This Policy explains the personal information Leadity handles. It covers two distinct things: information about you, our customer, and the business-contact personal information in the product, meaning the leads we compile and make available to customers. The two are treated very differently, and both are described below. This is version 2026-08-29 of this Policy.
Part A. Information about you, our customer
1. What we collect about you
- Account. Username, email address, and a hash of your password. We never store the password itself.
- Billing. Credit balance, purchase history and lifetime spend. We do not store card numbers. Payment is handled by our payment provider, Whop.
- Usage. Leads delivered to you, scrape and validation jobs you run, coverage you have swept, referral activity, and support conversations.
- Device and security signals. Your IP address, browser user-agent, browser timezone and language, a device identifier we set in a cookie, and a browser fingerprint computed at signup. We use these to detect duplicate and fraudulent accounts and to protect the Service. They are described in Section 9.
- Approximate location. An approximate country or region derived from your IP address, and your browser timezone, recorded when you sign up. It is approximate by nature. We do not use GPS or any precise location. We use it to understand where our customers are and to spot suspicious signups.
- Your agreement to our terms. When you accept the Terms of Service and this Policy, we record which version you accepted, the date and time, your IP address, your browser user-agent, and the device identifier and fingerprint described above. This is the record that evidences your agreement, and we keep it as described in Section 7.
2. How we use it
- To operate your account, run the jobs you order, process purchases and bill accurately.
- To send transactional email such as verification, purchase confirmations and job-completion notices. You can turn off the optional ones in Settings.
- To record your acceptance of our terms, detect fraud and abuse, enforce our Terms and meet legal obligations.
We do not sell your customer account data, and we do not share it for advertising. Part B below is about the business-contact data in the product, which is a different thing and is described separately.
Part B. The lead data in the product
3. What it is, and where it comes from
Leadity compiles business listings from publicly available sources, including Google Maps, Google Search, business directories and similar public listings. A listing can include the business name together with a contact's name, a business phone number, a business email address, a postal address, a website, and public ratings and review counts. Because some records identify an individual, for example a sole proprietor or a named owner, we treat the lead data as containing personal information for privacy-law purposes. The California business-to-business exemption that previously covered such data expired on January 1, 2023. We use this data to validate and classify records, including phone-line classification, to deliver leads to customers who order them, to bill, and for fraud-prevention and legal compliance.
4. Your privacy rights
Depending on where you live, including under the CCPA and CPRA in California, you may have the right to:
- Know or access the categories and specific pieces of personal information we hold about you;
- Delete your personal information, subject to legal exceptions;
- Correct inaccurate personal information; and
- Non-discrimination for exercising any of these rights.
To exercise any of these rights, including to have your information removed from the product, email support@leadity.io with the subject "Privacy request". We verify and respond within the time required by applicable law, generally 45 days, extendable once where permitted. An authorized agent may submit a request on your behalf with proof of authorization. Customers also remain responsible, as independent controllers of leads they export, for honoring requests they receive directly, as set out in the Terms of Service.
Part C. How we handle all of it
5. Service providers and sub-processors
We share information with a set of providers only to the extent needed to run the Service. Each operates under its own privacy policy.
- Railway hosts the Service and its databases, in the United States.
- Whop processes payments and provides the analytics pixel described in Section 9.
- Google provides the analytics and advertising tags on our marketing site, as described in Section 9.
- Resend delivers our transactional email.
- Cloudflare R2 stores files you upload, such as support attachments.
- Wistia serves the welcome video shown inside the app.
- Evomi provides the proxy network we use to collect public listings.
- Serper, BrightData, BulkVS, BounceBan and OpenRouter help us find, classify and verify the business records in the product. These receive lead data, not your account data.
- Discord and Telegram receive our internal operational notifications, which can name a customer account, so that we can run the Service.
6. Disclosure for legal reasons
We may disclose information when we believe in good faith that it is necessary to comply with a law, regulation, subpoena or legal process, to enforce our Terms, to detect, prevent or investigate fraud, security or technical issues, or to protect the rights, property or safety of Leadity, our customers or the public.
7. Retention
Account and billing records are kept while your account is active and, after you close or delete your account, for the period required by tax and accounting law. When you delete your account we retain the associated records for at least 12 months, and longer where required by law or reasonably necessary for security, audit, fraud-prevention, dispute-resolution or to enforce our Terms. We do not guarantee deletion of all records at any fixed point in time. The records that evidence your agreement to our terms, and our security and audit logs, are kept for those purposes. Lead records are retained while they remain part of the product, subject to the deletion and opt-out rights above.
8. Security
Passwords are hashed with Argon2id. Session, device and support cookies are httpOnly, so page scripts cannot read them. Access to production data is restricted and audited, and administrative access to a customer account is logged. Email deliverability is protected with SPF, DKIM and DMARC. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
9. Cookies, storage and similar technologies
We set three cookies. All are httpOnly, so no script on the page can read them.
- auth_v2 keeps you signed in. It lasts for the length of your session.
- ld_did is a device identifier, kept for up to 400 days. We use it to recognize that two accounts were created from the same browser, which is how we enforce one-per-person rewards and detect abuse. It is not used for advertising.
- ld_sup identifies you to the support chat so a conversation survives a page reload, kept for up to 400 days.
We also keep a small amount of data in your browser's local storage: leadity-theme, your light or dark display preference, and keys beginning leadity:catalog:, which cache the list of industries and areas so the app does not download them on every visit. Clearing your browser storage removes these.
Fingerprinting at signup. When you create an account, the signup form computes a browser fingerprint using FingerprintJS and sends it with your signup. We use it together with the device cookie to detect duplicate accounts. We do not use it for advertising and we do not share it.
Analytics and advertising. Our marketing site loads third-party scripts that measure how the site is used and let purchases be attributed to the visit that led to them. Today that means an analytics pixel from our payment provider, Whop, and the Google tag, which reports to Google Analytics and to the Google advertising products we have connected to it. We may add, change or remove these at any time, and we deliberately do not keep a list on this page that would go out of date as soon as we did. To find out exactly which ones are running right now, email support@leadity.io and we will tell you. Any of them may receive your IP address and user-agent and set their own cookies in your browser, each under its own privacy policy. The signed-in app loads none of this - no analytics and no advertising tracker at all - and our fonts are served from our own servers rather than a third-party CDN.
10. Where we operate
The Service and its data are hosted in the United States, and our Terms are governed by US law as set out in the Terms of Service. Some of the providers listed in Section 5 operate outside the United States. We honor the US state privacy rights described above for the people they protect, regardless of where you or we are located.
11. Business transfers
If Leadity is involved in a merger, acquisition, financing, reorganization or sale of assets, information may be transferred as part of that transaction. We will require the successor to honor this Policy, or we will notify you of any material change.
12. Children
The Service is for businesses and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe we have, contact us and we will delete it.
13. Changes and contact
We may update this Policy. Each version carries a version identifier and an effective date, both shown on this page. When we publish a version that materially changes how we handle your information, you will be asked to accept it the next time you use the Service, and we record which version you accepted as described in Section 1. If you do not want to accept a new version, you may delete your account from Settings instead. Privacy questions or requests: support@leadity.io.
