Privacy Policy
This policy explains what personal data FreshLeads handles and why. It covers two different groups of people, and they have different rights and expectations, so we address them separately:
- Our customers — people who subscribe to FreshLeads.
- Business contacts in our database — decision-makers at consumer brands whose work contact details we compile from public sources.
Controller: FreshLeads, a sole proprietorship of Ishaan Ratan Yadav, Gwarighat Road, Jabalpur, Madhya Pradesh 482002, India. Contact details are on our contact page.
Part 1 — If you are a customer
What we collect
- Account and billing: your name, email address, company, and country. Card details are entered directly with our payment provider and are never seen or stored by us.
- Usage: which leads you claim, filters you use, and basic product analytics.
- Correspondence: emails and support messages you send us.
Why, and on what basis
- To provide the Service and deliver the leads you claim (performance of our contract with you).
- To take payment, invoice you, and meet tax and accounting obligations (contract; legal obligation).
- To enforce claim limits and the three-buyer exclusivity cap (contract; legitimate interests).
- To send service messages about your subscription. Marketing email is sent only with your consent and you can unsubscribe at any time.
Who we share it with
Only with the providers needed to run the Service: our payment provider (who acts as merchant of record and is an independent controller for payment and tax data), our hosting provider, and our email provider. We do not sell customer data.
How long we keep it
Account and claim records for as long as you are a customer, then for up to 7 years where tax law requires it. Product analytics for up to 24 months.
Part 2 — If you are a business contact in our database
We compile a database of business (not personal) contact details for decision-makers at consumer brands: name, job title, company, company website, a work email address, and publicly reported facts about the company such as a funding round or product launch. This information is used by our customers for business-to-business outreach relevant to that person's professional role.
Where it comes from
Public sources only: company websites and contact/press pages, press releases and news coverage, public business directories, and public professional profiles. We do not buy consumer data, we do not collect special category data, and we do not collect personal (non-work) contact details.
Our lawful basis
We rely on legitimate interests (Article 6(1)(f) UK/EU GDPR) — namely our and our customers' interest in business-to-business communication with the appropriate person at a company, using work contact details, about services relevant to their role. We have weighed this against the interests and rights of the individuals concerned, and we limit our processing accordingly: work contacts only, business context only, and an immediate opt-out on request.
Where we obtain details from a third party rather than directly from you, this policy serves as the notice required by Article 14. If we cannot contact you directly, this page constitutes that notice.
Your rights
You can ask us to give you a copy of what we hold about you, correct it, delete it, restrict how we use it, or object to our use of it. If you object to our use of your details, we will stop and remove you — we do not require a reason.
Remove me from the database. Email the address on our contact page with the subject line REMOVE and the email address or company concerned. We will:
- remove the record within 7 days and confirm when it is done;
- add the address and domain to a permanent suppression list so it is never re-added by a future run;
- notify customers who have already claimed that lead that it must not be contacted further.
How long we keep it
Records are reviewed and refreshed regularly; details that are stale or unverifiable are removed. Suppression list entries are kept permanently — that is the only way to guarantee a removed contact is never re-added.
International transfers
We are based in India and use service providers that may process data in the EU, UK, and United States. Where data is transferred out of the UK/EEA we rely on appropriate safeguards, including the UK/EU Standard Contractual Clauses where applicable.
Cookies and analytics
The public site uses no advertising or tracking cookies. Our host may record standard, aggregated request logs (such as page and referrer counts) for security and performance. The dashboard stores your filter preferences locally in your browser only.
Security
Data is transmitted over HTTPS. Access to the lead database is restricted, and the public site is built so that unclaimed leads' contact details and identities are removed before publication rather than merely hidden.
Complaints
If you are unhappy with how we have handled your data, please contact us first — we would rather fix it. You also have the right to complain to your local data protection authority (for example the ICO in the UK, or your national supervisory authority in the EEA).
Changes
We will update this page when our practices change, and update the "last updated" date above.