Privacy Policy
This policy explains what Leads Ranger collects, why we collect it, who we share it with, how long we keep it and what you can ask us to do about it. It applies to leadsranger.com, app.leadsranger.com, our browser extension and every channel you use to talk to us.
The short version
- We sell software, not data. We do not sell personal information and we do not share it for advertising.
- There are two kinds of data here: information about you (which we control), and the business contacts in your workspace (which you control and we only process on your instructions).
- Your workspace data is never pooled with other customers, never resold, and never used to train AI models.
- You can export everything in your workspace at any time, and ask us to delete your account and its data.
- We use a short list of service providers to run the platform, and we publish it.
This summary is for convenience only. The numbered sections below are the binding text.
01Who we are and how to reach us
Leads Ranger ("Leads Ranger", "we", "us", "our") provides a lead generation, outreach and customer relationship platform available at leadsranger.com and app.leadsranger.com (together, the "Service"). We are established in the Islamic Republic of Pakistan.
For any question about this policy, to exercise a privacy right, or to raise a concern, contact us at support@leadsranger.com with "Privacy" in the subject line. We monitor that address and a person answers it.
Where the General Data Protection Regulation (EU) 2016/679 ("GDPR") or the UK GDPR applies, we are the data controller for the account information described in this policy, and a data processor for the contact data you upload, import or collect into your workspace. Section 3 explains the difference, and it matters.
02What this policy covers
This policy applies to our marketing website, our web application, our browser extension, our documentation and support channels, and any communication you have with us.
It does not apply to third-party services you choose to connect to your workspace (for example a mailbox provider, a messaging provider or an AI provider), to third-party websites we link to, or to how you use personal data once you export it out of the Service. Those are governed by the relevant third party and by your own privacy practices.
Business-to-business service
The Service is sold to businesses and professionals for business purposes. It is not directed to consumers, and it is not intended for anyone under 18.
03The two kinds of data, and who controls them
Almost every question about privacy on a platform like ours comes down to telling two categories apart. We keep them separate on purpose.
| Category | What it is | Who decides what happens to it |
|---|---|---|
| Account Data | Information about you as our customer: your name, email address, login credentials, plan, billing records, support messages and product usage. | We are the controller. This policy governs it. |
| Workspace Data | Everything you put into or generate inside your workspace: leads and business contacts, message content, sequences, notes, pipeline records, uploaded documents and knowledge-base material. | You are the controller. We are your processor. We act only on your documented instructions, as set out in our Data Processing Addendum. |
In plain terms: we decide how to run our business, and you decide how to run your outreach. We do not repurpose your Workspace Data, we do not merge it into a shared database, and we do not sell it or licence it to anyone.
04Information we collect
Information you give us
- Account and identity details: your name, business email address, and a password. Passwords are stored only in an irreversible, encrypted form and are never visible to us or to anyone else.
- Business profile details: company name, website, industry, role, country and any profile information you choose to add.
- Billing details: our payment processor collects and processes your payment method directly. We receive only the limited records we need for invoicing and accounting, such as billing name, billing country, plan, amounts, currency, invoice history and the last four digits and brand of the card. We never receive or store full payment card numbers.
- Support and correspondence: the content of tickets, emails, chats and any attachments or screenshots you send us.
- Optional submissions: survey answers, feedback, testimonials, beta programme requests and event registrations.
Information you create inside the Service (Workspace Data)
- Business contact records you discover, import, capture or add manually, including business names, business email addresses and phone numbers, websites, addresses, categories and any custom fields you create.
- Outreach content: sequences, templates, subject lines, message bodies, drafts, scheduling rules and the messages sent and received through channels you connect.
- Commercial records: pipeline stages, notes, tags, tasks, activity history and reporting derived from the above.
- Material you upload to train your AI assistant, such as documents, service descriptions, pricing information and website content you ask us to read.
Please do not upload sensitive categories of data
The Service is designed for ordinary business contact information. Do not upload special-category data (health, biometric, genetic, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation), government identifiers, payment card data, or information about children. If you do so, you do it at your own risk and you remain solely responsible for it.
Information from services you connect
When you connect a mailbox, a messaging channel, an AI provider or another third-party service, you grant the Service the access needed to carry out the actions you have configured, and nothing more. Credentials and access tokens you provide are held in encrypted form, are never displayed back to you or to your team once saved, and are used solely to perform the tasks you set up. You can disconnect any service at any time from within the application, which revokes our further use of that access.
Information collected automatically
- Device and connection information: IP address, approximate location derived from it (typically city or country level), browser and operating system, language and device type.
- Usage information: pages and screens viewed, features used, actions taken, timestamps, referring pages and the general path taken through the product.
- Diagnostic information: error reports and performance measurements that help us find and fix faults.
- Cookies and similar technologies: described in our Cookie Policy.
Information from other sources
- Our payment processor, for subscription status and payment outcomes.
- Publicly available business information returned by the discovery features you run, such as business listings, business websites and publicly published business contact details.
- Partners and referrers, where you arrive through a referral or affiliate link.
05Why we use information, and our legal bases
Where the GDPR or UK GDPR applies, we rely on the legal bases set out below. Where it does not apply, we still limit ourselves to these purposes.
| Purpose | What that looks like | Legal basis |
|---|---|---|
| Providing the Service | Creating and running your account, executing the actions you configure, storing your workspace, delivering the features on your plan. | Performance of a contract |
| Billing and account administration | Taking payment, issuing invoices, applying plan limits, handling renewals, cancellations and refunds. | Performance of a contract; legal obligation |
| Support | Answering tickets, investigating a problem you report, restoring access. | Performance of a contract; legitimate interests |
| Keeping accounts and the platform safe | Preventing unauthorised access, fraud, abuse of the Service and misuse of shared infrastructure, and enforcing our Acceptable Use Policy. | Legitimate interests; legal obligation |
| Improving the product | Understanding which features are used, diagnosing faults, measuring performance, planning the roadmap. We work from aggregated and de-identified information wherever it will answer the question. | Legitimate interests |
| Communicating with you | Service notices, security notices, billing notices, product updates and, where permitted, marketing. | Performance of a contract; legitimate interests; consent where required |
| Meeting legal obligations | Tax and accounting records, responding to lawful requests, establishing or defending legal claims. | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights, and we have concluded they are not. You can ask us for our assessment, and you can object at any time using the process in section 12.
06The contact data in your workspace
This section is the one that matters most on a lead generation platform, so we will be direct about it.
- You are the controller of that data. You decide who goes into your workspace, why, what you send them, and how long you keep them.
- We are your processor. We handle that data only to provide the Service to you and only on your instructions, on the terms of our Data Processing Addendum, which is incorporated into our Terms & Conditions.
- You are responsible for having a lawful basis for collecting and contacting the people in your workspace, and for complying with the marketing and privacy laws that apply where you and your recipients are located. That includes, without limitation, the GDPR and UK GDPR, the ePrivacy rules and PECR, CAN-SPAM, CASL, the TCPA and equivalent local rules, and the terms of any messaging provider you connect.
- We do not build a shared contact database. Data in your workspace is not pooled with other customers, is not resold, is not licensed, and is not offered as a data product.
- We do not use it to train artificial intelligence models, ours or anyone else’s.
- Recipients who contact us about a message sent from your account will be told that you are the controller and will be directed to you. Where we are legally obliged to act, we will notify you unless the law prevents it.
Compliance features are provided, not imposed
The Service includes unsubscribe handling, suppression of contacts who opt out, and validation that helps you avoid sending to addresses that should not receive mail. These tools exist to help you comply. They do not make you compliant on their own, and using them does not transfer your legal responsibility to us.
07Artificial intelligence features
- When you use a feature that generates or analyses content, the material needed to produce that output is sent to the AI provider configured for your workspace, processed to return the result, and returned to you.
- We do not use your prompts, your uploaded material or the generated output to train our own models, and our AI providers are engaged on terms that prohibit them from training their models on it.
- You can supply your own AI provider key, in which case that traffic runs under your own account and your own agreement with that provider.
- AI output can be wrong, out of date or unsuitable. It is a draft, not advice. You remain responsible for everything your account sends.
10International transfers
We operate from the Islamic Republic of Pakistan and use service providers located in a number of countries, including within the European Economic Area, the United Kingdom and the United States. That means personal information may be transferred to, stored in and processed in a country other than your own.
Pakistan is not the subject of an adequacy decision by the European Commission or the United Kingdom. Where we transfer personal information out of the EEA or the United Kingdom, we put an appropriate transfer mechanism in place, ordinarily the European Commission Standard Contractual Clauses together with the UK International Data Transfer Addendum, supplemented by contractual and organisational measures appropriate to the data. You can request a copy of the relevant mechanism by writing to us.
11How long we keep information
We keep personal information only for as long as we need it for the purposes described in this policy, and then delete it or de-identify it.
| Information | Retention period |
|---|---|
| Workspace Data | For as long as your account is open. Deleted or de-identified within 30 days of account closure or a verified deletion request, unless you ask us to keep it longer. |
| Account and profile records | For the life of the account, then up to 12 months, to handle reinstatement, disputes and abuse follow-up. |
| Billing and tax records | For the period required by applicable tax and accounting law, typically up to 10 years. This applies even after account closure. |
| Support correspondence | Up to 24 months from the last message in the conversation. |
| Diagnostic and access records | A short rolling window, kept only as long as needed for troubleshooting and platform safety. |
| Backups | Backups expire on a rolling cycle. Data deleted from the live Service disappears from backups as that cycle completes. |
| Suppression and opt-out records | Retained for as long as needed to keep honouring the opt-out, which is itself a legal requirement. |
12How we protect information
Protecting your account and your commercial data is a first-order engineering priority, not a checkbox. In practical terms:
- Traffic between you and the Service is encrypted in transit.
- Credentials and connection secrets are held encrypted and are not displayed back through the interface or the API once saved.
- Access to production systems is restricted to the small number of personnel who need it to operate the Service, and is granted on a least-privilege basis.
- Each workspace is logically separated so that customers cannot see one another’s data.
- We maintain layered protections against unauthorised access and abuse, and we review them on an ongoing basis. We do not publish the specifics of those controls, because publishing them would help the people they are designed to stop.
- We keep backups so that your workspace can be restored after a failure.
No online service can promise perfect security, and we do not. If a personal data breach occurs that is likely to result in a risk to individuals, we will notify the relevant supervisory authority and affected customers without undue delay and in line with applicable law.
You have a part to play too: keep your password unique and private, control who you invite into your workspace, and tell us immediately at support@leadsranger.com if you believe your account has been accessed without your permission.
13Your privacy rights
If you are in the European Economic Area, the United Kingdom or Switzerland
- Access: obtain confirmation of whether we process your personal data, and a copy of it.
- Rectification: have inaccurate personal data corrected and incomplete data completed.
- Erasure: ask us to delete personal data where one of the grounds in Article 17 applies.
- Restriction: ask us to limit how we use your personal data in defined circumstances.
- Portability: receive personal data you gave us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
- Objection: object to processing based on legitimate interests, and object at any time to direct marketing.
- Withdraw consent: where processing is based on consent, withdraw it at any time without affecting processing already carried out.
If you are in California or another United States state with a privacy law
- The right to know what personal information we collect, use and disclose, and the categories of recipients.
- The right to access a copy of that information, and the right to correct inaccuracies.
- The right to request deletion, subject to the exceptions the law allows.
- The right to opt out of the sale or sharing of personal information and of targeted advertising. We do not sell or share personal information, so there is nothing to opt out of.
- The right not to be discriminated against for exercising these rights. We will not deny you the Service, charge you a different price or give you a lower level of service because you made a request.
- The right to use an authorised agent, on proof of authorisation.
How to exercise a right
- 1Write to support@leadsranger.com from the email address on the account, with "Privacy request" in the subject line, and tell us what you want.
- 2We may need to verify your identity before we act, in proportion to the sensitivity of the request. We will ask for the minimum needed and we will not use that information for anything else.
- 3We respond within one month for GDPR and UK GDPR requests, and within 45 days for United States state privacy requests. Where a request is complex or numerous we may extend that period as the law allows, and we will tell you if we do.
- 4We do not charge for these requests unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline, and we will explain why.
Requests about data inside a customer workspace
If you are contacting us because a Leads Ranger customer holds your business contact details, that customer is the controller of that data, not us. Tell us which company contacted you and we will forward your request to them and support them in answering it, but we cannot amend or delete records inside their workspace on our own initiative.
Complaints
We would like the chance to resolve any concern first, so please come to us. You also have the right to complain to your local data protection supervisory authority, which for the United Kingdom is the Information Commissioner’s Office, and in the EEA is the authority in your country of residence, place of work or the place of the alleged infringement.
14Marketing choices
We send service messages (billing, security, important product changes) to all customers, because they are part of providing the Service and cannot be opted out of while your account is open.
Marketing messages are a different matter. Every marketing email carries a one-click unsubscribe, and you can also change your preferences in the application or write to us. Unsubscribing from marketing does not affect service messages.
15Automated decision-making
We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing. Automated processes inside the Service (such as scoring, prioritisation, drafting or routing) are decision support for you, and you remain in control of the outcome. Where we act on an automated signal in order to protect the platform, a person reviews the outcome on request.
16Children
The Service is not directed to children and is not available to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, write to us and we will delete it.
17Third-party sites and services
Our website and the Service may link to or interoperate with third-party sites and services. We do not control them and we are not responsible for their content or their privacy practices. Read their policies before you give them your information.
18Changes to this policy
We may update this policy as the Service, our providers or the law change. The "last updated" date at the top always reflects the current version. If a change materially affects how we handle personal information, we will give you reasonable advance notice by email or in the application before it takes effect. Continuing to use the Service after a change takes effect means you accept the updated policy.
19Contact us
Questions, requests, complaints and responsible disclosures all go to the same monitored address: support@leadsranger.com. Put "Privacy" in the subject line and a person will pick it up.
Postal correspondence can be sent to Leads Ranger, Pakistan. If you need a registered postal address for a formal notice, ask us and we will provide it.
