Greetlead

Greetlead Privacy Policy

Version of 3 October 2026.

1. Controller

Quantum Liquid LLC, a company governed by the laws of Wyoming (Limited Liability Company), 30 N Gould St, Ste R, Sheridan, WY 82801, United States of America, operates the Greetlead service ("Greetlead" or "the Service"). Contact for any question relating to personal data: hello@greetlead.io.

This policy applies under the Swiss Federal Act on Data Protection (FADP) and, for persons located in the European Union or the EEA, under the General Data Protection Regulation (GDPR).

2. Data subjects

3. Roles

Quantum Liquid LLC is the controller for organiser accounts and technical data. When a card is created at work, the organiser's organisation is the controller of the card content, of the invitation addresses and of the People list, and Greetlead is its processor, using these data only to run the card.

4. Data processed

4.1 Organisers

Greetlead manages no passwords. Sign-in takes place through the Lead Account, the identity service shared by the Lead apps (crmlead.io). Greetlead stores the Lead Account identifier, email address, name, language, organisation, role, plan and entitlements.

4.2 Cards

The occasion, the recipient's name, the recipient's email address (optional), the card title, the language and the delivery date.

4.3 Signatures

The signer's name, message and ink colour, a photo if one is added (stored in our database), the link to a GIF if one is chosen, and the signer's email address if they wish to receive the recipient's thank-you. A random key is placed in a cookie on the signer's device, so that only they can edit or remove their own message until delivery.

A signer can add a video of up to one minute and 40 MB. The video is stored in Neon object storage and is delivered through temporary links valid for one hour. A signer can also mark their message as private: it is then shown only to the recipient and the organiser, not to the other signers.

4.4 Invitations by email

The email addresses of colleagues that the organiser pastes. Greetlead uses them only for this card: one invitation to each person and, if they have not signed, at most one reminder two days before delivery. Each email says why the person receives it. The day before delivery, the organiser receives one reminder. These addresses are deleted with the card.

4.5 Gift collection register

When the organiser opens a register, signers can note how much they contributed to a common gift. An amount noted by a signer is visible only to the organiser. The other signers see the total only. Greetlead never receives, holds or transfers this money: payments are made directly between colleagues by the means the organiser indicates, and Greetlead is not a payment service.

4.6 People list (Pro)

Names, an optional email address, the birthday as day and month only (never the year) and the start date at work. These data are used only to remind the organisation's members 7 days before the date.

4.7 Technical data

To limit abuse, Greetlead keeps a hashed (HMAC) network identifier for at most two hours. The IP address itself is never stored. Greetlead uses no analytics and no advertising cookies.

5. Purposes and legal bases

Purpose Legal basis
Providing the Service and payment of cards and licences Performance of a contract (GDPR art. 6(1)(b))
Limiting abuse Legitimate interest (art. 6(1)(f))
Invitations and reminders to colleagues whose address the organiser entered Legitimate interest of the organiser's organisation in a workplace celebration (art. 6(1)(f))
Card content and People list handled for an organisation Processing on behalf (art. 28 GDPR, art. 9 FADP)

6. Retention periods

7. Processors

Processor Role
Vercel Inc. Hosting, Frankfurt region (Germany)
Neon (Databricks, Inc.) Database, AWS eu-central-1 (Frankfurt)
Neon (Databricks, Inc.) Object storage for videos, AWS eu-central-1 (Frankfurt)
Resend Emails
Stripe Payments Europe Payments
GIPHY GIF search and display

Greetlead never sees card numbers. GIPHY is used only when a signer uses GIFs: Greetlead keeps the link, and the GIF is loaded from GIPHY when the card is displayed.

8. Transfers abroad

Account and card data are hosted in Frankfurt (European Union). Quantum Liquid LLC is established in the United States, and some processors may handle data outside Switzerland and the EU/EEA. Such transfers rely on the safeguards of the FADP and the GDPR, such as standard contractual clauses.

9. Rights of data subjects

Any person may request access to their data, rectification, erasure, restriction of processing and data portability, and may object to processing based on legitimate interest. Requests should be sent to hello@greetlead.io. For card content, the organiser can also delete a message or a card directly.

A complaint may be lodged with the Federal Data Protection and Information Commissioner (FDPIC, www.edoeb.admin.ch) or with the supervisory authority of the place of residence in the European Union.

10. Cookies

Greetlead uses only cookies the Service needs: the organiser session, the sign-in request, the signer key and the language preference.

11. Changes

Material changes are announced on the website and, for organisers, by email or in the application before they take effect.