Privacy Policy

1. Scope

This Privacy Policy describes how Lyve Sheets collects, uses, and protects information in the course of providing the Service to staffing and consulting firms ("Customer") and the individuals whose records those firms manage ("consultants," "employees"). Customer is the data controller for its own tenant's data; we act as a data processor on Customer's behalf.

2. Information we collect

Account information for firm staff and consultant portal users (name, email, role); consultant and placement records entered by the firm (ledger entries, timesheets, invoices, vendor and client details); HR documents uploaded to the document vault; immigration case data (visa type, deadlines, USCIS status); and integration data from connected services such as QuickBooks or Dropbox, limited to what the firm authorizes.

3. How we use information

To provide and operate the Service — including generating invoices from approved timesheets, tracking receivables aging, sending expiry and deadline alerts, and syncing immigration case status; to secure and support your account; and to maintain audit logs of activity within your tenant. We do not use Customer Data to train models or for advertising.

4. Tenant isolation

Lyve Sheets is multi-tenant. Every table in our database enforces row-level security so that one firm's data is not visible to another, and consultant portal users can only see their own records.

5. Subprocessors

We share data with the following subprocessors as necessary to run the Service: Supabase (Postgres database, file storage, authentication), Vercel (application hosting), Resend (transactional email delivery), Nango (secure OAuth token vault for connected integrations), Documenso (e-signature processing), and the USCIS case-status API (immigration status checks). Each is bound to use data only to provide its service to us.

6. No sale of personal data

We do not sell personal data, and we do not share Customer Data with third parties for their own marketing purposes.

7. Data retention and deletion

We retain Customer Data for as long as the subscription is active. On termination, Customer Data is deleted from production systems within a reasonable period, except where retention is required by law or to resolve disputes. Backups are rotated out on our standard backup-retention schedule.

8. Security

We apply access controls, encryption in transit, and role-based permissions to protect data. Full detail is available on our Security page.

9. Your rights

Individuals whose data is processed within a Customer's tenant should direct access, correction, or deletion requests to that firm, as the data controller. We support Customer in fulfilling such requests.

10. International data transfers

Our infrastructure providers may process data in the United States. Where data is transferred internationally, we rely on our subprocessors' standard safeguards for cross-border transfer.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated to firm administrators.

12. Contact

Questions about this policy can be sent to sudheer@kreto.ai.

Last updated: July 16, 2026

This is a template pending review by counsel.