Legal

Privacy Policy

What data LeadCredit Pro collects, how we use it, who we share it with, and the choices you have.

Effective September 6, 2026

1. Who we are

LeadCredit Pro ("LeadCredit Pro", "we", "us") is operated by [LEGAL ENTITY NAME], a [STATE] limited liability company with offices at [ADDRESS]. You can reach us at privacy@leadcreditpro.com.

2. What data we collect

2.1 Account data

Name, email address, organization name, role, and authentication metadata. Authentication is provided by Clerk; we never store passwords ourselves.

2.2 Lead data you upload

When you upload a Local Services Ads CSV, we receive the lead records that file contains. That is the customer's name, phone number, email address, job type, service area, lead date and time, and any cost figures the export carries.

When you connect your Google Ads account, we receive the fields the Local Services Ads API returns for each lead: the customer's name, the phone number and the extension to dial with it, the lead type, Google's job-category id, the lead date and time, whether Google charged you for the lead, the lead status Google reports, and the credit state Google reports. The Google Ads API no longer returns a consumer email address, so a lead synced from Google carries none.

Phone numbers, phone extensions, and email addresses are encrypted at rest using AES-256-GCM before they are written to our database. For phone numbers and email addresses we also store a one-way HMAC-SHA-256 hash, salted with a server-side pepper, so we can detect duplicates without ever storing the raw value in a searchable form. Decryption happens only when you, an authorized member of your organization, or a documented support request opens a specific lead in your dashboard.

2.3 Usage and operational data

Standard request logs (timestamps, route, status code, request id), audit-log entries for security-sensitive actions (logins, role changes, exports, deletions, integration connect/disconnect, billing changes), and product telemetry (feature usage, error events). Logs and telemetry are scrubbed of PII via a deny-list redactor before they are written.

2.4 Payment data

Billing is processed by Stripe. We never see or store full card numbers. Stripe sends us an opaque customer id and the public attributes of your subscription (status, plan, trial end, period end).

3. How we use your data

  • To provide the audit, classification, and reporting features you signed up for.
  • To detect and prevent fraud, abuse, and security incidents.
  • To bill you for the plan you have chosen.
  • To communicate with you about your account, security alerts, and material changes to this policy.
  • To comply with legal obligations.

We do not sell your data, do not use lead PII to train machine-learning models, and do not use your data to advertise to you or to third parties.

4. Subprocessors

We rely on the following service providers to operate the product:

ProviderPurposeRegion
VercelApplication hostingUS
NeonPostgres databaseUS
Cloudflare R2Object storage for uploaded CSVsGlobal
ClerkAuthentication and organization managementUS
StripeSubscription billingUS
ResendTransactional emailUS/EU
InngestBackground job orchestrationUS
SentryError monitoring (PII-redacted)US
OpenAIOptional AI lead-quality advisor and report summaries, opt-in per organizationUS
UpstashRate-limit counters, hashed identifiers onlyGlobal
GoogleService-area address autocompleteGlobal

Each subprocessor has its own privacy policy and security commitments. We periodically review their compliance. We will update this list before adding a new subprocessor that processes customer data.

The OpenAI row applies only when an owner switches the AI advisor on for the organization. It is off by default, and with it off no lead data reaches OpenAI. When it is on, we send structural lead attributes and a truncated job-description summary. The customer name, phone number, and email address are excluded by construction, and phone and email patterns inside the job text are masked, but free text a customer typed can still contain a name we cannot detect.

5. Data retention

  • Lead data: retained while your subscription is active. The original uploaded CSV file is deleted from object storage as soon as the import job completes; only the parsed, encrypted lead rows persist.
  • Audit logs: retained for 24 months for security and compliance.
  • Account closure: when you delete your organization, lead rows and uploaded artifacts are erased within 30 days. Backups roll off within 35 days.

6. Your rights

Depending on where you live (CCPA, GDPR, or similar), you have the right to access, correct, export, or delete your personal data. Here is where each one lives:

  • Export: owners and members can download their lead data as CSV from the Export menu on the Leads page.
  • Correct: workspace details (industry, services, service areas, country, currency) are editable at Workspace profile.
  • Delete: an owner can delete the whole organization from the workspace switcher in the dashboard header, under Manage organization. Deleting erases lead rows and uploaded artifacts on the schedule in section 5. If that option is not available to you, email support@leadcreditpro.com and we will delete the organization for you.
  • Access, or anything else: email privacy@leadcreditpro.com and we will respond within 30 days.

7. Google API Services User Data Policy

When you connect a Google Ads account to LeadCredit Pro, our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

7.1 Scopes we request

ScopeWhy we need it
https://www.googleapis.com/auth/adwordsRead your Local Services Ads leads, lead conversations, and credit-state history so we can audit them for waste. The same scope also submits your rating for one lead to Google's Lead Feedback Survey. That write happens only when an owner in your workspace confirms it on that lead, once per lead, and never on a schedule or in bulk.
openid email profileIdentify the Google account you connected so we can show it in Settings and let you disconnect it.

7.2 What we store

  • Refresh token: encrypted at rest with AES-256-GCM. Used only to mint short-lived access tokens to call the Google Ads API on your behalf: to sync your Local Services leads, and to submit a lead rating when an owner confirms it on that lead.
  • Connected Google account email and customer id: shown in Settings so you know which account is connected.
  • Lead records returned by the API: stored under the same encryption and retention rules as Section 2.2.

7.3 What we do not do

  • We do not transfer Google user data to third parties for advertising or resale.
  • We do not use Google user data to train generalized AI or ML models.
  • We do not allow humans to read your Google user data except (a) with your explicit consent for support, (b) for security investigations, or (c) when required by law.
  • We do not request or store your Google account password.

7.4 How to revoke access

You can disconnect at any time from Settings → Integrations. Disconnecting revokes the refresh token at Google and nulls our encrypted copy. You can also revoke at any time directly from your Google Account at myaccount.google.com/permissions.

8. Security

Data is encrypted in transit (TLS 1.2+) and at rest. PII fields are encrypted at rest with AES-256-GCM using a 256-bit key held in our hosting provider's secret store, with each ciphertext bound to its own column. Matching hashes use HMAC-SHA-256 under a separate server-side pepper. We run continuous dependency scanning and respond to high-severity advisories on a target SLA of seven days.

9. International transfers

Our infrastructure is primarily located in the United States. If you access the product from outside the United States, you understand that your data may be transferred to and processed in the United States. Where required, we rely on Standard Contractual Clauses for the transfer of personal data to a third country.

10. Children

The product is intended for use by businesses. We do not knowingly collect personal data from anyone under the age of 16.

11. Changes to this policy

We will post material changes to this policy on this page and, where required, notify you by email. The "Effective" date at the top reflects the most recent change.

12. Contact

Questions or requests: privacy@leadcreditpro.com.


LeadCredit Pro is not affiliated with, endorsed by, or sponsored by Google. Google and Google Local Services Ads are trademarks of Google LLC.