Last updated: February 14, 2026 | GDPR Compliant
1. Information We Collect
We collect information necessary to provide our services:
Account Information
- Full name, email address, company name (during registration)
- Password (stored as a one-way bcrypt hash — we never store plain text passwords)
Transaction Information
- Order history, purchase amounts, payment method type
- Cryptocurrency transaction IDs (processed by NOWPayments — we do not store wallet addresses)
Usage Information
- IP address, browser type, pages visited, timestamps
- Sample download history
2. How We Use Your Information
- To process your orders and deliver purchased products
- To send order confirmations and payment notifications
- To provide customer support and respond to inquiries
- To prevent fraud and enforce our terms of service
- To enforce sample download rate limits
- To improve our website and services
We do NOT sell, rent, or share your personal information with third parties for marketing purposes.
3. Data Storage & Security
Your data is stored on secure servers with the following protections:
- 256-bit SSL/TLS encryption for all data in transit
- Bcrypt hashing for passwords (cost factor 12)
- CSRF token protection on all forms
- Prepared SQL statements to prevent injection attacks
- HTTP-only session cookies with strict mode
4. Third-Party Services
We use the following third-party services:
- NOWPayments — Cryptocurrency payment processing. See their privacy policy.
- Font Awesome — Icon library (CDN)
- Google Fonts — Typography (CDN)
5. Cookies
We use essential session cookies to maintain your login state and shopping cart. We do not use advertising cookies or third-party tracking cookies.
6. Your Rights (GDPR)
Right of Access: Request a copy of all personal data we hold about you.
Right to Rectification: Request correction of inaccurate personal data.
Right to Erasure: Request deletion of your personal data ("right to be forgotten").
Right to Data Portability: Receive your data in a machine-readable format.
Right to Restrict Processing: Request limitation of how we process your data.
Right to Object: Object to processing of your personal data.
Right to Withdraw Consent: Withdraw previously given consent at any time.
To exercise any of these rights, contact us at support@lead-mail.com or open a support ticket. We will respond within 30 days.
7. Data Retention
- Account data: Retained while your account is active. Deleted within 30 days of account deletion request.
- Order data: Retained for 7 years for legal/tax compliance.
- Support tickets: Retained for 2 years after resolution.
- Server logs: Automatically purged after 90 days.
8. Children's Privacy
Our Service is intended for business professionals aged 18 and older. We do not knowingly collect data from minors.
9. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email or website notice.
10. Contact Data Protection Officer
Email: support@lead-mail.com
Subject line: "GDPR Request" or "Data Protection Inquiry"
Response time: Within 30 calendar days