Overview & Scope
Welcome to Leadsgram ("we", "our", "us", "the Company"). Leadsgram is a Business-to-Business (B2B) intelligence and connectivity platform incorporated and operated from India. We help Indian and international businesses discover verified foreign contacts, manage outreach via WhatsApp Business messaging and custom-domain email, and grow their export and international sales pipeline.
This Privacy Policy applies to all users of the Leadsgram platform accessible at leadsgram.io, including our web application, APIs, integrations, and any associated services (collectively, the "Platform"). It governs the collection, use, storage, sharing, and protection of personal data we receive from:
- ›Registered users who create an account and subscribe to a plan
- ›Visitors who browse our website or submit contact / data-deletion requests
- ›Business contacts whose data is processed through our WhatsApp and email features
- ›Third-party API services that send us data (e.g., Meta webhook events, Razorpay payment notifications)
By creating an account, subscribing to a plan, or using any feature of the Platform, you acknowledge that you have read and understood this Privacy Policy. If you disagree with any part of this policy, please discontinue use immediately and contact [email protected] to close your account.
Information We Collect
Account & Identity Information
Collected when you register or update your profile:
- ›Full name, business name, registered email address, and phone number
- ›Password (stored as a bcrypt hash — never in plain text)
- ›Business category, industry vertical, target markets, and profile details you voluntarily add
- ›Profile photograph or business logo if uploaded
- ›Firebase User ID (UID) assigned upon sign-up — used as your primary account identifier across all platform features
- ›Google account display name and email if you choose to authenticate via Google (Google OAuth)
Alias / Sub-Account Information
If you create or use alias accounts (for team members or delegated access):
- ›Alias username, assigned email address, and configured display name
- ›Permissions assigned to each alias (read, write, send-only, etc.)
- ›Session tokens and authentication logs for each alias login
- ›Actions taken under the alias account are recorded against both the alias and the parent account
Subscription & Billing Information
- ›Selected subscription plan (Starter / Growth / Scale), billing cycle, and renewal dates
- ›Razorpay order IDs, payment status, and transaction reference numbers
- ›Invoice details including GST / tax ID if provided for billing purposes
- ›Payment failure events and retry history (no raw card data — see Section 10)
- ›Refund requests and associated correspondence
Business Directory Access & Lead Data
- ›Search queries, filters applied (country, industry), and business profiles you view or save
- ›Lead lists you access, download, or export within your subscription quota
- ›Notes, tags, or annotations you attach to business contacts within your workspace
- ›Lead download history and CSV export records
WhatsApp Business Data
- ›WhatsApp Business Account (WABA) ID and connected phone number
- ›Encrypted access tokens for the connected WABA (stored using AES-256-CBC encryption)
- ›Message templates you create or sync from Meta — including template name, body, header, footer, and approval status
- ›Contact lists you upload via CSV, including phone numbers and any additional fields in the upload
- ›WhatsApp validation status for each contact (has_whatsapp flag)
- ›Campaign details: name, template used, target audience, scheduled time, send time, and per-message delivery/read/failure statuses
- ›Inbound messages received in your WhatsApp inbox, including message content and sender phone number
- ›Outbound message logs, delivery receipts, read receipts, and failure reasons from Meta webhook events
Email Platform Data
- ›Custom email domains you configure and their verification status
- ›DNS records you add to your domain (SPF, DKIM, DMARC, MX values) — stored for verification and display
- ›Email aliases you create (e.g., [email protected]) and their linked routing addresses
- ›Emails sent and received through your configured inboxes, including full message content, attachments, headers, and metadata
- ›Email template content (HTML and plain text) you create in the Email Builder
- ›Draft emails and their auto-save history
- ›Outbound delivery status and bounce/error reports from our email infrastructure provider
Platform Usage & Activity Data
- ›Pages visited, dashboard features accessed, and time-on-page metrics
- ›Clicks, button interactions, search terms, and feature usage patterns
- ›Error logs, exception reports, and debugging information generated during your session
- ›Support tickets, chat messages, and form submissions (including Contact and Delete My Data forms)
Technical & Device Information
- ›IP address, approximate geographic region (country/city), and ISP
- ›Browser type and version, operating system, device type (desktop / mobile / tablet)
- ›Screen resolution and language/locale settings
- ›Referral source (e.g., how you arrived at our website)
- ›Firebase Analytics and Crashlytics diagnostic data (aggregated, not linked to individual identities in production)
Data You Submit via Public Forms
- ›Name, email, company, phone, topic, subject, and message — submitted via the Contact Us form
- ›Name, email, account ID, deletion scope, reason, and notes — submitted via the Delete My Data form
- ›These submissions are stored separately from your user account and are used solely to process your inquiry
Legal Basis for Processing
We rely on the following legal bases to process your personal data, as applicable under India's Digital Personal Data Protection Act 2023 (DPDP Act) and other applicable frameworks:
- ›Processing Google OAuth identity data when you choose to sign in with Google
- ›Sending marketing newsletters or promotional updates
- ›Using analytics cookies beyond essential session management
- ›Creating and managing your user account
- ›Processing subscription payments and delivering paid features
- ›Sending WhatsApp messages or emails on your behalf through connected accounts
- ›Processing CSV contact uploads to run your campaigns
- ›Fraud detection, abuse prevention, and platform security monitoring
- ›Improving product quality through anonymized usage analytics
- ›Maintaining audit logs for compliance and dispute resolution
- ›Retaining billing and transaction records for 7 years under Indian tax law
- ›Complying with law enforcement requests or court orders
- ›Processing data deletion requests under applicable privacy regulations
How We Use Your Information
We process your personal data only for the specific purposes below:
- ›Account management — create, authenticate, and maintain your user account and any alias accounts you configure
- ›Service delivery — provide access to the B2B directory, process lead exports, deliver WhatsApp messaging capabilities, and manage your email platform
- ›Campaign execution — process your contact lists, apply template messages, enqueue bulk WhatsApp sends, and track per-message delivery outcomes
- ›Payment processing — create Razorpay orders, verify payment callbacks, issue invoices, and manage subscription lifecycle (upgrade, downgrade, cancellation)
- ›Platform personalization — remember your preferences, filter defaults, recent searches, and workspace configurations
- ›Security & fraud prevention — detect and block unauthorized access, rate-limit API abuse, and maintain audit trails
- ›Product improvement — analyze anonymized usage patterns, run internal A/B testing, and prioritize feature development
- ›Customer support — review and respond to support tickets, Contact form submissions, billing inquiries, and data requests
- ›Legal & compliance — meet obligations under Indian law, respond to lawful government requests, and process data deletion requests
- ›Transactional communication — send payment receipts, subscription renewal notices, security alerts, and critical platform updates
Authentication & Account Security
Leadsgram uses Google Firebase Authentication to manage user identity. Firebase is operated by Google LLC and processes authentication data in accordance with Google's Privacy Policy.
What Firebase Collects
- ›Email address and display name (from email/password sign-up or Google OAuth)
- ›Hashed password (for email/password accounts — Firebase stores this, not Leadsgram directly)
- ›Firebase UID — a unique identifier we use to link your account to all platform data
- ›Device metadata and IP address for sign-in event logging and anomaly detection
- ›Refresh tokens used to maintain your authenticated session across browser sessions
Alias Authentication
Alias accounts allow a primary account holder to create secondary login credentials for team members or delegate access without sharing the primary account password. Alias sessions are tracked independently with their own JWT tokens and are revocable at any time by the primary account holder.
WhatsApp Business API Integration
Leadsgram integrates with the Meta WhatsApp Business API through Meta's authorized Business Solution Provider (BSP) programme. When you connect your WhatsApp Business Account (WABA):
Data We Store
- ›Your WABA ID and connected phone number — to route messages and display inbox data
- ›Your WhatsApp access token — encrypted at rest using AES-256-CBC before database storage
- ›Message templates — synced from Meta or created through our platform, stored with their approval status
- ›Contacts you upload via CSV — stored in our database with their WhatsApp validation status
- ›Sent messages and their delivery/read/failure statuses received via Meta webhook events
- ›Inbound messages from customers who reply to your business — stored to populate your inbox view
- ›Conversation threads linking inbound and outbound messages by phone number
How Meta Processes This Data
Messages you send or receive via our platform are transmitted through Meta's infrastructure. Meta processes this data in accordance with their WhatsApp Business Policy and Meta's Data Policy. Leadsgram does not intercept or read message content for any purpose other than displaying it in your inbox.
Contact Data from CSV Uploads
When you upload a CSV file of phone numbers to build a campaign audience, those phone numbers are stored in our database, validated against WhatsApp's API (to confirm whether each number has a WhatsApp account), and used solely for the campaigns you create. We do not share these contact lists with any third party.
Email Services & DNS Configuration
Leadsgram provides a professional email infrastructure layer that allows you to configure a custom email domain, create aliases, and send / receive business emails directly within the platform.
Domain & DNS Data
- ›The domain name you configure is stored and associated with your account
- ›DNS records you add to your domain registrar (SPF, DKIM, DMARC, MX values) are recorded in our system for verification and display
- ›Domain verification status is checked periodically via DNS lookup — no data is transmitted to your registrar on our side
Email Content & Metadata
- ›Full email content (subject, body, attachments) for emails sent and received through your configured inbox is stored on our servers
- ›Email headers (From, To, CC, BCC, timestamps, Message-IDs) are retained for routing, threading, and search
- ›Outbound email delivery status, bounce codes, and spam complaint signals from our SMTP infrastructure
- ›Draft emails are auto-saved and stored until you send or manually delete them
Email Templates
HTML email templates you create using the Email Builder (including code blocks, images, and formatting) are stored in your workspace and are not shared with or accessible by other users.
Campaign & Bulk Messaging Data
When you create and execute a WhatsApp campaign through Leadsgram, we process the following data:
- ›Campaign configuration — campaign name, selected template, selected audience (contact list), and send timestamp
- ›Message queue records — individual message records for each recipient in the campaign, including their phone number, the message body (resolved from the template), and current delivery status
- ›Delivery telemetry — per-message status updates (queued → sent → delivered → read, or failed) received via Meta's webhook and stored for your reporting dashboard
- ›Failure reasons — error codes and descriptions returned by Meta for failed messages (e.g., number not on WhatsApp, message blocked, template rejected)
- ›Campaign statistics — aggregate counts of queued, sent, delivered, read, and failed messages, computed from message-level records
Business Directory & Lead Data
Leadsgram's core feature is a curated B2B business directory containing over 50,000 verified international business contacts across 40+ countries and 20+ industry verticals. This directory is built and maintained by our research team.
How Directory Data is Compiled
- ›Business information is compiled from publicly accessible sources: government trade registries, chamber of commerce directories, official company websites, industry association listings, and legitimate B2B databases
- ›Each entry is manually reviewed and cross-referenced before inclusion
- ›Directory data is periodically refreshed — typically every 30 days — to reflect changes in business status, contact details, and industry classifications
- ›We do not purchase or licence data from data brokers or engage in web scraping of private profiles
What Directory Records Contain
- ›Business name, registered address, country, and industry classification
- ›Primary contact name, email address, and phone number (sourced from public business listings)
- ›Business website, LinkedIn profile link, and other publicly listed online presence
- ›Business description, services offered, and export/import activity where publicly available
Your Use of Directory Data
- ›Access to directory records is governed by your subscription plan and associated usage quotas
- ›You may download leads in CSV format within your plan's monthly export limit
- ›Leads you download or save to your workspace are stored in your personal lead list within the platform
- ›You are solely responsible for how you use contact information accessed through the directory
Payment Processing
All subscription payments are processed through Razorpay, a PCI-DSS Level 1 compliant payment gateway authorized by the Reserve Bank of India (RBI). Leadsgram does not collect, store, transmit, or process raw payment card data, bank account numbers, or UPI credentials.
- ›Payment card and banking credentials are entered directly on Razorpay's hosted payment page — this data never passes through Leadsgram's servers
- ›Upon successful payment, Razorpay sends us a tokenized transaction ID, payment status, and amount — used to activate or renew your subscription
- ›We retain Razorpay order IDs, payment reference numbers, subscription plan details, and invoice metadata
- ›GST invoices are generated on our side using the billing details you provide and stored for the legally required minimum of 7 years
- ›Payment failure events (without card details) are logged to allow our support team to assist you
- ›Refund transactions are processed through Razorpay and the corresponding records are stored in our billing history
Third-Party Service Integrations
Leadsgram integrates with the following third-party services to deliver platform functionality. Each provider operates under its own privacy framework and we enter into data processing agreements where required:
- ›Meta Platforms, Inc. — processes WhatsApp messaging data under Meta's Data Policy. Messages transit Meta's servers. We subscribe to Meta webhooks to receive delivery receipts and inbound messages
- ›Google LLC (Firebase) — handles authentication (sign-in, session tokens, OAuth). Firebase may collect device metadata and crash diagnostics per Google's Privacy Policy
- ›Razorpay Software Pvt. Ltd. — processes all payment transactions. PCI-DSS compliant, RBI authorized, Indian entity. Governed by Razorpay's Privacy Policy
- ›Email Infrastructure Provider — outbound emails are routed through our SMTP provider for delivery. Provider processes email headers and metadata necessary for delivery
- ›Cloud Infrastructure — our servers, databases, and file storage run on cloud infrastructure. Provider processes data in accordance with their DPA and ISO 27001 / SOC 2 certifications
Data Sharing & Disclosure
We do not sell, rent, or trade your personal data. We may share your information only in the following narrowly defined circumstances:
- ›Service Providers (Sub-processors): Vetted vendors providing cloud hosting, email delivery, payment processing, and authentication services — bound by data processing agreements that restrict use to the designated service only
- ›API Partners: Meta/WhatsApp for message delivery; Razorpay for payment processing — data shared is the minimum necessary for the integration to function
- ›Legal Compliance: When required by a binding court order, government authority, or applicable law — we will notify you where legally permitted before disclosing
- ›Safety & Security: To investigate or prevent fraud, unauthorized access, abuse of our platform, or threats to the safety of users or third parties
- ›Business Transfers: In connection with a merger, acquisition, asset sale, or corporate restructuring — subject to a confidentiality agreement and notification to affected users
- ›With Your Explicit Consent: For any purpose not described above, only with your informed, affirmative consent
International Data Transfers
Leadsgram is based in India and primarily processes data on servers located in India. However, some of our third-party service providers operate globally, which may involve transferring your data across international borders:
- ›Meta / WhatsApp: Message data transits Meta's global infrastructure, which includes servers in the United States and other jurisdictions. Meta's data transfers are governed by Standard Contractual Clauses and Meta's Data Policy
- ›Google Firebase: Authentication data may be processed on Google's global infrastructure. Google maintains data transfer mechanisms compliant with applicable regulations
- ›Cloud Hosting: Our primary infrastructure is hosted in India. Disaster recovery or backup systems may involve cross-border data replication within the provider's compliance framework
Where personal data is transferred outside India, we ensure appropriate safeguards are in place as required by the Digital Personal Data Protection Act, 2023, and any applicable cross-border transfer regulations notified by the Government of India.
Data Security
We implement layered technical and organisational security measures to protect your personal data against unauthorized access, accidental loss, alteration, or disclosure.
Technical Controls
- ›TLS 1.2+ encryption for all data in transit between client and server
- ›AES-256-CBC encryption for sensitive data at rest, including WhatsApp access tokens
- ›bcrypt password hashing (Firebase-managed) for email/password accounts
- ›JWT-based session management with short expiry and refresh token rotation
- ›Role-based access controls (RBAC) — alias account permissions are strictly scoped
- ›Database-level row-isolation ensuring one user's data cannot be queried by another
- ›API rate limiting and request throttling to prevent brute-force and abuse
Operational Controls
- ›Internal access to production data is restricted to authorised team members on a need-to-know basis
- ›Automated anomaly detection monitors for unusual login patterns and API usage spikes
- ›Security incident response plan with defined escalation procedures
- ›Periodic review of third-party service providers' security posture
Data Retention
We retain personal data only as long as necessary for the purposes for which it was collected:
- ›Active Account Data: Retained for the lifetime of your active account and subscription
- ›Post-Cancellation: Account data is retained for 30 days after subscription cancellation to allow account recovery, then deleted or anonymized
- ›After Deletion Request: Most personal data is permanently deleted within 30 days of a verified data deletion request (see our Delete My Data page)
- ›Campaign & Message Records: Message-level campaign records retained for up to 12 months post-send for reporting; then anonymized
- ›WhatsApp Inbox: Conversation messages retained for 12 months from last message date, or until you delete the connection
- ›Email Data: Inbox emails retained for the duration of your active subscription. Deleted on account closure after a 30-day grace period
- ›Billing & Invoice Records: Transaction records retained for a minimum of 7 years as required by Indian tax law (GST / Income Tax Act)
- ›Support Communications: Contact form submissions and support tickets retained for 3 years for quality and dispute resolution purposes
- ›Anonymized Analytics: Aggregated, de-identified usage statistics may be retained indefinitely for platform improvement
Your Rights & Choices
Under the Digital Personal Data Protection Act, 2023 (India) and applicable privacy principles, you have the following rights:
- ›Right to Access — request a summary of the personal data we hold about you and how it is being processed
- ›Right to Correction — request that we correct inaccurate or incomplete personal data held about you
- ›Right to Erasure — request deletion of your personal data, subject to legally mandated retention requirements (see Section 15)
- ›Right to Data Portability — request your lead data, contact lists, and account information in a structured, commonly used, machine-readable format
- ›Right to Restrict Processing — request that we limit processing of your data in specific circumstances
- ›Right to Object — object to processing based on legitimate interests or for direct marketing purposes
- ›Right to Withdraw Consent — withdraw consent you previously granted (e.g., marketing emails, analytics cookies) without affecting prior lawful processing
- ›Right to Nominate — under the DPDP Act, you may nominate another individual to exercise your rights on your behalf in the event of death or incapacity
To exercise any of these rights, please use our Data Deletion & Rights page or email [email protected] with the subject "Data Rights Request — [Your Name]". We will respond within 30 days. Identity verification may be required before processing your request.
Children's Privacy
Leadsgram is a professional B2B platform designed exclusively for business use by individuals who are 18 years of age or older. We do not knowingly collect personal data from anyone under 18. If we become aware that a minor has created an account or submitted personal data, we will promptly delete that information and close the account. If you believe a minor has registered, please contact [email protected] immediately.
India DPDP Act Compliance
Leadsgram is committed to compliance with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the rules notified thereunder. As a Data Fiduciary under the Act, we have implemented the following measures:
- ›We collect personal data only for lawful purposes with valid consent or under other lawful grounds specified in the Act
- ›We have appointed a Grievance Officer accessible to all Data Principals (users) — see Section 21
- ›We provide clear and accessible mechanisms for Data Principals to withdraw consent, request correction, and request erasure
- ›We implement reasonable security safeguards to prevent personal data breaches
- ›In the event of a personal data breach that is likely to cause harm, we will notify affected users and the Data Protection Board as required by the Act
- ›We retain data only for the period necessary for the specified purpose and delete it thereafter
- ›We do not process children's personal data and do not serve behavioural advertising to any users
Changes to This Policy
We review and update this Privacy Policy periodically. When we make material changes, we will:
- ›Update the "Last Updated" date shown at the top of this page
- ›Send a notification to your registered email address at least 14 days before significant changes take effect
- ›Display a prominent in-app banner upon your next login whenever the policy has been meaningfully revised
- ›For changes that materially reduce your rights or increase our data collection, we will seek fresh consent where required by law
Continued use of Leadsgram after the effective date of a revised policy constitutes your acceptance of the updated terms. If you do not agree to the revised policy, please stop using the platform and submit a data deletion request.
Grievance Officer
In accordance with the Information Technology Act, 2000, the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the Digital Personal Data Protection Act, 2023, we have designated a Grievance Officer to address privacy-related concerns:
Grievance Officer — Leadsgram
Email: [email protected]
Subject line: Privacy Grievance — [Your Name / Account Email]
Response time: Within 30 days of receiving a valid complaint
For urgent security issues, mark your email subject "URGENT: Security Concern" and we will respond within 72 hours.
You may also submit privacy inquiries or data rights requests via our Contact page or our Data Deletion page.