Privacy Policy

Last updated: August 31, 2026

How LeaderDaddy handles business and customer data
LeaderDaddy is a CRM and sales operations platform. This policy explains what data is collected, why it is used, when it is shared, and how privacy requests are handled.

1. Scope and roles

  • This policy applies to the LeaderDaddy website, CRM application, PWA experience, support channels, billing flows, and related services operated by ToolCross.
  • For account, billing, support, security, and website data, ToolCross decides how the data is processed for LeaderDaddy operations.
  • For lead, customer, activity, communication, and team data uploaded or entered by a workspace, the workspace owner controls the business purpose of that data. LeaderDaddy processes it to provide the service.
  • Workspace owners are responsible for giving their own leads, customers, prospects, and team members any notices or choices required by applicable law.

2. Information we collect

  • Account and workspace data such as name, username, email, phone number, role, company or business details, preferred locale, subscription status, and authentication details.
  • CRM data such as leads, contact details, addresses, companies, products, deal values, statuses, assignments, follow-up dates, notes, activities, timelines, reports, and imports created by authorized users.
  • Communication and integration data such as WhatsApp account configuration, Facebook Page, Instagram professional account, and Threads profile connection details, encrypted OAuth credentials, template records, post, comment, Direct Message, reply and message metadata, broadcast recipient details, notification delivery state, email support details, and contact form submissions.
  • Billing and wallet data such as subscription plan, recharge records, invoices or payment references, wallet balance, transaction logs, payment identifiers, and tax or compliance details. Full card or UPI credentials are handled by the payment provider, not stored by LeaderDaddy.
  • Technical data such as IP address, device and browser information, session metadata, logs, diagnostics, PWA cache state, push subscription tokens, cookies or similar identifiers, and usage events needed for security and reliability.
  • AI feature data such as prompts, lead context, conversation context, and generated suggestions when an authorized user requests AI-assisted sales guidance.

3. How we use information

  • To create and secure accounts, authenticate users, enforce role-based access, manage sessions, and keep workspaces separated.
  • To provide CRM features including lead capture, assignment, follow-up scheduling, activity history, reporting, notifications, WhatsApp workflows, social publishing, social inbox conversations, billing, wallet usage, and admin settings.
  • To provide support, respond to contact requests, send operational messages, process subscription and payment actions, and maintain legal or accounting records.
  • To detect abuse, prevent fraud, troubleshoot errors, improve performance, maintain audit logs, back up data, and protect the platform.
  • To generate AI-assisted recommendations only when the feature is enabled and requested, with outputs treated as suggestions that users must review before acting.

4. Lawful basis, consent, and customer responsibilities

  • LeaderDaddy processes personal data where it is necessary to provide the service, comply with law, protect the platform, support legitimate business operations, or where consent or another lawful basis applies.
  • Customers must ensure they have a valid basis to upload, import, contact, message, or otherwise process leads and customers through LeaderDaddy.
  • Customers using WhatsApp, email, broadcasts, imports, or AI features are responsible for lawful collection, consent, opt-out handling, message template approval, and compliance with applicable telecom, marketing, platform, and data-protection rules.
  • If a person withdraws consent or asks to stop communication, the customer must honor that request in the workspace and in any connected communication channel.

5. Sharing and service providers

  • LeaderDaddy does not sell personal data.
  • Data may be shared with trusted providers that help operate the service, such as hosting, database, analytics, email, notification, payment, WhatsApp, AI, mapping, security, and support providers.
  • Payment processing may be handled by Razorpay or another configured payment provider. WhatsApp, Facebook, Instagram, and Threads workflows may involve Meta and related messaging infrastructure. AI features may involve the configured AI provider.
  • Data may be disclosed when required by law, court order, regulator request, platform policy enforcement, fraud prevention, security investigation, business transfer, or to protect legal rights.

6. Security

  • LeaderDaddy uses reasonable technical and organizational safeguards such as authentication, role-based access, session controls, audit-oriented logs, input validation, scoped workspace access, and secure operational practices.
  • Sensitive flows such as payments, WhatsApp credentials, uploaded assets, sessions, and notification delivery are handled with restricted access and provider-specific safeguards where applicable.
  • No internet service can guarantee absolute security. Customers must use strong credentials, limit user access, keep devices secure, and promptly report suspected misuse.

7. Retention, deletion, and backups

  • LeaderDaddy keeps account, CRM, billing, support, and log data for as long as needed to provide the service, meet legal obligations, resolve disputes, prevent abuse, and maintain business records.
  • Workspace owners may request deletion or export of workspace data, subject to identity verification, legal retention duties, active disputes, backup cycles, and technical constraints.
  • Disconnecting a Meta social integration removes LeaderDaddy's stored OAuth credentials for that connection and stops using that connection for publishing, inbox replies, and webhook matching. If a Meta user removes LeaderDaddy from Meta settings and requests deletion, LeaderDaddy processes Meta's signed callback and deletes matching WhatsApp Embedded Signup and Meta social connection records when an identifier match exists.
  • Deleted data may remain in backups or logs for a limited period until routine retention and recovery processes remove it.

8. Rights and choices

  • Depending on applicable law, individuals may request access, correction, deletion, withdrawal of consent, grievance review, or information about how their personal data is handled.
  • Requests about lead or customer records controlled by a LeaderDaddy customer should normally be sent to that customer first, because the customer controls the business relationship and purpose of processing.
  • Account users can update certain profile, locale, notification, and workspace settings inside the application where available.
  • Users can disconnect supported integrations inside LeaderDaddy where available and may also remove LeaderDaddy access from their Meta account settings, Apps and Websites, or Business Integrations page. Meta may then send LeaderDaddy a deletion or deauthorization callback for the connected Meta user.
  • To exercise privacy rights directly with LeaderDaddy, contact contact@toolcross.com. We may need to verify identity and workspace authority before acting.

9. International processing and third-party services

  • LeaderDaddy and its providers may process or store data in India or other countries where the relevant infrastructure, providers, or support teams operate.
  • Third-party services connected by a customer, such as payment gateways, WhatsApp, Facebook, Instagram, Threads, email, AI, or maps, process data under their own terms and privacy notices in addition to LeaderDaddy policies.
  • Customers should review third-party terms before enabling integrations or sending personal data through them.

10. Children, changes, and contact

  • LeaderDaddy is intended for business users and is not directed to children. Customers should not knowingly upload children's personal data unless they have a lawful basis and required permissions.
  • We may update this policy when the product, providers, law, or security practices change. The updated date will show when the page was last revised.
  • For privacy questions, grievance requests, data access, correction, deletion, or security concerns, contact us at contact@toolcross.com.

11. Google Workspace and Gmail marketplace lead data

  • This optional feature is available only after an organization administrator chooses Connect Gmail and grants the restricted https://www.googleapis.com/auth/gmail.readonly permission. It is used only to turn supported OLX, CarWale, and Gaadi marketplace enquiries into CRM leads so authorized workspace users can action them.
  • To minimize access, LeaderDaddy checks the From, Subject, and Date headers of newly added Inbox messages first. It reads message text only when those headers identify a supported marketplace lead email. Attachments are not read or processed, and messages that do not match do not create CRM leads.
  • For a matching message with a valid Indian mobile number, LeaderDaddy stores only the parsed lead fields needed for the CRM record, such as name, email address, phone number, source, email subject, and Gmail message ID. While connected, we also retain the connected Gmail address, encrypted OAuth access and refresh tokens, Gmail message and thread identifiers, processing status, received date, and limited error information. We do not store raw email bodies or attachment content.
  • Matching lead information is visible only to authorized users in the connected workspace under LeaderDaddy access controls and may be included in configured operational lead notifications. Gmail-imported lead data is not sent to an external AI provider by the LeaderDaddy AI Sales Assistant.
  • LeaderDaddy does not use this integration to send, delete, archive, label, forward, compose, or otherwise modify Gmail messages. We do not sell Google user data, use it for advertising, data brokerage, surveillance, credit or lending decisions, or to train generalized AI or machine-learning models. We transfer Google user data only when necessary to provide or secure the user-facing CRM feature, to comply with law, or for security purposes.
  • You can disconnect Gmail from Integrations at any time. Disconnecting stops monitoring, requests revocation of the Google credentials, and deletes the stored Gmail account, tokens, watch state, and Gmail import metadata. CRM leads already created from matching emails remain workspace records until deleted through the CRM or requested from support; a non-content origin marker remains so LeaderDaddy continues to keep Gmail-imported lead data out of external AI processing.
  • LeaderDaddy's use of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

12. Meta social integrations: Facebook, Instagram, Threads, and WhatsApp

  • Meta integrations are optional and can be connected only by authorized workspace administrators. Depending on the integration enabled, LeaderDaddy may receive and store the connected Meta user identifier, selected Page or professional account identifiers, account display names, encrypted access tokens, webhook delivery metadata, posts, comments, replies, Direct Messages, and related conversation metadata needed to provide the user-facing feature.
  • LeaderDaddy uses Meta permissions only for the features shown in the product: selecting manageable Pages or professional accounts, publishing or deleting supported posts, receiving and replying to Messenger or Instagram conversations, managing supported comments or replies, and receiving Threads public reply notifications where Meta makes them available. LeaderDaddy does not use Meta data for advertising, data brokerage, surveillance, credit or lending decisions, or training generalized AI models.
  • Meta Direct Message and comment content is visible only to authorized users in the connected workspace under LeaderDaddy access controls. Threads Direct Messages are not supported by Meta's third-party API; LeaderDaddy can process Threads public reply webhooks only when the Threads app/use case, scopes, webhook fields, Advanced Access, and business-verification requirements are satisfied.
  • If you disconnect a Meta integration in LeaderDaddy, LeaderDaddy removes the stored OAuth credentials for that social connection. If you remove LeaderDaddy in Meta settings and request data deletion, Meta sends a signed request to LeaderDaddy's Data Deletion Request URL. LeaderDaddy verifies that request and deletes matching Meta connection records, then returns a status URL and confirmation code as required by Meta.
  • Existing CRM leads, activities, and conversation records created for the workspace may remain as customer-controlled business records until deleted by the workspace owner or through a verified privacy request, unless law, security, billing, dispute, or backup obligations require limited retention.
For privacy-related questions, contact contact@toolcross.com.