Privacy Policy

Version 2.0 | 17 August 2026 | Replaces the version of 28 May 2026

LeadTrackr handles personal data in two distinct roles. This policy explains both, so you can see exactly which part applies to you.

Two roles, two sets of rules

LeadTrackr processes personal data in two capacities, and the difference matters for your rights:

  • As a controller. For visitors to leadtrackr.io, people who contact us or book a demo, and the users of a LeadTrackr account, we decide why and how personal data is processed. This policy describes that processing, and you can exercise your rights directly with us.
  • As a processor. For the lead data our customers collect through their own websites and campaigns, our customer is the controller and we only act on their instructions. If you submitted a form on a website that uses LeadTrackr, the operator of that website is responsible for your data. That processing is governed by our Data Processing Agreement, and requests about it should be addressed to that website operator. See Lead data we process for our customers.

Who we are

LeadTrackr is a service of LeadTrackr B.V., located at Jan van Goyenplein 65, 2231 MM Rijnsburg, the Netherlands, and registered with the Dutch Chamber of Commerce under registration number 42066573. You can reach us at support@leadtrackr.io.

We are not required to appoint a data protection officer, and have not appointed one. Privacy questions are handled through the address above.

Personal data we process as a controller

Visitors to leadtrackr.io

  • What: IP address, device and browser characteristics, pages viewed, referrer, campaign parameters and the channels that preceded your visit, timestamps.
  • Why: to keep the website working and secure, to understand how it is used, and to measure which marketing channels bring visitors to us. With your consent we also share interaction data with Google and Meta for measurement and remarketing — see Our own advertising and analytics.
  • Legal basis: our legitimate interest in operating and securing our website (Article 6(1)(f) GDPR) for strictly necessary processing, and your consent (Article 6(1)(a) GDPR) for analytics and marketing cookies.

People who contact us, book a demo or register for a workshop

  • What: name, email address, telephone number, company name, and the content of your message or registration.
  • Why: to answer your question, plan and hold the appointment, and follow up on it.
  • Legal basis: steps taken at your request prior to entering into a contract (Article 6(1)(b) GDPR), or our legitimate interest in responding to enquiries (Article 6(1)(f) GDPR).

Account holders and their users

  • What: name, email address, telephone number, company name, role and access rights, login and usage data, support correspondence, and billing details such as company address, VAT number and payment history.
  • Why: to provide the platform, authenticate users, deliver support, invoice and collect payment, prevent abuse, and send service messages about the platform. We also use the fact that you created an account, together with your contact details in hashed form, to measure and optimise our own advertising — see Our own advertising and analytics below.
  • Legal basis: performance of the agreement with you (Article 6(1)(b) GDPR), compliance with our statutory retention obligations (Article 6(1)(c) GDPR), and our legitimate interest in the security and improvement of the platform (Article 6(1)(f) GDPR). For the advertising use described below, the legal basis is your consent (Article 6(1)(a) GDPR).

Marketing to customers and prospects

  • What: name, email address, company name, and your interaction with our emails.
  • Why: to send product updates, tips and offers.
  • Legal basis under the GDPR: your consent (Article 6(1)(a) GDPR), or our legitimate interest in direct marketing (Article 6(1)(f) GDPR, recital 47).
  • Whether we may email you at all is a separate question, governed by the Dutch Telecommunications Act (Article 11.7) implementing the ePrivacy Directive. Having a GDPR legal basis is not by itself enough:
    1. If you are not a customer, we send commercial email only with your prior consent.
    2. If you are a customer, we may email you about our own similar products and services without asking again, provided we obtained your address in the context of that relationship, we offered you the opportunity to object when we obtained it, and we offer that opportunity in every message.
  • Your control: every message contains an unsubscribe link, and unsubscribing takes effect immediately and free of charge. You also have an absolute right to object to direct marketing under Article 21(2) GDPR, which we honour without asking for a reason. Objecting to marketing does not affect your account or the service messages we need to send you about the platform.

Our own advertising and analytics

We advertise on Google Ads and on Meta (Facebook and Instagram), and we use Google Analytics 4 to understand how our website performs. This section describes what that means for your data. It concerns our own marketing, and is separate from the integrations our customers activate for their campaigns.

Visitors to our website

When you visit leadtrackr.io with analytics and marketing cookies enabled, we place and read identifiers that allow Google and Meta to recognise your browser. We use these to measure which campaigns bring visitors to us, and to show you our ads again on other websites and in Meta's apps (remarketing). The data shared consists of online identifiers, IP address, device and browser characteristics, the pages you viewed and the campaign that referred you.

When you create an account

Creating an account is a conversion for us, and we share it with our advertising platforms. When you sign up, we send a conversion event to Google Ads and Meta containing your email address and telephone number in hashed form (SHA-256), together with the fact that a signup took place and the campaign it can be attributed to. Google and Meta match that hash against their own user base to confirm which ad led to the signup, so we can optimise our advertising towards people like you.

This is the same mechanism our product provides to our customers, applied to our own marketing. We do not send the content of your account, your lead data, or the contact details of your own customers to any advertising platform.

Who receives this data and in what role

  • Google Ireland Ltd. — Google Ads and Google Analytics 4. Google acts as our processor for the analytics measurement and as an independent controller for its own advertising purposes, under the Google Ads Data Processing Terms.
  • Meta Platforms Ireland Ltd. — the Meta pixel and the Conversions API. For the collection and transmission of the data described above, we and Meta are joint controllers within the meaning of Article 26 GDPR, under Meta's Controller Addendum. Meta is solely responsible for what it does with the data afterwards. The essence of that arrangement is set out in Meta's Controller Addendum, and you can exercise your rights towards either of us.

Both parties process data outside the EEA. Those transfers rely on the EU–US Data Privacy Framework and the European Commission's Standard Contractual Clauses.

Your choice

The legal basis for all processing described in this section is your consent. You can withdraw it at any time, with effect for the future. You also have an absolute right to object to processing for direct marketing purposes under Article 21(2) GDPR — if you object, we stop, and no justification is required.

To withdraw consent or object, write to support@leadtrackr.io. You can also block these cookies in your browser, adjust your Google Ad Center settings, or your Meta ad preferences. Withdrawing consent does not affect your account or your use of the platform.

Lead data we process for our customers

The core of the platform is processing the leads of our customers. For that data our customer is the controller and we are the processor. We process it only on their instructions, for the purposes described in Annex I of the Data Processing Agreement, which also lists the exact categories of data involved.

In short, that data consists of: name and contact details submitted through a form or call, the content of the form, the advertising click identifiers and campaign parameters that preceded the submission, IP address and device data, and the status and value our customer assigns to the lead. We do not use this data for our own purposes, we do not enrich it for our own benefit, and we do not sell it.

If you submitted a form on a website that uses LeadTrackr and you want to access or delete your data, contact the operator of that website. They can do this directly in the platform. If you approach us instead, we will forward your request to them without undue delay.

Data we send to advertising platforms on our customers' instruction

LeadTrackr exists to send the outcome of a lead — qualified, won, or the deal value — back to the advertising platform that generated it. This transmission happens only for integrations our customer has connected and enabled.

Before we transmit an email address or telephone number to an advertising platform, we hash it with SHA-256. The platform receives the hash, not the plain value. What the receiving service then does with that data, and in which role it acts, is governed by the agreement between our customer and that service — not by us. An advertising platform will generally act as a controller for its own purposes; a CRM or similar business application will generally act as our customer's own processor. Either way we are not a party to that relationship.

Google API Services

LeadTrackr's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

  • What we access. When you connect your Google account, we request the scopes needed to read your Google Ads accounts, conversion actions and campaign performance, and to upload offline and enhanced conversions. Where you connect Google Analytics 4, we send conversion events through the Measurement Protocol.
  • What we store. We store the OAuth access and refresh tokens, account identifiers and configuration metadata needed to keep your integration working. Tokens are encrypted at rest with AES-256-GCM. We do not copy the contents of your Google Ads account into our systems beyond the reporting metrics shown in your dashboard.
  • What we do not do. We do not use Google user data to develop, improve or train generalised models. We do not sell it, and we do not transfer it to third parties other than to provide or improve the features you have enabled, to comply with applicable law, or as part of a merger or acquisition.
  • Revoking access. You can disconnect the integration in your LeadTrackr account, or revoke access at any time through your Google account permissions. On disconnection or account deletion we delete the associated tokens and integration metadata within 30 days.

Meta Platform data

LeadTrackr integrates with the Meta Conversions API. Our use of data received from Meta adheres to the Meta Platform Terms, the Business Tools Terms and the applicable developer policies.

  • What we access. With the permissions you grant, we read your business accounts, ad accounts, campaigns and event sets to configure the integration and to display performance in your dashboard.
  • What we send. Qualified lead events, including hashed identifiers and the deal value, so that your campaigns can optimise on outcomes rather than form fills.
  • What we store. Access tokens and integration metadata, encrypted at rest. We do not use Meta Platform data for our own purposes and do not share it with data brokers or other advertising networks.
  • Revoking access. You can remove LeadTrackr at any time through your Meta Business Integrations settings, after which we delete the associated tokens and metadata within 30 days.

Microsoft Advertising and LinkedIn

Where you connect Microsoft Advertising or LinkedIn, we process the same categories of data for the same purpose: reading account and campaign metadata to configure the integration, and sending conversion events with hashed identifiers. Access tokens are stored encrypted and deleted within 30 days of disconnection.

Who we share personal data with

We do not sell personal data. We share it in the following situations only:

  • Sub-processors and service providers. Our hosting, database and transactional email providers process lead data on behalf of our customers as sub-processors. Our payment provider processes only the billing details of account holders, not lead data. Both groups are listed separately, with their location and transfer mechanism, at leadtrackr.io/sub-processors, and each processes data under a data processing agreement.
  • Advertising platforms and other services you connect. Only for integrations you have enabled yourself, as described above. Their role under the GDPR follows from your agreement with them, not from ours.
  • Our own advertising and analytics partners. Google and Meta receive website interaction data and hashed signup events so that we can measure and optimise our own campaigns, on the basis of your consent. See Our own advertising and analytics.
  • Advisors and authorities. Where we are legally required to disclose data, or where disclosure is necessary to establish, exercise or defend legal claims.
  • In a corporate transaction. If LeadTrackr is merged with or acquired by another company, personal data may be transferred as part of that transaction. We will inform you before it takes effect.

International transfers

The database in which lead and account data is stored is located within the European Economic Area, and the application that processes it runs in European regions. Several of our sub-processors are nonetheless incorporated outside the EEA — principally in the United States — and may access data from there for support and operational purposes. For those transfers we rely on the EU–US Data Privacy Framework, the European Commission's Standard Contractual Clauses, or another mechanism permitted under Chapter V GDPR. The mechanism that applies per party is stated at leadtrackr.io/sub-processors.

How long we keep personal data

  • Account data: for the duration of the agreement and up to 6 months after it ends, so the account can be reactivated.
  • Lead data: for as long as our customer instructs. Our customer can delete individual leads at any time. After the agreement ends, lead data is deleted within 30 days of the export period, and from backups within a further 90 days, as set out in Article 12 of the Data Processing Agreement.
  • Invoices and financial records: 7 years, as required by Dutch tax law.
  • Integration tokens: deleted within 30 days of disconnecting an integration or deleting the account.
  • Support correspondence: up to 2 years after the last contact.
  • Marketing data: until you unsubscribe or object, and up to 2 years after the last interaction.

How we protect personal data

We apply technical and organisational measures appropriate to the risk, including encryption of all traffic in transit, encryption of integration credentials at rest with AES-256-GCM, hashing of identifiers before they are transmitted to advertising platforms, logical separation of every customer's data, access on a need-to-know basis, and an event log per lead recording every status change and every transmission. The full set of measures is described in Annex II of the Data Processing Agreement.

Your rights

Where we act as the controller, you have the right to access your personal data, to have it rectified or erased, to restrict or object to the processing, to data portability, and to withdraw consent at any time without affecting the lawfulness of processing before the withdrawal.

Send your request to support@leadtrackr.io. We respond within one month. We may ask for additional information to verify your identity, and we will use that information for no other purpose.

If you are not satisfied with how we handle your request, you can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), autoriteitpersoonsgegevens.nl, or with the supervisory authority in your country of residence.

Cookies and similar techniques

leadtrackr.io uses cookies and comparable techniques in the following categories:

  • Strictly necessary: needed for the website and your session to work. These are always placed.
  • Functional: remember your preferences and support the demo booking embed.
  • Analytics: tell us how the website is used, through server-side tag management operated for us by YesWeTrack B.V.
  • Marketing and attribution: record which channel and campaign brought you to us and allow us to show our ads again elsewhere. This includes the lt_channelflow cookie, the cookie used by our affiliate programme, and identifiers set for Google Ads and the Meta pixel.

Analytics and marketing cookies are placed on the basis of your consent. You can withdraw that consent at any time, and you can block or delete cookies at any time through your browser settings. The website remains usable without them, but some functionality — such as the demo booking embed — may not work.

To exercise your choice or to have data collected through these cookies erased, write to support@leadtrackr.io.

Children

The platform is a business service and is not directed at children. We do not knowingly collect personal data of children under 16. Our customers are contractually prohibited from submitting such data.

Changes to this policy

We may update this policy. When a change is material, we notify account holders by email at least 30 days in advance. The version and date at the top of this page always show which version is current.

Contact

For any question about this policy or about how we handle personal data, write to support@leadtrackr.io or to LeadTrackr B.V., Jan van Goyenplein 65, 2231 MM Rijnsburg, the Netherlands.