Legal

Privacy Policy

This policy explains what we collect, why, and what you can ask us to do with it. It is written to be read, not skimmed past.

Last updated 1 October 2026

Who this covers

LeadHound is operated by Pracpros (“LeadHound”, “we”, “us”). This policy covers two different groups of people, and the difference matters:

  • Our customers. The businesses and agencies who sign up for an account. For their account data we are the data controller.
  • Visitors to our customers’ websites. The people whose calls and form submissions are recorded as leads. For that data our customer is the controller and we are their processor, acting on their instructions.

If you filled in a form or called a number on someone else’s website and want your data removed, contact that business first. If you cannot reach them, write to us and we will pass the request on.

What we collect

Account data. Your name, work email, company name, hashed password, plan and billing status, plus the websites, phone numbers and integrations you configure.

Lead data captured for our customers.Depending on how the lead arrives, this can include the name, email address, phone number and message a visitor typed into a form, the caller’s phone number, the length of the call, a recording and transcript of it where the customer has recording switched on, and the value the customer later assigns to that lead.

Click and session data.The tracking snippet records the page a visitor landed on, the referring site, their IP address and user agent, and any advertising identifiers present in the URL, such as a Google click id, a Facebook click id or UTM tags. It stores a first-party session identifier in the visitor’s browser so a call or form later in the same visit can be matched to the click that started it.

Usage data. Standard server logs, error reports and product usage events from the dashboard.

Why we use it

  • To run the service: capturing leads, matching them to a source, and reporting.
  • To send conversion data to the advertising platforms our customer has connected, so their bidding reflects real results.
  • To authenticate you, keep accounts separate and prevent abuse.
  • To answer support requests and, where the law allows, tell you about the product.

Where the law requires a legal basis, ours is the contract with our customer, our legitimate interest in operating and securing the service, and consent where consent is the right basis (for example, marketing email).

Who we share it with

We do not sell personal data. We share it with the service providers needed to deliver the product:

  • Google for Google Ads conversion uploads, click enrichment and Analytics 4 events.
  • Meta for Conversions API events on Facebook and Instagram campaigns.
  • Plivo for provisioning tracking numbers, routing calls and storing recordings.
  • OpenAI for transcript analysis, where the customer has AI call analysis switched on for a number pool.
  • Our hosting and infrastructure providers for running the application and its databases.

Contact details sent to advertising platforms for conversion matching are hashed with SHA-256 before they leave our systems. The platform can match them against its own hashed records but cannot read them.

We also disclose data where we are legally required to, and we will tell you where we are allowed to.

Google user data

When a customer connects Google Ads, we ask for access to their Google Ads account. With that access we:

  • Read the Google Ads accounts they can manage (ids and names), their conversion actions, the campaign, ad group and keyword behind the Google click ids on their leads, and daily campaign cost, clicks and impressions for their ROI report.
  • Write a conversion action for LeadHound leads, and upload conversions and conversion adjustments for those leads to the same account.
  • Store the authorization token, encrypted, together with the account and conversion action the customer selected, and the campaign and keyword attributed to each lead.

How we use it. Only to provide the features the customer asked for: attributing their leads to the ads that produced them, reporting their return on ad spend, and sending their conversions back to their own Google Ads account.

Who we share it with.Nobody, apart from the hosting and infrastructure providers that run LeadHound on our behalf. We do not send Google user data to Meta, Plivo, OpenAI or any other provider listed above. We disclose it otherwise only where the law requires it or with the customer’s permission.

How we protect it. We protect Google user data with the following security measures:

  • Encryption at rest. The Google authorization token is encrypted with AES-256 before it is written to the database, and it is never returned by our API or shown in the dashboard.
  • Encryption in transit. All traffic to LeadHound and all calls to Google APIs use HTTPS (TLS).
  • Hashing. Contact details sent with a conversion are hashed with SHA-256 before they leave our systems.
  • Account isolation.Every record belongs to one customer account, and every database query is restricted to that account, so one customer can never read another customer’s Google data.
  • Access control.Only the customer’s own signed-in users can reach the data, and only administrators can connect or disconnect Google Ads. Our staff do not access it unless the customer asks us to for support, it is needed for security, or the law requires it.

More detail is on our security page.

How long we keep it and how to delete it. We keep the authorization token only while Google Ads stays connected. Clicking Disconnect on the Google Ads settings page permanently deletes the token and the connection straight away. A customer can also revoke our access at any time from myaccount.google.com/permissions, which stops us reaching their account. The attribution saved on leads and the imported campaign spend stay in the customer’s reports until they delete those leads or close their account. To have all Google user data we hold deleted, email privacy@getleadhound.io and we will delete it within 30 days.

What we never do with it.We do not sell Google user data. We do not share it with data brokers or information resellers. We do not use it to target ads: sending a customer’s own conversions back to their own Google Ads account, at their request, is the only advertising use. We do not use it to assess creditworthiness or for lending. We do not use it to train or improve AI or machine-learning models.

LeadHound’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Requests from public authorities

We disclose personal data to courts, regulators, law enforcement or other public authorities only when applicable law requires us to. When we receive such a request:

  • We review it. Every request is checked for its legal basis and validity before we act on it.
  • We challenge it where it is unlawful. If a request is overly broad, lacks a valid legal basis or conflicts with applicable law, we push back on it or refuse it, and use the legal remedies available to us.
  • We disclose the minimum. Where we must comply, we provide only the data the request strictly requires.
  • We keep a record. We document each request, our response, the legal reasoning behind it and who handled it.

Where the law allows, we tell the affected customer before we disclose their data, so they can object.

How long we keep it

  • Click sessions and number assignments are pruned automatically once they pass the retention window set on the account, which defaults to 90 days.
  • Leads, calls and their recordings are kept until the customer deletes them or closes the account.
  • Account and billing records are kept for as long as the account is open and afterwards for as long as tax and accounting rules require.

Deleting a website removes its tracking configuration and the calls recorded against it.

Your rights

Depending on where you live, you can ask for a copy of your data, ask us to correct or delete it, object to certain processing, or ask us to send it somewhere else. Email privacy@getleadhound.io and we will respond within the period the law allows, normally one month. We may need to confirm who you are before we act.

If we handle your request badly you can complain to your local data protection authority. We would rather you told us first so we can fix it.

Cookies and local storage

Our own website uses only what is needed to keep you signed in. The tracking snippet on our customers’ sites stores a first-party session identifier and the first click details in the visitor’s browser storage. It does not set third-party cookies and does not follow visitors across unrelated websites.

Changes and contact

If we change this policy in a way that matters, we will tell account holders by email before it takes effect. For anything else, write to privacy@getleadhound.io or use the contact page. Our security practices are described on the security page.