Privacy Policy
Effective date: 22 February 2026
1. Introduction
Lead2GrowMax ("we", "our", or "us") is committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you use our platform.
Questions? Email us at support@lead2growmax.com.
2. Information We Collect
We collect:
- Account info: name, email, phone, business name, password (stored as a hash).
- Business profile: business type, description, branch names and codes.
- Lead data: name, phone number, optional notes from customers who scan your QR.
- WhatsApp config: your Meta Business Account ID, phone number ID, access token (encrypted).
- Usage data: pages visited, features used, timestamps for security.
- Payment data: transaction IDs and billing status only. We do not store card numbers or UPI PINs.
3. How We Use Your Data
We use your data to:
- Create and manage your account.
- Send WhatsApp lead alerts and reminders via Meta Cloud API.
- Generate and track your QR codes.
- Process subscription payments.
- Send emails (verification, password reset, receipts).
- Improve platform performance and security.
- Comply with laws.
We do NOT sell your data to anyone. We do NOT use it for targeted ads.
4. Legal Basis (GDPR)
We process data on these grounds:
- Contractual necessity: to provide services you signed up for.
- Legitimate interests: to prevent fraud and improve our platform.
- Consent: for optional marketing (you can withdraw anytime).
- Legal obligation: to comply with applicable law.
5. Data Sharing
We share data with:
- Meta Platforms, Inc. — to deliver WhatsApp messages via official Cloud API.
- Database provider — data stored in encrypted PostgreSQL.
- Payment processors (UPI gateways) — for billing.
- Legal authorities — when required by law.
6. Data Retention
Your data is kept while your account is active. After deletion, we keep it for 90 days for legal compliance, then permanently delete it.
Lead data is deleted within 30 days of account closure.
7. Cookies
We use only essential cookies for login sessions. No advertising or analytics cookies. You can disable cookies in your browser but some features may not work.
8. Data Security
We use industry-standard security:
- TLS/HTTPS encryption for all data in transit.
- AES-256 encryption for sensitive data at rest.
- Row-level security in our database.
- JWT-based authentication with short-lived tokens.
- Regular vulnerability scans.
No system is 100% secure. If a breach happens, we will notify affected users as required by law.
9. Your Rights
You may have the right to:
- Access: get a copy of your data.
- Rectification: correct inaccurate data.
- Erasure: delete your data ("right to be forgotten").
- Portability: receive data in machine-readable format.
- Objection: restrict certain processing.
To exercise these rights, email us. We respond within 30 days.
10. Children's Privacy
Our platform is not for children under 18. We do not knowingly collect data from minors.
11. Changes to This Policy
We may update this policy. When we do, we update the date at the top and notify you if changes are major.