← Back to Home
leadedAccess

Privacy Policy

Effective: April 29, 2026
Draft. Have this reviewed by legal counsel before relying on it for compliance with GDPR, CCPA, or other regulations applicable to your customer data.

1. Who we are

leadedAccess ("we", "us") is a lead management platform operated from Atlanta, Georgia, USA. You can reach us at [email protected].

2. What we collect

  • Account data: name, email, company, phone, password hash.
  • Usage data: IP address, login timestamps, activity log, user agent.
  • Lead data: records you upload, query, or export through the platform.

3. How we use it

  • Operate and secure your account (authentication, lockout, audit trail).
  • Send security notifications (new IP login, password changes, account lock).
  • Improve the product based on aggregate usage patterns.

4. How we protect it

We hash passwords with bcrypt, enforce HTTPS, lock accounts after repeated failed login attempts, and log security-relevant events. No system is perfectly secure, but we follow industry-standard practices.

5. Sharing

We do not sell your data. We share it only with infrastructure providers strictly necessary to deliver the service, or where required by law.

6. Your rights

You can request access, correction, or deletion of your personal data by emailing [email protected]. We respond within 30 days.

7. Cookies

We use a single session cookie (LEADED_SESSID) marked HttpOnly, Secure, and SameSite=Strict. No third-party tracking cookies.

8. Changes

If we materially change this policy, we will notify account holders by email at least 30 days before changes take effect.