Privacy Policy
Last updated August 30, 2026
This Privacy Policy explains how Lefty Software LLC d/b/a StringBench ("StringBench," "we," "us," or "our") collects, uses, discloses, and retains personal information through the Service. This Policy describes our practices. Where a feature or law requires consent, we ask for it separately.
1. Scope and data roles
This Policy applies to StringBench platform accounts, the platform website at stringbench.com, and StringBench's operation of the multi-tenant Service. An "Account Holder" is a person with a StringBench login, including an Authorized User or a Shop Customer with customer-facing account access.
A Tenant Shop can publish separate terms and a privacy notice for its Shop Customers. Those documents govern the Shop's own practices.
StringBench determines why and how it uses account profile, security, platform communication, service-operation, and legal-compliance information. For those activities, contact StringBench about a privacy request.
A Shop determines why and how it uses the customer and business records that it enters into its workspace. StringBench processes that Shop Data to provide the Service and follow the Shop's instructions. A Shop Customer must normally contact the Shop first about those records.
Stripe processes payment information under its own terms and privacy notice. Other providers process information for the purposes described below.
2. Information we collect
- Account, Shop, and security information. We collect names, email addresses, password hashes, passkey public credentials and metadata, sessions, Shop identity and contact details, domains, memberships, roles, regional settings, preferences, and security events.
- Shop Customer and business records. Shops can enter customer names and contact details, notes, racket and string setups, job and appointment details, inventory, purchases, invoices, payments, tax settings, exemption records, and other operational records. These records can concern a minor customer.
- Documents, drafts, and outputs. Shops can upload receipts, tax-exemption documents, and Sergetti PDFs. We parse Sergetti PDFs to fill a form and retain the extracted fields that a user saves. The Service also creates seven-day server recovery drafts and can create downloads, exports, invoices, reports, statements, labels, and print jobs.
- Payment and transaction information. We collect Stripe connected-account identifiers and selected checkout, payment, receipt, refund, dispute, processing-fee, and reconciliation details. Checkout data can include a payer email, amount, service description, Shop identity, and return links. Stripe receives payment-card details directly. StringBench does not store full card numbers.
- Communications. We collect support messages, account emails, optional SMS enrollment and mobile information, consent and opt-out events, message content, delivery records, and replies.
- Technical and device information. We collect IP addresses, user-agent and request data, authentication cookies, local browser preferences, cached offline assets, printer configuration and status, and operational and security logs.
- Public-link information. We create unguessable QR tokens for racket pages and record the related Shop and racket data.
3. Sources of information
We receive information from Account Holders, Authorized Users, and Shop Customers who use customer-facing pages. We also receive information automatically from browsers and devices, and from providers such as Stripe, Sent.dm, email services, and security services.
If a user chooses address suggestions, our server sends the typed address text or selected place identifier to Google Places. Google does not receive the rest of the Shop form through this feature.
4. How we use information
We use information to:
- create accounts, authenticate users, manage Shops and roles, and provide requested features;
- process Shop Data under the Shop's instructions;
- create invoices, reports, labels, exports, print jobs, and Stripe checkout sessions;
- send account, security, access, support, and service communications;
- detect abuse, protect accounts and tenant boundaries, diagnose errors, and maintain the Service; and
- meet legal duties, enforce agreements, resolve disputes, and protect rights and safety.
We do not sell your personal information. We do not use personal information for cross-context behavioral advertising. No mobile information will be sold or shared with third parties for promotional or marketing purposes.
5. How we disclose information
We disclose information only for the purposes below:
- Within a Shop. Shop owners, administrators, and other Authorized Users can access information allowed by their roles. One Shop does not receive another Shop's private workspace data.
- Payment processing. Stripe receives checkout and transaction information for direct charges on the Shop's connected account. Stripe can send receipts and handle its own compliance records.
- Account messaging. Amazon Web Services Simple Email Service delivers email. Sent.dm processes optional StringBench account SMS, including mobile numbers, message content, replies, consent events, and delivery data. Sent.dm does not receive Shop Customer lists through this account-notification feature.
- Address and password security tools. Google Places receives address queries when a user chooses address suggestions. Have I Been Pwned receives a partial cryptographic password hash for breach screening, not the password itself.
- Service operations. Hosting, database, network, backup, monitoring, and security providers process the information needed to operate and protect the Service. A configured print agent and printer receive the content that a Shop sends to them.
- Legal and business events. We can disclose information when law requires it, to protect rights or safety, or as part of a merger, financing, acquisition, or sale of assets. We will require a recipient to honor applicable privacy duties.
Authorized Users can also choose recipients for exports, emails, downloads, and printed records. The Shop controls those disclosures.
6. QR labels and public racket pages
Scanning the QR code on a racket label opens the racket's public page without requiring sign-in. Anyone who has the label, a photograph of it, or a copy of the link can open the page.
The page shows Shop branding and contact information, racket details, string setup, service dates and status, and pricing-free stringing history. It does not display the Shop Customer's name, contact information, prices, notes, or internal database identifiers.
Hard-to-guess tokens and search-engine indexing controls reduce discovery, but they do not make the link private. The link has no fixed expiration and remains available while the related Shop, customer, and racket records remain available.
7. Cookies, browser storage, and tracking
We use secure cookies for authentication, session management, request protection, and other necessary functions. The browser can also store user- and tenant-scoped list and regional preferences in localStorage, plus a device theme preference. We disable htmx page snapshots and remove its legacy localStorage cache when a page loads.
Our service worker uses Cache Storage only for the offline page and static assets such as icons. It does not cache signed-in pages, API responses, authentication routes, or invoices.
Some forms send recovery drafts to the server so an Authorized User can recover recent work. We keep each draft for up to seven days after its latest save.
We do not use third-party advertising cookies or track activity across unrelated websites. Because we do not sell personal information or use it for cross-context behavioral advertising, browser Do Not Track and Global Privacy Control signals do not change how the Service operates.
8. Retention, account deletion, and Shop closure
We keep account and Shop information while it is needed to provide the Service. StringBench currently handles deletion requests through [email protected]. We verify the request and the requester's authority.
Removing an Account Holder's access to one Shop does not delete the login account. The account can remain active for another Shop relationship. We delete a login account only after all required Shop ownership, membership, and customer links are released.
Deleting a login account does not delete Shop-controlled customer or business records. Those records can remain with the Shop after we remove the deleted account's login link from them.
When a verified Shop owner requests closure, we make the Shop inactive and normally keep its data for a 60-day restoration period. The Shop then becomes eligible for final purge. Final purge removes active tenant business collections, settings, memberships, domains, and stored attachments. Limited offboarding, security, and legal records can remain.
Consent evidence, revocation and suppression records, rendered-message or send proof, and delivery evidence for account SMS are retained for five years. Ordinary support-reply bodies are retained for one year unless they become consent, dispute, or legal-hold evidence. Raw provider webhook payloads are retained for up to 30 days.
After account deletion, we suppress SMS and cancel pending work. After provider cleanup, we remove the active mobile number and messaging preferences. We retain required messaging evidence under a tombstoned account identifier for the periods above.
Deletion from active systems does not immediately remove backup copies from disaster-recovery systems. We can retain information for fraud prevention, security, tax, disputes, legal obligations, or a legal hold. Stripe and recipients of exports or printed records keep information under their own practices.
9. Security
We use administrative, technical, and physical safeguards that are designed for the type of information that we handle. These safeguards include tenant-scoped access controls, encrypted network connections, cryptographic password hashing, passkeys, session controls, audit records, and limited provider credentials.
No storage or transmission method is completely secure. You must protect your account and devices, give users only needed access, and report suspected unauthorized access to [email protected].
10. Your choices and privacy requests
Account Holders can update available profile and Shop settings in the Service. Shop owners and administrators can manage membership and roles. Authorized Users can use available export features before Shop closure.
You can opt out of optional account SMS at any time by replying STOP or by disabling SMS in the Account Center. START restores a prior enrollment only for the same account and mobile number. Email remains available for required account notices.
Depending on applicable law, you can have rights to access, correct, delete, or receive a copy of certain personal information, or to appeal a denied request. Send a request about StringBench-controlled account data to [email protected]. We verify requests before acting.
If your request concerns records that a Shop controls, contact that Shop first. We assist the Shop with a verified request when required.
11. Information about minors
The administrative Service is for adult business users, and a Shop's Authorized Users must be at least 18. StringBench does not direct account registration or marketing to children.
A Shop can enter customer records or provide customer-facing account access for a minor. These records can include contact, racket, and service information. The Shop decides whether to collect that information. The Shop must obtain any notice, consent, or parental permission required by law and must avoid information that it does not need.
If you believe that StringBench collected personal information directly from a child under 13 outside a Shop's instructions, contact us so we can review and act as required by law.
12. U.S. service and international access
StringBench is a U.S.-based service. We and our providers can process information in the United States and in other locations where our providers operate. Privacy laws in those locations can differ from the laws where you live.
If a Shop uses the Service for people outside the United States, the Shop is responsible for confirming that its use, notices, permissions, and transfer arrangements meet applicable law.
13. Changes to this Policy
We can update this Policy as the Service or law changes. We will post the updated Policy, revise the date above, and give additional notice through the Service or an account email when a change is material.
We will not apply a materially broader use to information that we collected under an earlier Policy without the notice or consent that applicable law requires.
14. Contact
Send questions or privacy requests about StringBench-controlled information to [email protected]. For Shop-controlled customer records, contact the applicable Shop first.