Privacy Policy
Last updated: April 29, 2026
1. Information We Collect
We collect information in the following categories: Account Information: Name, email address, phone number, role (Space Owner or Truck Owner), profile photo, bio, and location when you register. Business Information: For Truck Owners — business name, cuisine type, vehicle details, and operating hours. For Space Owners — space title, address, dimensions, amenities, and pricing. Compliance Documents: Permits, licenses, insurance certificates, health department documents, and other compliance files that Truck Owners upload to the Platform. These are stored in our secure file storage system. Tax Information: Legal name, business name, business entity type, and the last four digits of your Tax Identification Number (TIN/SSN/EIN) for 1099-NEC reporting purposes. We never store your full Social Security Number or Employer Identification Number on our systems. Payment and Financial Information: Payment processing is handled by Stripe, Inc. We do not store full credit card numbers or full bank account numbers on our servers. We may store card type, last four digits, and expiration dates for display purposes only. Bank account last four digits may be displayed in your payouts dashboard. Messaging Content: The full content of all messages sent between users through the LeaseBites in-platform messaging system is stored on our servers. See Section 3 for details. Booking and Transaction Data: Dates, pricing, payment amounts, booking status, and all transactional history associated with bookings made through the Platform. Usage and Technical Data: Pages visited, features used, timestamps, IP address, device type, browser type and version, operating system, and referring URLs. This data is collected automatically when you use the Platform. Communications With Us: Any emails, support requests, or other correspondence you send to LeaseBites.
2. How We Use Your Information
We use the information we collect to: • Create and manage your account and authenticate your identity • Facilitate bookings and connections between Space Owners and Truck Owners • Process payments and payouts through Stripe • Share relevant contact and business information between parties to facilitate confirmed bookings • Send transactional communications: booking requests, approvals, rejections, cancellations, payment receipts, and payout confirmations • Send service communications: account notifications, policy updates, and platform announcements • Fulfill tax reporting obligations, including issuing IRS Form 1099-NEC to qualifying Space Owners • Investigate and resolve disputes between users (see Section 3) • Detect and prevent fraud, abuse, and violations of our Terms of Service • Analyze usage patterns to improve the Platform's features and performance • Comply with applicable laws, regulations, legal process, and government requests • Enforce our Terms of Service and protect the rights and safety of our users and the public
3. Platform Messages — Storage and Review
LeaseBites stores all messages sent through the in-platform messaging system. This is a deliberate design decision that serves several important purposes: Dispute Resolution: When a user files a dispute regarding a booking or refund, LeaseBites staff may review the full conversation history between the parties as part of the investigation. Message content can provide crucial context about representations made, agreements reached, and the conduct of each party. Fraud and Abuse Prevention: LeaseBites may review messages to detect fraudulent activity, harassment, misrepresentation, off-platform transaction solicitation, or other violations of our Terms of Service. Safety and Legal Compliance: LeaseBites may review and disclose messages in response to valid legal process (such as subpoenas, court orders, or law enforcement requests), or where we believe disclosure is necessary to protect the safety of any person or to protect LeaseBites' legal rights. By using the LeaseBites messaging system, you knowingly and voluntarily consent to this storage and potential review. You should have no expectation of privacy in messages sent through our Platform beyond what is described in this Privacy Policy. LeaseBites does not actively monitor all messages in real time but reserves the right to do so. Message content is not sold to third parties. It will only be shared as described in Section 4 (Information Sharing) and this section. Messages are retained for 7 years from the date of creation, or longer if required by applicable law or ongoing legal proceedings.
4. Information Sharing
We share your information only in the following circumstances: With Other Users (to Facilitate Bookings): We share relevant profile and contact information between Space Owners and Truck Owners to enable bookings. This includes names, business names, contact information, and booking-relevant details. Compliance documents uploaded by Truck Owners are accessible to Space Owners who receive booking requests from those Truck Owners. With Stripe (Payment Processing): We share payment-related information with Stripe, Inc. to process transactions and payouts. Stripe is a PCI DSS Level 1 certified payment processor. See stripe.com/privacy. With Supabase (Data Infrastructure): Our database, file storage, and authentication are powered by Supabase, Inc. Your data is stored on Supabase's servers. See supabase.com/privacy. With Resend (Email Delivery): Transactional emails are delivered through Resend, Inc. Your email address and the content of transactional emails are processed by Resend. See resend.com/privacy. With Law Enforcement and Legal Authorities: We may disclose information when required by valid legal process, including subpoenas, court orders, and government investigations. We may also disclose information where we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others. In Business Transfers: If LeaseBites is involved in a merger, acquisition, asset sale, or similar transaction, your information may be transferred as part of that transaction. We will notify you via email or prominent Platform notice before your information becomes subject to a different privacy policy. We do not sell, rent, or trade your personal information to third parties for their marketing purposes. Ever.
5. Payment Data and Stripe
All payment card and bank account processing is handled exclusively by Stripe, Inc., one of the world's leading payment processors. Stripe is PCI DSS Level 1 certified — the highest available level of certification for payment security. LeaseBites never receives, processes, or stores your full payment card number, CVV, or full bank account number. When you add a payment method, that information goes directly to Stripe's secure servers. LeaseBites receives only a tokenized reference and limited metadata (card brand, last four digits, expiration month/year) for display purposes. For Stripe Connect payouts, your bank account details are stored and managed by Stripe. For more information about how Stripe handles your payment data, please review Stripe's privacy policy at stripe.com/privacy.
6. Compliance Documents
Compliance documents you upload (permits, licenses, insurance certificates, etc.) are stored in Supabase Storage with access controls. These documents are shared only with Space Owners who receive booking requests from you. LeaseBites does not share compliance documents with third parties except as required by law. Documents are retained for 7 years after upload or 7 years after account deletion, whichever is later, to support legal compliance and dispute resolution purposes. You are responsible for keeping your uploaded documents current and accurate. You may update or replace documents at any time through your dashboard.
7. Tax Information
Tax identification information you provide (legal name, business type, last four digits of TIN) is used solely for the purpose of fulfilling our IRS 1099-NEC reporting obligations as required by U.S. tax law. This information is accessible only to LeaseBites staff with a need-to-know basis. Your full Tax Identification Number (SSN or EIN) is encrypted at rest and never displayed in the Platform interface — only the last four digits are shown. Tax information is retained for a minimum of 7 years as required by applicable tax regulations. We do not use tax identification information for any purpose other than legal tax reporting compliance.
8. Data Security
We implement industry-standard technical and organizational security measures to protect your personal information from unauthorized access, use, disclosure, alteration, or destruction. These measures include: • TLS/HTTPS encryption for all data transmitted to and from the Platform • Encryption at rest for sensitive data stored in our database • Row-Level Security (RLS) policies in Supabase to ensure users can only access their own data • Administrative access controls limiting who can access production systems • Third-party services (Stripe, Supabase, Resend) that maintain their own industry-leading security programs No method of electronic transmission or storage is 100% secure. While we work hard to protect your information, we cannot guarantee absolute security. In the event of a data breach that is likely to affect your rights and freedoms, we will notify affected users as required by applicable law. If you become aware of a security vulnerability or incident involving LeaseBites, please report it immediately to info@leasebites.co.
9. Cookies and Tracking Technologies
LeaseBites uses cookies and similar technologies to operate and improve the Platform. Types of cookies we use: Strictly Necessary Cookies: Required for authentication and session management. Without these, you cannot log in or use the Platform. These cannot be disabled. Functional Cookies: Remember your preferences (such as selected role or display settings). These enhance your experience but are not required for basic functionality. Analytics Cookies: Help us understand how users interact with the Platform so we can improve it. These may be from first-party or third-party analytics providers. You can control non-essential cookies through your browser settings. Note that disabling certain cookies may affect Platform functionality. We do not use cross-site tracking cookies for advertising purposes. We do not sell cookie data to third parties.
10. Data Retention
We retain your personal information for as long as your account is active and for a period thereafter as necessary to fulfill the purposes described in this Privacy Policy. Specific retention periods: • Account data (name, email, role): retained for 7 years after account deletion • Booking and transaction records: retained for 7 years (financial and tax compliance) • Payment records: retained for 7 years (IRS and financial regulations) • Compliance documents: retained for 7 years after upload • Platform messages: retained for 7 years (dispute resolution and legal compliance) • Tax information: retained for 7 years (IRS requirements) • Usage and technical logs: retained for 2 years • Support communications: retained for 3 years After the applicable retention period, we will delete or anonymize your information. Some information may be retained longer if required by applicable law or ongoing legal proceedings.
11. Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal information: Access: Request a copy of the personal data we hold about you. Correction: Request correction of inaccurate or incomplete personal data. You can update most profile information directly in your dashboard. Deletion: Request deletion of your personal data. Note that we may retain certain data as described in Section 10 for legal compliance, even after account deletion. Portability: Request your data in a machine-readable format. Marketing Opt-Out: Every marketing email includes an unsubscribe link. You cannot opt out of transactional emails (booking notifications, payment receipts, etc.) while your account is active, as these are necessary to the service. California Residents (CCPA): California residents have the right to: know the categories of personal information collected and the purposes for which it is used; request deletion of personal information; opt out of the sale of personal information (we do not sell personal information); and non-discrimination for exercising privacy rights. To exercise any of these rights, contact us at privacy@leasebites.co. We will respond within 30 days. We may need to verify your identity before fulfilling your request.
12. Children's Privacy
LeaseBites is intended exclusively for users who are 18 years of age or older. We do not knowingly collect personal information from individuals under 18. If we become aware that we have inadvertently collected personal information from a person under 18, we will take steps to delete that information promptly. If you believe a minor has created an account or provided personal information to LeaseBites, please contact us immediately at privacy@leasebites.co.
13. Geographic Scope
LeaseBites is operated from the United States and is primarily intended for users in the United States. All data we collect is processed and stored on servers located in the United States. By using the Platform, you consent to the transfer, processing, and storage of your information in the United States. If you are accessing the Platform from outside the United States, please be aware that your information will be transferred to, stored, and processed in the United States where data protection laws may differ from those in your country.
14. Third-Party Links
The Platform may contain links to third-party websites, services, or resources. These links are provided for your convenience only. LeaseBites has no control over the content, privacy practices, or policies of any third-party site and accepts no responsibility for them. We encourage you to review the privacy policies of any third-party sites you visit. The inclusion of a link does not imply endorsement by LeaseBites.
15. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, applicable law, or the Platform's features. When we make material changes, we will notify you by email to the address on file and/or by displaying a prominent notice on the Platform. The updated policy will include a revised "Last updated" date at the top of this page. Your continued use of the Platform after the effective date of changes constitutes your acceptance of the updated Privacy Policy. If you do not agree to the updated policy, you must stop using the Platform.
16. Contact Us
For questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact our Privacy Team: Email: privacy@leasebites.co General inquiries: info@leasebites.co We aim to respond to all privacy inquiries within 30 days. For requests related to your rights (access, deletion, portability), please include your registered email address and a description of your request.
For privacy concerns, email us at privacy@leasebites.co.