Privacy Policy

Last updated: July 8, 2026

Effective date: June 29, 2026

This Privacy Policy explains how Leadr ("Leadr", "we", "us", "our") collects, uses, stores, shares, and protects information when you use the Leadr web dashboard at https://leadr.co.in and the Leadr Chrome extension (together, the "Service").

Leadr is a WhatsApp CRM that runs alongside WhatsApp Web to help businesses capture leads, send follow-ups, and manage their sales pipeline. This policy is written to be clear and complete, and to satisfy the requirements of the Google API Services User Data Policy, the Meta Platform Terms and Developer Policies, the Chrome Web Store Program Policies, the EU/UK GDPR, and India's Digital Personal Data Protection Act. By using the Service you agree to this policy.

Contents
  1. Who we are & how to reach us
  2. Key definitions
  3. Information we collect
  4. The Chrome extension: what it accesses & why
  5. How we collect information
  6. Legal bases for processing
  7. How we use information
  8. Third-party services & integrations
  9. How we share & disclose information
  10. Storage & security
  11. Data retention
  12. International data transfers
  13. Your rights & choices
  14. Cookies & local storage
  15. Children
  16. Changes to this policy
  17. Contact & grievances

1. Who we are & how to reach us

Leadr is the data controller for the personal data described in this policy. You can reach us at any time at contact@leadr.co.in for privacy questions, data-access requests, or complaints. Our website is https://leadr.co.in.

This policy covers three groups of people: (a) account owners / admins who sign up for Leadr, (b) their team members who are invited to sign in, and (c) the leads and contacts whose information an admin stores in their CRM. Where an admin uploads or captures the personal data of their own leads, the admin is the controller of that data and Leadr acts as a processor on the admin's behalf.

2. Key definitions

3. Information we collect

We collect only what we need to provide the Service. The categories are:

3.1 Account & identity data

Your name, email address, phone number, country code, organization name, role, and a securely hashed password. This is used to create and secure your account.

3.2 WhatsApp connection data

The WhatsApp number you connect through WhatsApp Web is bound to your account to prevent cross-account messaging and protect against account takeover. We do not store the contents of your WhatsApp conversations on our servers.

3.3 CRM & contact data

The leads and contacts you add, import, or capture — including names, phone numbers, email addresses, company, pipeline stage, custom attributes, and notes — together with the follow-up sequences, message templates, and automation triggers you configure. This data belongs to you; we store and process it so you can run your CRM.

3.4 Integration data (optional, only if you connect an integration)

3.5 Technical & usage data

Log data, IP address, browser and device information, and limited diagnostics needed to operate, secure, and troubleshoot the Service.

4. The Chrome extension: what it accesses & why

The Leadr Chrome extension has a single purpose: to display and operate your Leadr CRM alongside WhatsApp Web. It runs only on https://web.whatsapp.com. Here is exactly what each permission is used for:

Permission / hostWhy it is used
storageTo keep your extension settings and signed-in session on your own device.
web.whatsapp.com (content script)To render the CRM sidebar inside WhatsApp Web and read the contact name and phone number of the chat you open, so it can match or create the matching lead in your CRM.
api.leadr.co.inTo sync your leads with the Leadr backend and send the messages you compose.
File-host domains (ufs.sh, utfs.io)To load media/attachments you use in templates.

The extension does not:

5. How we collect information

7. How we use information

We do not sell your personal data, and we do not use it for advertising or unrelated profiling.

8. Third-party services & integrations

Each integration below is optional and is activated only when you connect it. We request the minimum access needed.

8.1 Google APIs — Gmail sending

If you connect Gmail so that Leadr can send your follow-up and test emails from your own mailbox, we use Google OAuth and request these scopes:

What we do and do not do with Google user data:

Google API Services Limited Use disclosure. Leadr's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to train generalized AI/ML models, we do not use it for advertising, and we do not sell it or transfer it to third parties except as necessary to provide or improve this user-facing feature, to comply with applicable law, or as part of a merger or acquisition.

8.2 Google Sheets (optional lead import)

If you connect Google Sheets, you share your specific spreadsheet with our Google service-account email. We use read-only access (spreadsheets.readonly) to import new lead rows from that one sheet. We do not access any other file in your Google Drive.

8.3 Meta Lead Ads & Conversions API

Meta Lead Ad Forms. If you connect a Facebook Page, we use the Meta Graph API with these permissions:

Lead data received from Meta is used solely to create the CRM record for the business that owns the Page. It is never sold, shared with unrelated third parties, or used for advertising. We store an encrypted Page access token to receive your leads; you can disconnect at any time, which removes it.

Meta Conversions API (optional). If you enable the Meta Conversions API to measure and optimize your ad campaigns, Leadr sends hashed (SHA-256) customer identifiers — such as email, phone, and name — together with lead/conversion event data to Meta. These identifiers are hashed before transmission and are used only for conversion measurement and ad optimization for your own account. You control which fields are sent and can disable this at any time.

8.4 Pabbly Connect (optional inbound leads)

If you connect a Pabbly webhook, we receive the lead data you choose to route to Leadr from other apps, using a unique per-account webhook token. We use it only to create the leads you send us.

8.5 System email delivery

To send our own transactional emails (verification, password resets, security and billing notices), we use standard SMTP (for example via an email provider) or the Resend email API. Only the recipient address and message content required to deliver these emails are shared with the delivery provider.

8.6 Hosting & infrastructure

9. How we share & disclose information

We share data only with the service providers listed in Section 8, under appropriate confidentiality and data-protection obligations, and only to run the Service. In addition, we may disclose information:

We never sell your personal data.

10. Storage & security

No method of transmission or storage is 100% secure, but we protect your data using industry-standard measures and review our practices regularly.

11. Data retention

We keep your information for as long as your account is active or as needed to provide the Service. Specifically:

When you delete your account or ask us to delete your data, we remove your personal data and stored third-party tokens, except where we must retain limited records to comply with legal obligations.

12. International data transfers

Your data may be processed in countries other than your own (including where our cloud providers operate). Where it is, we take steps to ensure it continues to be protected in line with this policy and applicable law.

13. Your rights & choices

Depending on your location, you may have the right to:

To exercise any of these rights, email contact@leadr.co.in. We will respond within the timeframe required by applicable law. You also have the right to complain to your local data-protection authority.

14. Cookies & local storage

We use a small number of essential and functional cookies and local-storage items to keep you signed in and remember your settings — including an HTTP-only refresh cookie for authentication. We do not use advertising or cross-site tracking cookies.

15. Children

The Service is intended for business use and is not directed to anyone under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

16. Changes to this policy

We may update this policy from time to time. We will revise the "Last updated" date above and, for material changes, provide additional notice where appropriate. Continued use of the Service after an update means you accept the revised policy.

17. Contact & grievances

For any privacy question, data request, or complaint, contact:

Leadr
Email: contact@leadr.co.in
Website: https://leadr.co.in


© 2026 Leadr. All rights reserved.