Privacy Policy
How HeyLead collects, uses, and protects personal data across our Website, agency services, Insights, Auto Blogger, free tools, and the HeyLead Ads API on Meta.
Last updated: September 10, 2026
HeyLead LLC ("HeyLead", "we", "us", or "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you visit https://heylead.com, use our free tools, engage our marketing services, use products such as HeyLead Insights and HeyLead Auto Blogger, or when we access Meta (Facebook and Instagram) advertising tools through the HeyLead Ads API. Please read it together with our Terms and Cookie Policy.
This page is HeyLead's own Privacy Policy. To ask us to delete your data, see How to request deletion of your data or email martin@heylead.com.
Who we are and how to reach us
This Privacy Policy is issued by HeyLead LLC ("HeyLead", "we", "us", or "our"), a company offering digital marketing services and software products.
- Legal entity: HeyLead LLC
- Website: https://heylead.com and regional variants (including /uk/, /au/, /sg/, /es/)
- Privacy contact email: martin@heylead.com
- Phone: Chat with us on WhatsApp
Where a local representative or data protection officer is required by law, we will provide those details on request at the contact address above.
Scope of this policy and roles (controller vs processor)
This Privacy Policy describes how we process personal data when you:
- Visit or use the Website, free tools, blogs, or contact forms
- Engage HeyLead for agency services (SEO, SEM, Meta Ads, web design, analytics, CRM integration, audits, consulting)
- Subscribe to or use HeyLead Insights (session recordings, heatmaps, behaviour analytics)
- Subscribe to or use HeyLead Auto Blogger (research-to-publish content system)
- Communicate with us by email, phone, WhatsApp, chat, or scheduling tools
- Connect a Meta (Facebook / Instagram) ad account, Page, pixel, or catalog so we can run or report on advertising through the HeyLead Ads API
2.1 When HeyLead is the controller
We act as an independent controller for personal data we collect for our own business purposes, including Website analytics, marketing, sales, billing, account administration, support, and security of our systems.
2.2 When HeyLead is a processor (client products)
For certain product features, our customers ("Clients") decide what data is collected on their properties and why. In those cases:
- The Client is the controller (or equivalent) of end-user / website-visitor data
- HeyLead is a processor (or service provider) processing data on the Client's instructions
- This Policy explains product processing at a high level; the Client's own privacy notice and any data processing agreement (DPA) with HeyLead govern the Client relationship
2.3 Related documents
- Terms & Conditions - contract terms for Website and services/products
- Cookie Policy - cookies and similar technologies on the Website and product trackers
Information we collect
3.1 Information you provide to us
- Identity and contact data: name, email, phone, company, job title, region
- Business data: website URL, industry, goals, budgets, CRM or ad-account details you choose to share
- Form and enquiry content: free audit requests, contact messages, proposal answers, WhatsApp messages
- Account and billing data: plan selection, invoices, payment references (card data is typically handled by payment processors, not stored by us in full)
- Credentials and integrations you supply for services or products (for example CMS, GTM, analytics, ad platforms) - used only to deliver the engagement
- Support communications and feedback
3.2 Information collected automatically on our Website
- IP address, approximate location derived from IP, device and browser type
- Pages viewed, referrers, timestamps, session duration, clicks and scroll behaviour on our Website
- Cookie and similar identifiers (see Cookie Policy)
- Diagnostic logs, security events, and error reports from hosting and edge providers (for example Cloudflare)
3.3 Information from third parties
- Analytics and advertising platforms (for example Google, Meta) about campaign performance and conversions
- Scheduling tools (for example Calendly) when you book a call
- CRM, email, and messaging tools used to manage leads and client work
- Publicly available business information you point us to for audits or SEO work
3.4 Sensitive personal data
We do not seek to collect special-category / sensitive data (health, biometric, religious, etc.) through the Website. Please do not submit such data in forms. If a Client project requires processing of sensitive data, we will only do so under a documented lawful basis and written instructions.
Meta Platform and the HeyLead Ads API
The HeyLead Ads API is a Meta developer app used by HeyLead staff and systems to manage advertising for HeyLead and for Clients who authorize us. It is a business Marketing API integration. It is not a consumer Facebook Login app and it is not directed at people under 18.
What information we collect from Meta
When a Client (or HeyLead) connects a Meta Business, ad account, Page, Instagram account, pixel/dataset, or catalog, we may receive:
- Business and ad-account identifiers, names, status, currency, and time zone
- Campaign, ad set, and ad names, IDs, budgets, targeting summaries, creatives metadata, and delivery status
- Performance insights such as impressions, clicks, spend, conversion counts, and quality scores
- Pixel / dataset IDs, event names, and match-quality summaries
- Page and Instagram account IDs needed to publish or attach ads
- Access tokens and system-user credentials stored as secrets so our systems can call Meta's APIs
We do not request consumer Facebook profile data (such as a person's friends list or timeline) through this app. Conversion events we send to Meta (Conversions API) use hashed identifiers such as email or name, plus click IDs, as described in Meta's Conversions API documentation.
How we use that information and why
- To create, update, pause, and report on Meta ad campaigns the Client has asked us to run
- To send conversion events (including hashed customer data) so Meta can measure and optimize those campaigns
- To diagnose tracking, creative, and delivery issues
- To provide dashboards, alerts, and recommendations to the Client and to HeyLead operators
- To secure the integration, prevent abuse, and keep audit logs
We process this advertising data to perform the Client contract (or HeyLead's own marketing). We do not sell Meta Platform data. We do not use it to build independent consumer profiles for sale to third parties. We do not use it to advertise unrelated products to people whose data we received only through a Client's ad account, except as needed to deliver that Client's campaigns on Meta.
Clients can revoke HeyLead's access at any time in Meta Business Settings by removing the system user, partner, or ad-account assignment.
HeyLead Insights (behaviour analytics product)
HeyLead Insights helps Clients understand on-page behaviour through features that may include session replay, click heatmaps, scroll and pageview context, multi-site dashboards, and related tools. Clients install a lightweight JavaScript snippet or Google Tag Manager tag on their own websites.
4.1 Data that may be collected via the Insights tracker
Depending on configuration and page content, the tracker and related backend may process:
- Technical and usage data: URLs, page titles, referrers, device type, browser, viewport, timestamps, session IDs, site IDs
- Interaction data: clicks, taps, mouse movements, scroll depth, form focus/blur, navigation path
- Session replay / DOM snapshots: reconstructed views of pages as experienced during a visit, which may incidentally include text users type into forms if not excluded
- Aggregated heatmap and engagement metrics derived from the above
- Operator account data: team logins, roles, ingest keys, site registration details
4.2 Personal data in session recordings
Session recordings and form interactions can include personal data if website visitors enter it (names, emails, phone numbers, messages). Clients should:
- Configure masking/blocking of sensitive fields where available
- Avoid collecting payment card data, passwords, government IDs, or health data through unmasked fields
- Disclose Insights (or equivalent analytics) in the Client privacy notice and cookie banner where required
- Obtain consent where ePrivacy / PECR / similar rules require it before non-essential tracking
4.3 Our role and instructions
- Client determines purposes (CRO, UX diagnosis, marketing optimisation) and installs the tracker
- HeyLead processes Insights data to operate the product, store sessions/heatmaps, display dashboards, maintain multi-site isolation, provide support, and secure the service
- We do not sell end-user Insights data and do not use Client end-user recordings to advertise HeyLead to those end users
- Staff access is limited to operations, support, and security needs under confidentiality obligations
4.4 Multi-site isolation and keys
Clients may register multiple properties. Site IDs and ingest keys are designed so data remains isolated per property. Clients must keep keys confidential and rotate them if compromised.
HeyLead Auto Blogger (content system product)
HeyLead Auto Blogger is a multi-client content system that may research, outline, draft, enrich, validate, and publish posts (for example via WordPress REST or static/Git publish paths).
5.1 Data processed
- Client playbook data: brand voice, keywords, seed topics, testimonials, industries, regions, publish rules
- Content artifacts: briefs, drafts, media metadata, quality grades, validation results, publish logs
- Integration credentials and endpoints you provide (CMS tokens, repository access) - used only for authorized publish paths
- Operator accounts, spend/run metrics, digests, and support tickets
- Third-party model/API processing: draft generation or enrichment may involve AI providers acting as subprocessors under our instructions
5.2 AI processing notice
Content generation may use third-party large language models or related APIs. Inputs (briefs, playbook snippets, research context) and outputs may be processed by those providers as needed to deliver the feature. We select providers and contractual settings intended for business use; Clients should not include secrets, card numbers, or unnecessary personal data of third parties in prompts or seed materials.
5.3 Client content responsibility
Clients remain responsible for reviewing published content for accuracy, legal compliance (advertising, regulated claims, IP), and brand safety, especially in human-review or auto-publish modes.
Free tools, APIs, audits, and lead capture
We offer free tools and forms (for example free audits, content briefs, analyzers, contact forms, URL checkers) and related APIs. When you use them we may process:
- Submitted URLs, form fields, and tool inputs
- Results generated for you and technical logs needed to run the tool
- Contact details if you request follow-up or book a call
Tool outputs are informational only. We may store submissions to improve tools, prevent abuse, and (where permitted) follow up about HeyLead services. Lead data may be stored in our CRM / email systems.
How we use information
Depending on context, we use personal data to:
- Provide, operate, secure, and improve the Website, free tools, agency services, Insights, and Auto Blogger
- Respond to enquiries, deliver audits/consultations, and manage client projects
- Create and manage accounts, billing, and support
- Send service messages (transactional, security, product notices)
- Send marketing communications where allowed (with opt-out)
- Measure marketing performance and Website analytics
- Detect, investigate, and prevent fraud, abuse, and security incidents
- Comply with law, enforce agreements, and protect rights
- As a processor: process Client product data only for documented product purposes and Client instructions
We do not sell personal information for money. Where "sale" or "sharing" is defined broadly under US state law (for example for cross-context behavioural advertising), we address that in Section 14 and provide opt-out rights.
Legal bases for processing (GDPR / UK GDPR)
Where EU/EEA or UK data protection law applies, we rely on one or more of:
- Contract - to provide services or products you request
- Legitimate interests - for example securing systems, improving products, B2B marketing to corporate contacts, analytics of our own Website (balanced against your rights)
- Consent - where required (for example certain cookies, email marketing, non-essential tracking)
- Legal obligation - tax, accounting, responding to lawful requests
You may withdraw consent at any time without affecting prior lawful processing. For processor activities, the Client is responsible for establishing a lawful basis for end-user data.
Sharing of information and subprocessors
We share personal data only as needed with:
- Infrastructure and security: hosting, CDN, DNS, WAF (for example Cloudflare), cloud storage
- Analytics and ads: Google Analytics / Ads, Meta, LinkedIn or similar tags used on our Website
- Communications and CRM: email delivery (for example Brevo or similar), CRM, WhatsApp Business, scheduling (for example Calendly)
- AI and content tooling: model/API providers used for Auto Blogger or internal tooling under contract
- Payment processors if you pay online
- Professional advisors (legal, accounting) under confidentiality
- Authorities when required by law or to protect rights and safety
- Business transfers in a merger, acquisition, or asset sale (with notice where required)
We require service providers that process personal data for us to implement appropriate security and to use data only for our instructions (or as controllers for their own limited purposes, such as fraud prevention, as disclosed in their policies).
A current list of key subprocessors is available on request at martin@heylead.com.
International data transfers
We operate internationally and may process data in the United States and other countries where our providers run infrastructure. Where we transfer personal data from the EEA/UK/Switzerland to countries without an adequacy decision, we use appropriate safeguards such as Standard Contractual Clauses (and UK addenda where applicable), plus supplementary measures as needed.
Clients using Insights or Auto Blogger acknowledge that product data may be processed in these locations to deliver the service.
Data retention
We keep personal data only as long as reasonably necessary for the purposes above, including:
- Sales and enquiry leads: typically up to 24 months after last meaningful contact, unless you become a client or ask us to delete sooner
- Client project records: for the engagement plus a retention period for accounting, claims, and legal requirements (often up to 7 years for financial records)
- Insights session/heatmap data: retained per product configuration and Client settings; default operational windows may range from weeks to months unless a longer archive is agreed
- Auto Blogger artifacts: while the account is active and for a limited period after cancellation to allow export/support, then deleted or anonymised
- Security logs: typically 30-180 days unless needed longer for investigations
- Website analytics: per tool defaults and our cookie settings
When retention ends, we delete or irreversibly anonymise data where feasible.
Security
We implement technical and organisational measures appropriate to risk, which may include TLS in transit, access controls, least-privilege staff access, logging, network protections via our edge/hosting providers, and multi-site isolation design for Insights.
No method of transmission or storage is 100% secure. You are responsible for safeguarding credentials, ingest keys, CMS tokens, and devices you use to access our products. Notify us promptly of suspected unauthorised access.
How to request deletion of your data
You can ask HeyLead to delete personal data we hold about you. This is the data-deletion process for our Website, products, and the HeyLead Ads API on Meta.
- Email martin@heylead.com with the subject line Delete my data.
- Tell us the email address, name, company, website, or Meta ad account you used so we can find the records.
- We will confirm receipt and complete deletion or irreversible anonymisation within 30 days, unless we must keep a limited copy for tax, legal, security, or dispute purposes.
You can also use the contact form. If you connected a Facebook or Instagram account or a Meta ad account to HeyLead, you may additionally remove the HeyLead Ads API app under Facebook Settings > Apps and Websites, and you (or the Business admin) can revoke HeyLead's system user in Meta Business Settings.
For visitor data collected on a Client website through HeyLead Insights, contact that Client first. We will help the Client as their processor.
Privacy contact (plain text for crawlers and people): martin@heylead.com · Chat with us on WhatsApp · HeyLead LLC
Your privacy rights
Depending on your location, you may have rights to:
- Access a copy of personal data we hold about you
- Correct inaccurate data
- Delete data (subject to legal exceptions)
- Restrict or object to certain processing
- Data portability
- Withdraw consent
- Lodge a complaint with a supervisory authority
To exercise rights for data HeyLead controls, email martin@heylead.com with enough detail to verify your request. We may need to confirm identity. Deletion steps are in How to request deletion of your data.
For data collected on a Client website via Insights (or similar), contact that Client first. We will assist Clients as a processor in responding to valid requests.
US state privacy notices (including California)
If you are a resident of California or another US state with comprehensive privacy law (for example CPRA, CPA, CTDPA, VCDPA, and similar), this section applies in addition to the rest of this Policy.
14.1 Categories of personal information
We may collect identifiers, commercial information, internet/network activity, professional information, and inferences used for lead qualification - as described in Section 3. We do not intentionally collect sensitive personal information for Website browsing.
14.2 Purposes and sources
Sources and purposes are described in Sections 3 and 7. We do not use or disclose sensitive personal information for purposes that require a right to limit under CPRA beyond what is necessary to provide services.
14.3 Sale / sharing
We do not sell personal information for money. Our Website may use advertising/analytics cookies that some laws treat as "sharing" or "targeted advertising." You can opt out via cookie controls, browser settings, Global Privacy Control (GPC) signals where we are able to honour them, and industry tools linked in the Cookie Policy. Email martin@heylead.com with the subject "Do Not Sell or Share" for additional assistance.
14.4 Your rights
- Know / access categories and specific pieces of personal information
- Delete
- Correct
- Opt out of sale/share/targeted advertising
- Non-discrimination for exercising rights
Authorized agents may submit requests with proof of authority. We aim to respond within statutory timelines.
UK, Australia, Singapore, and other regions
- UK: UK GDPR and Data Protection Act 2018 principles apply as described above; complaints may be directed to the ICO.
- Australia: We handle personal information in line with the Privacy Act 1988 (Cth) and Australian Privacy Principles where applicable. You may request access/correction via our contact email.
- Singapore: Where the PDPA applies, we process personal data with consent or other PDPA bases (for example legitimate interests / contractual necessity analogues as allowed), and maintain reasonable security.
- Regional site paths (for example /uk/, /au/, /sg/, /es/) do not change the core processing described here unless a local addendum is published.
Marketing communications
We may send B2B marketing emails or messages about HeyLead services where permitted. You can unsubscribe via the link in emails or by contacting us. Transactional and service messages (billing, security, product notices) are not marketing and may continue as needed to operate the service.
Children's privacy
Our Website, services, and products are directed to businesses and adults. We do not knowingly collect personal data from children under 16 (or higher age required locally). If you believe a child provided data, contact us and we will delete it where appropriate.
Third-party websites and Client sites
Our Website may link to third-party sites. Their privacy practices are their own. Client websites that install Insights or publish Auto Blogger content are controlled by those Clients - review the Client's privacy notice for end-user practices on those sites.
Changes to this Privacy Policy
We may update this Policy to reflect product, legal, or operational changes. We will post the revised version with a new "Last updated" date. Material changes may be highlighted on the Website or communicated to account holders. Continued use after the effective date constitutes acceptance where permitted by law.
Contact us
Questions, requests, or complaints about privacy:
HeyLead LLC
Email: martin@heylead.com
Phone: Chat with us on WhatsApp
Web: heylead.com/contact-us
Please include "Privacy Request" in the subject line and describe your request clearly.
Have questions about your privacy?
We are happy to explain how we handle data for the Website, Insights, Auto Blogger, and client work.