Legal

Privacy Policy

Effective: January 1, 2025Last Updated: April 26, 2026Leadsgram · India

This policy explains exactly what data we collect, why we collect it, how it is used, and your rights over it.

01

Overview & Scope

Welcome to Leadsgram ("we", "our", "us", "the Company"). Leadsgram is a Business-to-Business (B2B) intelligence and connectivity platform incorporated and operated from India. We help Indian and international businesses discover verified foreign contacts, manage outreach via WhatsApp Business messaging and custom-domain email, and grow their export and international sales pipeline.

This Privacy Policy applies to all users of the Leadsgram platform accessible at leadsgram.io, including our web application, APIs, integrations, and any associated services (collectively, the "Platform"). It governs the collection, use, storage, sharing, and protection of personal data we receive from:

  • Registered users who create an account and subscribe to a plan
  • Visitors who browse our website or submit contact / data-deletion requests
  • Business contacts whose data is processed through our WhatsApp and email features
  • Third-party API services that send us data (e.g., Meta webhook events, Razorpay payment notifications)

By creating an account, subscribing to a plan, or using any feature of the Platform, you acknowledge that you have read and understood this Privacy Policy. If you disagree with any part of this policy, please discontinue use immediately and contact [email protected] to close your account.

Key principle: We collect only what we need, we store it only as long as necessary, we never sell your personal data, and we give you meaningful control over your information.
02

Information We Collect

Account & Identity Information

Collected when you register or update your profile:

  • Full name, business name, registered email address, and phone number
  • Password (stored as a bcrypt hash — never in plain text)
  • Business category, industry vertical, target markets, and profile details you voluntarily add
  • Profile photograph or business logo if uploaded
  • Firebase User ID (UID) assigned upon sign-up — used as your primary account identifier across all platform features
  • Google account display name and email if you choose to authenticate via Google (Google OAuth)

Alias / Sub-Account Information

If you create or use alias accounts (for team members or delegated access):

  • Alias username, assigned email address, and configured display name
  • Permissions assigned to each alias (read, write, send-only, etc.)
  • Session tokens and authentication logs for each alias login
  • Actions taken under the alias account are recorded against both the alias and the parent account

Subscription & Billing Information

  • Selected subscription plan (Starter / Growth / Scale), billing cycle, and renewal dates
  • Razorpay order IDs, payment status, and transaction reference numbers
  • Invoice details including GST / tax ID if provided for billing purposes
  • Payment failure events and retry history (no raw card data — see Section 10)
  • Refund requests and associated correspondence

Business Directory Access & Lead Data

  • Search queries, filters applied (country, industry), and business profiles you view or save
  • Lead lists you access, download, or export within your subscription quota
  • Notes, tags, or annotations you attach to business contacts within your workspace
  • Lead download history and CSV export records

WhatsApp Business Data

  • WhatsApp Business Account (WABA) ID and connected phone number
  • Encrypted access tokens for the connected WABA (stored using AES-256-CBC encryption)
  • Message templates you create or sync from Meta — including template name, body, header, footer, and approval status
  • Contact lists you upload via CSV, including phone numbers and any additional fields in the upload
  • WhatsApp validation status for each contact (has_whatsapp flag)
  • Campaign details: name, template used, target audience, scheduled time, send time, and per-message delivery/read/failure statuses
  • Inbound messages received in your WhatsApp inbox, including message content and sender phone number
  • Outbound message logs, delivery receipts, read receipts, and failure reasons from Meta webhook events

Email Platform Data

  • Custom email domains you configure and their verification status
  • DNS records you add to your domain (SPF, DKIM, DMARC, MX values) — stored for verification and display
  • Email aliases you create (e.g., [email protected]) and their linked routing addresses
  • Emails sent and received through your configured inboxes, including full message content, attachments, headers, and metadata
  • Email template content (HTML and plain text) you create in the Email Builder
  • Draft emails and their auto-save history
  • Outbound delivery status and bounce/error reports from our email infrastructure provider

Platform Usage & Activity Data

  • Pages visited, dashboard features accessed, and time-on-page metrics
  • Clicks, button interactions, search terms, and feature usage patterns
  • Error logs, exception reports, and debugging information generated during your session
  • Support tickets, chat messages, and form submissions (including Contact and Delete My Data forms)

Technical & Device Information

  • IP address, approximate geographic region (country/city), and ISP
  • Browser type and version, operating system, device type (desktop / mobile / tablet)
  • Screen resolution and language/locale settings
  • Referral source (e.g., how you arrived at our website)
  • Firebase Analytics and Crashlytics diagnostic data (aggregated, not linked to individual identities in production)

Data You Submit via Public Forms

  • Name, email, company, phone, topic, subject, and message — submitted via the Contact Us form
  • Name, email, account ID, deletion scope, reason, and notes — submitted via the Delete My Data form
  • These submissions are stored separately from your user account and are used solely to process your inquiry
04

How We Use Your Information

We process your personal data only for the specific purposes below:

  • Account management — create, authenticate, and maintain your user account and any alias accounts you configure
  • Service delivery — provide access to the B2B directory, process lead exports, deliver WhatsApp messaging capabilities, and manage your email platform
  • Campaign execution — process your contact lists, apply template messages, enqueue bulk WhatsApp sends, and track per-message delivery outcomes
  • Payment processing — create Razorpay orders, verify payment callbacks, issue invoices, and manage subscription lifecycle (upgrade, downgrade, cancellation)
  • Platform personalization — remember your preferences, filter defaults, recent searches, and workspace configurations
  • Security & fraud prevention — detect and block unauthorized access, rate-limit API abuse, and maintain audit trails
  • Product improvement — analyze anonymized usage patterns, run internal A/B testing, and prioritize feature development
  • Customer support — review and respond to support tickets, Contact form submissions, billing inquiries, and data requests
  • Legal & compliance — meet obligations under Indian law, respond to lawful government requests, and process data deletion requests
  • Transactional communication — send payment receipts, subscription renewal notices, security alerts, and critical platform updates
We do not use your personal data to train AI or machine learning models, nor do we profile you for advertising purposes or sell your data to data brokers.
05

Authentication & Account Security

Leadsgram uses Google Firebase Authentication to manage user identity. Firebase is operated by Google LLC and processes authentication data in accordance with Google's Privacy Policy.

What Firebase Collects

  • Email address and display name (from email/password sign-up or Google OAuth)
  • Hashed password (for email/password accounts — Firebase stores this, not Leadsgram directly)
  • Firebase UID — a unique identifier we use to link your account to all platform data
  • Device metadata and IP address for sign-in event logging and anomaly detection
  • Refresh tokens used to maintain your authenticated session across browser sessions

Alias Authentication

Alias accounts allow a primary account holder to create secondary login credentials for team members or delegate access without sharing the primary account password. Alias sessions are tracked independently with their own JWT tokens and are revocable at any time by the primary account holder.

We never have access to your raw password. Passwords for email/password accounts are hashed by Firebase before storage. If you authenticate via Google, we never see your Google password — only the OAuth identity token that Google issues to confirm your identity.
06

WhatsApp Business API Integration

Leadsgram integrates with the Meta WhatsApp Business API through Meta's authorized Business Solution Provider (BSP) programme. When you connect your WhatsApp Business Account (WABA):

Data We Store

  • Your WABA ID and connected phone number — to route messages and display inbox data
  • Your WhatsApp access token — encrypted at rest using AES-256-CBC before database storage
  • Message templates — synced from Meta or created through our platform, stored with their approval status
  • Contacts you upload via CSV — stored in our database with their WhatsApp validation status
  • Sent messages and their delivery/read/failure statuses received via Meta webhook events
  • Inbound messages from customers who reply to your business — stored to populate your inbox view
  • Conversation threads linking inbound and outbound messages by phone number

How Meta Processes This Data

Messages you send or receive via our platform are transmitted through Meta's infrastructure. Meta processes this data in accordance with their WhatsApp Business Policy and Meta's Data Policy. Leadsgram does not intercept or read message content for any purpose other than displaying it in your inbox.

Contact Data from CSV Uploads

When you upload a CSV file of phone numbers to build a campaign audience, those phone numbers are stored in our database, validated against WhatsApp's API (to confirm whether each number has a WhatsApp account), and used solely for the campaigns you create. We do not share these contact lists with any third party.

You are responsible for ensuring that all recipients of WhatsApp messages sent through Leadsgram have opted in to receive communications from your business. Sending unsolicited messages violates WhatsApp's policies and may result in your WABA being suspended by Meta.
07

Email Services & DNS Configuration

Leadsgram provides a professional email infrastructure layer that allows you to configure a custom email domain, create aliases, and send / receive business emails directly within the platform.

Domain & DNS Data

  • The domain name you configure is stored and associated with your account
  • DNS records you add to your domain registrar (SPF, DKIM, DMARC, MX values) are recorded in our system for verification and display
  • Domain verification status is checked periodically via DNS lookup — no data is transmitted to your registrar on our side

Email Content & Metadata

  • Full email content (subject, body, attachments) for emails sent and received through your configured inbox is stored on our servers
  • Email headers (From, To, CC, BCC, timestamps, Message-IDs) are retained for routing, threading, and search
  • Outbound email delivery status, bounce codes, and spam complaint signals from our SMTP infrastructure
  • Draft emails are auto-saved and stored until you send or manually delete them

Email Templates

HTML email templates you create using the Email Builder (including code blocks, images, and formatting) are stored in your workspace and are not shared with or accessible by other users.

08

Campaign & Bulk Messaging Data

When you create and execute a WhatsApp campaign through Leadsgram, we process the following data:

  • Campaign configuration — campaign name, selected template, selected audience (contact list), and send timestamp
  • Message queue records — individual message records for each recipient in the campaign, including their phone number, the message body (resolved from the template), and current delivery status
  • Delivery telemetry — per-message status updates (queued → sent → delivered → read, or failed) received via Meta's webhook and stored for your reporting dashboard
  • Failure reasons — error codes and descriptions returned by Meta for failed messages (e.g., number not on WhatsApp, message blocked, template rejected)
  • Campaign statistics — aggregate counts of queued, sent, delivered, read, and failed messages, computed from message-level records
Campaign message records including recipient phone numbers are retained for up to 12 months after the campaign send date to allow you to review performance reports. After 12 months, message-level records may be anonymized or deleted as part of our standard data retention schedule.
09

Business Directory & Lead Data

Leadsgram's core feature is a curated B2B business directory containing over 50,000 verified international business contacts across 40+ countries and 20+ industry verticals. This directory is built and maintained by our research team.

How Directory Data is Compiled

  • Business information is compiled from publicly accessible sources: government trade registries, chamber of commerce directories, official company websites, industry association listings, and legitimate B2B databases
  • Each entry is manually reviewed and cross-referenced before inclusion
  • Directory data is periodically refreshed — typically every 30 days — to reflect changes in business status, contact details, and industry classifications
  • We do not purchase or licence data from data brokers or engage in web scraping of private profiles

What Directory Records Contain

  • Business name, registered address, country, and industry classification
  • Primary contact name, email address, and phone number (sourced from public business listings)
  • Business website, LinkedIn profile link, and other publicly listed online presence
  • Business description, services offered, and export/import activity where publicly available

Your Use of Directory Data

  • Access to directory records is governed by your subscription plan and associated usage quotas
  • You may download leads in CSV format within your plan's monthly export limit
  • Leads you download or save to your workspace are stored in your personal lead list within the platform
  • You are solely responsible for how you use contact information accessed through the directory
Business contact information in the directory is sourced from publicly available records and is intended to facilitate legitimate initial B2B outreach. Leadsgram does not guarantee the continued accuracy, completeness, or operational status of listed businesses. Always independently verify contact details before initiating communication or entering commercial arrangements.
10

Payment Processing

All subscription payments are processed through Razorpay, a PCI-DSS Level 1 compliant payment gateway authorized by the Reserve Bank of India (RBI). Leadsgram does not collect, store, transmit, or process raw payment card data, bank account numbers, or UPI credentials.

  • Payment card and banking credentials are entered directly on Razorpay's hosted payment page — this data never passes through Leadsgram's servers
  • Upon successful payment, Razorpay sends us a tokenized transaction ID, payment status, and amount — used to activate or renew your subscription
  • We retain Razorpay order IDs, payment reference numbers, subscription plan details, and invoice metadata
  • GST invoices are generated on our side using the billing details you provide and stored for the legally required minimum of 7 years
  • Payment failure events (without card details) are logged to allow our support team to assist you
  • Refund transactions are processed through Razorpay and the corresponding records are stored in our billing history
For disputes, chargebacks, or payment-specific issues, please contact Razorpay support directly or email us at [email protected] with your transaction reference number.
11

Third-Party Service Integrations

Leadsgram integrates with the following third-party services to deliver platform functionality. Each provider operates under its own privacy framework and we enter into data processing agreements where required:

Meta / WhatsApp Business API
Google Firebase Auth
Razorpay Payments
Email SMTP Infrastructure
Cloud Hosting & Storage
DNS Verification Services
  • Meta Platforms, Inc. — processes WhatsApp messaging data under Meta's Data Policy. Messages transit Meta's servers. We subscribe to Meta webhooks to receive delivery receipts and inbound messages
  • Google LLC (Firebase) — handles authentication (sign-in, session tokens, OAuth). Firebase may collect device metadata and crash diagnostics per Google's Privacy Policy
  • Razorpay Software Pvt. Ltd. — processes all payment transactions. PCI-DSS compliant, RBI authorized, Indian entity. Governed by Razorpay's Privacy Policy
  • Email Infrastructure Provider — outbound emails are routed through our SMTP provider for delivery. Provider processes email headers and metadata necessary for delivery
  • Cloud Infrastructure — our servers, databases, and file storage run on cloud infrastructure. Provider processes data in accordance with their DPA and ISO 27001 / SOC 2 certifications
We do not sell data to any third party. We share data with service providers only to the extent strictly necessary to deliver the services described in this policy, under contractual obligations requiring equivalent data protection standards.
12

Data Sharing & Disclosure

We do not sell, rent, or trade your personal data. We may share your information only in the following narrowly defined circumstances:

  • Service Providers (Sub-processors): Vetted vendors providing cloud hosting, email delivery, payment processing, and authentication services — bound by data processing agreements that restrict use to the designated service only
  • API Partners: Meta/WhatsApp for message delivery; Razorpay for payment processing — data shared is the minimum necessary for the integration to function
  • Legal Compliance: When required by a binding court order, government authority, or applicable law — we will notify you where legally permitted before disclosing
  • Safety & Security: To investigate or prevent fraud, unauthorized access, abuse of our platform, or threats to the safety of users or third parties
  • Business Transfers: In connection with a merger, acquisition, asset sale, or corporate restructuring — subject to a confidentiality agreement and notification to affected users
  • With Your Explicit Consent: For any purpose not described above, only with your informed, affirmative consent
13

International Data Transfers

Leadsgram is based in India and primarily processes data on servers located in India. However, some of our third-party service providers operate globally, which may involve transferring your data across international borders:

  • Meta / WhatsApp: Message data transits Meta's global infrastructure, which includes servers in the United States and other jurisdictions. Meta's data transfers are governed by Standard Contractual Clauses and Meta's Data Policy
  • Google Firebase: Authentication data may be processed on Google's global infrastructure. Google maintains data transfer mechanisms compliant with applicable regulations
  • Cloud Hosting: Our primary infrastructure is hosted in India. Disaster recovery or backup systems may involve cross-border data replication within the provider's compliance framework

Where personal data is transferred outside India, we ensure appropriate safeguards are in place as required by the Digital Personal Data Protection Act, 2023, and any applicable cross-border transfer regulations notified by the Government of India.

14

Data Security

We implement layered technical and organisational security measures to protect your personal data against unauthorized access, accidental loss, alteration, or disclosure.

Technical Controls

  • TLS 1.2+ encryption for all data in transit between client and server
  • AES-256-CBC encryption for sensitive data at rest, including WhatsApp access tokens
  • bcrypt password hashing (Firebase-managed) for email/password accounts
  • JWT-based session management with short expiry and refresh token rotation
  • Role-based access controls (RBAC) — alias account permissions are strictly scoped
  • Database-level row-isolation ensuring one user's data cannot be queried by another
  • API rate limiting and request throttling to prevent brute-force and abuse

Operational Controls

  • Internal access to production data is restricted to authorised team members on a need-to-know basis
  • Automated anomaly detection monitors for unusual login patterns and API usage spikes
  • Security incident response plan with defined escalation procedures
  • Periodic review of third-party service providers' security posture
No system is 100% secure. If you discover a security vulnerability, please disclose it responsibly to [email protected] before public disclosure. We are committed to addressing confirmed vulnerabilities promptly.
15

Data Retention

We retain personal data only as long as necessary for the purposes for which it was collected:

  • Active Account Data: Retained for the lifetime of your active account and subscription
  • Post-Cancellation: Account data is retained for 30 days after subscription cancellation to allow account recovery, then deleted or anonymized
  • After Deletion Request: Most personal data is permanently deleted within 30 days of a verified data deletion request (see our Delete My Data page)
  • Campaign & Message Records: Message-level campaign records retained for up to 12 months post-send for reporting; then anonymized
  • WhatsApp Inbox: Conversation messages retained for 12 months from last message date, or until you delete the connection
  • Email Data: Inbox emails retained for the duration of your active subscription. Deleted on account closure after a 30-day grace period
  • Billing & Invoice Records: Transaction records retained for a minimum of 7 years as required by Indian tax law (GST / Income Tax Act)
  • Support Communications: Contact form submissions and support tickets retained for 3 years for quality and dispute resolution purposes
  • Anonymized Analytics: Aggregated, de-identified usage statistics may be retained indefinitely for platform improvement
16

Your Rights & Choices

Under the Digital Personal Data Protection Act, 2023 (India) and applicable privacy principles, you have the following rights:

  • Right to Access — request a summary of the personal data we hold about you and how it is being processed
  • Right to Correction — request that we correct inaccurate or incomplete personal data held about you
  • Right to Erasure — request deletion of your personal data, subject to legally mandated retention requirements (see Section 15)
  • Right to Data Portability — request your lead data, contact lists, and account information in a structured, commonly used, machine-readable format
  • Right to Restrict Processing — request that we limit processing of your data in specific circumstances
  • Right to Object — object to processing based on legitimate interests or for direct marketing purposes
  • Right to Withdraw Consent — withdraw consent you previously granted (e.g., marketing emails, analytics cookies) without affecting prior lawful processing
  • Right to Nominate — under the DPDP Act, you may nominate another individual to exercise your rights on your behalf in the event of death or incapacity

To exercise any of these rights, please use our Data Deletion & Rights page or email [email protected] with the subject "Data Rights Request — [Your Name]". We will respond within 30 days. Identity verification may be required before processing your request.

17

Cookies & Tracking Technologies

We use cookies and similar browser storage technologies to operate the platform and improve your experience:

  • Essential / Functional Cookies: Required for authentication sessions, security tokens, and core dashboard functionality. Cannot be disabled without breaking platform access
  • Preference Storage: localStorage is used to remember sidebar state, selected filters, recent searches, and UI preferences across sessions
  • Session Tokens: Firebase-issued JWT access tokens and refresh tokens are stored in browser memory or localStorage to maintain your authenticated session
  • Analytics: We may use anonymized, aggregated analytics to understand feature usage. No individual user is identified in analytics reports

You can clear cookies and localStorage via your browser settings. Note that clearing session tokens will log you out of the platform. We do not use cross-site tracking cookies or serve targeted advertising cookies on the Leadsgram platform.

18

Children's Privacy

Leadsgram is a professional B2B platform designed exclusively for business use by individuals who are 18 years of age or older. We do not knowingly collect personal data from anyone under 18. If we become aware that a minor has created an account or submitted personal data, we will promptly delete that information and close the account. If you believe a minor has registered, please contact [email protected] immediately.

19

India DPDP Act Compliance

Leadsgram is committed to compliance with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the rules notified thereunder. As a Data Fiduciary under the Act, we have implemented the following measures:

  • We collect personal data only for lawful purposes with valid consent or under other lawful grounds specified in the Act
  • We have appointed a Grievance Officer accessible to all Data Principals (users) — see Section 21
  • We provide clear and accessible mechanisms for Data Principals to withdraw consent, request correction, and request erasure
  • We implement reasonable security safeguards to prevent personal data breaches
  • In the event of a personal data breach that is likely to cause harm, we will notify affected users and the Data Protection Board as required by the Act
  • We retain data only for the period necessary for the specified purpose and delete it thereafter
  • We do not process children's personal data and do not serve behavioural advertising to any users
If you believe your rights under the DPDP Act have not been honoured, you may first approach our Grievance Officer (Section 21). If unsatisfied with the resolution, you have the right to file a complaint with the Data Protection Board of India once it is constituted.
20

Changes to This Policy

We review and update this Privacy Policy periodically. When we make material changes, we will:

  • Update the "Last Updated" date shown at the top of this page
  • Send a notification to your registered email address at least 14 days before significant changes take effect
  • Display a prominent in-app banner upon your next login whenever the policy has been meaningfully revised
  • For changes that materially reduce your rights or increase our data collection, we will seek fresh consent where required by law

Continued use of Leadsgram after the effective date of a revised policy constitutes your acceptance of the updated terms. If you do not agree to the revised policy, please stop using the platform and submit a data deletion request.

21

Grievance Officer

In accordance with the Information Technology Act, 2000, the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the Digital Personal Data Protection Act, 2023, we have designated a Grievance Officer to address privacy-related concerns:

Grievance Officer — Leadsgram

Email: [email protected]

Subject line: Privacy Grievance — [Your Name / Account Email]

Response time: Within 30 days of receiving a valid complaint

For urgent security issues, mark your email subject "URGENT: Security Concern" and we will respond within 72 hours.

You may also submit privacy inquiries or data rights requests via our Contact page or our Data Deletion page.