Back to website

Last updated:

Privacy policy

How GridLead handles account information, business search results and the data you choose to export.

Who is responsible

GridLead (gridlead.app) is an online service for finding business contacts. The operator of GridLead (“we”) is responsible for the processing described in this policy. For privacy questions or requests about your data, write to [email protected] or use the contact form; we reply from that address. If the operator’s name and postal address are available, they are listed below and in the legal notice.

Scope and responsibilities

This policy covers GridLead accounts, searches, exports, CRM connections and support messages. The site owner administers the service and receives privacy requests through the contact form. You are responsible for how you use business contacts after collecting or exporting them, including any legal requirements for outreach. This policy is not permission to send unsolicited marketing.

Account and Google sign-in

We store your name, email, account ID, plan, role, account status, creation date and saved searches. Passwords are stored as salted scrypt hashes, not readable passwords. Google sign-in requests only openid, email and profile: we use your Google identifier, verified email and name to create or identify the account. We do not request access to Gmail, Drive or Calendar, and do not store Google access or refresh tokens. Signing out ends the current session; it does not delete the account.

Why data is used

Account data supports authentication, access control and plan limits. Search data supports collection, history, filtering and exports. Support submissions contain your name, reply email, subject, message and language; the owner can add internal handling notes and a status. They are not published or treated as marketing consent. Security controls use hashed client-address keys to limit repeated requests. Where applicable, service delivery relies on performance of the service agreement, abuse prevention on legitimate security interests, and the contact form on the consent requested there. Any legal obligations or rights depend on applicable law. The current service does not collect payment card details. To understand where visitors come from and to detect abuse, the server logs each page view: time, page, referring site and campaign tags, IP address, country determined by our network provider Cloudflare, browser user agent and, if you are signed in, your account. This relies on our legitimate interest in running and securing the site; no cookies or tracking scripts are used for it. IP addresses are erased after 30 days and visit records are deleted after 180 days; only the site owner can see them.

Private support tickets

Registered users can create private support tickets. We store the account association, subject, messages, author role, status and timestamps. Only the account holder and site owner can access the conversation through the service. Owner replies and status changes are recorded in the administration audit log without copying message text into that log. Closing a ticket does not delete its history. Tickets currently have no automatic deletion schedule; data requests can be submitted through the contact form. Replies are available in your account, not automatically sent by email. Do not include passwords or API tokens.

CRM connections and exports

Connecting HubSpot or Pipedrive stores account metadata and a server-encrypted access token (AES-256-GCM). The token is used to check the connection and perform exports you initiate. Selected business data is sent to the connected CRM; HubSpot exports can create or reuse email contacts and associate them with companies. We retain transfer identifiers and status to avoid duplicate exports. Disconnecting removes the saved credential but retains connection metadata and transfer history; it does not delete CRM records. Excel and CSV files are downloaded to your device. You control these files and CRM copies, which are not erased by deleting a GridLead search.

Cookies and browser storage

gridlead.session is an essential sign-in cookie valid for 30 days. gridlead.google is a temporary Google sign-in cookie valid for 10 minutes and removed after the callback. Both are HttpOnly and Secure on HTTPS. gridlead.language stores your language preference for one year; language, currency and sidebar preferences also use localStorage until you clear them. A temporary gridlead.crmExport.<jobId> entry lets an export resume its progress display. The current app code includes no advertising or cross-site analytics trackers. Clearing the session cookie signs you out; blocking essential cookies can prevent Google sign-in. Browser settings let you inspect and clear this storage.

Recipients and international processing

The owner can access account, search and support information to administer the service. Hosting and network infrastructure process requests and may keep technical logs such as IP addresses, request times and URLs. Google handles Google sign-in. Map tiles are loaded directly by your browser from VersaTiles (tiles.versatiles.org), which receives your IP address and the map area requested. Connected CRMs receive the data you export. These providers have their own privacy practices and may process information in other countries. We do not promise a particular data-residency region or that third-party copies follow GridLead retention rules.

Retention and deletion

Account records, search results and support messages currently have no general automatic deletion schedule. Removing a search from the workspace hides it and stops active work; it is a soft deletion, not immediate permanent removal from the database. Session validity is 30 days and the temporary Google cookie lasts 10 minutes; these are not retention periods for all account data. You can request account or data deletion through the contact form. Requests are reviewed, including any necessary security or legal retention. Disconnecting CRM removes its stored credential, not exported records. Browser storage and downloaded files must also be cleared on your device.

Security

Controls include hashed passwords, hashed session tokens, encrypted CRM credentials, owner-only administration and request limits. Production sign-in cookies use HTTPS security settings. No online service can guarantee complete security. Do not share credentials or include them in support messages. If you suspect unauthorized access, sign out, change your password where applicable, revoke affected CRM tokens with the provider and contact us.

Your choices and requests

Depending on applicable law, you may have rights to access, correct, delete or receive your personal data, restrict processing, object to certain uses or withdraw consent. Withdrawal does not invalidate earlier lawful processing. Use the contact form and state which account or data your request concerns; we may ask for proportionate identity verification. Requests are handled within applicable legal deadlines. You may also complain to the competent data protection authority where that right applies. This policy may change as features or processing practices change; the date above identifies this version.