Privacy Policy
Last updated: September 23, 2026
This page explains what we (B2BLeads — “we”, “us”, “our”) collect about you when you use our website, API, and MCP server (the “Service”), why we collect it, and what control you have over it.
One distinction worth making up front: this policy is about data about you, our user. It’s separate from the business lead data (company records, contact details) you search for and export through the Service — that’s Content, and it’s covered by our Terms of Use, not this page.
What we collect
Directly from you, when you sign up or reach out:
- Account details: name, email, and a hashed (never plaintext) password — or, if you sign in with Google or connect a CRM, whatever identifier and profile info that provider hands us.
- Billing details: our payment provider handles your card; we only see the resulting transaction history and billing status, never the full card number.
- What you build in the app: saved lists, notes, tags, search history, and any files you upload (e.g. for CRM enrichment).
- Support conversations: whatever you tell us when you email or message support.
- Referral activity: the referral code you pick and which signups it brought in.
Automatically, as you use the Service:
- Request logs: IP address, browser/client details, timestamps, and which endpoints you hit.
- Usage patterns: API call volume, which plan features you use, rate-limit consumption, and rough timezone/country inferred from access.
- Device details: device type, OS, and browser.
- Approximate location: derived from IP address, mainly to flag suspicious logins.
- Cookies / local storage: just the essentials — staying signed in, remembering your language. No ad trackers.
And from elsewhere: fraud-prevention signals from security partners, and whatever data you actively choose to sync when you connect a CRM or webhook through Integrations.
Why we collect it
- To run the Service — authenticate you, process your searches, keep the API responsive.
- To bill you correctly and manage your subscription or credit balance.
- To remember your preferences, like your selected display language.
- To email you things you need: account activation, password resets, usage alerts, and — only if you’ve opted in — product updates.
- To credit referral rewards when someone you referred signs up and pays.
- To catch fraud, credential sharing, and abuse of API keys or rate limits before they hurt other users.
- To meet legal obligations and protect our users, ourselves, or others when we need to.
We sometimes aggregate or strip identifying details from this data to study usage patterns or improve our search and enrichment pipeline — once it’s de-identified, we don’t try to re-identify it. We do not use your account activity, saved lists, or search queries to train any third-party AI model, and we never sell your personal data.
Who else sees it
- Infrastructure vendors: hosting, cloud storage, email delivery, analytics, and payment processing providers — bound by confidentiality, and limited to what they need to do their job for us.
- Acquirers, if we’re ever acquired: in a merger, acquisition, or asset sale, your data can move to the successor as part of that deal.
- Authorities, when the law requires it: or when we believe it’s necessary to enforce our terms, investigate fraud, or protect someone’s safety.
- Your team’s admins: if you’re part of a team account, owners/admins on that team can see team usage and manage membership and billing.
- Integrations you turn on yourself: whatever you sync to a connected CRM or webhook goes to that provider, under their own privacy policy — not ours.
We also share aggregated, de-identified data for the same purposes listed above — it just can’t be traced back to you.
How long we keep it
Roughly: as long as your account is active, plus a reasonable window afterward for things like disputes, security, and legal record-keeping. In practice:
- You can delete individual leads, lists, or API keys, or your whole account, right from the dashboard — deleted data is gone from our systems within 30 days, subject to the exceptions below.
- Billing and transaction records stick around longer for accounting, tax, and dispute-resolution purposes, even after account deletion.
- If we’re legally required to keep something (e.g. a valid legal request), we hold onto it for as long as that obligation lasts.
- We keep a record that you asked us to delete your data, so we can prove we did it.
Your controls
- Edit your name and profile from Account Settings.
- Revoke API keys or disconnect CRM integrations whenever you want.
- Delete individual leads, lists, or search history — or your whole account.
- Pick your display language from the language switcher; it’s remembered locally in your browser.
- Unsubscribe from marketing email via the link in any such message (transactional emails, like password resets, can’t be turned off while your account is active).
Your rights
Depending on where you’re located, you can typically:
- Ask what personal data we hold about you and how we use it.
- Have it corrected if it’s wrong.
- Have it deleted.
- Get a portable copy of it.
- Object to or ask us to restrict certain processing, including anything based on legitimate interest or direct marketing.
- Withdraw consent, wherever we relied on your consent in the first place.
- Complain to your local data protection authority.
Most of this you can do yourself (see Your controls above). For anything else, email [email protected] and we’ll handle it in line with the law that applies to you.
Not for kids
The Service is a business tool, not something aimed at children. We don’t knowingly collect personal data from anyone under 16. If you think a child’s data ended up with us, tell us at [email protected] and we’ll look into it and delete it if appropriate.
How we protect it
Encrypted connections (TLS), hashed passwords, access controls on our systems — standard stuff, taken seriously. That said, no system connected to the internet is 100% unbreakable, and we can’t promise perfect security, so be thoughtful about what you send us.
Our legal basis for processing (GDPR and similar laws)
- Performing our contract with you: running your searches, billing your plan, keeping your account working.
- Our legitimate interests: improving the Service, personalizing your experience, stopping fraud and abuse, keeping our systems secure — weighed against your rights.
- Legal obligations: retaining financial records, responding to valid legal demands.
- Your consent: wherever we specifically ask for it, such as opt-in marketing email — withdrawable anytime.
Data crossing borders
We may process your data on servers outside your own country, including infrastructure run by our hosting and cloud providers. Protection standards differ from place to place, but wherever your data ends up, we apply the same safeguards described here, and we use appropriate legal transfer mechanisms (such as Standard Contractual Clauses) where the law requires them. Using the Service means you’re fine with that.
If this policy changes
We’ll update this page when the policy changes, with a new effective date at the top. For anything material, we’ll also notify you by email or an in-app notice, unless the law demands a different kind of notice. Keep using the Service after a change takes effect, and that counts as accepting it.
Who's responsible for your data
B2BLeads is the data controller for the personal data described in this policy. Reach us using the contact details below.
Get in touch
Questions, requests, complaints — email [email protected].
See also
Our Terms of Use cover the rules of using the Service itself, including how we treat the business lead data you search for and export.