Privacy Policy
How LeadStream handles account, workspace, and service data.
Effective: May 26, 2026
Scope
This policy applies to LeadStream websites and the LeadStream application.
Workspace customers control the records they add to LeadStream. Users should contact their workspace admin for questions about a specific workspace invite or record.
Data
LeadStream processes account data such as name, email address, membership, authentication state, and activity needed to run the service.
Workspaces may contain property records, people, contact details, notes, campaigns, calls, SMS conversations, tasks, imports, connected Gmail account metadata, linked email thread history, and follow-up history.
When a user connects Gmail, LeadStream may process Gmail message metadata, message bodies, participants, labels, attachments metadata, and attachment bytes requested on demand so the user can use visible Gmail features inside LeadStream.
Use
LeadStream uses data to provide the application, authenticate users, deliver transactional account email, secure the service, troubleshoot issues, and maintain reliability.
LeadStream uses Google Workspace API data only for visible Gmail product features: private mailbox viewing, manual one-to-one sending and replies, owner-controlled mailbox actions, user-controlled lead linking, linked lead read-only history, sync status, and attachment access requested by the user.
LeadStream does not sell personal information.
LeadStream does not use Google Workspace API data for advertising, retargeting, creditworthiness, lending decisions, or training generalized AI or machine learning models.
Providers
LeadStream uses service providers for hosting, authentication, email delivery, calling, SMS, storage, logging, and monitoring.
Providers receive data only as needed to operate the service.
Security
LeadStream uses authenticated access, organization-scoped data, and operational safeguards.
Google OAuth tokens are stored server-side only, encrypted before persistence, and are not returned to the browser.
Google Workspace API data is transmitted over HTTPS and protected with access controls that keep unlinked Gmail mailbox data private to the connected account owner.
LeadStream keeps redacted audit records for Gmail security review and incident investigation. These records document service actions without storing Gmail subjects, bodies, recipients, attachment filenames, raw headers, OAuth tokens, token ciphertext, raw provider payloads, or authorization codes.
Users should protect their credentials and report suspected unauthorized access to their workspace admin.
Requests
Unexpected account invites can be ignored. Invite links expire automatically.
Workspace admins control workspace membership and workspace data requests.
Users can disconnect Gmail to revoke Google access, delete stored token material, stop Gmail sync, and remove unlinked private mailbox cache. Linked lead email snapshots remain CRM history unless the Gmail account owner unlinks the thread or deletes the linked snapshot.
Redacted Gmail audit records may be retained as security and compliance evidence after disconnect because they do not retain Gmail message content.
LeadStream's use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.