LeadOpera

Privacy Policy

Last updated: September 2026

This Privacy Policy explains how LeadOpera LLC, a Colorado limited liability company (“Company,” “we,” “us,” or “our”), collects, uses, and shares information in connection with LeadOpera™ platform and lead marketplace, LeadProof™, TermsProof™, and our related websites and services (the “Services”). It should be read together with our Terms & Conditions.

1. Our role: two kinds of data

The Services handle two categories of data that are treated differently:

(a) Account data — information about the businesses and users who sign up for and operate the Services. For this data we act as the controller.

(b) Certified records — the consumer-consent events or agreement acceptances that an integrating business or account captures and asks us to certify and seal on its behalf. For this data the integrating business or account is the controller and the Company acts as a service provider / processor: we process it under the business’s instructions to produce a tamper-evident record, and we do not sell it or use it to build consumer or signer profiles for our own purposes. For an agreement acceptance (TermsProof), the parties’ identifiers (such as a signer’s name and email) and the assent context (timestamp, IP, and intent-to-sign) are processed to produce the sealed record; identity is one-way hashed on the certificate, and no session recording is made. A consumer or signer who wishes to access, correct, or delete their information should contact the business or account that collected it; we will assist that party as its processor. See Your choices & rights.

2. Information we collect

Account & billing. Company name, contact name, email address, authentication identifiers, API keys, credit balance and transaction history, and support communications. Payments are processed by our payment processor (Stripe); we do not receive or store full payment-card numbers.

Financial account data (accounting). If you connect a bank or credit-card account to our accounting features, we access that account’s balances and transaction details (such as amount, merchant, and date) through Stripe Financial Connections, in order to categorize and reconcile those transactions in your books and produce financial reports. Authentication happens directly between you and your financial institution through Stripe; we never receive your online-banking credentials, and we do not store full bank-account or payment-card numbers. This data is used only to provide the accounting features to the account that connected the financial account, and is not sold or used to build profiles.

Consent records (on behalf of integrating businesses). At the moment a consumer consents on an integrating business’s property, the Services may capture: the consent language and form markup presented, the URL and the documents linked from it, the timestamp, the originating IP address, behavioral signals from the session (for example mouse movement, keyboard interaction, pointer events, and time-to-complete), and an anti-bot / anti-fraud assessment. Phone numbers and email addresses provided for later matching are hashed with a secret salt at capture and the plaintext is discarded — we store only the one-way hash, never the raw number or address.

Agreement records (on behalf of accounts). When a party accepts or executes an agreement, the Services may capture: the exact document and any exhibits presented, the acceptance statement and version, the signer’s name and email, the timestamp, the originating IP address, the recorded intent to sign, and the identity-assurance method and result. Signer identifiers used on the certificate are one-way hashed as above, and no session recording is made.

Technical & usage. Standard server and security logs, and cookies strictly necessary to keep you signed in and to run the anti-bot challenge. We do not use advertising or cross-site tracking cookies. See Cookies.

3. How we use information

We use account data to provide, secure, bill for, and support the Services. We process consent and agreement records solely to perform the certification the integrating business or account requested — archiving and hashing what was observed, applying a trusted timestamp, scoring trust and fraud signals, and, on request, running verification, drift analysis, or generating evidence packages and attestations. We also use limited data as needed to detect abuse, comply with law, and enforce our Terms. We do not sell personal information.

4. Sharing & subprocessors

We share information with vendors that help us run the Services, each under contractual confidentiality and data-protection obligations, and only as needed for their function:

  • Cloud hosting & database — application hosting (Vercel) and the primary database and authentication (Supabase).
  • Object storage & key management — durable archival of sealed documents and evidence packages, and encryption-key management (Amazon Web Services — S3 and KMS).
  • Payments — payment processing and stored payment methods for credit purchases, auto-recharge, and marketplace payouts (Stripe, including Stripe Connect for payouts).
  • Bank & card connectivity (accounting) — when an account connects a financial account to the accounting features, our provider (Stripe Financial Connections) provides secure, read-only access to that account’s balances and transactions so they can be categorized and reconciled in the account’s books. Stripe processes this under its own terms; we do not receive online-banking credentials.
  • Bot mitigation & page rendering — the human/bot challenge at capture (Cloudflare Turnstile) and headless rendering of linked documents.
  • Fraud scoring — an independent IP-based fraud/risk scoring service applied to the capture request.
  • Phone verification add-ons (optional) — when a buyer runs a Check verification add-on, lead data the buyer already holds is sent to an independent verification provider (currently Twilio) solely to return that signal: for Identity Match, the phone plus the name and postal code the buyer supplies, returning a name-to-number match confidence; for Line Type, the phone only, returning its line type and carrier. We do not retain the inputs or the returned result beyond running the check and recording that a check occurred, and the provider processes the data under its own terms. Identity Match is confirm-only — it reports whether the buyer’s supplied values match the number and returns no third-party name, address, or national-identifier data. These add-ons are used only for fraud prevention and identity/lead-quality verification — not for marketing, not to create a consumer report, and not for credit, insurance, or employment eligibility; and the buyer represents it holds the consumer consent necessary to process the data.
  • Trusted timestamping — independent RFC-3161 timestamp authorities (DigiCert and Sectigo) that bind a record to a point in time.
  • AI analysis — a large-language-model provider (Anthropic) used, on request, for compliance-language (Confirm) and drift analysis over captured content.
  • Email delivery — transactional email (sign-in links, receipts, notifications) via Resend.

These providers are engaged as subprocessors under contractual confidentiality and data-protection obligations. A current list of subprocessors is available on request at support@leadopera.com.

Connected platforms (data sources). Separately, when an account connects a Meta (Facebook/Instagram) or Google lead-ad source, we receive lead-form submissions and form metadata from that platform to certify and route them — the platform is a source, not a subprocessor we send your data to. What we access from each platform, and how it is used and deleted, is described in §12.

We may also disclose information to comply with law or valid legal process, to protect the rights, safety, and security of our users and the public, or in connection with a corporate transaction (for example a merger or acquisition), in which case we will require the recipient to honor this Policy.

5. Data minimization

The Services are designed to seal evidence, not to accumulate personal data. Contact identifiers used for matching are stored only as one-way salted hashes; the certification record is a cryptographic seal over what was observed. Where a field is absent, we record its absence honestly rather than substituting a placeholder.

6. Retention

Account data is retained for the life of the account and as required for legal, tax, and audit purposes. Because a certificate’s value is evidentiary, sealed consent records and evidence are retained as directed by the integrating business (for example, for a chosen retention term) and for so long as they may be needed to demonstrate the integrity of a record. Retention on behalf of an integrating business is governed by our agreement with that business.

7. Security

We use technical and organizational safeguards including encryption in transit and at rest, scoped access controls, cryptographic integrity hashing, and database-level immutability of sealed fields so a certified record cannot be silently altered after capture. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

8. Your choices & rights

Depending on where you live, you may have rights to access, correct, delete, or port your personal information, or to object to or restrict certain processing. For account data, you may exercise these by contacting us at the address below. For consumer consent records, because the integrating business is the controller, please direct requests to that business; we will support the business in responding as its processor. Note that we may retain information where required by law or where a sealed record must remain intact for its evidentiary purpose, and that hashed identifiers are pseudonymous and not reversible by us. For California and other state-specific rights, and our data-broker status, see Your state privacy rights.

9. Cookies

We use only cookies that are strictly necessary: a session cookie to keep you signed in, and cookies set by our bot- mitigation provider to run the human/bot challenge. We do not use advertising, analytics-profiling, or cross-site tracking cookies. You can block cookies in your browser, but the Services may not function correctly without the necessary ones.

10. International data transfers

We operate in the United States, and our vendors may process information in the United States and other countries. Where required, transfers of personal data are made under appropriate safeguards. By using the Services you understand your information may be processed in the United States.

11. Children’s privacy

The Services are intended for businesses and are not directed to children. We do not knowingly collect personal information from children. If you believe a child’s information has been provided to us, contact us and we will take appropriate steps.

12. Connected ad-platform accounts (Google & Meta)

When an advertiser connects a hosted lead-ad source, we receive a narrow slice of that platform’s data — with the advertiser’s OAuth authorization — strictly to power a user-facing feature (certifying and routing the resulting leads). In this flow the platform is the source and we are the recipient; we access only what the feature needs and never write to the advertiser’s ad account. This section describes that access specifically, as required by the Google API Services User Data Policy and Meta’s Platform Terms.

Google Ads. When an advertiser connects Google Ads (Setup → Social & hosted lead-ad forms → Google Ads):

  • What we access. With the advertiser’s OAuth authorization, we read — read-only— the advertiser’s Google Ads lead-form assets (lead_form_asset) via a GAQL query: the lead form’s consent disclosure text and privacy-policy URL, plus the identifiers needed to match a form (form / campaign / customer ids). Via the openid and email scopes we also receive the connecting account’s basic identity, solely to record which Google login was connected. We do not read, create, edit, pause, or delete campaigns, ads, budgets, keywords, audiences, or any other Google Ads data, and we never spend on the advertiser’s behalf.
  • How we use it. Solely to produce and maintain the advertiser’s own tamper-evident consent certificates — sealing the disclosure the consumer was shown and monitoring the linked privacy page for drift. The data is used only to provide this user-facing feature.
  • What we share / transfer. We do not sell this data or transfer it to data brokers, advertisers, or any third party for advertising, lending, or profiling. A consent disclosure sealed into a certificate is available to the parties who rely on that certificate (for example, the lead buyer, or a court or regulator verifying it) — that is the certificate’s purpose — and to our subprocessors acting on our behalf under contract (see §4).
  • How we protect it. Encrypted in transit and at rest; OAuth refresh tokens are stored encrypted; access is scoped and least-privilege; sealed fields are database-immutable (see §7).
  • Retention & deletion. OAuth tokens are retained only while the connection is active and are deleted when the advertiser disconnects the account in the portal or on request to support@leadopera.com; the advertiser can also revoke access at any time via Google Account → Security → Third-party access. Consent disclosures already sealed into a certificate are retained for the certificate’s evidentiary term (see §6).

Meta (Facebook / Instagram). When an advertiser connects a Meta account (Setup → Social & hosted lead-ad forms → Meta):

  • What we access. With the advertiser’s authorization, we retrieve their Lead Ads submissions from their connected Facebook Pages — the consent / disclosure text shown on the lead form and the lead fields the consumer submitted — plus the Page and form identifiers needed to list and match forms, and the connecting user’s basic public profile solely to record which Meta login connected. Our use is retrieval-oriented: we do not publish posts, create or manage ads or campaigns, or spend on the advertiser’s behalf.
  • Facebook and Instagram. Instagram Lead Ads (Instant Forms) are handled through the same Page connection — Meta delivers those submissions on the linked Facebook Page’s leadgen webhook — provided the Instagram professional account is linked to a connected Facebook Page (Meta’s own requirement for Instagram lead ads). We do not connect to or read an Instagram account separately.
  • How we use it. Solely to produce and maintain the advertiser’s own tamper-evident consent certificates for those leads — sealing the disclosure the consumer was shown — and, where configured, to route the certified lead. The data is used only to provide this user-facing feature.
  • What we share / transfer. We do not sell this data or transfer it to data brokers or any third party for advertising or profiling. A sealed disclosure is available to the parties who rely on the certificate (as with any certificate) and to our subprocessors acting on our behalf under contract (see §4).
  • How we protect it. Encrypted in transit and at rest; OAuth tokens stored encrypted; access scoped and least-privilege; sealed fields database-immutable (see §7).
  • Retention & deletion. OAuth tokens are retained only while the connection is active and are deleted when the advertiser disconnects in the portal or on request to support@leadopera.com; the advertiser (or a consumer) can also remove our access at any time via Facebook Settings → Business Integrations. See our Data Deletion instructions. Disclosures already sealed into a certificate are retained for the certificate’s evidentiary term (see §6).

Limited Use. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements; and our use of data received through the Meta platform adheres to Meta’s Platform Terms and Developer Policies.

13. Marketplace lead-data flows

When you use the marketplace Services (LeadOpera — lead ingestion, routing, the auction, settlement, and closed-loop measurement), lead data moves between participating accounts. When a supplying account ingests a lead and it is routed and sold, that lead — the fields the supplier provides and, on delivery to the winning buyer, the lead’s contact and form data — is transmitted to the purchasing account so it can receive and work the lead. In this flow the Company acts as a conduit and service provider that routes and settles the transaction on the participants’ instructions; the supplying and purchasing accounts are the controllers of the lead data they respectively supply and receive, and the purchasing account becomes a controller of the lead it buys and is responsible for its own use of it (including any subsequent contact, which remains subject to the buyer’s own consent, TCPA, and do-not-call obligations). Screening steps use one-way hashed identifiers rather than plaintext where possible (for example, ping-level match checks, deduplication, and suppression), so leads can be matched or suppressed without exchanging raw contact data until a lead is actually delivered. Closed-loop measurement records outcome and conversion signals about a sold lead; the buyer’s own contact records for that lead live in the buyer’s environment, not the Company’s.

14. Your California & other state privacy rights; data-broker status

(a) State privacy rights. Depending on your state of residence — for example under the California Consumer Privacy Act as amended by the CPRA, or comparable laws in Colorado, Virginia, Texas, and other states — you may have the right to know or access the personal information we hold about you, to correct or delete it, to obtain a portable copy, to opt out of the “sale” or “sharing” of personal information and of targeted advertising, to limit the use of sensitive personal information, and to be free from discrimination for exercising these rights. We do not sell personal information and do not use it for cross-context behavioral advertising. To exercise a right regarding account data, contact us at the address below; an authorized agent may submit a request with proof of authorization, and we will verify your identity before responding. For consumer or signer data we process on an integrating business’s behalf, please direct your request to that business as the controller; we will assist it as its service provider.

(b) Data-broker status. Because the marketplace Services route leads between businesses, the Company or a participating account may, for some transactions, meet the definition of a “data broker” under certain state laws (such as California’s Delete Act and the data-broker registration laws of Texas, Oregon, and Vermont). Where a registration or consumer deletion mechanism (such as California’s Delete Request and Opt-out Platform, “DROP”) applies to us, we will register and honor deletion requests as required, and we operate a hashed suppression mechanism so a deletion or opt-out can be enforced across future processing without our retaining the underlying plaintext. Each participating account remains responsible for its own data-broker registration and compliance obligations where they apply to that account. See also our Data Deletion instructions.

15. Changes to this Policy

We may update this Policy from time to time. Material changes take effect when posted with an updated date; your continued use of the Services constitutes acceptance of the revised Policy.

16. Contact

Questions about this Privacy Policy may be directed to support@leadopera.com.

LeadOpera™ is a trademark of LeadOpera LLC, a Colorado limited liability company. Its products and services — including LeadProof™ and TermsProof™ — are proprietary and operated through their independent websites; LeadProof™ and TermsProof™ are trademarks of LeadOpera LLC. Unauthorized use of these marks is strictly prohibited. The certification method used by LeadOpera’s products is patent pending. A certificate is a tamper-evident technical record — not a determination of legal or regulatory compliance, validity, or enforceability, and not legal advice.

TrustedForm, Jornaya, Boberdoo, Phonexa, LeadsPedia, Google, Meta, Facebook, Instagram, Twilio, DigiCert, and Sectigo are trademarks of their respective owners; their mention describes interoperability only and does not imply any affiliation with, endorsement by, or sponsorship from those companies.

Press, partnership, and general inquiries: inquiry@leadopera.com

© 2026 LeadOpera LLC. All rights reserved.