LeadArrow Privacy Policy

EFFECTIVE July 16, 2026 · LAST UPDATED July 16, 2026

This Privacy Policy explains how Eliot Samurin, an individual operating as a sole proprietor under the LeadArrow brand ("LeadArrow," "we," "us," or "our"), collects, uses, discloses, and protects personal information through getleadarrow.com and LeadArrow's applications, browser extensions, integrations, lead-routing tools, alerts, analytics, support, and related services (collectively, the "Service").

This Policy applies to LeadArrow customers, prospective customers, website visitors, account owners, administrators, sales representatives, and other authorized users. It also explains how we process personal information about consumer leads on behalf of our business customers.

The Service is intended for business use in the United States and is not intended for children or personal, family, or household use.

1. LeadArrow's Role

LeadArrow processes personal information in two principal roles:

  1. As a business or controller. We determine how and why we process information about website visitors, prospective customers, account owners, authorized users, billing contacts, and people who communicate directly with LeadArrow.
  2. As a service provider or processor for customers. Our business customers determine how and why their lead, CRM, and representative data is processed. We process that information on their instructions to provide lead ingestion, routing, alerts, integrations, and related services.

If your information was submitted to LeadArrow by one of our customers, that customer is generally responsible for its privacy practices and for responding to your privacy request. You may contact the customer directly. We will reasonably assist the customer where required by law and technically feasible.

LeadArrow currently sends SMS only to customer users and sales representatives who voluntarily enroll in operational LeadArrow Alerts. LeadArrow does not currently use the Service to send a customer's marketing or sales texts to consumer leads.

2. Personal Information We Collect

The information we collect depends on how you interact with the Service.

2.1 Account and Profile Information

We may collect:

  • name;
  • business email address;
  • mobile or business telephone number;
  • company or organization name;
  • job title and role;
  • account username or identifier;
  • password hash and authentication information;
  • account permissions;
  • notification preferences;
  • time zone;
  • subscription, plan, and account status; and
  • information provided during onboarding.

2.2 Customer and Representative Information

We may collect information about a customer's owners, administrators, managers, setters, closers, sales representatives, employees, and contractors, including their contact information, account role, lead assignments, routing status, availability, notification selections, and Service activity.

2.3 Lead and CRM Information

When a customer connects a CRM or another lead source, we may process information selected or made available by the customer, such as:

  • lead name;
  • telephone number;
  • email address;
  • general location or time zone;
  • lead source and campaign;
  • form-submission data;
  • CRM record identifiers;
  • assigned representative;
  • lead status and disposition;
  • appointment or booking information;
  • routing history;
  • response and activity timestamps;
  • call metadata; and
  • other CRM fields or notes that the customer chooses to make available.

Customers control what data they submit and are responsible for ensuring that they have the necessary rights, notices, and consents.

2.4 SMS Alert and Consent Information

For representatives who enroll in LeadArrow Alerts, we may process:

  • mobile telephone number;
  • SMS enrollment and opt-out status;
  • date, time, source, and method of consent;
  • the disclosure presented when consent was obtained;
  • delivery, failure, and carrier-status information;
  • STOP, START, HELP, and similar keyword events;
  • notification type and routing event; and
  • related compliance and suppression records.

LeadArrow's application is not designed to store full SMS conversations. Our messaging provider processes the content needed to deliver operational alerts and automated responses and may retain message records under its own terms and policies. LeadArrow may retain templates, notification types, routing statistics, delivery statistics, and compliance records.

2.5 Call and Routing Information

We may process call and routing statistics, including originating and destination telephone numbers, call time, duration, connection status, routing attempt, assigned representative, acceptance or pass status, and disposition.

LeadArrow does not store call audio recordings or call transcripts. A connected CRM or telephony provider may record or transcribe calls independently at the customer's direction. Those providers' practices are governed by their own terms and privacy policies, and the customer is responsible for obtaining any legally required recording consent.

2.6 Integration Information

When a customer connects a third-party service, we may process:

  • integration account identifiers;
  • API keys, OAuth tokens, webhook secrets, and similar credentials;
  • connected account and workspace information;
  • synchronization status;
  • data mappings;
  • webhook events; and
  • error and diagnostic information.

We use integration credentials to provide and secure the requested connection. Customers should grant only the permissions reasonably necessary for the integration.

2.7 Browser Extension and Application Information

Our browser extension and applications may process information necessary to display alerts, connect to supported CRM pages, enable representative actions, maintain sessions, and provide requested features. Depending on the permissions granted, this may include supported page URLs, page context needed for an integration, extension interactions, notification activity, device information, and diagnostic events.

LeadArrow does not use the browser extension to sell general browsing histories or track activity across unrelated websites for advertising.

2.8 Technical and Usage Information

We and our service providers may automatically collect:

  • IP address;
  • browser type and version;
  • device type and operating system;
  • approximate location inferred from IP address;
  • language and time zone;
  • referring and exit pages;
  • pages and features used;
  • login and activity timestamps;
  • session, cookie, and device identifiers;
  • crash and error reports;
  • performance and diagnostic information; and
  • security and fraud-prevention events.

2.9 Billing and Transaction Information

We may collect billing name, billing contact information, subscription plan, invoices, payment status, transaction identifiers, limited payment-method details such as card brand and last four digits, and tax-related information.

Payment processing is handled by Stripe or another disclosed payment processor. LeadArrow does not receive or store complete payment-card numbers or card security codes.

2.10 Communications and Support

We collect information you provide when requesting support, scheduling a demonstration, responding to a survey, reporting a problem, communicating with us, or otherwise submitting information directly. This may include the communication, attachments, screenshots, diagnostic information, and contact details.

2.11 Sensitive Information

The Service is not designed for Social Security numbers, complete payment-card information, government identification numbers, protected health information, biometric identifiers, highly sensitive financial-account credentials, information about children, or other unnecessary sensitive information. Customers and users must not submit this information to the Service.

3. Sources of Personal Information

We collect personal information:

  • directly from you;
  • from your employer or the organization that invites you to the Service;
  • from LeadArrow customers;
  • from connected CRMs, forms, webhooks, lead sources, and integrations;
  • automatically from your browser, device, extension, and use of the Service;
  • from communications providers, carriers, payment processors, hosting providers, security services, and other vendors; and
  • from referrals, demonstrations, and other lawful business-development sources.

LeadArrow does not purchase consumer telephone lists for marketing through the Service.

4. How We Use Personal Information

We may use personal information to:

  • provide, operate, maintain, and improve the Service;
  • create and administer accounts;
  • authenticate users and manage permissions;
  • receive, route, assign, and display lead information;
  • send browser, push, email, telephone, and optional SMS alerts;
  • connect and synchronize authorized integrations;
  • process subscriptions, payments, invoices, and trials;
  • provide customer service and technical support;
  • personalize configurations and notification preferences;
  • monitor performance, reliability, routing, delivery, and feature usage;
  • create aggregated or de-identified statistics;
  • detect, investigate, prevent, and respond to fraud, abuse, security incidents, spam, and unlawful activity;
  • enforce our agreements and acceptable-use requirements;
  • manage consent, opt-outs, suppression records, and communications compliance;
  • comply with legal obligations and lawful requests;
  • establish, exercise, or defend legal claims;
  • communicate about the Service, security, billing, policy updates, and support; and
  • market LeadArrow to business prospects where permitted by law and honor applicable opt-out requests.

We do not use customer lead data for unrelated advertising or to train public, general-purpose artificial-intelligence models.

5. How We Disclose Personal Information

We may disclose personal information as described below. The providers used at launch or during development may change as the Service evolves.

5.1 Service Providers

We may disclose information to vendors that perform services for us, subject to appropriate contractual or operational restrictions. These may include:

  • Vercel for website or application hosting;
  • Render or another cloud provider for backend hosting;
  • Neon for managed database infrastructure;
  • Twilio for SMS, telephone, carrier connectivity, delivery, consent, and communications compliance;
  • Resend for transactional email;
  • Stripe for payment processing and subscription billing;
  • Sentry for application performance and error monitoring;
  • authentication, security, fraud-prevention, backup, support, and infrastructure providers; and
  • professional advisers such as attorneys, accountants, insurers, and auditors.

These providers may process information only as permitted by their agreements, their own legal obligations, and the purposes for which the information was disclosed.

5.2 Customer-Directed Integrations

At a customer's direction, we may exchange information with connected services such as Close, GoHighLevel, HubSpot, Salesforce, Slack, and other systems selected by the customer. The customer controls which integrations it enables. Information sent to a connected service is also governed by that service's privacy policy and the customer's agreement with it.

5.3 Within the Customer Organization

Account owners and administrators may access information about their authorized users, representatives, leads, routing activity, notification status, and Service usage. Customer organizations determine internal access rights and are responsible for appropriately configuring user permissions.

5.4 Legal, Safety, and Compliance Disclosures

We may disclose information when we reasonably believe disclosure is necessary to:

  • comply with law, regulation, subpoena, court order, or lawful government request;
  • respond to legal process;
  • establish, exercise, or defend legal rights;
  • enforce our agreements;
  • investigate or prevent fraud, abuse, spam, unlawful communications, or security incidents;
  • protect recipients, users, LeadArrow, service providers, carriers, or the public; or
  • satisfy carrier, messaging-provider, and communications-compliance requirements.

5.5 Business Transfers and Organizational Changes

We may disclose or transfer information in connection with financing, formation of a LeadArrow legal entity, incorporation, merger, acquisition, reorganization, sale of assets, business transfer, bankruptcy, or similar transaction. A successor that receives personal information will be required to process it consistently with this Policy unless it provides legally required notice of a change.

5.6 With Your Direction or Consent

We may disclose information for another purpose at your direction or with your consent.

6. No Sale or Behavioral Advertising

LeadArrow does not sell personal information for money. LeadArrow does not share personal information for cross-context behavioral advertising and does not use customer lead data for targeted advertising on unrelated services.

If our practices materially change, we will update this Policy and provide any choices required by applicable law before beginning the changed practice.

7. Cookies and Similar Technologies

We may use cookies, local storage, pixels, and similar technologies to:

  • keep users signed in;
  • maintain security and prevent fraud;
  • remember preferences;
  • operate requested features;
  • measure performance and reliability;
  • diagnose errors; and
  • understand how the Service is used.

We do not currently use advertising cookies to track users across unrelated websites for targeted advertising. Browser settings may allow you to block or delete cookies, but blocking essential cookies may prevent parts of the Service from functioning.

Because there is no universally accepted standard for ordinary browser "Do Not Track" signals, the Service may not respond to those signals. Where required, we will process legally recognized opt-out preference signals, such as Global Privacy Control, in a manner appropriate to the practices to which the signal applies.

8. SMS Privacy and Mobile Information

This section applies to LeadArrow Alerts and is intended to be read together with the SMS terms in the LeadArrow Terms of Service.

8.1 Voluntary SMS Consent

Customer representatives may voluntarily enroll in operational LeadArrow Alerts through a separate, optional, unchecked consent control. Consent to receive SMS is not a condition of purchasing LeadArrow or using non-SMS features. Message frequency varies. Message and data rates may apply. Reply STOP to opt out or HELP for help. You may also contact eliotsamurin@gmail.com.

8.2 No Marketing Disclosure of Mobile Information

LeadArrow does not sell, rent, or share mobile telephone numbers, SMS opt-in data, or text-messaging consent information with third parties or affiliates for their own marketing or promotional purposes.

All categories of disclosure described in this Policy exclude text-messaging originator opt-in data and consent, except that this information may be disclosed to messaging providers, carriers, aggregators, compliance vendors, and other service providers solely as necessary to deliver messages, maintain consent and suppression records, prevent fraud or abuse, provide support, or comply with law. Those parties are not permitted to use the information for their own marketing.

8.3 Opt-Out Records

We and our messaging provider may retain opt-in, opt-out, consent, and suppression records after account deletion when reasonably necessary to honor the request, prevent future unwanted messages, demonstrate compliance, and resolve disputes.

9. Data Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including providing the Service, meeting contractual obligations, protecting security, resolving disputes, enforcing agreements, and complying with law.

Our general retention approach is:

  • Account and operational data: while the account is active and generally for up to 30 days after termination or a valid deletion request, subject to the exceptions below;
  • Customer lead and routing data: as directed by the customer and generally for the account term plus a limited post-termination export and deletion period;
  • SMS consent, opt-out, suppression, and related compliance records: generally for at least five years after the relevant consent, message, or opt-out event, or longer if reasonably necessary for a legal claim or compliance obligation;
  • Billing, transaction, and tax records: generally for up to seven years;
  • Security, access, and diagnostic logs: generally for up to two years, unless a longer period is needed to investigate an incident;
  • Support and legal records: for as long as reasonably necessary to address the matter and establish or defend legal rights; and
  • Backups: deleted information may remain in encrypted or access-restricted backups for up to 90 days before being overwritten, unless legal preservation is required.

These periods are general targets, not guarantees that every record is retained for the entire period. We may delete information earlier when it is no longer necessary. We may retain aggregated or de-identified information that no longer reasonably identifies a person.

Automated export and deletion features are still being developed. Until those controls are available, eligible requests may be handled manually through the contact information below.

10. Security

We use reasonable administrative, technical, and organizational measures designed to protect personal information. Depending on the system and stage of deployment, these measures may include encryption in transit, encryption or provider-managed protection at rest, credential encryption, access controls, least-privilege practices, account authentication, logging, backups, monitoring, and incident-response procedures.

No method of transmission, storage, or security is perfectly secure. We cannot guarantee that unauthorized parties will never defeat safeguards or that information will never be lost, altered, or improperly accessed. You are responsible for securing your account, devices, credentials, connected systems, and user permissions.

If you believe your information or account has been compromised, contact us promptly at eliotsamurin@gmail.com.

11. Your Privacy Rights and Choices

Depending on where you live and applicable law, you may have the right to:

  • know whether we process your personal information;
  • access or obtain a copy of personal information;
  • correct inaccurate information;
  • request deletion;
  • request portability of certain information;
  • restrict or object to certain processing;
  • opt out of sale, targeted advertising, or certain profiling;
  • withdraw consent where processing is based on consent;
  • appeal a denied privacy request; and
  • receive equal service without unlawful discrimination for exercising a privacy right.

LeadArrow does not currently sell personal information or use it for cross-context behavioral advertising.

To submit a request, email eliotsamurin@gmail.com with the subject line "Privacy Request." Describe the request and identify the account or relationship involved. We may take reasonable steps to verify your identity and authority before acting. We will respond within the time required by applicable law.

You may use an authorized agent where permitted by law. We may request proof of the agent's authority and may need to verify your identity directly.

We may deny or limit a request where an exception applies, such as where information is needed to provide a requested service, maintain security, prevent fraud, honor an SMS opt-out, comply with law, protect another person's rights, or establish or defend legal claims. If applicable law provides an appeal right, you may appeal by replying to our decision or emailing the same address with "Privacy Appeal" in the subject line.

Customer-Controlled Data

If your information was provided by a LeadArrow customer, submit your request to that customer first. LeadArrow generally cannot independently determine whether the customer's underlying lead record should be accessed, corrected, or deleted. We will assist the customer as reasonably required.

Communication Choices

  • SMS: Reply STOP or contact us to withdraw consent from LeadArrow Alerts.
  • Marketing email: Use the unsubscribe link or contact us. You may still receive non-marketing account, billing, security, and service communications.
  • Cookies: Use browser controls to block or delete cookies, subject to functional limitations.
  • Account notifications: Change available settings or contact the account administrator.

12. Children's Privacy

The Service is intended only for adults engaged in business activity. We do not knowingly collect personal information from children under 18. Customers may not create accounts for children or knowingly submit children's information as Customer Data.

If you believe a child has provided personal information, contact us at eliotsamurin@gmail.com so we can investigate and take appropriate action.

13. United States Service and Data Processing

The Service is intended for United States business customers. Personal information may be stored and processed in the United States and other locations where our service providers operate. Those locations may have data-protection rules different from the rules where you live.

Customers must not use the Service in a jurisdiction where doing so would require LeadArrow to satisfy additional localization, registration, or international-transfer obligations unless LeadArrow has agreed in writing.

14. Third-Party Services and Links

The Service may contain links to or integrations with services that LeadArrow does not control. This Policy does not govern an independent third party's privacy practices. Review that party's privacy policy before providing information or enabling an integration.

15. Changes to This Privacy Policy

We may update this Policy to reflect changes in the Service, vendors, technology, law, or our practices. We will post the updated Policy and revise the Last Updated date. If a change materially affects how we use personal information, we will provide additional notice or obtain consent where required by law.

16. Contact Us

For questions, concerns, privacy requests, SMS support, or complaints, contact:

LeadArrow
Operated by Eliot Samurin, sole proprietor
Columbus, Ohio, United States
Email: eliotsamurin@gmail.com
Website: https://getleadarrow.com