Privacy policyEffective July 21, 2026

How LeadLift handles business and lead data.

This policy explains what LeadLift Automations collects, how information is used, which providers help deliver the service, and the choices available to account holders and visitors.

No sale of personal informationLeadLift does not sell personal information or use it for unrelated advertising.
Purpose-limited processingInformation is used to provide, secure, improve, and support the requested service.
Human responsibilityClients control their outreach and remain responsible for lawful use of lead information.
01

Scope

This policy applies to leadliftauto.com, LeadLift workspaces, the public LiftOff AI demo, free pilots, paid services, support communications, and information processed by LeadLift on behalf of a client. A separate signed agreement may add requirements for a particular client.

02

Information collected

LeadLift may collect contact details, business profile information, account and plan details, service areas, workflow settings, support requests, lead-source configuration, lead records submitted by a client, message drafts, approval decisions, usage and credit records, public-source references, and billing status. Payment card numbers are collected and processed by Stripe rather than stored by LeadLift.

Technical information may include browser type, device type, approximate network location, timestamps, requested pages, security events, and diagnostic information needed to operate and protect the service.

03

How information is used

Information is used to create and secure accounts, provide pilots and paid services, organize leads, generate and review drafts, perform requested research, manage credits and subscriptions, answer support requests, prevent abuse, troubleshoot problems, maintain records, improve reliability, and comply with applicable obligations.

LeadLift does not sell personal information, rent client lead lists, or use client lead data to advertise unrelated products.

04

Accounts, authentication, and device preferences

Clerk handles account authentication, password processing, verification, and session management. LeadLift receives account identifiers and profile details needed to operate the workspace but does not receive readable passwords. Theme choices, demo limits, and other device preferences may be stored locally in the browser.

Account holders are responsible for protecting access to their email and devices, using accurate account information, and promptly reporting suspected unauthorized access.

05

LiftOff AI, prompts, and images

When LiftOff AI is used, the prompt, selected task, business context, limited conversation history, and any attached image may be sent to OpenAI to produce a response. OpenAI states that API content is not used to train its models by default. Under default API controls, content may appear in abuse-monitoring logs for up to 30 days, or longer when required by law. Certain API features may retain application state as described by the provider.

AI output can be incomplete, outdated, or wrong. Users must review customer-facing drafts and important facts. Do not upload passwords, payment cards, identity documents, sensitive health information, confidential records that are unnecessary for the task, or images the user is not authorized to share.

06

Web research and Opportunity Finder

At a user's request, LiftOff AI or Opportunity Finder may search or analyze public websites, business listings, permit or project information, public requests, and other publicly available sources. LeadLift may store source URLs, search criteria, match notes, timestamps, and review status.

A public match is not a verified customer, guaranteed lead, endorsement, or promise of demand. Clients must verify source terms, accuracy, contact permissions, and outreach requirements before acting.

07

Connected inboxes and services

If a client chooses to connect Gmail or another service, LeadLift requests only the permissions shown during authorization and uses authorized data to provide the selected workflow, such as identifying possible lead messages, preparing drafts, or recording status. LeadLift does not send messages automatically unless an authorized user has enabled and approved an applicable playbook.

Connections may be revoked through the provider or LeadLift settings. Revoking access stops new retrieval but may not automatically delete records already required for service, security, accounting, or legal purposes.

08

Service providers and other disclosures

LeadLift may share information with providers that support hosting, security, authentication, AI processing, scheduling, payments, email, analytics, and customer support. Current providers may include OpenAI, Clerk, Stripe, Cal.com, Google Workspace, and website hosting or security vendors. Providers process information under their own terms and privacy practices.

Information may also be disclosed when reasonably necessary to comply with law, protect users or the service, investigate fraud or abuse, enforce agreements, respond to a valid legal request, or complete a business transfer. LeadLift does not disclose client data to a buyer without appropriate confidentiality and notice measures where required.

09

Cookies, local storage, and analytics

The site may use essential cookies or browser storage for sessions, security, theme preferences, demo limits, and feature settings. Basic analytics may count visits and product actions to understand reliability and use. LeadLift does not use this information to create cross-site advertising profiles.

The public AI demo may use a random browser identifier and temporary rate-limit signals to enforce its message limit and reduce abuse.

10

Retention and deletion

LeadLift keeps information for as long as reasonably needed to provide the service, maintain account and billing records, resolve disputes, enforce agreements, protect the service, meet legal obligations, and preserve approved client workflows. Different record types may have different retention periods.

Deletion requests are evaluated against these needs. Deleting an account may not immediately remove provider records, backups, payment records, security logs, or information that LeadLift must retain.

11

Security and incident response

LeadLift uses reasonable administrative and technical measures designed for the nature of the service, including limited access, provider-managed authentication, encrypted connections, secret management, and abuse controls. No internet service, account, or transmission method is completely secure.

If LeadLift learns of a security incident affecting information for which notice is legally required, LeadLift will evaluate the incident and provide notice as required by applicable law. Clients should promptly report suspected account compromise through the contact page.

12

Your choices and privacy requests

You may request access, correction, deletion, or a copy of information associated with your account by emailing hello@leadliftauto.com. LeadLift may verify identity and authority before acting. Some requests may be limited by security, fraud prevention, contractual, accounting, or legal requirements.

Marketing messages from LeadLift may be declined using the instructions in the message. Service, security, billing, and account notices may still be sent when necessary.

13

Age and authority

LeadLift is designed for businesses and is not directed to children under 13. A person creating a paid business account must be legally able to enter the agreement or act with authorization from the business and, when required, a parent or legal guardian.

14

Changes, review, and contact

LeadLift may revise this policy when features, providers, data practices, security requirements, or applicable rules change. The effective date will be updated. Material changes may also be communicated through the service or account email when appropriate.

Questions and requests may be sent to hello@leadliftauto.com. The mailing address or legal entity details, when established and required for a specific notice, will be provided in the applicable client agreement.