Privacy Policy

Version 2

Effective Date: August 9, 2026

Effective date: August 9, 2026
Last updated: August 9, 2026

GENERAL SOFTWARE COMPANY LLC, doing business as centerleap (“centerleap,” “we,” “us,” or “our”), explains in this Privacy Policy how we collect, use, disclose, retain, and protect personal information when you use centerleap.com, app.centerleap.com, and the centerleap mobile applications.

This Policy applies when we act as a controller of personal information, such as for website visitors, account holders, billing contacts, and support contacts. When an organization uses CenterLeap to process information about its customers, employees, contractors, or other people, that organization is generally the controller and centerleap acts as its processor or service provider under our Data Processing Addendum.

1. Scope and the mobile applications

This Policy applies to one CenterLeap mobile application for each platform:

  • centerleap for iOS — bundle identifier com.centerleap.ios.
  • centerleap for Android — application identifier com.centerleap.android.

These applications provide access to authorized CenterLeap platform features. Not every feature is available to every organization or user.

2. Personal information we collect

The categories below depend on the Services you use, administrator settings, and the choices you make.

2.1 Information you provide or an organization provides

  • Account and organization information: name, business name, email address, optional phone number, role, profile details, organization membership, and authentication information.
  • Customer Content: messages, emails, SMS/MMS, call and voicemail information, recordings and transcripts when enabled, documents, e-signature information, CRM records, contact information, notes, tasks, files, images, and other material submitted through the Services.
  • AI inputs and outputs: prompts, documents, queries, and generated output that you choose to submit to an AI-assisted feature.
  • Support, feedback, and legal communications: information you include when you contact us, report content, respond to a survey, or submit a rights request.
  • Payment and transaction information: billing contact details, subscription information, and payment-status information. Payment-card information is processed by the applicable payment processor rather than stored by centerleap except as needed to confirm payment status.

2.2 Information collected automatically

  • Device and technical information: IP address, device identifier, browser or operating-system information, app version, language, time zone, crash diagnostics, and security events.
  • Usage and audit information: feature interactions, sign-in and session events, organization and permission changes, and activity records needed to operate collaborative and security features.
  • Communications metadata: information necessary to deliver or operate phone, text, email, meeting, and notification features, such as sender/recipient, timestamp, delivery status, call routing, and device push token.
  • Location information: precise or approximate location only when you enable and use a location-dependent feature, such as turn-by-turn navigation, work-site clock-in, route dispatch, or ETA sharing. The mobile apps do not request background location access.
  • Cookies and similar technologies: session, security, organization-selection, and device-recognition cookies used on our websites and web application. See https://centerleap.com/legal/cookies for more information.

2.3 Information from other sources

We may receive information from your organization’s administrators, connected services you authorize, communications carriers, app stores, payment processors, security providers, and public or third-party sources that you direct us to import.

3. How we use personal information

We use personal information to:

  • provide, authenticate, secure, and support the Services;
  • establish and administer organization accounts, subscriptions, and permissions;
  • deliver communications, notifications, calling, messaging, routing, meetings, document, e-signature, and workflow features you request;
  • process Customer Content and AI inputs to provide the requested feature;
  • prevent fraud, abuse, security incidents, and unlawful activity;
  • maintain logs, backups, and audit trails needed for security, accountability, and legal compliance;
  • respond to support requests, rights requests, and legal obligations;
  • measure and improve the reliability, usability, and performance of the Services; and
  • send service, security, billing, and legal notices, and marketing communications where permitted by law and subject to your choices.

4. AI-assisted features

AI-assisted features process only the prompts, documents, data, and context that an authorized user or organization configuration makes available to that feature. AI output may be inaccurate or unsuitable; it must be reviewed by a responsible person before use.

We do not use Customer Content to train our own general-purpose AI models. Third-party AI providers may process selected inputs to perform the requested inference. Their processing is governed by our contracts, the applicable feature configuration, and the current Subprocessor list. Do not submit information to an AI feature unless you are authorized to do so.

5. How we disclose personal information

We may disclose personal information to:

  • your organization and authorized users, according to its permissions and configuration;
  • service providers and subprocessors that help us host, secure, operate, communicate, map, store, process payments, provide AI inference, or support the Services, as listed at https://centerleap.com/legal/subprocessors;
  • connected services that you or your organization authorize us to connect;
  • professional advisers, insurers, auditors, and authorities when necessary for legal, security, tax, accounting, or compliance purposes;
  • parties to a corporate transaction such as a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate safeguards; and
  • other parties with your direction or consent.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising, and the mobile applications do not use advertising identifiers or track you across other companies’ apps or websites for advertising purposes.

6. Mobile permissions and platform data

The mobile apps request permissions only when a feature needs them:

  • Camera and selected photos/files: to capture or attach media you choose to send or upload. Android uses the system picker for existing library media rather than broad library access.
  • Microphone: to place or participate in calls, meetings, huddles, or transcription-enabled features.
  • Location: to provide route navigation, work-site clock-in, vehicle/route functions, or a location-sharing feature that you activate.
  • Notifications: to deliver service, message, call, and operational notifications.

You can decline or later change these permissions in device settings. A feature that depends on a denied permission may not work. iOS and Android may independently collect limited technical or transaction information under their own privacy policies.

7. Retention and deletion

We retain personal information for as long as reasonably necessary to provide the Services, maintain security and audit records, meet legal obligations, resolve disputes, and enforce agreements. Retention depends on the data type, organization settings, subscription status, and applicable law.

You can request account deletion through the in-product deletion flow or as described at https://centerleap.com/legal/data-deletion. We remove or anonymize data from active systems as described there, generally complete verified deletion requests within 30 days, and retain encrypted backups for up to 30 additional days. We may retain limited data where required or permitted by law, including billing, fraud-prevention, security, and legal-compliance records.

8. Security

We use administrative, technical, and organizational safeguards designed to protect personal information, including access controls, encryption where appropriate, logging, and security monitoring. No system is completely secure. You and your organization are responsible for protecting credentials, devices, and administrator access.

9. Your privacy choices and rights

Depending on where you live and our role in processing the information, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information. You may also opt out of marketing communications by using the unsubscribe instructions in a marketing message.

To make a request, email privacy@generalsoftwarecompany.com from the account email address or use the in-product account controls. We may need to verify your identity and authority. If we process information on behalf of your organization, direct your request to that organization first; we will assist it as required by applicable law.

California and other U.S. state residents

California and other applicable U.S. state privacy laws may provide rights to know, access, correct, delete, and obtain a portable copy of personal information, and to opt out of sale, sharing, targeted advertising, or certain profiling. centerleap does not sell personal information or share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes that would require a separate right to limit under California law. You may use an authorized agent where permitted by law; we may verify the request and the agent’s authority.

EEA, UK, and Switzerland

Where we are a controller, we rely on contract necessity, legitimate interests, legal obligations, consent where required, and other lawful bases under applicable law. You may have the right to complain to your local data-protection authority. Where we act as a processor, your organization is generally the controller.

10. International transfers

centerleap operates primarily from the United States. Personal information may be processed in the United States and other countries where we or our providers operate. When required, we use appropriate safeguards for restricted transfers, such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism.

11. Children’s privacy

The Services are business tools and are not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided personal information to us, contact privacy@generalsoftwarecompany.com; we will investigate and delete the information as required by law.

12. Changes to this Policy

We may update this Policy to reflect changes to the Services, law, or our practices. For material changes, we will provide notice by email, in-product notice, or another reasonable method before the change takes effect where required by law. The current version is posted at https://centerleap.com/legal/privacy.

13. Contact us

For privacy questions or requests, contact:

  • Privacy: privacy@generalsoftwarecompany.com
  • Support: support@generalsoftwarecompany.com
  • Legal: legal@generalsoftwarecompany.com
  • Mail: GENERAL SOFTWARE COMPANY LLC, Attn: Privacy, 32 N Gould St., Sheridan, WY 82801, USA