Privacy Policy
LeadCat is a product of Staminal Technologies Private Limited.
This Privacy Policy explains how STAMINAL TECHNOLOGIES PRIVATE LIMITED (CIN: U62013TN2023PTC165254) collects, uses, stores, and protects information when businesses use LeadCat CRM ("CRM", "Service", "we", "our", or "us").
For customer lead and enquiry data, the subscribing business normally decides why the data is collected and how it is used, and STAMINAL TECHNOLOGIES PRIVATE LIMITED processes that data to provide the CRM on the business's instructions. For CRM account, billing, service security, and platform-operation data, STAMINAL TECHNOLOGIES PRIVATE LIMITED determines the purposes described in this Policy.
1. Information We Collect
Depending on how a business uses the CRM, we may process the following information:
- Business account information such as business name, business category, owner name, email, phone number, address, plan, and paid-pilot or subscription status.
- User account information such as staff name, email, phone number, role, login status, and activity timestamps.
- Lead and enquiry information such as customer name, phone number, email, social username, source, message text, product/service interest, location, budget range, lead status, priority, notes, follow-up dates, and assigned staff.
- Social media event information received through official platform APIs and webhooks, including message/comment text, sender identifiers, page/account identifiers, timestamps, and raw event payloads needed for debugging and duplicate protection.
- Integration configuration such as connected platform name, account name, account ID, connection status, and encrypted access tokens where needed to operate integrations.
- Legal acceptance evidence such as the accepted document type, version and cryptographic hash; acceptance wording; signer and business details; authority confirmation; acceptance time; and limited request metadata such as IP address, user agent, and request ID.
- Technical information such as request timestamps, system logs, error details, and basic security/audit information required to operate and protect the Service.
2. Meta, Instagram, and Facebook Data
When a business connects Instagram or Facebook, the CRM receives only the data that the business authorizes through Meta permissions and webhooks. This may include Instagram direct messages, Instagram comments, Facebook Page messages, Facebook comments, lead identifiers, sender/page/account metadata, and related timestamps.
We use this information to create or update leads, detect duplicate events, show message history, classify enquiries, suggest human-reviewed replies, and help the business follow up with customers. We do not use Meta data for unrelated advertising, profiling, or sale to third parties.
3. How We Use Information
- To create and manage tenant-isolated business workspaces.
- To capture enquiries and convert them into CRM leads.
- To classify leads by product/service interest, lead quality, urgency, sentiment, and missing information.
- To show dashboards, source reports, product interest reports, follow-ups, and staff performance reports.
- To notify authorized business users about new leads when alert integrations are enabled.
- To maintain security, troubleshoot integration issues, prevent duplicate lead creation, and improve reliability.
4. AI Assistance and Replies
The CRM may generate lead classifications and suggested reply text to assist business users. Suggested replies are intended for review by the business before use. The CRM should not make final pricing, discount, stock, delivery, warranty, or availability commitments unless the business has explicitly configured and approved that information.
5. Data Sharing
We do not sell customer enquiry data. We may share information only in these cases:
- With authorized users of the business workspace that owns the data.
- With service providers required to host, secure, process, back up, or operate the CRM.
- With third-party platforms that the business intentionally connects, such as Meta, Telegram, or future messaging providers.
- When required by law, regulation, legal process, or to protect rights, safety, and security.
6. Security
We use HTTPS, tenant separation, role-based access control, password hashing, encrypted integration tokens, server-side access controls, and backup procedures to protect CRM data. No method of transmission or storage is completely secure, but we take reasonable steps to reduce unauthorized access and exposure.
7. Data Retention
Lead and workspace records are retained while the business account is active, unless an authorized deletion request is completed. To reduce unnecessary duplication, our standard operational schedule redacts raw social-message and webhook payloads after 30 days, old completed background-job payloads after 30 days, expired authentication secrets after 30 days, and raw billing-provider payloads after 90 days. Security and access-audit records are normally kept for 365 days, with a minimum 180-day security-log period. IP address, user-agent, and request-ID metadata attached to legal acceptance evidence is normally redacted after 365 days. The minimized acceptance record, including the signer, business, document version, document hash, acceptance wording, authority confirmation, and acceptance time, may be retained while the contract is active and afterwards where reasonably required to establish the agreement, resolve disputes, or comply with law. Contact details attached to a closed deletion request are redacted after three years, while a minimized completion record is retained to support backup-restoration controls.
A legal hold, fraud or security investigation, payment dispute, or a statutory accounting/tax obligation may require selected records to be kept longer. In that case we minimize the retained data and restrict its use to that purpose. Deleted data may remain in access-controlled backups until the applicable backup rotation expires and is not used for ordinary CRM operations.
8. User Choices and Deletion
Businesses can disconnect integrations by removing saved integration credentials from the CRM or revoking app access from the connected platform. Disconnecting revokes the CRM's stored credentials but does not by itself erase historical leads. Authorized workspace, integration, and lead deletion requests are verified, tracked to a due date, and completed only after database and stored-media deletion steps finish. Requests can be submitted using our Data Deletion Instructions.
9. Children's Data
The CRM is intended for business use and is not directed to children. Businesses should not knowingly submit data from children unless they have the required legal basis and consent.
10. Changes To This Policy
We may update this Privacy Policy as the Service evolves. The updated version will be posted on this page with a revised "Last updated" date.