Legal
Privacy Policy
Information about data protection and the processing of personal data.
Status
May 2026
1. General information
This privacy policy explains the type, scope and purpose of the processing of personal data when using our website and the SaaS platform LeadTS.
Personal data means all information relating to an identified or identifiable natural person.
Processing is carried out in accordance with the General Data Protection Regulation (GDPR) and applicable national data protection laws.
2. Controller
LeadTS (sole proprietorship)
Owner: Rotinda Getiren
Gruenhainer Str. 8
08340 Schwarzenberg
Germany
Phone: 017641567624
Email: support@leadts.com
Website: https://leadts.com
3. Processing roles
LeadTS processes personal data depending on the specific processing context.
As controller
For the following processing activities, we act as an independent controller:
* website and visitor data
* contract and billing data
* customer data
* user account data
* support and communication data
* marketing and analytics data (where used)
As processor
Where customers process personal data of third parties (e.g. leads, contacts, prospects) within LeadTS, we act as a processor pursuant to Art. 28 GDPR.
In such cases, processing is carried out exclusively on the customer's instructions.
4. Data processing when visiting the website
When our website is accessed, technical access data is processed automatically:
* IP address
* date and time of access
* browser type and browser version
* operating system
* referrer URL
* hostname of the accessing device
* pages/files accessed
Processing is carried out for:
* technical provision of the website
* ensuring stability and security
* error analysis
* detection of misuse and attacks
Legal basis: Art. 6(1)(f) GDPR
5. Registration and user account
When creating and using a user account, we process in particular:
* email address
* password (stored only in hashed form)
* display name / name
* profile information
* language settings
* optional avatar/profile image data
Legal basis: Art. 6(1)(b) GDPR
6. Use of the LeadTS platform / processing of CRM and lead data
Within use of the platform, and depending on customer usage, the following data may be processed in particular:
* names of leads / contacts
* email addresses
* phone numbers
* company data
* lead sources / campaign mappings
* funnel/pipeline data
* status and activity histories
* revenue/deal/conversion data
* custom additional fields
Data may be introduced in particular via:
* API/webhook integrations
* third-party interfaces
* CSV/file imports
* manual input
Legal basis:
Art. 6(1)(b) GDPR / Art. 6(1)(f) GDPR
7. Processing on behalf
Where our customers process personal data of third parties within the platform, this takes place as processing on behalf pursuant to Art. 28 GDPR.
A corresponding data processing agreement (DPA) is provided.
8. Payment processing / contract administration
For payment processing and subscription management, we use Stripe Payments Europe Ltd.
In particular, we process:
* billing and contract data
* customer data
* Stripe customer IDs
* plan and subscription data
* payment status
Complete payment data is processed exclusively by Stripe.
Legal basis: Art. 6(1)(b) GDPR
Further information: https://stripe.com/privacy
9. Support and communication
If you contact us, we process your details to handle your request.
This includes in particular:
* name
* email address
* communication content
* support/ticket information
Legal basis:
Art. 6(1)(b) GDPR / Art. 6(1)(f) GDPR
10. Service providers / recipients used
To provide our services, we use the following service providers:
* Supabase – database, authentication, backend infrastructure
* Vercel – hosting / frontend infrastructure
* Stripe – payment processing
* Resend – delivery of transactional emails
* Nango – OAuth/integration management
* Google – OAuth/Google integrations / Search Console
* Meta Platforms – Meta/Facebook integrations
* Cookiebot (Usercentrics A/S) – consent management
Disclosure is limited to what is necessary.
11. Hosting and storage location
Primary processing of platform data takes place in data centers within the European Union, in particular Frankfurt am Main.
12. Third-country transfers
Where personal data is transferred to recipients outside the European Union or the European Economic Area, this takes place only in compliance with the legal requirements under Art. 44 et seq. GDPR.
In particular based on:
* adequacy decisions
* EU standard contractual clauses
* other permissible safeguards
13. Security measures
We take appropriate technical and organizational measures to protect personal data, including in particular:
* TLS/HTTPS encryption
* access restrictions
* role and authorization concepts
* authentication and session management
* security monitoring / logging
* protection against unauthorized API/webhook access
* regular security updates
14. Cookies and consent management
We use cookies and comparable technologies.
Technically necessary cookies
These are required for operation, security and functionality of the website/platform.
Optional cookies / tracking
Non-essential technologies are used only based on your consent.
To manage consent, we use Cookiebot by Usercentrics A/S.
15. Analytics and performance tools
Vercel Analytics / Speed Insights
We use analytics and performance services from Vercel to evaluate technical usage and performance data of our website.
This may include in particular:
* technical usage data
* browser and device information
* page views
* load times / performance metrics
* referrer information
Processing is based on our legitimate interest in technical optimization and stability of our website pursuant to Art. 6(1)(f) GDPR, where consent is not required.
Google Search Console
We use Google Search Console for technical analysis, SEO and monitoring the discoverability of our website in search engines.
Aggregated search and performance data is processed.
We do not perform direct personal profiling in this context.
Legal basis: Art. 6(1)(f) GDPR
16. Retention period
We store personal data only as long as necessary for the respective processing purposes or as required by statutory retention obligations.
Data is then deleted or anonymized.
17. Obligation to provide data
Providing certain personal data is required for conclusion and performance of the contractual relationship.
Without this data, use of the platform may be impossible in whole or in part.
18. Automated decision-making / profiling
Automated decision-making or profiling within the meaning of Art. 22 GDPR does not take place, unless explicitly stated otherwise.
19. Data subject rights
Data subjects have the following rights:
* access pursuant to Art. 15 GDPR
* rectification pursuant to Art. 16 GDPR
* erasure pursuant to Art. 17 GDPR
* restriction of processing pursuant to Art. 18 GDPR
* data portability pursuant to Art. 20 GDPR
* objection pursuant to Art. 21 GDPR
* withdrawal of consent pursuant to Art. 7(3) GDPR
Requests to: support@leadts.com
20. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority.
21. Google user data (Google APIs and OAuth)
This section supplements the disclosures above and is intended to meet the transparency requirements of the Google API Services User Data Policy and the Google APIs Terms of Service for customers who connect a Google account to LeadTS.
When this applies
If you optionally connect Google to LeadTS (for example via OAuth through our integration provider Nango), LeadTS accesses limited Google user data as described below. Connecting Google is voluntary and used to ingest lead data from spreadsheets you select. LeadTS does not use Google Sign-In for website or app authentication.
Data accessed (categories)
* OAuth authorization data: When you authorize the integration, Google provides authorization artifacts needed to call Google APIs on your behalf (handled through Nango).
* Google Drive (metadata): To help you pick a spreadsheet, we may list Google Drive items such as folders and spreadsheet files. We process identifiers and descriptive metadata returned by Google (for example file IDs, names, parent folder references, and web view links where provided by Google).
* Google Sheets (content and structure for the selected spreadsheet only): We read spreadsheet metadata needed for setup (for example worksheet/tab titles) and cell values from the specific spreadsheet and range you configure in LeadTS.
* What we do not access: LeadTS does not access, collect, or use Gmail messages, Google Calendar, Google Contacts, Google Photos, YouTube, or other Google services beyond the Drive/Sheets functionality described here.
How we use Google user data (purposes and processing)
* Google Sheets lead source: We use the data solely to (1) establish and maintain the connection you requested, (2) display selectable spreadsheets/folders in the product UI, and (3) read the configured sheet range to import rows as leads into your LeadTS workspace.
* Secure operation: We use OAuth tokens/credentials only as required to perform these API calls. Token storage and refresh are handled by Nango as our OAuth/integration infrastructure.
* No unrelated purposes: We do not sell Google user data. We do not use Google user data for advertising. We do not use Google user data to train generalized artificial intelligence or machine learning models.
* Automated decisions: Importing rows does not constitute automated decision-making about individuals within the meaning of Art. 22 GDPR.
Storage, sharing, and subprocessors
* Our systems: Imported sheet rows are stored in LeadTS like other lead records you choose to process in the product, subject to this privacy policy and (where applicable) our DPA.
* Nango: OAuth connection management and API proxying may involve processing by Nango (USA/EU). Disclosure is limited to what is necessary to provide the integration.
* Google: API requests are processed by Google as the provider of Google Drive/Google Sheets.
Retention and revocation
You can disconnect the Google integration in LeadTS and/or revoke LeadTS access in your Google Account security settings. After disconnection, we stop initiating new data access via that connection (subject to reasonable technical propagation delays).
Legal bases (GDPR)
Where you connect Google as a LeadTS customer user, processing is typically based on Art. 6(1)(b) GDPR (performance of the contract) and/or Art. 6(1)(f) GDPR (legitimate interest in providing the integration you requested), depending on the processing context.
If you have questions about this integration, contact: support@leadts.com
22. Changes to this privacy policy
We reserve the right to amend this privacy policy if this becomes necessary due to legal, technical or business changes.