Privacy
Last updated 18 August 2026
This policy explains what LapseDesk collects, why, who can see it, and how to ask us to change or delete it. It covers the website at lapsedesk.com, the agent app, and the client app.
This app does not take the money. We don’t charge your clients. Premium is paid to the insurer or office, not through us. See We are not a payment processor.
Who we are
LapseDesk is operated by Enmirth, in the Philippines. For privacy requests, email privacy@lapsedesk.com.
We follow the Data Privacy Act of 2012 (Republic Act No. 10173) and its implementing rules. If you write to us from another country, we will still handle a reasonable request to access, correct, or delete your information.
Whose information this covers
Agents create an account, pay for a plan, keep books (businesses), invite clients, and verify I’ve paid confirmations.
Clients are invited; they are never added silently. A client account is keyed to a phone number (E.164). Email is optional. The same person may belong to more than one agent and more than one book.
When a client joins a book, that agent is the person they already deal with. LapseDesk provides the desk. We do not sell a public client directory.
What we collect
From agents:
- Email (required), optional phone, display name, password or one-time sign-in code
- Business mini pages: name, logo, description, purpose, contact details, hours, service area, languages, accent color, and payment instructions (how to pay the insurer or office — never a card form)
- Dues you record: amount, currency, due date, notes, and status
- Stripe customer and subscription identifiers for your plan (we do not see your full card number)
- SMS and shoutout credit balances
From clients:
- Phone number (the account key) and optional email and display name
- Invite responses: accept, decline, leave, block, or Report spam or scam
- I’ve paid submissions: date paid, amount, method, reference, and an optional receipt photo
- Reminder preferences per book (email, SMS, WhatsApp, or stopped)
In the course of running the service:
- Session cookies needed to stay signed in
- Server logs (IP address, time, path) used to run and protect the site
- Audit events such as viewed, confirmed, blocked, or reported — never the OTP code itself
- Rate-limit counters for OTP, join, and report
- Global opt-out records keyed to phone, including from STOP or the opt-out page
What we never store
We do not store card numbers, CVV, one-time passcodes, banking passwords, or full track data. I’ve paid is a confirmation with optional proof for the agent, not a charge through LapseDesk.
Why we use it
- To create and secure accounts (email or phone OTP)
- To show each agent only their own books, and each client only the books they joined
- To send due reminders the client agreed to, and to honor STOP
- To let a client confirm payment and the agent mark Confirmed or Needs follow-up
- To bill agents on the web via Stripe
- To handle block, leave, and report, and to keep the service safe
- To diagnose faults and prevent abuse
We do not use client information to advertise other products. We do not sell personal information.
Who can see it
An agent sees the clients who joined that agent’s books: name, phone, email if present, dues, confirmations, and receipts for those books. An agent cannot read another agent’s books. A client cannot see other clients.
If you block or report, the agent sees No longer available or Invite not accepted — never that you reported them. Reports stay on file with LapseDesk after unblock. Unblock does not put you back in the book; a new invite is required.
Business logos on a mini page are public so an invite looks like the same company. Receipt photos are private. They are shown with short-lived signed URLs to the client who uploaded them and to the agent for that book.
Invite links use unguessable codes. Block is tied to phone (and email if present), not to a device.
Companies that process data for us
We use other companies to run LapseDesk. They only get what they need to do that job:
- Vercel — hosts the website
- Supabase — authentication, database, and file storage
- Stripe — agent plan checkout and the customer portal (cards are handled by Stripe)
- Resend — transactional and reminder email
- An SMS or WhatsApp provider, only when that channel is turned on — they receive the destination number and the message body
Those companies have their own privacy terms. Hosting and databases may be in the United States or another region the provider operates. If we add a provider, we will update this page.
Messages
Email is the routine reminder channel. WhatsApp is optional on higher plans. SMS is capped and reserved for overdue reminders and OTP fallback — not weekly marketing. The core product (sign in, dues, I’ve paid, verify) still works when SMS credits are zero.
You can change reminder preferences after you join. Reply STOP to opt out of text messages from this agent. The opt-out page does the same even if you never open the app. Stopping messages does not delete your account. More detail: SMS and email consent.
Cookies and similar
We use cookies and similar storage so you can stay signed in. They are required for the logged-in product. We do not use advertising cookies, and we do not drop trackers to sell an audience.
How long we keep it
- Account, books, dues, and confirmations: while the account is open, and for a short period after so we can complete a deletion request
- Receipt files: with the confirmation they belong to; removed when that record is deleted
- Session and magic-link tokens: until they expire or are used
- Global STOP / opt-out records: kept so we do not message that number again
- Blocks: kept against the phone (and email if present) so a new device cannot walk around a block
- Reports: kept after unblock, so a safety record remains
- Agent billing records: as long as tax and accounting rules require
- Server logs: a short operational window unless we need them for a security incident
Your choices and rights
You can:
- Decline an invite, leave a book, block, or report
- Stop reminders without deleting your space
- Ask us for a copy of the personal information we hold about you
- Ask us to correct it
- Ask us to delete your account and associated personal information
There is no self-serve delete button yet. Email privacy@lapsedesk.com from the address on the account, or include the phone number that is the client key. We will verify it is you before we act.
We may keep what the law requires, what we need to complete billing, and the limited safety records above (STOP, block, report). If we cannot fully delete something, we will say so.
You may also complain to the National Privacy Commission of the Philippines if you believe your data privacy rights were violated.
Children
LapseDesk is for licensed or working agents and the clients they already serve. It is not directed at children. If we learn we have an account for a child, we will delete it.
Security
Access to books is enforced in the database: agent A cannot read agent B; a client cannot see other clients. Invite codes are unguessable. OTP, join, and report are rate-limited. Receipts are in a private bucket. Application audit logs do not store OTP codes. Production data is not used on preview deployments.
No internet service is perfectly secure. If we become aware of a breach that affects you, we will notify you and the Commission as the law requires.
Changes
If we change what we collect or who can see it, we will update this page and the date above. Continued use after a material change means you have had a chance to read the new version.
Contact
Privacy: privacy@lapsedesk.com
Related pages: Terms, SMS and email consent, Not a payment processor, Opt out.