Privacy Policy

Last updated: February 15, 2026

1. Introduction

Leadflip ("we", "us", or "our") operates the Leadflip platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

2. Information We Collect

2.1 Account Information

When you create an account, we collect your name, email address, and password. If you sign up via Google OAuth, we receive your Google profile information.

2.2 Lead Data

You may store lead data within the Service, including names, email addresses, phone numbers, and custom fields as defined by your entities. This data is stored as data processor on your behalf.

2.3 Usage Data

We automatically collect information about how you interact with the Service, including pages visited, features used, browser type, and IP address.

2.4 Payment Information

Payment processing is handled by Stripe, Inc. We do not store your full credit card details on our servers. Stripe's privacy policy applies to payment data.

3. How We Use Your Information

  • To provide and maintain the Service
  • To process your transactions and manage your subscription
  • To send you important service updates and notifications
  • To improve the Service and develop new features
  • To comply with legal obligations

4. Data Processing (GDPR)

We process personal data based on the following legal bases under the General Data Protection Regulation (GDPR):

  • Contract performance: Processing necessary to provide the Service you requested.
  • Legitimate interest: Processing for analytics and service improvement.
  • Consent: Where you have given explicit consent (e.g., marketing communications).
  • Legal obligation: Processing required by applicable law.

5. Data Encryption

Lead field data marked as encrypted is stored using AES-256-CBC encryption. Encrypted fields cannot be searched or sorted in the database. All data in transit is protected via TLS/SSL.

6. Data Sharing

We do not sell your personal data. We may share data with:

  • Service providers: Stripe (payments), AWS (hosting and storage), email delivery services.
  • Distribution partners: When you configure lead distribution, lead data is shared with your designated partners as configured by you.
  • Legal requirements: When required by law, regulation, or legal process.

7. Data Retention

We retain your account data for as long as your account is active. Lead data is retained according to your account settings. You may request deletion of your account and associated data at any time.

8. Your Rights (GDPR)

Under GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate personal data
  • Request erasure of your personal data
  • Restrict processing of your personal data
  • Data portability
  • Object to processing
  • Withdraw consent at any time

9. Cookies

We use essential cookies for authentication and session management. We do not use third-party tracking cookies. You can control cookie settings in your browser.

10. Security

We implement appropriate technical and organizational measures to protect your data, including encryption at rest, secure infrastructure on AWS, and access controls.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or through the Service.

12. Contact

For privacy-related inquiries, please contact us at privacy@leadflip.net.