Privacy Policy

LeadLocker is a business name of Red Capital Group Pty Ltd (ABN 41 696 755 530).

Last updated: 6 July 2026

LeadLocker ("LeadLocker", "we", "us", "our") is committed to protecting the privacy of individuals who use our website and services. This Privacy Policy explains how personal information is collected, used, stored, disclosed, and transferred in connection with LeadLocker.

This statement should be read alongside our Privacy Policy and Terms of Service.

Scope and purpose

LeadLocker is a software platform designed to organise business enquiries and leads. It is not designed to monitor private communications or access personal accounts. We collect and process only the information necessary to provide the service.

Information we collect

Depending on which integrations you configure, LeadLocker receives lead data from the following sources:

SourceData received
Meta Facebook/Instagram Lead AdsLead name, email, phone, custom question responses, Page ID, Page access token
Inbound email (via Mailgun)Full email: From, To, Subject, message body (text and HTML), headers
Inbound SMS (via Telnyx)Sender phone number, SMS message body
Inbound voice calls (via Telnyx)Caller phone number, call duration, call recording, call transcript
Google Ads lead form webhookLead name, phone, comments
Public lead formLead name, email, phone, description
Custom webhookName, email, phone, description (as submitted by the integrating system)

All inbound lead data is stored in Firebase Firestore, located in australia-southeast1 (Sydney, Australia).

We may also collect account information (name, email address), billing details handled by Stripe, and limited technical information such as IP addresses and usage data for security and operational purposes.

Where voice call features are used, we collect and store call metadata (phone numbers, call times, duration, outcomes), call recordings where provided by our telephony provider, and call transcripts — text records of conversations between your business and your callers. Transcripts may contain personal information spoken during the call and may be processed by OpenAI for analysis.

Information we do not access

LeadLocker does not access personal email inboxes, private messages, or communications unrelated to enquiries. We do not request, store, or have visibility into passwords for email accounts, social media accounts, or other third-party services. We do not log into external accounts on your behalf.

When third-party services are connected, access is granted using secure authorisation methods provided by those services. LeadLocker receives only the specific enquiry or lead data required to operate the platform.

Data LeadLocker does not use

Use of information

Personal information is used solely to provide, operate, and improve LeadLocker. This includes delivering and organising enquiries, notifying users of new leads, maintaining account functionality, communicating service-related information, automated classification and analysis of leads (including via OpenAI as described below), and meeting legal or regulatory requirements.

Automated analysis and OpenAI

When we receive a lead via inbound email or Facebook Lead Ads, and when a voice call is completed on an account with call features enabled, certain lead information — including names, contact details, message content, and full call transcript text — is sent to OpenAI's API for automated classification, scoring, and analysis. This is for inference only. Under OpenAI's API data usage policies, API data is not used to train OpenAI's models by default. OpenAI processes data in the United States. Full details are in our Data Handling Statement.

Third-party service providers (subprocessors)

LeadLocker engages the following third-party service providers to deliver the service. Each provider acts as a data processor under our instructions, except where noted. Operational logs are currently handled by Vercel only; we do not use Better Stack or Upstash in production today.

Google Firebase (Google LLC)

  • Purpose: Primary data store for all account data, lead data, conversations, call transcripts, attachments, and authentication
  • Data processed: Account details (email, name, hashed password), lead data (names, emails, phones, message content, call transcripts, attachments, quote data), organisation metadata, push notification tokens, Facebook Page tokens
  • Storage location: australia-southeast1 (Sydney, Australia) — Firestore and Firebase Storage
  • Authentication location: Google Identity Platform (global Google infrastructure)
  • Own use: Google processes data as cloud infrastructure under Google Cloud's data processing terms. Google does not use Firestore content to train public AI models.
  • Privacy policy: policies.google.com/privacy
  • Data processing terms: firebase.google.com/terms/data-processing-terms

Vercel Inc.

  • Purpose: Application hosting and serverless API processing
  • Data processed: All data passes through Vercel's servers in transit during API request processing (lead data, webhook payloads, account data). Vercel retains structured operational logs per their log retention policy.
  • Storage location: Washington DC, USA (iad1) — data is processed transiently; not stored long-term on Vercel
  • Own use: Vercel uses data only to host and operate the application per their DPA
  • Privacy policy: vercel.com/legal/privacy-policy

OpenAI (OpenAI, LLC)

  • Purpose: AI-powered lead classification, lead scoring, and call transcript analysis
  • Data processed:
    • Lead classification: lead subject, sender, and up to 600 characters of message body
    • Lead scoring: lead subject, sender, and up to 1,500 characters of message body
    • Transcript analysis: full call transcript text
  • Triggered by: Inbound email leads, Facebook/Instagram Lead Ads leads, and completed voice calls
  • Storage location: United States
  • Own use: Under OpenAI's API data usage policy, data submitted via the API is not used to train OpenAI's models by default. LeadLocker stores only the parsed output (classification result, score, suggestions) — not raw OpenAI responses.
  • API data policy: openai.com/policies/api-data-usage-policies

Telnyx LLC

  • Purpose: Inbound and outbound SMS, inbound voice calls, call transcription
  • Data processed: Phone numbers (E.164 format), SMS message content (including lead name snippets and job details), call metadata (from/to numbers, duration, call outcome), call transcripts delivered via webhook
  • Storage location: United States — Telnyx retains call and message records per carrier regulatory requirements and their data retention policy
  • Own use: Carrier/CPaaS processing for routing, billing, fraud prevention, and regulatory compliance
  • Privacy policy: telnyx.com/privacy-policy

Mailgun (Sinch)

  • Purpose: Inbound email processing — forwarding emails sent to your LeadLocker inbox to the LeadLocker API
  • Data processed: Full inbound email content (From, To, Subject, body text and HTML, headers)
  • Storage location: United States
  • Own use: Email delivery and processing per Mailgun's terms. LeadLocker does not retain raw Mailgun payloads beyond what is extracted into Firestore.
  • Privacy policy: mailgun.com/privacy-policy

Resend (Resend Inc.)

  • Purpose: Transactional email delivery (account onboarding, setup links, quote delivery)
  • Data processed: Recipient email address, recipient name, email content (onboarding links, quote details including lead name and quote total)
  • Storage location: United States
  • Own use: Transactional email delivery only per Resend's terms
  • Privacy policy: resend.com/legal/privacy-policy

Meta Platforms Inc. (Facebook/Instagram)

  • Purpose: OAuth authentication for Page connections, Lead Ads webhook delivery, Graph API for lead retrieval and page subscription
  • Data processed: Page access tokens, Lead Ads form submissions (name, email, phone, custom question responses), Page and Instagram business account metadata
  • Storage location: Global (Meta infrastructure, primarily United States)
  • Own use: Meta processes data per Meta's Platform Terms and data policies. LeadLocker uses Page tokens only to receive leads and maintain the connection — not for advertising.
  • Platform terms: developers.facebook.com/terms
  • Privacy policy: facebook.com/privacy/policy

Stripe (Stripe Payments Australia Pty Ltd)

  • Purpose: Payment processing and subscription management
  • Data processed: Customer email address, subscription plan and status, Stripe customer ID, Stripe subscription ID. LeadLocker does not store or access card numbers — payment details are handled entirely by Stripe's hosted checkout.
  • Storage location: Australia/Global (Stripe Australia entity)
  • Own use: Payment processing, fraud prevention, and financial compliance per Stripe's terms
  • Privacy policy: stripe.com/privacy

Overseas disclosure of personal information

Your primary data is stored in Australia (Firebase, Sydney — australia-southeast1). Some service providers process data in the United States (Vercel, OpenAI, Telnyx, Mailgun, Resend, Meta). When data is transferred outside Australia, we engage only providers with appropriate data protection practices and contractual terms. For more information, see the subprocessor list above.

Facebook Lead Ads data handling

LeadLocker receives lead data from Meta Lead Ads via the Facebook Graph API and webhook subscriptions. This data is:

End consumer deletion requests: if an individual whose information was collected via a Facebook Lead Ad wishes to have their information deleted from LeadLocker's systems, they may contact us at support@leadlocker.app. We will process deletion requests within 30 days.

Account holder deletion: when you disconnect your Facebook Page or delete your LeadLocker account, your Page access tokens are permanently deleted from our systems. Lead data associated with your account is deleted in accordance with our account deletion process.

Lead data and customer responsibility

LeadLocker processes lead data on behalf of its customers. Customers retain ownership of their lead data and are responsible for ensuring that they collect, use, and manage that data in compliance with applicable privacy and marketing laws, including informing their own customers where required (for example, about call transcription or lead form collection).

Data storage and security

Information is stored primarily in Google Firebase (Firestore and Cloud Storage) in Australia (Sydney), Google Cloud region australia-southeast1. We implement the following technical measures to protect data:

Disclosure of information

LeadLocker does not sell personal information. Information may be disclosed to the subprocessors listed above solely for the purpose of operating the platform, or to legal and regulatory authorities where required by law.

Data retention and deletion

Data typeRetentionDeletion
Account dataDuration of accountDeleted on account deletion
Lead dataDuration of account, or until manually deletedDeleted on lead deletion or account deletion
Call transcriptsDuration of accountDeleted on account deletion
AttachmentsDuration of accountDeleted on account deletion
Facebook Page tokensUntil Page disconnected or account deletedPermanently deleted on disconnection or account deletion
BackupsUp to 30 days after account deletionPurged within 30 days of account deletion
Stripe billing recordsPer Stripe's retention requirementsManaged by Stripe

Access, correction, and deletion

Account holders may delete their LeadLocker account and all associated data at any time from within the app's account settings. This permanently removes the account and its associated lead data.

Individuals whose information was submitted through a lead form connected to LeadLocker (for example, via a Facebook Lead Ad) may not hold a LeadLocker account themselves. They may request access to, correction of, or deletion of their personal information by contacting us as set out below. Requests will be handled within 30 days in accordance with applicable laws.

Changes to this policy

This Privacy Policy may be updated from time to time. Continued use of LeadLocker after any changes indicates acceptance of the updated policy.

Contact

For data handling enquiries or to submit a deletion request:

Email: support@leadlocker.app

Business: LeadLocker, operated by Red Capital Group Pty Ltd (ABN 41 696 755 530)

← Back to home