Privacy Policy
Last updated: July 2026
What we process, and why
Account data (your name, company, email, hashed password): to operate your account, send service emails and provide support. Kept while your account exists.
Screened lead data (form values our customers submit for validation — typically email, name, company, phone, message — plus IP address, user agent and a browser-side hashed device fingerprint): processed in real time to produce a risk verdict, then retained on a rolling window of 90 days by default before automatic deletion, so customers can review their dashboard history. Retention is configurable, including immediate deletion after scoring.
Billing data: handled entirely by Stripe. We store only Stripe's customer/subscription identifiers — never card details.
Our role
For lead data screened on our customers' websites we act as a processor on the customer's behalf; the customer remains the controller of their visitors' data. For account and billing data we are the controller.
Third parties we rely on
- Stripe — payment processing
- Google (Gemini API) — AI analysis of ambiguous lead content, processed transiently
- AbuseIPDB — IP reputation lookups (IP address only)
- Our email delivery provider — transactional and lifecycle email
- Google Analytics — website statistics, loaded only after cookie consent
Your rights
You can request access to, correction of, or deletion of your personal data, and unsubscribe from non-essential email via the link in any message. UK/EU visitors also have the right to complain to their supervisory authority (in the UK, the ICO).
Security
All traffic is TLS-encrypted, passwords are stored hashed, API keys can be rotated instantly, and lead data is purged automatically per the retention schedule. See Security for detail.
Contact
Privacy questions or requests: leadshield.ai/contact.