Privacy Policy
Last updated: June 7, 2026
1. Who We Are
MapLeads (themapleads.com) is a data discovery platform that helps businesses find publicly available business information.
This Privacy Policy explains:
- β’What personal data we collect from YOU (our users)
- β’How we use and protect that data
- β’Your rights regarding your data
2. Data We Collect
2.1 Account Data (when you register)
- β’Full name
- β’Email address
- β’Password (encrypted with bcrypt, never stored in plain text)
- β’Account creation date and IP address
2.2 Subscription Data
- β’Plan type (Free/Pro/Agency)
- β’Subscription status
- β’Payment reference numbers (NOT full card details β handled by our payment processor)
2.3 Usage Data
- β’Search queries you enter (business type + location)
- β’Contacts you save to your account
- β’Email templates you create
- β’Campaign names and statistics (emails sent/opened counts only)
- β’Feature usage patterns
- β’Login history and IP addresses
2.4 Technical Data
- β’Browser type and version
- β’Device type and operating system
- β’Referral source (how you found us)
- β’Session duration and page views
2.5 What We Do NOT Collect
- β’Full payment card details
- β’Government ID or identity documents
- β’Biometric data of any kind
- β’Location tracking data
- β’Contents of emails you send
3. How We Use Your Data
We use your data ONLY to:
- β’β Provide and maintain the MapLeads service
- β’β Process your subscription payments
- β’β Send essential account notifications (password reset, plan changes, invoices)
- β’β Respond to your support requests
- β’β Detect and prevent platform abuse
- β’β Improve our search accuracy and features
- β’β Send product updates (you can opt out)
We NEVER:
- β’β Sell your personal data to any third party
- β’β Share your search history or saved contacts
- β’β Use your data for advertising targeting
- β’β Share your email with marketing companies
- β’β Build profiles to sell to data brokers
4. Legal Basis for Processing
For users in the European Union (GDPR), our legal bases for processing are:
Contract Performance
Processing necessary to provide the service you signed up for.
Legitimate Interests
Security monitoring, fraud prevention, and service improvement.
Consent
Marketing emails (you can withdraw consent at any time).
5. Third-Party Services
Google Places API
Purpose: Retrieve business search results
Data shared: Search queries and locations (NOT your personal details)
Privacy: policies.google.com/privacy
Payment Processor
Purpose: Payment processing (merchant of record)
Data shared: Email, billing details β we receive only transaction references
Privacy: Provided at checkout
Supabase
Purpose: Database and authentication (SOC 2 Type II certified)
Data shared: All account and usage data
Privacy: supabase.com/privacy
Anthropic Claude API
Purpose: AI email generation (optional feature)
Data shared: Business contact data you choose to generate emails for
Privacy: anthropic.com/privacy
Vercel
Purpose: Website hosting and CDN
Data shared: Server access logs, IP addresses
Privacy: vercel.com/legal/privacy-policy
6. Data Retention
- β’Active accounts: data retained for duration of account
- β’Deleted accounts: personal data permanently deleted within 30 days. Anonymized usage statistics may be retained.
- β’Payment records: retained 7 years for tax/legal compliance
7. Data Security
We protect your data using:
- β’β AES-256 encryption at rest
- β’β TLS 1.3 encryption in transit
- β’β HTTPS enforced on all connections
- β’β SMTP passwords encrypted before storage
- β’β Row-level security on all database tables
- β’β Regular security audits
- β’β Principle of least privilege access
If we experience a data breach affecting your personal data, we will notify you within 72 hours as required by applicable law.
8. Your Rights
All users
- β’Access β Request a copy of your data
- β’Correction β Fix inaccurate information
- β’Deletion β Delete your account and data
- β’Export β Download your saved contacts as CSV
- β’Opt-out β Unsubscribe from marketing emails
EU/UK users (GDPR/UK GDPR)
- β’Erasure β Right to be forgotten
- β’Restriction β Limit how we use your data
- β’Portability β Receive data in machine-readable format
- β’Object β Object to processing
- β’Automated decisions β Not subject to solely automated decision-making
9. Cookies
Essential (cannot be disabled)
- β’auth-session β Keeps you logged in
- β’csrf-token β Security protection
Preference
- β’dismissed_banners β UI state
We do NOT use advertising cookies or tracking pixels (except those you explicitly add via our Analytics settings in your account).
10. International Transfers
Your data may be processed in:
- β’United States (Supabase, Vercel, Anthropic)
- β’European Union (various)
We ensure appropriate safeguards are in place for all international transfers including Standard Contractual Clauses where required by GDPR.
11. Children's Privacy
MapLeads is not directed at children under 16 years of age. We do not knowingly collect data from minors. Contact us immediately if you believe a minor has registered.
12. Changes
We will notify you of significant changes via email with 14 days advance notice. Minor changes may be made without notice. Always check the βLast updatedβ date.
13. Chrome Extension & LinkedIn Data
MapLeads offers an optional Chrome extension (βMapLeads LinkedIn Email Finderβ) that operates on LinkedIn pages. This section explains what data the extension accesses and how it is used.
What the extension reads
When you use the extension on LinkedIn, it reads publicly visible information from LinkedIn profile pages and search results, including: full name, job title, company name, location, LinkedIn profile URL, and profile photo URL. The extension only reads data that is already visible to you on screen.
What is sent to MapLeads servers
To find an email address, the extension sends the following to our servers: name, company name, and LinkedIn profile URL. This data is used solely to perform the email lookup and is not stored permanently on our servers beyond the duration of the lookup request.
Email addresses found
Email addresses discovered through the extension are stored in your MapLeads account and associated with the corresponding lead record. You control this data and can delete it at any time from your dashboard.
Local storage
The extension uses chrome.storage.local to temporarily store your selected profiles during an active LinkedIn session. This data is stored locally on your device and is cleared when you save your selection or manually clear it. Your MapLeads API key is also stored locally to authenticate requests.
LinkedIn compliance
The extension reads only publicly visible data that is rendered in your browser. It does not bypass any LinkedIn authentication or access data you would not otherwise see. The extension never performs automated actions on your behalf β it does not send connection requests, follow profiles, send messages, or interact with LinkedIn in any way other than reading visible page content.
Data retention
Profile data temporarily processed during email lookups is not retained on our servers. Email addresses found and saved to your account are retained until you delete them.
14. Contact
Privacy questions: privacy@themapleads.com
Response time: within 30 business days. For EU users: we aim to respond within the GDPR-required 30-day period.