1. Roles and scope
LeadPending acts as a service provider for customer-submitted lead data. The customer determines why that contact data is collected and must provide any notice or legal basis required on its website.
2. Data we process
We process account and security data needed to provide access, configure organizations, and protect sessions. We also process connected-site settings and inbound lead content.
- Account identity, email, authentication and security events.
- Site name, domain, sender profile, response context, locale, and API-key prefix.
- Lead name, email, optional phone and company, message, source page, locale, and customer-defined metadata.
- Email thread content, draft revisions, delivery state, bounce or complaint events, and suppression records.
- For an optional Telegram connection: Telegram user and private-chat numeric identifiers, username and display name, binding status, and content-free delivery and security audit records.
- Operational telemetry such as provider status, duration, token usage, and audit events.
3. How data is used
We use data to receive and display leads, prepare an operator-requested draft, send an explicitly approved reply, receive responses, enforce plan limits, prevent abuse, support customers, and operate the service. Lead content is not used to train a general LeadPending model.
4. Service providers
Only the data required for a specific operation is sent to the relevant provider. This may include an OpenAI-compatible AI provider for draft generation, AWS SES and related AWS services for email transport and inbound parsing, VeriMail for address validation, Telegram for an optional content-minimized new-lead alert in a linked private chat, and infrastructure or observability providers for secure operation. Web search is not used for draft generation.
5. Retention and deletion
Messages and account data are retained while needed to provide the service and meet security or legal obligations. Deleting a site or account begins a 30-day recovery window before hard deletion, except where a longer period is required by law, dispute preservation, fraud prevention, or backup lifecycle.
6. Security
Site API keys are stored as one-way hashes and the full secret is displayed only when created. Sessions use opaque random tokens. Access checks scope customer data to its organization, and provider callbacks are authenticated and deduplicated. No online service can promise absolute security.
7. International processing and rights
Providers may process data in countries outside your own. Where applicable, you may request access, correction, deletion, restriction, or portability. Customers should direct lead data requests to the organization that collected the request; we assist customers with valid requests.
8. Changes and contact
We may update this policy as the service changes and will publish the revised date here. Privacy questions can be sent to [email protected].