Privacy policy
⚠️ Drafted for a sole proprietor who both sells datasets and handles buyer data. Review with counsel before launch, particularly section 2.
Who we are
The data controller is REPLACE_LEGAL_NAME, an individual trading as Lead Huntr, at REPLACE_STREET, REPLACE_CITY, REPLACE_STATE REPLACE_PIN, India. For any privacy question or request, email buy@leadhuntr.shop.
We handle personal data in two distinct roles, and they work differently. This policy covers both.
1. Data about you, our customer
When you buy a bundle, request a sample, or send a custom-list request, we handle:
- Your email address, to deliver your file, answer support, and honour the guarantee. Basis: performance of our contract with you.
- Your order record, held by Polar as merchant of record and visible to us. Basis: contract, and our record-keeping obligations.
- What you told us in a custom request. Basis: our legitimate interest in replying to you.
- Server and rate-limit logs, including IP address, kept briefly to stop the forms being abused. Basis: our legitimate interest in site security.
- Searches that returned nothing, stored as the typed words and a count of how often they were asked, so we know which list to build next. No IP address, cookie, account, or session is stored alongside them, and they are not linked to you. Basis: our legitimate interest in knowing what our customers want.
We never see or store your card details, as Polar handles payment end to end. We do not sell customer data, and we never put a buyer into any dataset we sell.
2. The data in our datasets
We compile and sell business-contact datasets. Where a record identifies a person, usually a work name, role, and work email at a company, that person is a data subject and we are the controller of that record until it is sold.
What the records contain: company name, website, sector, and business contact details in a professional capacity. We focus on role-based business contacts, not personal or consumer data.
Where it comes from: publicly and commercially available business sources, including company websites, public exhibitor and directory listings, and public technology signals. We do not collect it from the individual directly, which is precisely why this section exists: it is the notice required by GDPR Art. 14.
Lawful basis: legitimate interest in business-to-business communication (Art. 6(1)(f)). We have weighed that interest against the rights of the people in the data, kept what we hold to a professional context, and we operate the suppression process described below.
Who receives it: customers who buy the relevant bundle, under a licence requiring lawful outreach with a working opt-out. Once a customer sends their own campaign, they become the controller for it.
Fuller detail on lawful basis and sender obligations is on the Compliance & GDPR page.
3. Your rights
Whether you are a customer or someone appearing in a dataset, you can ask us for a copy of what we hold about you, or ask us to correct it, erase it, restrict it, object to our use of it, or send it to you in a portable form.
The right to object is absolute for direct marketing. If you tell us you do not want to be in our data, we weigh it against nothing: we erase the record and add it to our suppression list so it stays out of future deliveries. Email buy@leadhuntr.shop and we will action it free of charge, normally within 30 days.
We cannot recall a file already delivered to a customer, so erasure covers our copy and everything we ship from that point on. Customers are contractually required to honour opt-outs in their own campaigns.
4. Who we share data with
We use these providers to run the service. Each handles only what its job needs.
- Polar: Payment processing, tax, merchant of record. (United States)
- Resend: Sending delivery and support email. (United States)
- Cloudflare R2: Storing the data files you purchase. (Global)
- InMotion Hosting: Website hosting and server request logs. (United States)
- Upstash: Rate limiting the sample and custom-request forms. (United States)
- Microsoft Clarity: Website analytics, heatmaps and session replay on public pages. (United States)
We share personal data with nobody else, except where the law requires it. Polar additionally acts as its own controller for payment and tax purposes, under its privacy policy.
5. International transfers
We operate from India, and the providers above are largely US-based or global, so personal data is transferred outside the UK and EEA. Those transfers rely on the providers' Standard Contractual Clauses and equivalent safeguards.
6. How long we keep things
Customer email and order records are kept while you might still need support or a re-send, and after that for as long as tax and accounting rules require. Dataset records are kept while commercially current and refreshed on a rolling basis. Server logs are kept briefly. Suppression entries are kept permanently and deliberately, because a suppression list only works if it outlives the record it suppresses.
7. Cookies and tracking
This site uses no advertising cookies and no cross-site tracking, and we do not sell or share what we measure. Polar may set cookies necessary to process your checkout.
We do use Microsoft Clarity on our public pages to understand how they are used. It sets its own cookies and records how visitors interact with a page, including clicks, scrolling and mouse movement. Microsoft reconstructs those into a replayable session and aggregates them into heatmaps. It runs on the public site only, never inside a signed-in account area, and Microsoft masks text content by default so field entries are not captured. You can opt out for every site that uses it via Microsoft's opt-out page, and browser Do Not Track and cookie controls apply as normal.
If another analytics or tracking provider is added later, this section and the provider list above must be updated before it ships.
8. Complaints
Please raise anything with us first at buy@leadhuntr.shop, as most things are quicker to fix directly. You also have the right to complain to your local data-protection authority, and in India to the authority established under the Digital Personal Data Protection Act.
9. Changes
We update this policy as our practices change. The version in force is always the one on this page.
Last updated: 11 August 2026