HVACR Studio Privacy Policy
This notice explains the information used to operate HVACR Studio on the web and mobile, authorize access, support engineering workflows, deliver service notifications and improve LEAL’s engineering products.
Information we collect
Account information may include name, email address, mobile number, company or organisation, designation, professional role, city, country and account profile image. If you use Google sign-in, Google provides the account identity information you authorize, typically your verified email, name and profile image.
Contact and business enquiries
If you use the public Contact form, HVACR Studio can record the name, company or organisation, role/designation, email address, optional mobile/WhatsApp number, city/country, enquiry type and message that you choose to submit. The information is used to route and respond to the requested account, technical, commercial, billing, privacy, grievance or partnership enquiry. Do not submit card numbers, CVV, OTPs, banking passwords or unrelated confidential project information through the Contact form.
Access authorization
Registration and authentication do not automatically guarantee calculator access. HVACR Studio can record an access request, the campaign or managed invitation link associated with that request, its approval status, decision time and whether access was approved manually or automatically under a configured access policy. Authorized LEAL administrators can approve, reject or revoke access. High-volume event or campaign links can be configured for automatic or scheduled approval during an authorized access window.
Engineering projects and evidence
When a workflow lets you save project or field records, the information you deliberately save can be stored with your HVACR Studio account or project. Evidence can include notes, measurements, selected documents and photos that you choose to upload. On mobile, camera and photo-library access is requested only when you choose to capture or select engineering evidence; HVACR Studio does not use those permissions to scan your media library in the background. Evidence uploaded to the service is retained with the relevant project/workflow record until it is removed under the product’s retention or account-deletion process, subject to applicable audit or legal requirements.
Calculator data
Routine tool-usage analytics do not capture calculator inputs or calculated engineering results. Calculations that remain unsaved stay within the active tool experience. If you deliberately save, sync or attach calculation information to a project, report, commissioning record or other workflow, that saved engineering record can be stored by HVACR Studio as part of the feature you chose to use.
Tool usage, search and product-improvement analytics
For signed-in users with an approved account and completed profile, HVACR Studio can record which registered engineering tool was opened and when it was opened. Toolbox search can record the engineering search phrase, number of matching tools, selected result if one is opened, source page and time of the search. Suggestions submitted through the improvement control can record the source page, suggestion category, message, status and, when signed in, the submitting account. These analytics are used to understand feature demand and improve the product, not to capture calculator inputs or outputs.
Event, campaign and UTM visits
Official event links or QR routes can record a random first-party visitor token, campaign/source identifier, managed link identifier, UTM source/medium/campaign/content values, first and latest visit times and visit/touch counts. Historical entries keep the UTM values that applied when that entry occurred even if an administrator later changes a link for future use. After you sign in, a campaign visit may be linked to your HVACR Studio account so LEAL can distinguish newly acquired accounts from returning users and measure subsequent campaign-attributed activity. The campaign tracker is not intended to store an IP address, browser fingerprint, calculator input or calculated engineering result.
Mobile notifications
If you enable push notifications, HVACR Studio may register a platform and device push token with your account so enabled service reminders and workflow notifications can be delivered. Push-notification preference, delivery status and token activity may be retained to operate and troubleshoot the notification service. A push token is not used as calculator-input analytics. You can disable notifications through the application controls where available or your device settings.
Payment and billing information
When paid subscriptions are enabled, payment processing may be handled by CCAvenue or another authorized payment service provider. HVACR Studio is not intended to store full payment-card numbers, CVV, OTPs or internet-banking passwords. LEAL may retain limited payment and billing information such as transaction/order reference, payment status, amount, tax/invoice data, subscription period, refund status and reconciliation records as needed to deliver the service, support customers, prevent fraud, resolve disputes, maintain accounts and meet legal or accounting obligations.
Why we use information
We use account, authorization, contact-enquiry, project/evidence, notification, campaign, UTM, payment, tool-usage, search-demand and suggestion data to authenticate users, control access, respond to enquiries, deliver requested engineering workflows, secure accounts, send enabled service notifications, deliver and reconcile subscriptions, support users, improve HVACR Studio and related LEAL products, and measure event or campaign engagement.
Authorized internal access
Access to cross-user account, authorization, contact-enquiry, campaign, UTM, payment, search-demand, suggestion, notification and usage reports is restricted to authorized LEAL administrators. Project and evidence access is limited to the people and operational roles permitted by the applicable workflow. Authentication secrets, password hashes and session/reset tokens are not exposed through the normal reporting console.
Marketing and optional communication choices
Creating an HVACR Studio account or sending a Contact enquiry does not by itself opt you into promotional email or WhatsApp messages. Marketing choices are separate from acceptance of the service terms and this privacy notice. Signed-in users can update email marketing consent and separate R81 renewal/grace and re-engagement email controls from Communication Preferences. Re-engagement email requires both current email-marketing consent and the separate re-engagement switch. Renewal/grace email is separately opt-in and uses the approved commercial lifecycle timing; enabling it does not authorize automatic renewal or payment.
Retention, invitation and communication analytics
HVACR Studio may calculate aggregate activation and retention cohorts from account registration time, tracked tool-open activity, subscription starts and paid-order status. For secure Organization invitations, LEAL may also measure invitation creation, creator-initiated copy/share actions, the first verified matching-account preview, invitation acceptance and later fixed-window activation or conversion. The invitation measurement layer stores a one-way hash of the invited email rather than a second plaintext invitee-email snapshot and may label the collaboration context such as team member, client collaborator or delivery partner. Share actions record interface intent only; they do not prove that a message was delivered or read. These reports are intended to understand product adoption rather than to rank individual users. When an optional R81 email is queued, LEAL may retain delivery status, policy authority, timestamps, retry/suppression information and a one-way hash of the recipient email address for audit and deduplication. R81 analytics are not entitlement, payment, partner-commission or engineering-record authority.
Authentication and service providers
Google is used only when you choose Google sign-in. Email and push-delivery infrastructure may process the identifiers needed to deliver verification, password-recovery, reminder and other enabled service messages. Hosting, database and file-storage providers process service data as required to operate the application. When paid checkout is enabled, the payment gateway and its banking/network partners process payment information under their own security and privacy obligations.
Security and retention
Passwords are stored as one-way password hashes, not plaintext. Authentication tokens are time-limited. Account, consent, authorization, contact-enquiry, project/evidence, notification-token/delivery, campaign/UTM-visit, invitation-growth measurement, payment/reconciliation, search-demand, suggestion and usage-event records are retained as needed to operate and secure the service, respond to enquiries, maintain project or audit history, resolve transactions or disputes, and meet applicable business or legal obligations.
Your account data
You may request correction or deletion of account information, subject to records that must be retained for security, fraud prevention, transaction reconciliation, taxation, audit or applicable legal obligations. You can use the account deletion page for the published deletion process, or the Contact Us page for account or privacy requests.