Last updated: June 29, 2026

Privacy Policy

1. Who we are

Foliole (“we”, “us”, “our”) is a lead management and follow-up tool for small service businesses. This Privacy Policy explains how we collect, use, and share information when you use our website and services at foliole.app.

2. Information we collect

When you or your clients use Foliole, we collect the following personal information:

  • Account holders (businesses): name, email address, business name, and password (stored securely using industry-standard authentication services).
  • Leads (your clients): name, email address, phone number, and the inquiry message they submit through your public intake page.
  • Uploaded images: header images and service images you upload to customize your intake page.
  • Payment information: billing details processed by our payment provider. We never store card numbers directly.
  • Usage data: pages visited, actions taken, and basic analytics to improve the service.

3. How we use your information

  • To provide and operate the Foliole service.
  • To send follow-up reminder emails to you and (on your behalf) to your leads.
  • To process subscription payments.
  • To improve the product and diagnose technical issues.
  • To communicate with you about your account or service updates.

4. Third parties we share data with

We share your data only with the service providers necessary to operate Foliole:

  • Authentication provider — managing user accounts and secure login.
  • Email delivery provider — sending transactional and follow-up emails on your behalf.
  • SMS delivery provider — sending SMS messages where you or your clients have consented.
  • Cloud storage provider — storing images you upload to customise your page.
  • Payment processor — processing subscription payments. Your payment data is handled under that provider's own privacy policy and is never stored on our servers.
  • Hosting and infrastructure provider — serving the application and storing database records.

We do not sell your personal information to third parties.

5. Data retention

We retain your account data for as long as your account is active. Lead and follow-up data is retained until you delete it or close your account. You may request deletion of your data at any time (see Section 7).

6. Cookies

We use essential cookies to keep you logged in (via secure httpOnly cookies). We do not use third-party advertising or tracking cookies.

7. Your rights — CCPA / CPRA (California)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to know: You may request a copy of the personal information we hold about you, including the categories and specific pieces of data collected.
  • Right to delete: You may request deletion of your personal information. We will delete your data within 45 days of a verified request, subject to any legal obligations to retain it.
  • Right to correct: You may request correction of inaccurate personal information we hold about you.
  • Right to opt out of sale or sharing: We do not sell or share your personal information for cross-context behavioral advertising.
  • Right to non-discrimination: We will not discriminate against you for exercising any of these rights.

Use the form below to submit a request. We will verify your identity before processing and respond within 45 days as required by the CCPA. You may also email [email protected] directly.

Submit a data rights request

8. US federal law compliance

Foliole operates in compliance with applicable US federal laws governing electronic communications and privacy:

  • CAN-SPAM Act (15 U.S.C. § 7701): All commercial emails sent through Foliole include a clear sender identification and an unsubscribe mechanism. Recipients may opt out of follow-up emails at any time. We honor opt-out requests promptly in accordance with the Act.
  • TCPA (Telephone Consumer Protection Act, 47 U.S.C. § 227): SMS messages are sent only where the recipient has provided consent. Recipients may opt out at any time by replying “STOP” to any message. We do not use autodialing or robocalling systems.
  • COPPA (Children's Online Privacy Protection Act, 15 U.S.C. § 6501): Foliole is not directed at children under 13. We do not knowingly collect personal information from children. See Section 9 for more detail.
  • ECPA (Electronic Communications Privacy Act, 18 U.S.C. § 2510): We do not intercept, access, or disclose the contents of electronic communications except as required to provide the Service or as compelled by law.
  • GLBA / FCRA: Foliole is not a financial institution or consumer reporting agency and does not collect financial records or consumer credit data.

9. Children's privacy

Foliole is not directed at children under 13. We do not knowingly collect personal information from children under 13 in compliance with COPPA. If you believe we have collected data from a child, contact us and we will delete it promptly.

10. Security

We use industry-standard security measures including encrypted connections (TLS), httpOnly cookies, and access controls. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.

11. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by posting a notice on our website. Continued use of Foliole after changes constitutes acceptance of the updated policy.

12. Contact us

Questions about this policy or your data? Email us at [email protected] or use the data rights form in Section 7.