Data Handling Statement
LeadLocker is a business name of Red Capital Group Pty Ltd (ABN 41 696 755 530).
Last updated: 6 July 2026
Overview
This Data Handling Statement describes how LeadLocker processes personal information, which third-party services receive data and for what purpose, and where data is stored. It is intended to provide transparency for account holders, their customers (leads), and third parties such as Meta who review our data practices.
This statement should be read alongside our Privacy Policy and Terms of Service.
Data flows
Inbound lead sources
LeadLocker receives lead data from the following sources, depending on which integrations you have configured:
| Source | Data received |
|---|---|
| Meta Facebook/Instagram Lead Ads | Lead name, email, phone, custom question responses, Page ID, Page access token |
| Inbound email (via Mailgun) | Full email: From, To, Subject, message body (text and HTML), headers |
| Inbound SMS (via Telnyx) | Sender phone number, SMS message body |
| Inbound voice calls (via Telnyx) | Caller phone number, call duration, call recording, call transcript |
| Google Ads lead form webhook | Lead name, phone, comments |
| Public lead form | Lead name, email, phone, description |
| Custom webhook | Name, email, phone, description (as submitted by the integrating system) |
All inbound lead data is stored in Firebase Firestore, located in australia-southeast1 (Sydney, Australia).
Third-party subprocessors
LeadLocker engages the following third-party service providers to deliver the service. Each provider acts as a data processor under our instructions, except where noted. Operational logs are currently handled by Vercel only; we do not use Better Stack or Upstash in production today.
Google Firebase (Google LLC)
- Purpose: Primary data store for all account data, lead data, conversations, call transcripts, attachments, and authentication
- Data processed: Account details (email, name, hashed password), lead data (names, emails, phones, message content, call transcripts, attachments, quote data), organisation metadata, push notification tokens, Facebook Page tokens
- Storage location: australia-southeast1 (Sydney, Australia) — Firestore and Firebase Storage
- Authentication location: Google Identity Platform (global Google infrastructure)
- Own use: Google processes data as cloud infrastructure under Google Cloud's data processing terms. Google does not use Firestore content to train public AI models.
- Privacy policy: policies.google.com/privacy
- Data processing terms: firebase.google.com/terms/data-processing-terms
Vercel Inc.
- Purpose: Application hosting and serverless API processing
- Data processed: All data passes through Vercel's servers in transit during API request processing (lead data, webhook payloads, account data). Vercel retains structured operational logs per their log retention policy.
- Storage location: Washington DC, USA (iad1) — data is processed transiently; not stored long-term on Vercel
- Own use: Vercel uses data only to host and operate the application per their DPA
- Privacy policy: vercel.com/legal/privacy-policy
OpenAI (OpenAI, LLC)
- Purpose: AI-powered lead classification, lead scoring, and call transcript analysis
- Data processed:
- Lead classification: lead subject, sender, and up to 600 characters of message body
- Lead scoring: lead subject, sender, and up to 1,500 characters of message body
- Transcript analysis: full call transcript text
- Triggered by: Inbound email leads, Facebook/Instagram Lead Ads leads, and completed voice calls
- Storage location: United States
- Own use: Under OpenAI's API data usage policy, data submitted via the API is not used to train OpenAI's models by default. LeadLocker stores only the parsed output (classification result, score, suggestions) — not raw OpenAI responses.
- API data policy: openai.com/policies/api-data-usage-policies
Telnyx LLC
- Purpose: Inbound and outbound SMS, inbound voice calls, call transcription
- Data processed: Phone numbers (E.164 format), SMS message content (including lead name snippets and job details), call metadata (from/to numbers, duration, call outcome), call transcripts delivered via webhook
- Storage location: United States — Telnyx retains call and message records per carrier regulatory requirements and their data retention policy
- Own use: Carrier/CPaaS processing for routing, billing, fraud prevention, and regulatory compliance
- Privacy policy: telnyx.com/privacy-policy
Mailgun (Sinch)
- Purpose: Inbound email processing — forwarding emails sent to your LeadLocker inbox to the LeadLocker API
- Data processed: Full inbound email content (From, To, Subject, body text and HTML, headers)
- Storage location: United States
- Own use: Email delivery and processing per Mailgun's terms. LeadLocker does not retain raw Mailgun payloads beyond what is extracted into Firestore.
- Privacy policy: mailgun.com/privacy-policy
Resend (Resend Inc.)
- Purpose: Transactional email delivery (account onboarding, setup links, quote delivery)
- Data processed: Recipient email address, recipient name, email content (onboarding links, quote details including lead name and quote total)
- Storage location: United States
- Own use: Transactional email delivery only per Resend's terms
- Privacy policy: resend.com/legal/privacy-policy
Meta Platforms Inc. (Facebook/Instagram)
- Purpose: OAuth authentication for Page connections, Lead Ads webhook delivery, Graph API for lead retrieval and page subscription
- Data processed: Page access tokens, Lead Ads form submissions (name, email, phone, custom question responses), Page and Instagram business account metadata
- Storage location: Global (Meta infrastructure, primarily United States)
- Own use: Meta processes data per Meta's Platform Terms and data policies. LeadLocker uses Page tokens only to receive leads and maintain the connection — not for advertising.
- Platform terms: developers.facebook.com/terms
- Privacy policy: facebook.com/privacy/policy
Stripe (Stripe Payments Australia Pty Ltd)
- Purpose: Payment processing and subscription management
- Data processed: Customer email address, subscription plan and status, Stripe customer ID, Stripe subscription ID. LeadLocker does not store or access card numbers — payment details are handled entirely by Stripe's hosted checkout.
- Storage location: Australia/Global (Stripe Australia entity)
- Own use: Payment processing, fraud prevention, and financial compliance per Stripe's terms
- Privacy policy: stripe.com/privacy
Data LeadLocker does not use
- LeadLocker does not sell personal information to any third party
- LeadLocker does not use lead data for advertising or marketing to your customers
- LeadLocker does not use any third-party analytics, advertising tracking, or behavioural monitoring tools (no Google Analytics, Mixpanel, Hotjar, Segment, or similar)
- LeadLocker does not access your email inbox or send emails on your behalf beyond the transactional emails described above
- LeadLocker does not use your data to train AI models
Facebook Lead Ads data handling
LeadLocker receives lead data from Meta Lead Ads via the Facebook Graph API and webhook subscriptions. This data is:
- Received in real time and stored in Firebase Firestore (australia-southeast1, Sydney)
- Displayed within your LeadLocker dashboard
- Used to send you lead notifications via SMS (Telnyx) and email (Resend) where configured
- Optionally processed by OpenAI for classification and scoring
- Never shared with other LeadLocker account holders
- Never used for advertising or marketing unrelated to delivering the LeadLocker service
- Deleted from LeadLocker's systems when you delete the lead or delete your account
End consumer deletion requests: if an individual whose information was collected via a Facebook Lead Ad wishes to have their information deleted from LeadLocker's systems, they may contact us at support@leadlocker.app. We will process deletion requests within 30 days.
Account holder deletion: when you disconnect your Facebook Page or delete your LeadLocker account, your Page access tokens are permanently deleted from our systems. Lead data associated with your account is deleted in accordance with our account deletion process.
Data security
We implement the following technical measures to protect data:
- All data transmitted between users and the LeadLocker application is encrypted in transit using HTTPS/TLS
- Firebase Security Rules restrict data access so users can only access data belonging to their organisation
- Firebase Authentication manages account access using industry-standard practices
- Passwords are hashed by Firebase Authentication — we do not have access to plain-text passwords
- API routes are protected by authentication checks and rate limiting
Data retention and deletion
| Data type | Retention | Deletion |
|---|---|---|
| Account data | Duration of account | Deleted on account deletion |
| Lead data | Duration of account, or until manually deleted | Deleted on lead deletion or account deletion |
| Call transcripts | Duration of account | Deleted on account deletion |
| Attachments | Duration of account | Deleted on account deletion |
| Facebook Page tokens | Until Page disconnected or account deleted | Permanently deleted on disconnection or account deletion |
| Backups | Up to 30 days after account deletion | Purged within 30 days of account deletion |
| Stripe billing records | Per Stripe's retention requirements | Managed by Stripe |
International data transfers
Your primary data is stored in Australia (Firebase, Sydney — australia-southeast1). Some service providers process data in the United States (Vercel, OpenAI, Telnyx, Mailgun, Resend, Meta). When data is transferred outside Australia, we engage only providers with appropriate data protection practices and contractual terms. For more information, see the subprocessor list above.
Contact
For data handling enquiries or to submit a deletion request:
Email: support@leadlocker.app
Business: LeadLocker, operated by Red Capital Group Pty Ltd (ABN 41 696 755 530)