Privacy Policy

How LeadSender handles your data

Effective 31 Aug 2026 · leadsender.io
In plain terms
  • We read your Facebook Page's lead form submissions only to deliver them to the email, SMS number, or Google Sheet you configure — nothing else.
  • We never sell your data, and we never use your leads' answers for advertising.
  • You can disconnect Facebook or Google, or delete your account and its data, at any time.
  • We use a small number of named subprocessors (listed below) strictly to run the service — email delivery, SMS delivery, database, and hosting.
01

Information we collect

LeadSender is a service that connects your Facebook Lead Ads to destinations you choose — email, SMS, Google Sheets, and (as we add them) other CRMs. We collect only what's needed to make that connection work.

Account information

When you create a LeadSender account, we store your email address and a securely hashed password. We never store your password in plain text.

Integration configuration

When you set up an integration, we store the configuration you build: which Facebook Page and lead form it watches, the destination (an email address, phone number, or spreadsheet), the message template you write, and the field mappings you choose.

02

Facebook & Meta Platform data

When you connect your Facebook account, LeadSender requests access to the following, using Meta's own login flow — we never see or store your Facebook password:

pages_show_list
the list of Facebook Pages you manage, so you can pick which one to connect
leads_retrieval
the actual answers a person submits on your Page's lead forms — this is the core data the product exists to route
ads_read
the campaign and ad name a lead came from, so your notifications can include that context

What we do with it

A lead's answers are used for exactly one purpose: delivering them to the destination you configured for that integration, in the format you designed. We do not use lead data to build advertising audiences, do not use it to train any model, and do not sell or share it with anyone outside the specific destination you set up and the subprocessors listed in Section 5.

Facebook Page and lead data is retained only for as long as an integration using it stays active, plus a short operational window for delivery logs, and is removed on request (see Section 6).

03

Google data (Sheets & Drive)

If you connect Google Sheets as a destination, LeadSender requests:

openid, email, profile
to confirm which Google account is connected and show it back to you
drive.file
to create a new spreadsheet on your request, and to write lead rows into a spreadsheet you explicitly pick through Google's own file picker. This scope only ever grants access to that one file you selected or a file LeadSender created for you — never a list of anything else in your Drive, and never any file you haven't chosen through LeadSender.

LeadSender's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we only use this access to write real lead data into a spreadsheet you've chosen. We never use it for targeted advertising, never sell it or transfer it to data brokers, never use it for credit assessment or lending decisions, and never use it to train generalized or non-personalized AI/ML models. We never transfer this data to any third party except to provide this feature itself or to comply with the law.

04

How we use information

  • To deliver leads through the integrations you build — this is the entire product.
  • To authenticate you and keep your account secure.
  • To send you operational notifications, like a failed delivery alert, if you've turned those on in Settings.
  • To respond when you contact support.
  • To maintain and improve the reliability of the service.
05

Sharing & subprocessors

We don't sell personal information. We share data only with the following subprocessors, each strictly to perform their part of the service, and each under their own data protection terms:

ProviderWhat they handle
Meta / Facebooksource of your Page and lead data
Googlesource of Sheets/Drive access, when connected
Resenddelivers your email notifications
ClickSenddelivers your SMS notifications
Supabasehosts our database (integration configs, delivery logs)
Vercelhosts the LeadSender application itself

We may also disclose information if required by law, or to protect the rights, property, or safety of LeadSender, our users, or others.

06

Retention & deletion

We keep integration configurations and delivery logs for as long as your account is active. If you delete an integration, its stored configuration is removed. If you delete your account, we delete your account data and disconnect any linked Facebook or Google access.

To request deletion of your account or data, email us at the address in Section 12 — we'll act on it within 30 days.

07

Security

All traffic to LeadSender is encrypted in transit (HTTPS/TLS). Access tokens and API keys are stored server-side only and are never sent to your browser. Passwords are stored as salted hashes, never in plain text. We limit access to production data to what's operationally necessary.

No method of transmission or storage is perfectly secure, and we can't guarantee absolute security — but we treat it as a priority, not an afterthought.

08

Cookies & local storage

LeadSender uses your browser's local storage to keep you signed in and remember your preferences (like which tab you last had open) — this isn't a cookie, and it's essential to how the app works.

On leadsender.io, our public website, we use Google Analytics — a third-party cookie — to see which pages are useful and improve the site. It only loads if you accept it in the cookie banner shown on your first visit; declining means it never loads, and nothing is tracked. We don't use any advertising or retargeting cookies anywhere.

09

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise any of these, contact us using the details in Section 12.

10

Children's privacy

LeadSender is a business tool and isn't directed at, or intended for use by, anyone under 18. We don't knowingly collect information from children.

11

Changes to this policy

If we make material changes, we'll update the effective date at the top of this page and, where appropriate, notify you directly.

12

Contact us

Questions about this policy, or a request about your data:

Email
contact@leadsender.io
LeadSender.io — this policy describes the LeadSender lead-routing service.