LeadCat CRM

Privacy Policy

Last updated: August 13, 2026

Version 1.1

LeadCat is a product of Staminal Technologies Private Limited.

This Privacy Policy explains how STAMINAL TECHNOLOGIES PRIVATE LIMITED (CIN: U62013TN2023PTC165254) collects, uses, stores, and protects information when businesses use LeadCat CRM ("CRM", "Service", "we", "our", or "us").

The CRM is built for businesses that want to capture customer enquiries from Instagram, Facebook, YouTube, website, walk-in, phone, referral, manual entry, and imported lead sources into one follow-up dashboard.

For customer lead and enquiry data, the subscribing business normally decides why the data is collected and how it is used, and STAMINAL TECHNOLOGIES PRIVATE LIMITED processes that data to provide the CRM on the business's instructions. For CRM account, billing, service security, and platform-operation data, STAMINAL TECHNOLOGIES PRIVATE LIMITED determines the purposes described in this Policy.

1. Information We Collect

Depending on how a business uses the CRM, we may process the following information:

2. Meta, Instagram, and Facebook Data

When a business connects Instagram or Facebook, the CRM receives only the data that the business authorizes through Meta permissions and webhooks. This may include Instagram direct messages, Instagram comments, Facebook Page messages, Facebook comments, lead identifiers, sender/page/account metadata, and related timestamps.

We use this information to create or update leads, detect duplicate events, show message history, classify enquiries, suggest human-reviewed replies, and help the business follow up with customers. We do not use Meta data for unrelated advertising, profiling, or sale to third parties.

3. How We Use Information

4. AI Assistance and Replies

The CRM may generate lead classifications and suggested reply text to assist business users. Suggested replies are intended for review by the business before use. The CRM should not make final pricing, discount, stock, delivery, warranty, or availability commitments unless the business has explicitly configured and approved that information.

5. Data Sharing

We do not sell customer enquiry data. We may share information only in these cases:

6. Security

We use HTTPS, tenant separation, role-based access control, password hashing, encrypted integration tokens, server-side access controls, and backup procedures to protect CRM data. No method of transmission or storage is completely secure, but we take reasonable steps to reduce unauthorized access and exposure.

7. Data Retention

Lead and workspace records are retained while the business account is active, unless an authorized deletion request is completed. To reduce unnecessary duplication, our standard operational schedule redacts raw social-message and webhook payloads after 30 days, old completed background-job payloads after 30 days, expired authentication secrets after 30 days, and raw billing-provider payloads after 90 days. Security and access-audit records are normally kept for 365 days, with a minimum 180-day security-log period. IP address, user-agent, and request-ID metadata attached to legal acceptance evidence is normally redacted after 365 days. The minimized acceptance record, including the signer, business, document version, document hash, acceptance wording, authority confirmation, and acceptance time, may be retained while the contract is active and afterwards where reasonably required to establish the agreement, resolve disputes, or comply with law. Contact details attached to a closed deletion request are redacted after three years, while a minimized completion record is retained to support backup-restoration controls.

A legal hold, fraud or security investigation, payment dispute, or a statutory accounting/tax obligation may require selected records to be kept longer. In that case we minimize the retained data and restrict its use to that purpose. Deleted data may remain in access-controlled backups until the applicable backup rotation expires and is not used for ordinary CRM operations.

8. User Choices and Deletion

Businesses can disconnect integrations by removing saved integration credentials from the CRM or revoking app access from the connected platform. Disconnecting revokes the CRM's stored credentials but does not by itself erase historical leads. Authorized workspace, integration, and lead deletion requests are verified, tracked to a due date, and completed only after database and stored-media deletion steps finish. Requests can be submitted using our Data Deletion Instructions.

9. Children's Data

The CRM is intended for business use and is not directed to children. Businesses should not knowingly submit data from children unless they have the required legal basis and consent.

10. Changes To This Policy

We may update this Privacy Policy as the Service evolves. The updated version will be posted on this page with a revised "Last updated" date.