Draft — not yet reviewed by a lawyer

This is a first-draft template, not finished legal advice. The registered entity details below are still placeholders (see brand.legalEntity in the codebase). Have this reviewed by a qualified lawyer in your jurisdiction and fill in your real company details before relying on it or presenting it to customers as final.

Privacy Policy

Last updated: 7 October 2026

1. Who this applies to

This policy covers two different groups, and treats them differently:

  • You, the TreeLead customer, and anyone you invite to your organisation — we are the data controller for your account data.
  • The businesses and contacts you discover, pitch, or invoice through the Service — for that data, you are the controller and TreeLead is a processor acting on your instructions. What you may lawfully do with their data is governed by the compliance rules in our Terms of Service, not by this policy.

2. Data we collect about you

  • Account data: name, email, password (hashed by our authentication provider, never visible to us), organisation name, and country.
  • Billing data: your subscription plan and billing history. Card details are entered directly into Stripe and never touch our servers.
  • Payment-connection data: if you connect Stripe or MercadoPago to collect from your own clients, we store the connected account identifier, not your banking details.
  • Usage data: which features you use and how often, so we can enforce plan limits and improve the Service.
  • Support communications, if you contact us.

3. Why we process it

  • To provide the Service you have signed up for (performance of our contract with you).
  • To bill you and prevent fraud (contract and legal obligation).
  • To improve the Service and understand feature usage (our legitimate interest, balanced against your privacy).
  • To comply with legal and tax obligations.
  • Where you have given it, your consent — for example, an optional language preference cookie.

4. Who we share it with

We share the minimum necessary data with the following processors so the Service can function. None of them may use your data for their own purposes.

  • Supabase — database hosting and authentication.
  • Stripe and MercadoPago — payment processing, both for your subscription and for payments you collect from your own clients.
  • Resend — delivery of outbound email you send through the Service.
  • Google Places — business discovery data (this is how prospect data enters the Service).
  • Anthropic and/or OpenAI — generation of AI proposals and website concepts. Prompts sent to these providers include the business data needed to generate relevant content, not your account credentials.
  • Sentry — error monitoring, so we can find and fix bugs.
  • Vercel — application hosting.

We do not sell your data, and we do not share it with anyone else except where required by law or with your explicit direction.

5. International transfers

Some of the processors above operate outside the UK, including in the United States. Where that happens, we rely on their own compliance with recognised transfer mechanisms (such as the EU-US Data Privacy Framework or Standard Contractual Clauses) to keep your data protected to an equivalent standard.

6. How long we keep data

We keep your account data for as long as your account is active, and for a limited period afterward to meet legal and accounting obligations, then delete or anonymise it.

Prospect and business records you add to your pipeline are retained for as long as your account is active. Records with no recorded activity are automatically eligible for deletion after a retention period your organisation controls (180 days by default) — this limits how long dormant contact data is kept, consistent with data minimisation principles.

7. Cookies

We use a small number of cookies: session cookies required for you to stay signed in, and an optional cookie that remembers your chosen display language. We do not use advertising or cross-site tracking cookies.

8. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these, contact us at hello.treelead@gmail.com. If you are in the UK or EU and are not satisfied with our response, you have the right to complain to your local data protection authority (the ICO, in the UK).

9. Security

We use industry-standard measures to protect your data, including encryption in transit, row-level access controls so one customer's data is never visible to another, and restricted internal access to production data. No system is completely secure, and we cannot guarantee absolute security.

10. Children

The Service is intended for business use by adults. We do not knowingly collect data from children.

11. Changes to this policy

We may update this policy as the Service evolves. We will give notice of material changes before they take effect.

12. Contact

Privacy questions or requests: hello.treelead@gmail.com. General support: hello.treelead@gmail.com.