LeadOrigin CRM Privacy Policy
Last updated: July 30, 2026
LeadOrigin CRM (“LeadOrigin”, “we”, “us”) is a customer relationship management application for small sales teams, operated by LeadOrigin, LLC, 10101 Southwest Freeway, Suite #430, Houston, Texas 77074.
This policy explains what we collect when you use the CRM at app.leadorigin.com, why, and what we do with it. It covers the application only. The leadorigin.com marketing site is covered by a separate policy.
Two roles are worth separating up front:
- You, our customer — the organization and the people in it. This policy describes our handling of your data.
- Your leads and contacts — the people you track in the CRM. That information is yours. We process it on your behalf and under your instructions, and we do not use it for our own purposes.
1. Information we collect
Account information. Your name, email address, password (stored hashed, never in plain text), and profile photo. If you sign in with Google, we receive your name, email address, and profile picture from your Google account instead of a password.
Organization content. The information you and your team put into the CRM: leads, contacts, companies, deals, notes, tasks, files, message templates, and the settings that describe your organization. Anything you import is included.
Communications sent and received through the app. Emails and text messages exchanged with your contacts through LeadOrigin, including their content, recipients, timestamps, and delivery status.
Google account data. Only if you connect Gmail or Google Calendar. See Section 6, which governs that data specifically.
Billing information. Your plan, seat count, and billing history. Card details go directly to our payment processor, Stripe — we never see or store full card numbers.
Technical and usage data. IP address, browser and device type, pages visited, actions taken in the app, and error diagnostics. We use this to operate the service, investigate problems, and detect abuse.
Cookies. We use cookies that are necessary for the app to function — keeping you signed in and protecting your session. We do not use advertising or cross-site tracking cookies in the CRM.
2. How we use information
We use the information above to:
- provide the CRM and its features;
- send and receive email and text messages on your instruction;
- sync and display your email and calendar, if you connect Google;
- authenticate you and keep accounts secure;
- bill you and manage your subscription;
- provide support and respond to your requests;
- monitor reliability, diagnose faults, and prevent abuse or fraud;
- meet legal obligations.
We do not sell personal information. We do not use your organization content or your contacts’ information for advertising, and we do not share it with advertisers or data brokers.
3. How we share information
We share information only with service providers that help us run LeadOrigin, under contracts limiting them to that purpose:
| Provider | Purpose |
|---|---|
| Supabase | Database, file storage, authentication |
| Vercel | Application hosting |
| Gmail and Calendar integration, if you connect it | |
| Twilio | Sending and receiving text messages |
| Stripe | Subscription billing and payment processing |
We may also disclose information when required by law, valid legal process, or to protect the rights, safety, or property of LeadOrigin, our customers, or the public. If LeadOrigin is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction; we will give notice before your information becomes subject to a different policy.
Within your organization, your team can see the CRM records you share with them. Email conversations synced from a personal Gmail account are private to that user unless they assign the conversation to a teammate. See Section 6.
4. How we protect information
- Data is encrypted in transit with TLS and encrypted at rest by our hosting providers.
- Google refresh tokens are encrypted and held in Supabase Vault, separately from application data, and are decrypted only by the server process that needs them.
- Every record carries database-level row security scoping it to its organization, so one customer’s data is not reachable from another customer’s session.
- Access to production systems is limited to the personnel who need it to operate and support the service.
No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your data, we will notify you as required by law.
5. How long we keep information, and how to delete it
- Organization content is kept for as long as your account is active, so your team keeps its history.
- You can delete leads, contacts, tasks, and uploaded files yourself, at any time in the app. Deleted records are removed from our live systems promptly, and age out of our encrypted backups on a rolling basis within 30 days.
- You can delete your own account from Settings → General. This removes your sign-in, your connected Google account, and your private email conversations. Records you created that belong to the organization — leads, contacts, notes — stay with your team.
- An admin can close the whole organization from Settings → Organization. A closed organization is kept for 30 days, so an accidental closure can be undone, and is then permanently deleted along with everything in it. If you are the only person in an organization, deleting your account closes it the same way.
- Anything you cannot remove yourself — a specific email conversation, say — we will delete on request. Email [email protected] and we will action it within 30 days, except where we must retain records to meet a legal or tax obligation.
- Billing records are retained as long as tax and accounting law requires.
6. Google user data
LeadOrigin offers optional integrations with Gmail and Google Calendar. They are off by default, begin only when a user explicitly connects their Google account from Settings → Gmail, and can be turned off from the same screen at any time. Where this section differs from the rest of this policy, this section governs.
Permissions we request
| Permission | Why LeadOrigin needs it |
|---|---|
View your email messages and settings (gmail.readonly) | To sync the email conversations between you and your leads into your LeadOrigin inbox, so replies appear alongside the rest of that lead’s history. |
Send email on your behalf (gmail.send) | To send the emails you write in LeadOrigin — one-off replies and scheduled follow-up steps — from your own address, so your leads receive them from you rather than from a third party. |
View and edit events on all your calendars (calendar.events) | To create, update, and cancel meetings booked through your LeadOrigin booking page, including the Google Meet link and the invitation email. |
View your calendars (calendar.readonly) | To read your free/busy times so your booking page only offers slots when you are available, and never double-books you. |
We do not request permission to permanently delete your mail, to change your mailbox settings, or to reach any Google product besides Gmail and Calendar.
Signing in with “Continue with Google” is separate: it gives us only your name, email address, and profile picture, and no access to your mail or calendar.
What we access and store
- Your Google account address — so we can show which mailbox is connected and send from the right address.
- Email messages — sender, recipients, subject, date, body, and attachments of messages received in your Gmail inbox. On connecting we import the previous 30 days of inbox mail, and after that new inbox mail as it arrives. Mail you sent is skipped. Each sender becomes a conversation in your LeadOrigin inbox so a lead’s reply is never missed, which means mail from senders who are not yet leads is imported as well.
- Calendar availability — your busy blocks, used to calculate open booking slots.
- Calendar events created through LeadOrigin — identifiers for meetings we book, so we can update or cancel them later.
We do not read mail outside your inbox: archived mail, spam, and trash are not imported. We do not build advertising or marketing profiles from your mailbox.
How we use Google data
Only to provide the features you connected the integration for: showing your email conversations inside LeadOrigin and on a lead’s record; sending the emails you write or schedule, from your own address; detecting replies and bounce notices so follow-up sequences stop when someone responds and bounced addresses are suppressed; and showing availability and booking, rescheduling, or cancelling meetings.
We do not use Google user data for advertising, ad targeting, ad measurement, credit or lending decisions, or anything unrelated to the features above. We do not sell it.
How Google data is shared
Email conversations synced from your mailbox are private to you by default. A teammate can see one only if you assign that conversation to them, so they can pick up a lead’s thread while you are out. Other organization members, including administrators, cannot read your synced mail unless you assign it to them.
Outside your organization, Google user data goes only to the infrastructure providers that run LeadOrigin on our behalf — Supabase for database and storage, Vercel for hosting — under contracts limiting them to providing services to us. We do not transfer or sell Google user data to data brokers, advertising networks, information resellers, or any other third party for their own purposes.
AI and machine learning
We do not use Google user data to develop, improve, or train artificial intelligence or machine learning models. We do not transfer Google user data to any third-party AI or machine learning service, including general-purpose language model providers.
Retention and deletion of Google data
- Email and calendar data synced from your Google account is kept while your organization is active, because it forms your conversation history with each lead.
- Disconnecting from Settings → Gmail immediately revokes our access token with Google and permanently deletes the stored credentials for that mailbox. We stop accessing your Google account at that moment.
- You can also revoke our access from your Google account at https://myaccount.google.com/permissions.
- Conversations already synced remain in your organization after you disconnect, so your team does not lose past history. Deleting your account removes them, or you can ask us to remove them at [email protected].
- When an organization is closed, all data obtained from Google APIs is deleted within 30 days.
Limited Use
LeadOrigin’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. SMS and text messaging
LeadOrigin sends and receives text messages in two different situations, and they work differently.
Messages we send to you. If you give us your mobile number and agree to receive text messages, we use it only to send the messages you opted into — account updates, appointment reminders, support replies, and, where you agreed to them, promotions.
Messages you send to your contacts. When your team texts a lead through LeadOrigin, you are the sender and we are the platform delivering it on your instruction. You are responsible for having the consent needed to text that person. We keep the message content, the numbers involved, timestamps, and delivery status so the conversation appears in your organization.
Opting out. Anyone can reply STOP to any message to opt out, or HELP for help. Opt-outs are enforced automatically and immediately: the number is blocked from receiving any further message from that organization, and any follow-up sequence it was in is ended. No one in the organization can remove a number from that block list. Replying START re-subscribes. The first message a contact receives from an organization includes the business name and opt-out instructions.
Message frequency varies. Message and data rates may apply.
No mobile information will be shared with or sold to third parties or affiliates for their marketing or promotional purposes. Mobile opt-in data and consent are never shared with any third parties. Information may be shared with service providers that help us operate the platform — such as our messaging provider, Twilio — solely to deliver the service.
8. Your choices and rights
You can review and update your account information in the app, disconnect Google or other integrations at any time, export your leads, delete your own account, and — if you are an admin — close your organization. Anything you cannot do yourself, you can ask us to do.
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, to opt out of sale or sharing (we do neither), and to be free from discrimination for exercising those rights. To make a request, email [email protected]. We will verify your identity before acting and respond within the time the law allows.
If you are a contact in a customer’s CRM rather than a customer yourself, direct your request to that business — they control the record. We will help them respond.
9. International users
LeadOrigin is operated from the United States and your information is processed there. If you use the service from outside the United States, you understand your information will be transferred to and processed in the United States, where privacy laws may differ from those in your country.
10. Children
LeadOrigin is a business tool and is not directed to anyone under 18. We do not knowingly collect personal information from children.
11. Changes
We may update this policy. When we make material changes, we will update the date at the top and notify organization administrators by email or in the app before the change takes effect.
12. Contact
Questions about this policy or your data: [email protected]