Terms of Service
LeadLocker is a business name of Red Capital Group Pty Ltd (ABN 41 696 755 530).
Last updated: 6 July 2026
These Terms of Service govern access to and use of the LeadLocker website and services. By accessing or using LeadLocker, you agree to be bound by these Terms. If you do not agree, you must not use the service.
This statement should be read alongside our Privacy Policy and Terms of Service.
The service
LeadLocker is a software platform designed to collect, organise, and present business enquiries and leads from connected sources. The service is provided on an "as is" and "as available" basis. We may modify, update, suspend, or discontinue any part of the service at any time.
Accounts and access
To access certain features, you may be required to create an account. You are responsible for maintaining the confidentiality of your login credentials and for all activity that occurs under your account. You must ensure that the information you provide is accurate and kept up to date.
LeadLocker does not request or store passwords for third-party services. Where external services are connected, access is granted through secure authorisation methods provided by those services. You may revoke access at any time through the relevant third-party platform.
Use of the service
You agree to use LeadLocker only for lawful purposes and in accordance with these Terms. You must not misuse the service, attempt to gain unauthorised access to systems, interfere with the operation of the platform, or use the service to send unsolicited or unlawful communications.
Lead data and responsibility
You retain ownership of any lead or enquiry data processed through LeadLocker. By using the service, you grant LeadLocker permission to process and store that data solely for the purpose of providing the service, including through the third-party subprocessors described below and in our Privacy Policy and Data Handling Statement.
You are responsible for ensuring that your collection and use of lead data complies with all applicable privacy, marketing, and data protection laws. LeadLocker does not verify the legality of how you obtained lead data and is not responsible for your compliance obligations. Where you use features such as inbound email, Facebook Lead Ads, voice calls, or automated lead analysis, you are responsible for providing any notices and obtaining any consents required for your business and your customers.
Depending on your configuration, LeadLocker receives lead data from the following sources:
| Source | Data received |
|---|---|
| Meta Facebook/Instagram Lead Ads | Lead name, email, phone, custom question responses, Page ID, Page access token |
| Inbound email (via Mailgun) | Full email: From, To, Subject, message body (text and HTML), headers |
| Inbound SMS (via Telnyx) | Sender phone number, SMS message body |
| Inbound voice calls (via Telnyx) | Caller phone number, call duration, call recording, call transcript |
| Google Ads lead form webhook | Lead name, phone, comments |
| Public lead form | Lead name, email, phone, description |
| Custom webhook | Name, email, phone, description (as submitted by the integrating system) |
All inbound lead data is stored in Firebase Firestore, located in australia-southeast1 (Sydney, Australia).
Privacy and data processing
Your use of LeadLocker is also governed by our Privacy Policy and Data Handling Statement. By using LeadLocker, you acknowledge that:
- Lead and enquiry data (including names, contact details, and message content) may be sent to OpenAI for automated classification, scoring, and call transcript analysis via API inference only, and is not used to train OpenAI's models under OpenAI's default API data usage policies
- Where voice features are enabled, call metadata, call recordings, and call transcripts may be stored and transcripts may be sent to OpenAI for analysis
- Personal information may be processed in countries outside Australia (including the United States) by subprocessors as set out below
- Your primary data is stored in Australia (Firebase, Sydney — australia-southeast1)
Third-party subprocessors
LeadLocker engages the following third-party service providers to deliver the service. Each provider acts as a data processor under our instructions, except where noted. Operational logs are currently handled by Vercel only; we do not use Better Stack or Upstash in production today.
Google Firebase (Google LLC)
- Purpose: Primary data store for all account data, lead data, conversations, call transcripts, attachments, and authentication
- Data processed: Account details (email, name, hashed password), lead data (names, emails, phones, message content, call transcripts, attachments, quote data), organisation metadata, push notification tokens, Facebook Page tokens
- Storage location: australia-southeast1 (Sydney, Australia) — Firestore and Firebase Storage
- Authentication location: Google Identity Platform (global Google infrastructure)
- Own use: Google processes data as cloud infrastructure under Google Cloud's data processing terms. Google does not use Firestore content to train public AI models.
- Privacy policy: policies.google.com/privacy
- Data processing terms: firebase.google.com/terms/data-processing-terms
Vercel Inc.
- Purpose: Application hosting and serverless API processing
- Data processed: All data passes through Vercel's servers in transit during API request processing (lead data, webhook payloads, account data). Vercel retains structured operational logs per their log retention policy.
- Storage location: Washington DC, USA (iad1) — data is processed transiently; not stored long-term on Vercel
- Own use: Vercel uses data only to host and operate the application per their DPA
- Privacy policy: vercel.com/legal/privacy-policy
OpenAI (OpenAI, LLC)
- Purpose: AI-powered lead classification, lead scoring, and call transcript analysis
- Data processed:
- Lead classification: lead subject, sender, and up to 600 characters of message body
- Lead scoring: lead subject, sender, and up to 1,500 characters of message body
- Transcript analysis: full call transcript text
- Triggered by: Inbound email leads, Facebook/Instagram Lead Ads leads, and completed voice calls
- Storage location: United States
- Own use: Under OpenAI's API data usage policy, data submitted via the API is not used to train OpenAI's models by default. LeadLocker stores only the parsed output (classification result, score, suggestions) — not raw OpenAI responses.
- API data policy: openai.com/policies/api-data-usage-policies
Telnyx LLC
- Purpose: Inbound and outbound SMS, inbound voice calls, call transcription
- Data processed: Phone numbers (E.164 format), SMS message content (including lead name snippets and job details), call metadata (from/to numbers, duration, call outcome), call transcripts delivered via webhook
- Storage location: United States — Telnyx retains call and message records per carrier regulatory requirements and their data retention policy
- Own use: Carrier/CPaaS processing for routing, billing, fraud prevention, and regulatory compliance
- Privacy policy: telnyx.com/privacy-policy
Mailgun (Sinch)
- Purpose: Inbound email processing — forwarding emails sent to your LeadLocker inbox to the LeadLocker API
- Data processed: Full inbound email content (From, To, Subject, body text and HTML, headers)
- Storage location: United States
- Own use: Email delivery and processing per Mailgun's terms. LeadLocker does not retain raw Mailgun payloads beyond what is extracted into Firestore.
- Privacy policy: mailgun.com/privacy-policy
Resend (Resend Inc.)
- Purpose: Transactional email delivery (account onboarding, setup links, quote delivery)
- Data processed: Recipient email address, recipient name, email content (onboarding links, quote details including lead name and quote total)
- Storage location: United States
- Own use: Transactional email delivery only per Resend's terms
- Privacy policy: resend.com/legal/privacy-policy
Meta Platforms Inc. (Facebook/Instagram)
- Purpose: OAuth authentication for Page connections, Lead Ads webhook delivery, Graph API for lead retrieval and page subscription
- Data processed: Page access tokens, Lead Ads form submissions (name, email, phone, custom question responses), Page and Instagram business account metadata
- Storage location: Global (Meta infrastructure, primarily United States)
- Own use: Meta processes data per Meta's Platform Terms and data policies. LeadLocker uses Page tokens only to receive leads and maintain the connection — not for advertising.
- Platform terms: developers.facebook.com/terms
- Privacy policy: facebook.com/privacy/policy
Stripe (Stripe Payments Australia Pty Ltd)
- Purpose: Payment processing and subscription management
- Data processed: Customer email address, subscription plan and status, Stripe customer ID, Stripe subscription ID. LeadLocker does not store or access card numbers — payment details are handled entirely by Stripe's hosted checkout.
- Storage location: Australia/Global (Stripe Australia entity)
- Own use: Payment processing, fraud prevention, and financial compliance per Stripe's terms
- Privacy policy: stripe.com/privacy
Data LeadLocker does not use
- LeadLocker does not sell personal information to any third party
- LeadLocker does not use lead data for advertising or marketing to your customers
- LeadLocker does not use any third-party analytics, advertising tracking, or behavioural monitoring tools (no Google Analytics, Mixpanel, Hotjar, Segment, or similar)
- LeadLocker does not access your email inbox or send emails on your behalf beyond the transactional emails described above
- LeadLocker does not use your data to train AI models
Facebook Lead Ads data handling
LeadLocker receives lead data from Meta Lead Ads via the Facebook Graph API and webhook subscriptions. This data is:
- Received in real time and stored in Firebase Firestore (australia-southeast1, Sydney)
- Displayed within your LeadLocker dashboard
- Used to send you lead notifications via SMS (Telnyx) and email (Resend) where configured
- Optionally processed by OpenAI for classification and scoring
- Never shared with other LeadLocker account holders
- Never used for advertising or marketing unrelated to delivering the LeadLocker service
- Deleted from LeadLocker's systems when you delete the lead or delete your account
End consumer deletion requests: if an individual whose information was collected via a Facebook Lead Ad wishes to have their information deleted from LeadLocker's systems, they may contact us at support@leadlocker.app. We will process deletion requests within 30 days.
Account holder deletion: when you disconnect your Facebook Page or delete your LeadLocker account, your Page access tokens are permanently deleted from our systems. Lead data associated with your account is deleted in accordance with our account deletion process.
International data transfers
Your primary data is stored in Australia (Firebase, Sydney — australia-southeast1). Some service providers process data in the United States (Vercel, OpenAI, Telnyx, Mailgun, Resend, Meta). When data is transferred outside Australia, we engage only providers with appropriate data protection practices and contractual terms. For more information, see the subprocessor list above.
Data security
- All data transmitted between users and the LeadLocker application is encrypted in transit using HTTPS/TLS
- Firebase Security Rules restrict data access so users can only access data belonging to their organisation
- Firebase Authentication manages account access using industry-standard practices
- Passwords are hashed by Firebase Authentication — we do not have access to plain-text passwords
- API routes are protected by authentication checks and rate limiting
Data retention and deletion
| Data type | Retention | Deletion |
|---|---|---|
| Account data | Duration of account | Deleted on account deletion |
| Lead data | Duration of account, or until manually deleted | Deleted on lead deletion or account deletion |
| Call transcripts | Duration of account | Deleted on account deletion |
| Attachments | Duration of account | Deleted on account deletion |
| Facebook Page tokens | Until Page disconnected or account deleted | Permanently deleted on disconnection or account deletion |
| Backups | Up to 30 days after account deletion | Purged within 30 days of account deletion |
| Stripe billing records | Per Stripe's retention requirements | Managed by Stripe |
Availability and performance
While we aim to provide a reliable service, uninterrupted access is not guaranteed. LeadLocker may be unavailable from time to time due to maintenance, updates, or circumstances beyond our control.
Limitation of liability
To the maximum extent permitted by law, LeadLocker excludes all warranties, express or implied. We are not liable for any indirect, incidental, or consequential loss, including loss of revenue, loss of business, or loss of data.
Our total liability to you, whether in contract, tort, or otherwise, is limited to the amount paid by you for the service in the twelve months preceding the claim, or zero where no fees have been paid.
Termination
We may suspend or terminate your access to LeadLocker at any time if you breach these Terms or if we reasonably believe continued access may cause harm to the service or other users. You may stop using the service at any time. Account deletion is available in settings and permanently removes your account and associated lead data as described in our Privacy Policy and Data Handling Statement.
Governing law
These Terms are governed by the laws of Australia, and the courts of Australia have exclusive jurisdiction over any disputes arising from them.
Contact
For data handling enquiries or to submit a deletion request:
Email: support@leadlocker.app
Business: LeadLocker, operated by Red Capital Group Pty Ltd (ABN 41 696 755 530)