Summary
- We do not own or maintain a proprietary database of business contacts. Search and reveal requests are relayed to licensed providers in real time; we return results through the Service rather than selling access to a standing directory.
- We process professional information about people in a business context: name, role, employer and, once verified, a work email.
- We never collect or sell phone numbers, home addresses or personal (non-work) email addresses.
- Anyone can remove themselves at /opt-out. Suppression applies to every customer, within minutes.
- We do not sell personal information for money. We do not use customer data to train generalised AI models.
Who we are
Boolean and Bean Pty Ltd, doing business as "Leadscart" ("we", "us" or "our") operates the Service, from Melbourne, Victoria, Australia. The Service is the website at leadscart.io, the Leadscart application, the REST API and the MCP server.
We do not compile or sell a contact database of our own. When you search or reveal a person, we query licensed third-party providers on your behalf and present the response. We may store results you save in your workspace, short-lived caches for performance, suppression records, and operational logs — but we are not a data broker holding a directory for general resale.
For professional contact data we process to produce search results and enrichment, we act as a controller. For data our customers upload or create in their workspace (for example lists, notes and suppression entries), we act as a processor on the customer's behalf. Customers may use results only for internal B2B prospecting unless we have agreed separate commercial terms in writing; they may not resell or redistribute our output without that agreement (see our terms of service).
Scope
This privacy policy describes how we collect, use, disclose and otherwise process personal information through the Service and related marketing activities. It applies to visitors, account holders and individuals whose professional information appears in our results. If you use the Service on behalf of an organisation, your organisation may have its own policies governing the data you upload.
Information we collect
Information you provide
- Account and contact data: name, email address, workspace name, team membership and communications when you contact us.
- Authentication data: when you sign in with Google, we receive your email address and basic profile information from Google as permitted by your account settings.
- Workspace content: ideal customer profiles, lists, notes, CSV uploads for enrichment, API key labels and suppression entries you add.
- Payment data: billing details are collected and processed directly by Stripe. We receive transaction identifiers, subscription status and invoice metadata, not full card numbers.
- Opt-out requests: a LinkedIn profile URL and/or work email you submit on our opt-out page. We store a one-way hash of email addresses for suppression, not the raw address.
Information from third-party sources
Contact and company fields shown in the Service are sourced from licensed providers at the time of your request. We do not claim ownership of that underlying data and do not offer it as a downloadable database independent of the Service.
- Licensed data providers: professional profile and company data (name, title, seniority, employer, company size, industry, location at country or city level, public LinkedIn profile URL), retrieved live when you search or reveal.
- Email verification: a work email is returned with the date our data provider last verified it. We do not run checks of our own and never send email to the person to verify an address.
Information collected automatically
- Device and usage data: browser type, operating system, pages viewed, features used, timestamps, referring URL and general location inferred from IP address (city or region level).
- Security data: salted hashes of IP addresses for rate limiting; authentication session identifiers.
- Analytics events: when PostHog is enabled, page views and button clicks on the public site (counted without cookies or a persistent identifier) and product events for signed-in use, under strict event schemas; we do not send contact data or message content to analytics.
We do not intentionally collect sensitive personal information or information about children.
Cookies and tracking technologies
We and our service providers use cookies and similar technologies to operate the Service, keep you signed in, remember preferences and (when enabled) understand product usage.
You can control cookies through your browser settings. Blocking essential cookies may prevent you from signing in. We do not respond to “Do Not Track” signals. We do not use cookies for cross-site interest-based advertising.
How we use information
We use personal information to:
- provide, operate, secure and maintain the Service;
- authenticate users, manage workspaces and process subscriptions;
- search for professionals, verify emails, enrich CSV files and honour suppression;
- enforce fair use, rate limits and fraud prevention;
- communicate with you about the Service, including security alerts and support;
- analyse usage to improve the Service (analytics events only; no sale of personal information);
- comply with law, respond to lawful requests and protect our rights;
- create aggregated or de-identified data that cannot reasonably identify you.
We use AI models to map natural-language ICP descriptions to search filters. Customer prompts and workspace content sent to AI providers are used only to deliver the Service, not to train generalised models, under our agreements with those providers.
How we share information
We may share personal information with:
- Service providers listed under Subprocessors, who process data on our behalf under data processing agreements;
- Other users in your workspace when you invite team members;
- Customers who export or view results that include your professional information (see People in our results);
- Professional advisers (lawyers, auditors, insurers) where necessary;
- Authorities when required by law or to protect rights, safety and security;
- Successors in connection with a merger, acquisition or sale of assets.
We do not sell personal information for money and do not share personal information for cross-context behavioural advertising. We do not license our output to customers for resale; any redistribution requires separate commercial terms with us (see our terms of service).
Retention
- Search results that no customer saves are not kept: provider responses sit in a cache for up to 10 minutes (search pages) or 24 hours (individual records) and then expire.
- Leads a customer saves to a List remain in that customer's workspace until they delete them or close their account.
- Public demo runs expire after 30 days.
- Suppression records are kept indefinitely, because deleting them would allow a person to reappear.
- Account, billing and ledger records are kept as long as required for tax, accounting and legal obligations.
- Analytics data is retained according to our analytics provider's settings, typically up to 12 months.
If you appear in our results
You may appear in a customer's search results if your professional profile matches the filters they use — for example title, employer, industry, location or company size.
We do not keep a record of you by default. A search result comes from our data provider at the moment a customer searches and is held only in a short-lived cache (search pages for up to 10 minutes, individual records for up to 24 hours) so that paging back and forth does not repeat the request; after that it is gone. We keep a record about you only if a customer acts on it:
- if a customer saves you to a List: name, title, seniority, employer and company details, and your public LinkedIn profile URL, kept in that customer's workspace until they delete the lead or close their account;
- if a customer reveals your work email: the address, but only once it has been verified as deliverable, plus the verification result and date;
- never phone numbers, personal email addresses, home addresses or special category data.
Suppression and opt-out
Use the opt-out form with your LinkedIn profile URL, your work email, or both. No account is needed and we show the same confirmation whether or not we hold data about you. Within minutes you are excluded from all future searches, enrichment and exports, for every customer, including through the API and MCP server.
Opt-out stops future processing. For erasure of anything a customer has saved about you, or to ask what we hold, email contact@leadscart.io. Data a customer has already exported is under their control; we will tell you which customers exported it where the law gives you that right.
Customer accounts
When you sign up we process your account email, name, workspace details, API key metadata (we store only a hash of each key), usage and credit ledger, and payment records from Stripe. The free credit grant is once per person; we store a hash of your email address to prevent repeat grants. Product analytics identify you only once you are signed in; before that, visits are counted without cookies.
Subprocessors
We use these service providers to run Leadscart. Each is bound by a data processing agreement or equivalent contractual protections.
International transfers
We are based in Melbourne, Australia. Some subprocessors store or process data outside your country, including in the United States and the European Union. Where personal information is transferred from the UK or EEA to countries without an adequacy decision, we rely on Standard Contractual Clauses and supplementary measures, or another lawful transfer mechanism. Where Australian Privacy Principle 8 applies, we take reasonable steps to ensure overseas recipients handle personal information consistently with the Australian Privacy Principles.
Your rights
Depending on where you live, you may have the right to:
- know whether we process your data and get a copy (access);
- correct inaccurate data (rectification);
- have your data deleted (erasure);
- object to processing based on legitimate interests, including for direct marketing — we always honour marketing objections;
- restrict processing and receive your data in a portable format;
- withdraw consent where processing is based on consent;
- complain to your data protection authority.
To exercise these rights, email contact@leadscart.io. We respond within one month where required by law. We may ask for information to confirm your identity. For the fastest removal from future results, use /opt-out.
Notice to Australian users
We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You can ask for access to the personal information we hold about you, or ask us to correct it, by emailing contact@leadscart.io. If you are unhappy with how we handled a privacy question, tell us first and we will respond within 30 days; you can then complain to the Office of the Australian Information Commissioner (oaic.gov.au). Marketing email we send is subject to the Spam Act 2003 (Cth), and every message carries an unsubscribe link.
U.S. state privacy rights
Residents of California, Colorado, Connecticut, Virginia and other states with comprehensive privacy laws may have additional rights, including the right to know what personal information we collect, to delete or correct it, and to opt out of the sale or sharing of personal information.
- We do not sell personal information for money. We do not share personal information for cross-context behavioural advertising.
- Categories collected (last 12 months): identifiers (name, email, account IDs); commercial information (subscription and credit usage); internet or network activity (usage logs, analytics events); professional information (for people in results).
- Business purposes: providing the Service, security, analytics, compliance and customer support, as described in this policy.
- Shine the Light (California): California residents may request information about disclosures to third parties for their own direct marketing purposes by emailing contact@leadscart.io with “Shine the Light Request” in the subject line.
Notice to European users
This section applies if you are in the United Kingdom or European Economic Area. References to “personal information” in this policy include “personal data” as defined in the GDPR and UK GDPR.
Legal bases
We rely on the following legal bases:
- Contract: processing needed to provide the Service to customers (account management, billing, API access).
- Legitimate interests (Article 6(1)(f)): for professional contact data in our results — ours in operating a B2B prospecting service, and our customers' in reaching professionals about relevant products. We balance these interests by limiting data to professional information, excluding phone numbers and personal contact details, and making opt-out immediate and global.
- Legitimate interests: for security, fraud prevention, product improvement and analytics (where not based on consent).
- Consent: where required for optional analytics cookies or marketing communications you have opted into.
- Legal obligation: where we must retain or disclose data to comply with law.
Automated decision-making
Search filter matching and ICP-to-filter mapping involve automated processing, but they do not produce legal or similarly significant effects on individuals. Customers decide whether and how to contact anyone.
Complaints
You may lodge a complaint with your local supervisory authority. In the UK, this is the Information Commissioner's Office (ico.org.uk). Our EU representative, if required, will be listed here once appointed.
Security
We employ technical, organisational and physical safeguards designed to protect personal information, including encryption in transit and at rest, row-level security for tenant isolation, hashed API keys, and salted hashing of IP addresses used for rate limiting. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
Children
The Service is not intended for anyone under 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, contact us and we will delete it as required by law.
Changes
We may update this policy from time to time. If we make material changes, we will post the updated policy on this page and update the date above. Where required by law, we will provide additional notice.
This policy was adapted from templates made publicly available by General Legal, PC under CC0. They are provided for reference and do not create an attorney-client relationship with General Legal or with us.
Contact
Privacy questions and requests: contact@leadscart.io. To remove yourself right away, use the opt-out form.