Privacy Policy
Last updated: September 22, 2026
This policy explains what LeadFlow collects and why, who processes it with us, and when it is deleted. Provider: ANWAR AWAD — [email protected]
1. What we keep about the office
The office's name, domain, language, time zone and currency; users' names, emails and languages, with passwords stored hashed, never as text; sign-in sessions; and the subscription status. Card details never reach us: Paddle handles them.
2. Leads' data
When someone fills in an office's form we keep what they wrote: name, phone, email if given, city, what they are looking for and their budget, the page language, the time of consent, and a hashed fingerprint of the IP address to prevent abuse — not the address itself. The office is the controller of this data; we process it on the office's behalf as processor.
3. Why we process it
To run the service: showing leads to the office, ranking and matching them, and sending their email notifications; protecting forms from abuse; and billing. No advertising, no selling of data, no tracking across other sites.
4. Who processes it with us
Hetzner (server hosting, Germany) · Neon (database) · Cloudflare (domain and connection encryption) · Resend (email delivery) · Paddle (payment, invoice and tax). We update this list before adding any new processor.
5. Cookies
The dashboard uses a session cookie needed to sign in and a cookie for the light or dark theme preference. There are no advertising or analytics cookies in the dashboard or on landing pages.
6. How long we keep it
Data is kept for as long as the account exists. When the office owner requests deletion, a 14-day undo period follows, after which the office's and its leads' data is permanently deleted. Paddle keeps payment records under its own legal obligations.
7. Your rights
You may ask to access, correct, delete or port your data under the Turkish KVKK and the EU GDPR. A lead first contacts the office whose form they filled in; they can also write to us at [email protected] and we pass the request to the office.
8. Security
Connections are encrypted (HTTPS), each office's data is isolated from the others in the database, passwords are hashed, and password-reset and invitation codes are not stored as text.
9. Changes
We email office owners before any material change to this policy.