Privacy Policy
Last updated: 20 July 2026
1. Who we are
LeadScanner is operated by Philipp R. Stegmann (data controller). The full postal address and responsible-person details are listed in our Imprint.
Contact: hello@lead-scanner.com
2. Data we collect and store
- Account email address — used for magic-link authentication, billing communications, and account management.
- Scanned lead data — names, companies, titles, email addresses, phone numbers, and LinkedIn profiles collected via badge/card scanning and third-party enrichment. Stored in our EU database, isolated per account.
- Voice notes — audio recordings attached to leads (Pro plan). Stored encrypted in our database.
- Usage data — scan count, credit usage, subscription status. Used for billing and fair-use enforcement.
- Session cookie — one httpOnly, signed JWT that keeps you logged in after a magic link (90-day expiry).
- Analytics & advertising (optional, consent-based) — only if you accept the cookie banner, Google Tag Manager / Google Analytics may set analytics cookies, Google Ads and Meta (Facebook) Pixel may set advertising cookies to measure ad conversions and build audiences. Decline and none of these are loaded.
3. How we use your data
- To provide the LeadScanner service (scanning, enrichment, CRM push)
- To send you magic-link login emails
- To process your subscription and billing
- To enforce fair-use credit limits
- We do not sell your data. We never share who scanned a contact, or link a contact back to your account, with any other user — see §8 for the one narrow exception (a shared, non-attributable enrichment-result cache).
4. Data processors (sub-processors)
| Processor | Purpose | Location |
|---|---|---|
| Vercel | Application hosting, edge delivery, cookieless web analytics | EU/US |
| Tag Manager / Analytics / Ads (conversion measurement) — only with your consent | US (SCC) | |
| Meta Platforms (Facebook) | Meta Pixel (conversion measurement, ad audience) — only with your consent | US (SCC) |
| Stripe | Payment processing and subscription management | US (SCC) |
| Resend | Magic-link transactional email | US (SCC) |
| Google (Gemini API) | AI badge/card parsing — primary vision model for scan photos | US (SCC) |
| NVIDIA | AI badge/card parsing — fallback vision inference for scan photos | US (SCC) |
| OpenRouter | AI badge/card parsing — fallback vision routing for scan photos | US (SCC) |
| xAI | AI badge/card parsing — last-resort fallback for scan photos | US (SCC) |
| Explorium | Lead enrichment (email, phone, title, LinkedIn) | US (SCC) |
| Hunter.io | Email finder fallback for enrichment | EU |
| Zoho CRM | CRM push (when connected by user) | EU/US (user choice) |
| HubSpot | CRM push (when connected by user) | EU/US |
| Salesforce | CRM push (when connected by user) | US/EU |
| Pipedrive | CRM push (when connected by user) | EU/US |
US-based processors are covered by Standard Contractual Clauses (SCC) under GDPR Chapter V.
5. Your rights (GDPR)
- Right to access — export all your data as CSV from the app at any time.
- Right to erasure — delete your account and all associated data from Settings → Account.
- Right to portability — CSV export available anytime on all plans.
- Right to object / restrict processing — contact hello@lead-scanner.com.
- You may also lodge a complaint with your national data protection authority.
6. Data retention
Lead data and account data are retained for as long as your account is active. After account deletion all personal data is removed within 30 days. Billing records (Stripe) are retained for 7 years for tax/legal compliance.
7. Cookies
Essential: one signed, httpOnly session cookie keeps you logged in after a magic link (90-day expiry, or until logout). It is required for the app to function and is not used for tracking.
Analytics (optional): we use Google Tag Manager / Google Analytics and Vercel Web Analytics to understand product usage. Google analytics cookies are loaded only after you accept our cookie banner — you can decline at any time, and Vercel Web Analytics is cookieless.
Advertising (optional): we use Google Ads and the Meta (Facebook) Pixel to measure the effectiveness of our advertising campaigns (conversion tracking) and to build advertising audiences. These cookies and tracking scripts are loaded only after you accept our cookie banner and are never set if you decline. Meta acts as a joint controller for data processed through the Pixel; see Meta's Privacy Policy for details.
8. Shared enrichment cache
When enrichment (Explorium, Hunter.io, or our LinkedIn lookup) successfully finds someone's email, phone, title, or LinkedIn profile, we cache that result so that if a different LeadScanner account later scans the same person, we don't pay a data provider a second time to re-verify information we already have. This is the only case where a lookup outcome is shared across accounts.
- What is stored: the found email/phone/title/LinkedIn only. The lookup key is a one-way cryptographic hash of the person's normalized name and company — not the plaintext name, and never your account ID, team ID, or lead ID. The cache cannot be used to look up who scanned a given contact, or which contacts a given account has scanned.
- Legal basis: legitimate interest (GDPR Art. 6(1)(f)) — avoiding duplicate paid lookups of the same publicly-sourced professional contact information. We only reuse data our providers already found and verified; we don't create new categories of data about anyone.
- Retention: a cache entry expires after 180 days and is re-verified from scratch on the next lookup.
- Your right to object: if you are the person a cached entry is about (not a LeadScanner account holder), email hello@lead-scanner.com with the name and company and we will delete the cached entry.
9. Changes to this policy
We will notify you by email and update the "last updated" date above before any material changes take effect.