Privacy Policy
Last updated: 2026-05-24
Who we are
LeadsLockAI is operated from Toronto, Ontario, Canada. We build an AI assistant that responds to inbound leads on behalf of local service businesses (plumbers, HVAC, med spas, and similar). You can reach our privacy contact at support@leadslockai.com.
What data we collect
- Business profile information you provide during setup: company name, owner name, phone number, address, hours, services, and pricing notes.
- Lead messages and contact detailssent through the web chat widget or SMS forwarding: the lead's name, phone number, email if provided, and the text of their conversation with the AI.
- Account credentials: your email address and a hashed password. We never store the password in plain text.
- Payment metadata from Stripe: a customer ID and subscription status. We do not see or store credit card numbers, expiry dates, or CVV codes. Stripe handles all card data directly.
- Basic usage data: anonymous pageviews via Vercel Analytics, plus error logs that help us fix bugs.
Why we collect it
We collect this data for three reasons: to run the lead-response AI (the AI needs to know what your business does so it can answer leads accurately), to contact you about service issues or product changes, and to handle billing through Stripe. We do not sell your data and we do not use lead conversations to train public AI models.
Where your data lives
- Supabase (Postgres + auth) in the ca-central-1 region. This is where your business profile, leads, and conversation history live.
- Stripe (United States) for subscription billing and customer records.
- Twilio(United States) for SMS delivery. Messages pass through Twilio to reach the lead's phone.
- Groq (United States) for the AI inference that generates replies. Lead messages are sent to Groq at the moment a reply is generated and are not retained by Groq for model training per their API terms.
- Vercel (global edge) for hosting the website and API.
How long we keep it
Active business and lead data is retained for the life of your subscription. If you cancel, we keep your data for up to 90 days so you can reactivate without losing history, then it is permanently deleted. You can request earlier deletion at any time by emailing support@leadslockai.com.
Your rights
We operate in line with PIPEDA (Canada) and CASL (Canadian Anti-Spam Law) where applicable. You have the right to:
- Access the data we hold about you.
- Correct anything that is wrong.
- Delete your account and the associated data.
- Withdraw consent for SMS communication at any time. Customers who receive SMS from us can text STOP to opt out at any moment.
To exercise any of these rights, email support@leadslockai.com and we will respond within 30 days.
Cookies and tracking
We use a session cookie to keep you logged in to the dashboard. We use Vercel Analytics to count pageviews in aggregate, which does not set third-party advertising cookies. We do not run Google Ads, Meta Pixel, or any third-party advertising trackers.
Children's data
LeadsLockAI is built for businesses. We do not knowingly collect data from anyone under the age of 18. If you believe we have collected data from a minor, contact us and we will delete it.
Changes to this policy
We may update this policy as the product changes. The "Last updated" date at the top reflects the most recent change. For material changes that affect how your data is used, we will email account owners at least 30 days before the change takes effect.
Contact
For privacy questions, data requests, or to report a concern, email support@leadslockai.com. We aim to respond within 24 hours, Monday to Friday.