. How we use it
  3. Automated processing of your work descriptions
  4. Who processes data for us
  5. Cookies
  6. How long we keep it
  7. Security
  8. Your choices and rights
  9. Children
  10. Changes and contact

Contents

  1. What we collect
  2. How we use it
  3. Automated processing of your work descriptions
  4. Who processes data for us
  5. Cookies
  6. How long we keep it
  7. Security
  8. Your choices and rights
  9. Children
  10. Changes and contact

This policy describes what Lehvel collects, why, who processes it, and what you can ask us to do about it. It covers lehvel.com and the operator and contractor applications.

What we collect

You give us:

  • Account details — name, email address, password (stored only as a hash by our authentication provider), and the organisation you belong to.
  • Business details — for contractors, the trades you work, service area, and the licence, registration or insurance evidence you choose to provide.
  • Property and project data — addresses and unit details of properties you manage, descriptions of the work, photos, scopes of work, bids and line items, material requests and receipts, signatures, messages between the parties, approvals, and reviews.

We generate:

  • The audit record — an append-only log of who did what and when on a job. It is the product's core: scopes, signatures, approvals and payment events are written to it and are not silently editable.
  • Payment identifiers — the identifiers our processor issues for a customer, a connected account, a payment and a transfer.

We never store card numbers or bank account numbers. Those are collected and held by Stripe. Our database holds Stripe's identifiers, not your instrument.

Collected automatically: IP address, browser and device type, pages requested, and timestamps, for security and to understand which pages are used.

How we use it

To operate the platform: to match work to contractors, to structure a scope, to produce and sign a scope of work, to move money on your instructions, to notify you about a job, to support you, to detect fraud and abuse, to meet tax and accounting obligations, and to improve the product.

We do not sell your personal information, and we do not share it with third parties for their own advertising.

Automated processing of your work descriptions

When an operator describes a job, that description — with the property label and target dates — is sent to our AI provider so it can be structured into scoped jobs with price ranges. This is disclosed plainly because it is a real data flow that most policies leave vague: the text you type describing the work leaves our systems and is processed by Anthropic. Under the commercial terms that apply to that service, the content is not used to train their models.

The structured output is a draft. A person reviews and edits it before it becomes a posted job, and no decision with a legal or similarly significant effect on anyone is made automatically.

Who processes data for us

Processor What it handles
Supabase Database, authentication and file storage
Vercel Hosting, request logs, and privacy-friendly traffic analytics
Stripe Payments, payouts, escrowed funds, and identity checks on connected accounts
Anthropic Structuring the work descriptions described above
Google Analytics Site usage measurement, where enabled

Each acts on our instructions or as an independent controller for their own regulated purposes — Stripe, in particular, is a controller of the payment data it collects. We may also disclose data where the law requires it, to protect someone's safety or our rights, or to a successor if the business is acquired.

Cookies

We use a session cookie to keep you signed in — without it, the application cannot know who you are. Vercel's traffic analytics is cookieless. Where Google Analytics is enabled, it sets its own cookies for usage measurement; you can block them in your browser without losing access to any part of the site.

How long we keep it

Account and job records are kept while your account is open and afterwards for as long as we need them for tax, accounting and dispute purposes — generally seven years for transaction records. The audit log is append-only by design, so a job's history is retained even when related content is edited. Guides and reviews stay published unless removed under the terms.

Security

Traffic is encrypted in transit; the site is served over HTTPS with HSTS. Database access is governed by row-level security so an organisation's records are reachable only by its members. Payment credentials are held by Stripe, not by us. No system is perfectly secure, and we do not claim to be certified against a standard we have not been assessed for.

Your choices and rights

You can review and correct most of your information in the application, and you can ask us to close your account. Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, and to appeal a refusal. Write to privacy@lehvel.com and we will respond within the time the applicable law allows.

Some data cannot be deleted on request where we must keep it — a completed transaction and its audit trail, for example, are records we are obliged to retain, and they are also the other party's evidence.

Children

Lehvel is for business use by adults. It is not directed at anyone under 18 and we do not knowingly collect their information.

Changes and contact

Material changes will be posted here with a new effective date. Questions or requests: privacy@lehvel.com.

Terms of service →