Draft. These terms are being reviewed and the operating entity is not yet finalised. Anything in square brackets is unresolved.
Privacy Policy
Last updated 8 September 2026
Who we are
LeadInBio is operated by [operating entity — sole trader or registered company], based in Israel. Questions about this policy or your data go to [contact email].
The short version
We hold two different kinds of information, and the distinction matters for your rights:
- Your account. Your email, your pages, the images you upload. We decide how this is handled, so we are the controller.
- Leads submitted through your page. These belong to you. We store and forward them on your instructions, so you are the controller and we are the processor. We do not use anyone's leads for our own purposes, and we never sell data.
What we collect
If you have an account
- Email address, and a password hash — never the password itself.
- The content of your pages: titles, links, text, and any photo you upload.
- Private settings you enter, such as a webhook URL or notification address. These are stored separately from your public page and are never served to visitors.
When someone visits a published page
- A record that the page was viewed, which link was tapped, and whether a form was seen or submitted.
- The referring website and the browser's user-agent string, used to show the page owner where visits came from and roughly what device was used.
- Any utm_ parameters in the URL, so the owner can tell which campaign produced an enquiry.
We do not set cookies on published pages and we do not build a profile of visitors across pages or sites. Analytics are counted, not tracked to an individual.
If you submit a form on someone's page
Whatever you type into it — typically a name, email, phone number or message — is stored for, and sent to, the owner of that page. That person decides what happens to it next. Contact them directly to correct or delete it; you can also contact us and we will pass the request on.
Cookies
Published bio pages set no cookies at all. If that ever changes — for example if we add optional third-party tracking that an owner can switch on — the page will ask visitors for consent first, and this policy will be updated before it ships.
On the dashboard we use a single essential cookie to keep you signed in. It is required for the service to function and cannot be turned off while you are logged in.
Our own marketing pages use privacy-friendly analytics that do not use cookies and do not identify individuals. These are not loaded on published bio pages.
Who else processes your data
We use a small number of providers to run the service:
- Supabase — database, authentication and file storage. Data is held in [Supabase region].
- Vercel — application hosting and delivery.
- Resend — sends transactional email, such as lead notifications and password resets.
- [Payment provider, once billing is enabled — if this is a merchant of record such as Lemon Squeezy or Paddle, they are the seller of record and handle payment data; we never see card details.]
If you configure a webhook, we send lead data to the URL you provide. What happens to it there is governed by that service's terms, not ours.
How long we keep it
- Account data: until you delete your account.
- Pages, leads and analytics: until you delete them, or until your account is deleted. Deleting a page deletes its blocks, leads and analytics with it, and this cannot be undone.
- Waitlist emails: until we launch or you ask to be removed, whichever comes first.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your data, to object to processing, or to complain to a regulator. In Israel that is the Privacy Protection Authority; in the EU or UK it is your national data protection authority.
You can export your leads to CSV from the dashboard at any time without asking us. For anything else, write to [contact email] and we will respond within 30 days.
Security
Data is isolated per account at the database level, so one customer's pages, leads and files cannot be read by another. All traffic is served over HTTPS. Private settings such as webhook URLs are held in a separate table that public page requests have no access to.
No system is perfectly secure. If we discover a breach affecting your data, we will tell you and the relevant regulator as required by law.
Changes
If we make a material change we will update the date at the top and, for anything significant, email account holders. Continuing to use LeadInBio after a change means you accept the updated policy.