Privacy Policy
Last updated: June 2026
Who we are
ClientLift (“we”, “us”) provides branded client-onboarding portals for consultants and studios. This policy explains what we collect, why, and your rights. Contact: support@clientlift.com.
What we collect
Account data — your name, email, business name and password (passwords are handled by our authentication provider and never stored in plain text).
Client onboarding data — information your clients submit through onboarding links: form answers, uploaded files, typed signatures and, where they choose to share access, encrypted credentials.
Usage data — basic technical logs (pages visited, errors) used to keep the service running and secure.
How we use it
To provide the service: storing and displaying onboarding data to the workspace that requested it.
To send transactional email (invites, reminders, account messages).
We do NOT sell personal data, and we do not use your clients' data for advertising.
Where it lives
Data is stored with our infrastructure providers: Supabase (database, file storage, authentication) and Vercel (hosting). Both apply industry-standard security.
Credentials shared through the Vault are encrypted with AES-256-GCM before storage; plaintext is never written to the database. Reveals are logged.
Your rights
You may request access to, correction of, or deletion of your personal data at any time by contacting us.
If you are a client of one of our customers (you filled in an onboarding link), the consultant who sent you the link is the data controller; we process data on their behalf. Contact them first, or us directly.
You may lodge a complaint with your data-protection authority (in the UK, the ICO).
Retention & deletion
We keep data for as long as the workspace account is active. Deleting your account removes your workspace data from production systems within 30 days, except where law requires longer retention.
Changes
We will post any changes to this policy on this page with an updated date.