Privacy Policy
LeadLocker is a business name of Red Capital Group Pty Ltd (ABN 41 696 755 530).
Last updated: 6 July 2026
LeadLocker ("LeadLocker", "we", "us", "our") is committed to protecting the privacy of individuals who use our website and services. This Privacy Policy explains how personal information is collected, used, stored, disclosed, and transferred in connection with LeadLocker.
This statement should be read alongside our Privacy Policy and Terms of Service.
Scope and purpose
LeadLocker is a software platform designed to organise business enquiries and leads. It is not designed to monitor private communications or access personal accounts. We collect and process only the information necessary to provide the service.
Information we collect
Depending on which integrations you configure, LeadLocker receives lead data from the following sources:
| Source | Data received |
|---|---|
| Meta Facebook/Instagram Lead Ads | Lead name, email, phone, custom question responses, Page ID, Page access token |
| Inbound email (via Mailgun) | Full email: From, To, Subject, message body (text and HTML), headers |
| Inbound SMS (via Telnyx) | Sender phone number, SMS message body |
| Inbound voice calls (via Telnyx) | Caller phone number, call duration, call recording, call transcript |
| Google Ads lead form webhook | Lead name, phone, comments |
| Public lead form | Lead name, email, phone, description |
| Custom webhook | Name, email, phone, description (as submitted by the integrating system) |
All inbound lead data is stored in Firebase Firestore, located in australia-southeast1 (Sydney, Australia).
We may also collect account information (name, email address), billing details handled by Stripe, and limited technical information such as IP addresses and usage data for security and operational purposes.
Where voice call features are used, we collect and store call metadata (phone numbers, call times, duration, outcomes), call recordings where provided by our telephony provider, and call transcripts — text records of conversations between your business and your callers. Transcripts may contain personal information spoken during the call and may be processed by OpenAI for analysis.
Information we do not access
LeadLocker does not access personal email inboxes, private messages, or communications unrelated to enquiries. We do not request, store, or have visibility into passwords for email accounts, social media accounts, or other third-party services. We do not log into external accounts on your behalf.
When third-party services are connected, access is granted using secure authorisation methods provided by those services. LeadLocker receives only the specific enquiry or lead data required to operate the platform.
Data LeadLocker does not use
- LeadLocker does not sell personal information to any third party
- LeadLocker does not use lead data for advertising or marketing to your customers
- LeadLocker does not use any third-party analytics, advertising tracking, or behavioural monitoring tools (no Google Analytics, Mixpanel, Hotjar, Segment, or similar)
- LeadLocker does not access your email inbox or send emails on your behalf beyond the transactional emails described above
- LeadLocker does not use your data to train AI models
Use of information
Personal information is used solely to provide, operate, and improve LeadLocker. This includes delivering and organising enquiries, notifying users of new leads, maintaining account functionality, communicating service-related information, automated classification and analysis of leads (including via OpenAI as described below), and meeting legal or regulatory requirements.
Automated analysis and OpenAI
When we receive a lead via inbound email or Facebook Lead Ads, and when a voice call is completed on an account with call features enabled, certain lead information — including names, contact details, message content, and full call transcript text — is sent to OpenAI's API for automated classification, scoring, and analysis. This is for inference only. Under OpenAI's API data usage policies, API data is not used to train OpenAI's models by default. OpenAI processes data in the United States. Full details are in our Data Handling Statement.
Third-party service providers (subprocessors)
LeadLocker engages the following third-party service providers to deliver the service. Each provider acts as a data processor under our instructions, except where noted. Operational logs are currently handled by Vercel only; we do not use Better Stack or Upstash in production today.
Google Firebase (Google LLC)
- Purpose: Primary data store for all account data, lead data, conversations, call transcripts, attachments, and authentication
- Data processed: Account details (email, name, hashed password), lead data (names, emails, phones, message content, call transcripts, attachments, quote data), organisation metadata, push notification tokens, Facebook Page tokens
- Storage location: australia-southeast1 (Sydney, Australia) — Firestore and Firebase Storage
- Authentication location: Google Identity Platform (global Google infrastructure)
- Own use: Google processes data as cloud infrastructure under Google Cloud's data processing terms. Google does not use Firestore content to train public AI models.
- Privacy policy: policies.google.com/privacy
- Data processing terms: firebase.google.com/terms/data-processing-terms
Vercel Inc.
- Purpose: Application hosting and serverless API processing
- Data processed: All data passes through Vercel's servers in transit during API request processing (lead data, webhook payloads, account data). Vercel retains structured operational logs per their log retention policy.
- Storage location: Washington DC, USA (iad1) — data is processed transiently; not stored long-term on Vercel
- Own use: Vercel uses data only to host and operate the application per their DPA
- Privacy policy: vercel.com/legal/privacy-policy
OpenAI (OpenAI, LLC)
- Purpose: AI-powered lead classification, lead scoring, and call transcript analysis
- Data processed:
- Lead classification: lead subject, sender, and up to 600 characters of message body
- Lead scoring: lead subject, sender, and up to 1,500 characters of message body
- Transcript analysis: full call transcript text
- Triggered by: Inbound email leads, Facebook/Instagram Lead Ads leads, and completed voice calls
- Storage location: United States
- Own use: Under OpenAI's API data usage policy, data submitted via the API is not used to train OpenAI's models by default. LeadLocker stores only the parsed output (classification result, score, suggestions) — not raw OpenAI responses.
- API data policy: openai.com/policies/api-data-usage-policies
Telnyx LLC
- Purpose: Inbound and outbound SMS, inbound voice calls, call transcription
- Data processed: Phone numbers (E.164 format), SMS message content (including lead name snippets and job details), call metadata (from/to numbers, duration, call outcome), call transcripts delivered via webhook
- Storage location: United States — Telnyx retains call and message records per carrier regulatory requirements and their data retention policy
- Own use: Carrier/CPaaS processing for routing, billing, fraud prevention, and regulatory compliance
- Privacy policy: telnyx.com/privacy-policy
Mailgun (Sinch)
- Purpose: Inbound email processing — forwarding emails sent to your LeadLocker inbox to the LeadLocker API
- Data processed: Full inbound email content (From, To, Subject, body text and HTML, headers)
- Storage location: United States
- Own use: Email delivery and processing per Mailgun's terms. LeadLocker does not retain raw Mailgun payloads beyond what is extracted into Firestore.
- Privacy policy: mailgun.com/privacy-policy
Resend (Resend Inc.)
- Purpose: Transactional email delivery (account onboarding, setup links, quote delivery)
- Data processed: Recipient email address, recipient name, email content (onboarding links, quote details including lead name and quote total)
- Storage location: United States
- Own use: Transactional email delivery only per Resend's terms
- Privacy policy: resend.com/legal/privacy-policy
Meta Platforms Inc. (Facebook/Instagram)
- Purpose: OAuth authentication for Page connections, Lead Ads webhook delivery, Graph API for lead retrieval and page subscription
- Data processed: Page access tokens, Lead Ads form submissions (name, email, phone, custom question responses), Page and Instagram business account metadata
- Storage location: Global (Meta infrastructure, primarily United States)
- Own use: Meta processes data per Meta's Platform Terms and data policies. LeadLocker uses Page tokens only to receive leads and maintain the connection — not for advertising.
- Platform terms: developers.facebook.com/terms
- Privacy policy: facebook.com/privacy/policy
Stripe (Stripe Payments Australia Pty Ltd)
- Purpose: Payment processing and subscription management
- Data processed: Customer email address, subscription plan and status, Stripe customer ID, Stripe subscription ID. LeadLocker does not store or access card numbers — payment details are handled entirely by Stripe's hosted checkout.
- Storage location: Australia/Global (Stripe Australia entity)
- Own use: Payment processing, fraud prevention, and financial compliance per Stripe's terms
- Privacy policy: stripe.com/privacy
Overseas disclosure of personal information
Your primary data is stored in Australia (Firebase, Sydney — australia-southeast1). Some service providers process data in the United States (Vercel, OpenAI, Telnyx, Mailgun, Resend, Meta). When data is transferred outside Australia, we engage only providers with appropriate data protection practices and contractual terms. For more information, see the subprocessor list above.
Facebook Lead Ads data handling
LeadLocker receives lead data from Meta Lead Ads via the Facebook Graph API and webhook subscriptions. This data is:
- Received in real time and stored in Firebase Firestore (australia-southeast1, Sydney)
- Displayed within your LeadLocker dashboard
- Used to send you lead notifications via SMS (Telnyx) and email (Resend) where configured
- Optionally processed by OpenAI for classification and scoring
- Never shared with other LeadLocker account holders
- Never used for advertising or marketing unrelated to delivering the LeadLocker service
- Deleted from LeadLocker's systems when you delete the lead or delete your account
End consumer deletion requests: if an individual whose information was collected via a Facebook Lead Ad wishes to have their information deleted from LeadLocker's systems, they may contact us at support@leadlocker.app. We will process deletion requests within 30 days.
Account holder deletion: when you disconnect your Facebook Page or delete your LeadLocker account, your Page access tokens are permanently deleted from our systems. Lead data associated with your account is deleted in accordance with our account deletion process.
Lead data and customer responsibility
LeadLocker processes lead data on behalf of its customers. Customers retain ownership of their lead data and are responsible for ensuring that they collect, use, and manage that data in compliance with applicable privacy and marketing laws, including informing their own customers where required (for example, about call transcription or lead form collection).
Data storage and security
Information is stored primarily in Google Firebase (Firestore and Cloud Storage) in Australia (Sydney), Google Cloud region australia-southeast1. We implement the following technical measures to protect data:
- All data transmitted between users and the LeadLocker application is encrypted in transit using HTTPS/TLS
- Firebase Security Rules restrict data access so users can only access data belonging to their organisation
- Firebase Authentication manages account access using industry-standard practices
- Passwords are hashed by Firebase Authentication — we do not have access to plain-text passwords
- API routes are protected by authentication checks and rate limiting
Disclosure of information
LeadLocker does not sell personal information. Information may be disclosed to the subprocessors listed above solely for the purpose of operating the platform, or to legal and regulatory authorities where required by law.
Data retention and deletion
| Data type | Retention | Deletion |
|---|---|---|
| Account data | Duration of account | Deleted on account deletion |
| Lead data | Duration of account, or until manually deleted | Deleted on lead deletion or account deletion |
| Call transcripts | Duration of account | Deleted on account deletion |
| Attachments | Duration of account | Deleted on account deletion |
| Facebook Page tokens | Until Page disconnected or account deleted | Permanently deleted on disconnection or account deletion |
| Backups | Up to 30 days after account deletion | Purged within 30 days of account deletion |
| Stripe billing records | Per Stripe's retention requirements | Managed by Stripe |
Access, correction, and deletion
Account holders may delete their LeadLocker account and all associated data at any time from within the app's account settings. This permanently removes the account and its associated lead data.
Individuals whose information was submitted through a lead form connected to LeadLocker (for example, via a Facebook Lead Ad) may not hold a LeadLocker account themselves. They may request access to, correction of, or deletion of their personal information by contacting us as set out below. Requests will be handled within 30 days in accordance with applicable laws.
Changes to this policy
This Privacy Policy may be updated from time to time. Continued use of LeadLocker after any changes indicates acceptance of the updated policy.
Contact
For data handling enquiries or to submit a deletion request:
Email: support@leadlocker.app
Business: LeadLocker, operated by Red Capital Group Pty Ltd (ABN 41 696 755 530)