Last updated: July 8, 2026
Effective date: June 29, 2026
This Privacy Policy explains how Leadr ("Leadr", "we", "us", "our") collects, uses, stores, shares, and protects information when you use the Leadr web dashboard at https://leadr.co.in and the Leadr Chrome extension (together, the "Service").
Leadr is a WhatsApp CRM that runs alongside WhatsApp Web to help businesses capture leads, send follow-ups, and manage their sales pipeline. This policy is written to be clear and complete, and to satisfy the requirements of the Google API Services User Data Policy, the Meta Platform Terms and Developer Policies, the Chrome Web Store Program Policies, the EU/UK GDPR, and India's Digital Personal Data Protection Act. By using the Service you agree to this policy.
Leadr is the data controller for the personal data described in this policy. You can reach us at any time at contact@leadr.co.in for privacy questions, data-access requests, or complaints. Our website is https://leadr.co.in.
This policy covers three groups of people: (a) account owners / admins who sign up for Leadr, (b) their team members who are invited to sign in, and (c) the leads and contacts whose information an admin stores in their CRM. Where an admin uploads or captures the personal data of their own leads, the admin is the controller of that data and Leadr acts as a processor on the admin's behalf.
We collect only what we need to provide the Service. The categories are:
Your name, email address, phone number, country code, organization name, role, and a securely hashed password. This is used to create and secure your account.
The WhatsApp number you connect through WhatsApp Web is bound to your account to prevent cross-account messaging and protect against account takeover. We do not store the contents of your WhatsApp conversations on our servers.
The leads and contacts you add, import, or capture — including names, phone numbers, email addresses, company, pipeline stage, custom attributes, and notes — together with the follow-up sequences, message templates, and automation triggers you configure. This data belongs to you; we store and process it so you can run your CRM.
Log data, IP address, browser and device information, and limited diagnostics needed to operate, secure, and troubleshoot the Service.
The Leadr Chrome extension has a single purpose: to display and operate your Leadr CRM
alongside WhatsApp Web. It runs only on https://web.whatsapp.com. Here is exactly what each
permission is used for:
| Permission / host | Why it is used |
|---|---|
storage | To keep your extension settings and signed-in session on your own device. |
web.whatsapp.com (content script) | To render the CRM sidebar inside WhatsApp Web and read the contact name and phone number of the chat you open, so it can match or create the matching lead in your CRM. |
api.leadr.co.in | To sync your leads with the Leadr backend and send the messages you compose. |
File-host domains (ufs.sh, utfs.io) | To load media/attachments you use in templates. |
The extension does not:
We do not sell your personal data, and we do not use it for advertising or unrelated profiling.
Each integration below is optional and is activated only when you connect it. We request the minimum access needed.
If you connect Gmail so that Leadr can send your follow-up and test emails from your own mailbox, we use Google OAuth and request these scopes:
https://www.googleapis.com/auth/gmail.send — to send emails on your behalf, from your own Gmail account, only when you (or a follow-up sequence you set up) trigger them. We send via the Gmail API users.messages.send endpoint. This scope does not grant read access to your mailbox.openid, email, profile — to identify the Google account you connected and show its address in your settings.What we do and do not do with Google user data:
If you connect Google Sheets, you share your specific spreadsheet with our Google service-account email.
We use read-only access (spreadsheets.readonly) to import new lead rows from that one sheet.
We do not access any other file in your Google Drive.
Meta Lead Ad Forms. If you connect a Facebook Page, we use the Meta Graph API with these permissions:
pages_show_list, pages_read_engagement — to list the Pages you manage so you can pick the correct one, and read its basic details.pages_manage_metadata — to subscribe your Page to lead-generation webhooks so new leads flow into Leadr.leads_retrieval — to retrieve the answers a person submitted to your lead-ad form (name, phone, email) and create them as a lead in your CRM.Lead data received from Meta is used solely to create the CRM record for the business that owns the Page. It is never sold, shared with unrelated third parties, or used for advertising. We store an encrypted Page access token to receive your leads; you can disconnect at any time, which removes it.
Meta Conversions API (optional). If you enable the Meta Conversions API to measure and optimize your ad campaigns, Leadr sends hashed (SHA-256) customer identifiers — such as email, phone, and name — together with lead/conversion event data to Meta. These identifiers are hashed before transmission and are used only for conversion measurement and ad optimization for your own account. You control which fields are sent and can disable this at any time.
If you connect a Pabbly webhook, we receive the lead data you choose to route to Leadr from other apps, using a unique per-account webhook token. We use it only to create the leads you send us.
To send our own transactional emails (verification, password resets, security and billing notices), we use standard SMTP (for example via an email provider) or the Resend email API. Only the recipient address and message content required to deliver these emails are shared with the delivery provider.
We share data only with the service providers listed in Section 8, under appropriate confidentiality and data-protection obligations, and only to run the Service. In addition, we may disclose information:
We never sell your personal data.
storage permission.No method of transmission or storage is 100% secure, but we protect your data using industry-standard measures and review our practices regularly.
We keep your information for as long as your account is active or as needed to provide the Service. Specifically:
When you delete your account or ask us to delete your data, we remove your personal data and stored third-party tokens, except where we must retain limited records to comply with legal obligations.
Your data may be processed in countries other than your own (including where our cloud providers operate). Where it is, we take steps to ensure it continues to be protected in line with this policy and applicable law.
Depending on your location, you may have the right to:
To exercise any of these rights, email contact@leadr.co.in. We will respond within the timeframe required by applicable law. You also have the right to complain to your local data-protection authority.
We use a small number of essential and functional cookies and local-storage items to keep you signed in and remember your settings — including an HTTP-only refresh cookie for authentication. We do not use advertising or cross-site tracking cookies.
The Service is intended for business use and is not directed to anyone under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
We may update this policy from time to time. We will revise the "Last updated" date above and, for material changes, provide additional notice where appropriate. Continued use of the Service after an update means you accept the revised policy.
For any privacy question, data request, or complaint, contact:
Leadr
Email: contact@leadr.co.in
Website: https://leadr.co.in
© 2026 Leadr. All rights reserved.