Legal
Privacy Policy
1. Who we are
LEOPARD WEB SERVICES PTY. LTD., ABN 86 166 927 457, trading as Leopard Web Services, handles personal information when people visit our website, complete a quiz, contact us, subscribe, or work with us. This policy also covers relevant information supplied during client projects.
Contact hello@leopardwebservices.com for privacy requests or complaints. Our business email is forwarded through Cloudflare to a Gmail mailbox. We primarily serve Australian clients and consider overseas projects individually.
2. Information we collect and where it comes from
Enquiries and proposals: names, business names, email addresses or phone numbers, messages, service needs, timing, budget information where provided, correspondence and proposal briefs. We receive these directly from you or your authorised business contacts. We may also record public business information used to prepare a proposal and information you ask us to consider.
Quiz responses: the questions and selected answers, score, result, summary and completion time. We save completed responses and notify our team by email. A response initially submitted without a name may later be associated with an enquiry or client account. We use these assessments to understand service needs and prioritise follow-up; you can contact us to discuss or correct the information. An unnamed response is not necessarily anonymous.
Client accounts and projects: name, business and contact details, account identifiers, project briefs, files, messages, milestones, approvals, work orders and relevant internal working notes. Information may include details about other people that you supply for the project.
Authentication and security: sign-in and session records, necessary cookies, IP addresses, browser/device information and technical records used to provide access and prevent misuse. Our portal uses emailed sign-in links rather than a password-based login. That does not mean an account contains only an email address.
Payments: billing details, invoices, payment references, amounts, currency and payment status. Card entry for our hosted checkout takes place with Stripe rather than in our application. Please do not send card details or financial credentials through messages or uploads.
Newsletter: email address, the signup wording accepted, signup source and time, and unsubscribe or suppression records.
Website attribution: campaign parameters, advertising click identifiers, referring page, landing page and relevant conversion events. Browser storage may retain attribution information. Section 5 explains the selected tracking policy and outstanding verification.
Website usage: pages viewed, clicks, scrolling and mouse movement, device and browser details, approximate location derived from IP address, and session recordings and heatmaps showing how pages are used.
3. Why we use information and your choices
We use information to answer enquiries, assess service fit, prepare proposals, deliver and support projects, manage access, communicate about work, bill and reconcile payments, protect our systems, resolve disputes and meet applicable record-keeping obligations. We use limited attribution and conversion measurement to understand which campaigns lead to enquiries.
You may browse without opening an account and make a general enquiry anonymously or under a pseudonym where practicable. If you withhold information needed to contact you, establish a client account, invoice or deliver a service, we may be unable to provide that part of the service.
Please provide only information relevant to your enquiry or project. We do not ordinarily seek health records, identity documents, tax file numbers or financial account credentials. Contact us before a project requires sensitive or unusually confidential information so suitable arrangements can be agreed. When providing another person's information, ensure you have authority and any required permissions to do so.
4. Newsletter and service messages
Enquiries, quiz submissions and purchases do not automatically subscribe you to marketing. Newsletter subscription requires a separate, unticked opt-in choice and we keep evidence of it. Service-related messages, such as sign-in links, project correspondence and invoices, are handled separately.
You can withdraw newsletter consent using the unsubscribe facility in a marketing message or by emailing hello@leopardwebservices.com. We honour unsubscribe requests within five working days and keep only the suppression evidence needed to avoid sending unwanted marketing and demonstrate consent handling.
5. Cookies, attribution and advertising measurement
We use necessary authentication/session cookies and browser storage for site functions and attribution. Our selected policy permits limited campaign attribution and conversion measurement, excludes detailed quiz answers from advertising platforms and does not use remarketing. We do not describe the whole website as anonymous or cookieless.
We partner with Microsoft Clarity and Microsoft Advertising to capture how you use and interact with our website through behavioural metrics, heatmaps and session replay to improve and market our products and services. Website usage data is captured using first- and third-party cookies and other tracking technologies to determine the popularity of products and services and online activity. Additionally, we use this information for site optimisation, fraud and security purposes, and advertising. For more information about how Microsoft collects and uses your data, visit the Microsoft Privacy Statement at privacy.microsoft.com/privacystatement.
We also use Google Analytics and Cloudflare Web Analytics to measure website traffic and performance.
Your browser allows you to manage cookies and storage. Blocking necessary storage can affect sign-in or other features. Browser settings alone are not a substitute for any consent choices we must provide.
6. Providers and other recipients
Cloudflare supports website hosting, database and file storage, bot protection and email routing. Stripe processes hosted payments and invoices. Resend delivers application emails, including customer messages and owner notifications that may contain enquiry or quiz information.
We use Google services for Gmail and Google Drive, and Google advertising and analytics services for the measurement described in section 5. Microsoft Clarity provides the usage analytics and session replay described in section 5. We use Xero for accounting. Relevant records and working files may also be held on our local computer and in backups. Providers receive the information needed for their role and may handle some information under their own applicable terms and privacy notices.
Optional proposal drafting uses Vercel AI Gateway and a selected model provider. We use public or genuinely de-identified information by default. Before sending confidential or identifiable client information to external AI, we obtain written client approval and check retention and training settings. This approval does not replace any permissions required for other people's information.
No subcontractors currently have access to client or prospect information. If used, their access is limited to what their work requires and subject to confidentiality and data-handling obligations. We may disclose relevant information to professional advisers or where required or authorised by law. We do not buy, sell or exchange personal information or lead lists.
7. Overseas handling
Some providers may store or access information outside Australia, including through support operations and subprocessors. Serving Australian clients does not mean their information stays exclusively in Australia. We assess overseas handling and applicable safeguards for the services we use.
8. Security
We use access controls and reasonable safeguards suited to the information we handle. The business owner has confirmed two-factor authentication on Google and Xero, full-disk encryption and automatic screen locking on the local computer, and regular backups. Portal access controls are intended to restrict project information to authorised users.
No system is completely secure. If an incident affects personal information, we will investigate and take appropriate containment and response steps, including notification where required by applicable law. Please contact us promptly if you suspect unauthorised access to your information or account.
9. Retention and deletion
Our selected retention policy is: completed quiz responses not linked to an enquiry or client are deleted or genuinely de-identified after 90 days, including identifiable email copies. Linked responses follow the associated enquiry or client record's retention rule.
Unsuccessful enquiries and their linked quiz data are deleted or genuinely de-identified 12 months after the last meaningful contact, unless a documented legal reason requires retention. Newsletter consent does not justify retaining the full enquiry indefinitely.
Unnecessary project working copies are deleted 90 days after confirmed handover, with a download opportunity and reminder first. For ongoing services, we retain only the files needed while the service continues, then delete unnecessary copies 90 days after it ends, with a handover opportunity first.
Contracts, invoices, required financial records and necessary dispute evidence follow separate legal and operational retention requirements. Company financial records generally must be kept for at least seven years after the relevant transactions are completed. We retain only what is needed for the applicable purpose or obligation, rather than treating that period as permission to retain every project file.
10. Access, correction and deletion requests
Email hello@leopardwebservices.com to request access to information we hold about you, correction of inaccurate information or deletion. We may ask for proportionate information to verify your identity and authority before disclosing or changing records. Please do not send identity documents unless we first agree a suitable method and need.
We assess requests under applicable requirements, protect other people's information and explain any reason we cannot comply, such as required financial records or a legal preservation obligation. We will explain relevant retention limits rather than promise deletion from every system immediately.
11. Privacy complaints and legal coverage
Send privacy complaints to hello@leopardwebservices.com with enough detail for us to investigate. We aim to acknowledge complaints within two business days and resolve them within 30 calendar days, with updates if delayed. Applicable legal deadlines take precedence over these targets. Business days in this policy exclude weekends and Victorian public holidays.
If you remain dissatisfied, you can seek guidance from the Office of the Australian Information Commissioner at oaic.gov.au about available complaint avenues and its jurisdiction. This does not assert that the OAIC has jurisdiction over every complaint about us.
12. Changes and contact
We update this policy when relevant practices change and show the updated date. Where a change materially affects how we handle information, we explain it and provide any notice or obtain any permission required. Updating the policy does not itself create consent for a new use.
Privacy requests and complaints: hello@leopardwebservices.com. Routine invoice enquiries: billing@leopardwebservices.com. Our Terms and Conditions describe our service arrangements; this privacy policy is not blanket consent to unrelated processing.