This Privacy Policy explains how LeadReply (“LeadReply”, “we”, “us”, “our”) collects, uses, shares, and protects personal data when you visit leadreply.xyz, create a LeadReply account, or chat with a LeadReply widget embedded on one of our customers’ websites. It applies to the LeadReply website, dashboard, application programming interfaces, and the embeddable AI chat widget (together, the “Service”).
Please read it carefully. If anything is unclear, contact us at help@leadreply.xyz (product and support questions) or admin@leadreply.xyz (account, billing, and privacy requests, including data subject requests).
Summary in plain language
Business customers give us account, business, and billing details, plus the content they configure for their widgets.
Visitors who chat with a LeadReply widget share whatever they choose to type; we store the conversation so the business can reply to the lead.
We use a small random identifier in your browser to recognise returning visitors. We do not run advertising trackers and we do not sell personal data.
Messages are processed by an external AI provider to generate replies. We do not use conversations to train any model.
Conversations older than 90 days are automatically archived, and data is deleted after account closure or a verified deletion request.
You have rights over your data under the GDPR and Spanish data protection law.
Who is responsible for what
There are two distinct situations:
If you are a LeadReply customer (a business that creates an account): LeadReply is the data controller for your account information and usage data.
If you are a visitor chatting with a widget on someone else’s website: that website owner is the data controller of the conversation and any details you share. LeadReply processes that data on their behalf as a data processor, strictly to power the widget and deliver the captured lead to them.
If you are a visitor and want to exercise rights over a conversation you had on a specific website, please contact that website owner directly. You may also contact us; where appropriate we will forward your request to the website owner or assist them in responding.
Information we collect
Account and business information
Your name, work email address, and password (stored only as a secure hash).
Confirmation that you are 18 or older. You enter your date of birth at signup so we can check this; we don’t store the date itself.
When you accepted the Terms of Service and which versions of the Terms and this policy you accepted.
Your email preferences, including any optional emails you have unsubscribed from.
Your business name, website URL, industry, and similar profile details.
Widget configuration: colours, greeting messages, FAQ entries, AI knowledge base content, and behavioural triggers.
Conversations and leads captured on behalf of customers
Transcripts of chats between visitors and the AI assistant.
Contact details a visitor volunteers in chat, such as a name, email address, phone number, or enquiry message, which become a lead.
Delivery status of lead notification emails sent to the business.
Visitor technical data
A random visitor identifier stored in the visitor’s browser (local storage with a session-storage fallback and a first-party cookie lasting up to 400 days).
How the visit arrived: the referring page address (without its query string), UTM parameters (source, medium, campaign), the name of an ad click identifier if present (not its value), and whether the page was opened inside a social media app, used to show the business where its leads come from.
Simple page-view counts, session events, and timestamps used for the business’s visitor journey and engagement analytics.
Usage, payment, and communication data
Dashboard usage events and aggregate widget analytics (message counts, engagement rates, lead totals).
Billing status and transaction references from our payment processor. We never receive or store full card numbers.
Messages you send to support, and records of those exchanges.
What we do not do
We do not sell or rent personal data to anyone.
We do not run third-party advertising or cross-site tracking cookies on the Service or inside the widget.
We do not build advertising profiles of visitors, and we do not use conversations or knowledge base content to train any machine-learning model, ours or anyone else’s.
We do not send marketing to your website visitors. Visitors only ever hear from the businesses whose widget they chatted with.
How we use information
To provide, maintain, and secure the Service — including generating AI responses, storing conversations, and delivering leads to businesses.
To manage your account, subscriptions, and billing through our payment processor.
To send service emails you need to use your account: signup confirmations, sign-in and password reset links, payment and trial notices, and important service announcements. These can’t be turned off while you have an account.
To send optional notification emails (lead alerts, weekly summaries, and usage notices). Every one of these includes an unsubscribe link, and you can turn each type off at any time under Settings Email preferences. We honour an unsubscribe immediately.
We do not send you marketing emails unless you have separately agreed to receive them.
To provide customer support and respond to requests.
To detect, investigate, and prevent abuse, fraud, and security incidents.
To improve the Service using aggregated or de-identified statistics.
To comply with legal obligations, resolve disputes, and enforce our agreements.
Legal bases for processing (EEA and UK)
Where the GDPR applies, we rely on the following legal bases:
Performance of a contract — to provide the Service you signed up for, including storing conversations and sending lead notifications.
Legitimate interests — to secure our systems, prevent abuse, remember visitor preferences through functional storage, and improve the Service, always balanced against your rights and expectations.
Consent — where you actively provide contact details in a chat, or where local law requires consent for storage technologies.
Legal obligations — to keep billing records and comply with tax, commercial, and consumer-protection law.
Cookies and browser storage
The widget uses only first-party, strictly functional browser storage. No advertising or analytics networks are involved.
Visitor identifier — a random ID kept in local storage (with a cookie fallback of up to 400 days) so a returning visitor can be recognised by the business and their journey analysed.
Conversation reference — stored locally so a visitor can resume a recent conversation instead of starting over.
Page-view counters — lightweight counters used to trigger widget behaviour sensibly (for example, not opening instantly on every page view).
Note for business customers: because the widget runs on your website, you remain responsible for disclosing these technologies in your own privacy policy and for obtaining any consents required in your jurisdiction. See our privacy-policy setup guide for a checklist and wording you can adapt for your website.
AI processing
When a visitor sends a message, we transmit the conversation together with the business’s configured knowledge base, FAQs, and persona instructions to our AI inference provider (currently accessed via OpenRouter), which forwards the request to a large language model provider, solely to generate the assistant’s reply. The reply is returned to the visitor and stored with the conversation.
We do not use conversations, knowledge base entries, or visitor contact details to train any model. The AI provider processes data under its own published terms, available at openrouter.ai. Businesses that prefer to limit AI processing should contact us before enabling the assistant.
How we share information
We share personal data only with the categories of recipients listed below, and only as needed to operate the Service. We never sell personal data.
Vercel — web hosting and content delivery for the website, dashboard, and APIs.
Stripe — payment processing and subscription management. Card details go directly to Stripe and are not stored by us.
Resend — delivery of transactional email (confirmations, lead notifications, digests).
OpenRouter and underlying model providers — AI inference to generate widget replies.
Professional advisers and authorities — where reasonably required for legal compliance, dispute resolution, or the establishment, exercise, or defence of legal claims.
Some of these providers process data outside the European Economic Area. Where that happens, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and, where available, adequacy decisions. A current list of sub-processors and a pre-signed Data Processing Addendum are available on request at admin@leadreply.xyz.
Data retention
Conversations and leads — retained while the related business account is active. Conversations older than 90 days are automatically archived by a background job; archived conversations remain retrievable by the business but are flagged inactive. On a verified deletion request or account closure, they are deleted within 30 days.
Account and configuration data — retained for the life of the account, then deleted within 30 days of closure, except where we must keep records longer.
Billing records — invoices and transaction references are kept as long as required by Spanish commercial and tax law (ordinarily up to six years).
Visitor identifiers — up to 400 days, or until the visitor clears their browser storage.
Backups — encrypted rolling backups may retain residual copies for a limited additional period until rotation completes; backups are progressively overwritten and are not used to restore deleted user data on request.
Your rights
Under the GDPR and Spanish Organic Law 3/2018 (LOPDGDD), you have the right to:
Access the personal data we hold about you and receive a copy;
Rectify inaccurate data or complete incomplete data;
Erase your data (the “right to be forgotten”);
Restrict or object to processing;
Data portability, where technically applicable;
Withdraw consent at any time, without affecting prior lawful processing;
Lodge a complaint with a supervisory authority — in Spain, the Agencia Española de Protección de Datos (www.aepd.es), or the authority of your habitual residence.
To exercise any right, email admin@leadreply.xyz from the address associated with your account (or tell us which website and conversation the request concerns if you were a visitor). We respond within one month of receiving a verified request, extendable by two further months for unusually complex cases, which we will explain to you.
Security
We protect personal data with encryption in transit (TLS) and at rest through our infrastructure providers, role-scoped database keys, least-privilege access for staff and automated jobs, secret management for all credentials, and continuous monitoring of background jobs and error rates. No system is perfectly secure; if a personal data breach affecting your rights occurs, we will notify affected customers and, where required, the relevant supervisory authority without undue delay.
Children
The Service is intended for businesses, and accounts are only available to people aged 18 or over; we check this at signup. We do not knowingly collect personal data from children under 14, the minimum age set by Spanish law (or the higher minimum age of your jurisdiction). If you believe a child has provided us personal data, contact us and we will delete it promptly.
Changes to this policy
We may update this Privacy Policy as the Service evolves. The “Last updated” date above always reflects the current version. For material changes that affect your rights, we will additionally notify account holders by email or in-app notice a reasonable time before the changes take effect.