This Privacy Policy describes how LeadMagnet OS ("we," "us," or "our") collects, uses, and shares information in connection with the LeadMagnet OS platform (the "Service"). It applies to two distinct groups of people, described separately below because our role toward each is different:
- Customers — agencies and their team members who sign up for and use the Service. For Customer information, we act as the data controller.
- End Leads — individuals who submit their contact details through a capture widget embedded on one of our Customers' client websites. For End Lead information, we act as a data processor / service provider on behalf of the Customer, who determines what is collected and why. If you are an End Lead and have questions about how your information is used, please contact the business whose website you submitted your information on — they control that relationship, not us.
1. Information We Collect
From Customers (agencies & team members)
- Account information: name, email address, timezone, and authentication data.
- Billing information: processed directly by our payment processor, Stripe — we do not store your full payment card number on our own servers.
- Agency and workspace information: agency name, team member roles, client domains you enter, and content you generate through the Service.
- Usage data: pages visited, features used, and actions taken within the Service, collected to operate, secure, and improve the Service.
- Support communications: messages sent through our in-app Help & Support system.
From End Leads (via embedded capture widgets)
- Information voluntarily submitted through a capture form: typically an email address, and optionally a name, phone number, and answers to any custom questions the Customer has configured.
- Technical data automatically collected at the time of submission: IP address, browser user agent, the page URL the form was submitted from, and basic interaction events (e.g. widget shown, form viewed, submitted, download clicked) used for fraud prevention, rate limiting, and to show the Customer their own conversion analytics.
2. How We Use Information
We use the information above to:
- Provide, operate, and maintain the Service, including generating and delivering lead magnet content and emails;
- Process payments and manage subscriptions;
- Communicate with Customers about their account, billing, and support requests;
- Send opt-in notifications Customers have enabled (e.g. new-lead alerts) — Customers control these preferences and can disable them at any time;
- Monitor, secure, and rate-limit the Service against abuse, fraud, and unauthorized access;
- Analyze aggregate, de-identified usage trends to improve the Service; and
- Comply with legal obligations.
We do not sell personal information, and we do not use End Lead information for our own marketing purposes — it is used solely to operate the Service on behalf of the Customer who collected it.
3. How We Share Information
We share information with the following categories of third parties, solely as needed to operate the Service:
- Infrastructure & hosting — our application hosting and database providers, which store Service data on our behalf.
- Payments — Stripe, to process subscription payments.
- Email delivery — our transactional email provider, to send lead magnet deliveries, notifications, and account emails.
- AI & search-data providers — third-party AI and keyword-research services, used to generate content and detect relevant search topics from information you or your widgets submit.
- Error monitoring — an error-tracking service that helps us detect and fix bugs, which may incidentally receive technical diagnostic data.
- CRM sync (Customer-configured) — if a Customer configures an outbound webhook to their own CRM, End Lead information they collected is sent there at the Customer's direction, not ours.
- Legal & safety — where required to comply with law, enforce our Terms, or protect the rights, property, or safety of LeadMagnet OS, our Customers, or others.
We require these providers to protect information consistently with this Policy and to use it only for the purposes we specify.
4. Cookies & Local Storage
Our dashboard uses standard authentication cookies necessary to keep you signed in. Our embeddable capture widget stores a small flag in the visitor's browser local storage to avoid showing the same capture form to someone who already submitted it — this is functional, not used for cross-site tracking or advertising.
5. Data Retention
We retain Customer account information for as long as the account is active, and for a reasonable period afterward to comply with legal, tax, and accounting obligations. End Lead information is retained for as long as the Customer's workspace and lead records exist, or until the Customer deletes it, whichever comes first. We may retain de-identified or aggregated data indefinitely.
6. Your Rights
Depending on your location, you may have rights to access, correct, delete, or export your personal information, or to object to or restrict certain processing.
- Customers can exercise these rights directly within the Service (e.g. editing your profile, deleting content) or by contacting us through the in-app Help & Support system.
- End Leads should contact the business whose website they submitted information to, since that business controls the data. If you contact us directly, we will reasonably assist by directing your request to the relevant Customer or, where appropriate, acting on it ourselves.
7. Data Security
We use industry-standard technical and organizational measures — including encryption in transit, access controls, and audit logging of administrative actions — designed to protect information against unauthorized access, alteration, disclosure, or destruction. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. International Data Transfers
We and our service providers may process and store information in the United States and other countries. Where required, we take steps intended to ensure appropriate safeguards are in place for such transfers.
9. Children's Privacy
The Service is not directed to individuals under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can take appropriate action.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email or in-app notice before taking effect. The "Last updated" date above reflects the most recent revision.
11. Contact Us
Questions about this Privacy Policy can be sent through the Help & Support form available in your dashboard once signed in, or to the contact address listed on our website.
This document is a general template and does not constitute legal advice. We recommend having it reviewed by a qualified attorney familiar with your business, the jurisdictions you operate in, and applicable privacy law (such as GDPR or CCPA) before relying on it.