Privacy Policy

Last updated: August 2026 · Governing jurisdiction: State of Texas, United States

Raplead is operated by Intelacis LLC ("we", "us", "our"), which acts as the data controller for the personal data described below. This Privacy Policy explains what we collect, how we use it, and the rights you have over it.

1. What We Collect

We collect only the data necessary to provide the Raplead service. This includes:

Account Data

  • Email address — used for login and transactional emails
  • Hashed password — stored and managed by Supabase Auth; we never see your plaintext password
  • Subscription tier and billing status

Usage Data

  • Searches performed (count, location, business type)
  • Audit results generated per search
  • Saved leads and lead management actions (save, dismiss, blocklist)
  • Feature interactions (email generation, vision audit, CSV export)

Visitors Without an Account

You can run a small number of free searches without creating an account. To stop that allowance being abused by automated traffic, we count those searches against a keyed hashof your IP address — a one-way fingerprint from which the original address cannot be recovered. We do not store the IP address itself, and the hash is not linked to any account, name or email. The counter expires automatically at the end of each 30-day window. Signing up starts a fresh monthly allowance and does not carry the anonymous counter over.

Business Data

  • Business names, domains, addresses, phone numbers retrieved from Google Maps
  • Website performance scores generated via Google PageSpeed Insights
  • Chatbot and social presence signals extracted from public web pages

Payment Data

Payment processing is handled entirely by Stripe. We do not store or have access to your credit card number, CVV, or full card details. We store only your Stripe customer ID and subscription ID for billing management purposes.

2. How We Use Your Data

We use the data we collect for the following purposes:

  • Provide the Raplead service — search, audit, lead management, and email generation
  • Process billing and manage your subscription via Stripe
  • Enforce tier limits and prevent quota abuse, including the free allowance for visitors without an account
  • Send transactional emails (billing receipts, account notices)
  • Improve the service based on aggregate, anonymised usage patterns
  • Respond to support requests and data inquiries

We do not use your data for advertising, behavioural profiling, or sale to third parties.

3. Data Processors

We use the following sub-processors to deliver the service. Each processes only the data necessary for their stated function.

  • Supabase — database hosting and authentication; location: United States
  • Stripe — payment processing and subscription management; location: United States
  • Google — Places API, PageSpeed Insights, Maps JavaScript SDK; location: United States
  • OpenAI — AI-powered vision audit for Agency tier (GPT-4o-mini); location: United States
  • Anthropic / Claude — AI-powered pitch-email generation for Pro and Agency tiers (Haiku); location: United States
  • Vercel — application hosting and serverless function execution; location: United States
  • ScreenshotOne — website screenshots feeding the Agency tier vision audit; location: European Union
  • Resend — transactional email delivery (e.g. contact form); location: United States
  • PostHog — opt-in product analytics; location: United States
  • Cloudflare Turnstile — bot and abuse protection on signup, contact and logged-out search; location: United States
  • Overpass / OpenStreetMap — location autocomplete and geocoding; location: European Union

Each sub-processor is bound by a Data Processing Agreement (DPA) or equivalent contractual obligation. We review sub-processors annually and will update this list when processors change.

Legal basis for processing

We process personal data under the following legal bases: contract performance, to deliver the Raplead service you have signed up for (account management, search, audit, lead management, billing); legitimate interests, for fraud prevention, abuse protection, and service security; and consent, for optional product analytics (PostHog), which is off by default and only activated if you opt in via the cookie banner. You may withdraw consent for analytics at any time without affecting your ability to use the service.

International transfers

Your data may be processed by sub-processors located in the United States and the European Union, as listed above. Where personal data is transferred outside your jurisdiction, we rely on Standard Contractual Clauses (SCCs) or equivalent safeguards recognised under applicable data protection law to ensure an adequate level of protection.

Legal-wording notice: the Legal Basis and International Transfers language above is drafted for attorney review and finalization. It reflects our technical and operational reality accurately, but has not yet been certified by qualified legal counsel — do not treat it as a final legal opinion.

4. Data Retention

  • Account data: retained while your account is active; deleted immediately when you delete your account (Settings → Account → Delete account) — including your profile, saved leads, and blocklist
  • Lead data: subject to tier-based expiry — Free tier: 24 hours; paid tiers: 7 days from creation; expired leads are permanently deleted by a daily automated purge
  • Audit results: retained as part of lead data; same expiry and purge apply
  • Search history: retained for up to 30 days for deduplication and session continuity
  • Payment records: retained as required by applicable tax and financial regulations (typically 7 years)

5. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you
  • Deletion — permanently delete your account and all associated data yourself at any time (Settings → Account → Delete account); active subscriptions are cancelled as part of deletion
  • Portability — export your saved leads at any time via the CSV export feature
  • Correction — update your account information through the settings page
  • Restriction — request that we restrict processing of your data in certain circumstances
  • Objection — object to processing based on legitimate interests

To exercise any of these rights, contact us at privacy@raplead.com. We will respond within 30 days. For general support enquiries, use support@raplead.com.

6. Cookies & Local Storage

Essential Cookies

We use authentication cookies managed by Supabase to maintain your login session, plus a small consent cookie that remembers your cookie preferences. These are strictly necessary for the service to function and cannot be opted out of while using Raplead.

Local Storage

We use browser local storage for UI preferences, including theme selection and search result deduplication state. This data does not leave your device.

Product Analytics (PostHog) — Opt-In

With your consent, we use PostHog to understand how Raplead is used (page views, feature engagement, sign-up funnel) so we can improve the product. PostHog stores a small cookie + local storage entry tying anonymous events together; once you sign in we attach your user id and tier so funnels can span sign-up to first paid event. We do not share your full email with PostHog — only the email domain (e.g. gmail.com) as a cohort signal.

Analytics are off by default. The consent banner at the bottom of the screen lets you accept or decline analytics on first visit, and you can change your mind anytime via the Cookies link in the footer. Declining keeps the app fully functional — analytics are not load-bearing.

No Advertising or Cross-Site Tracking

We do not run advertising pixels (Meta, Google Ads, TikTok, etc.) and we do not sell or share analytics data with third parties beyond PostHog as our analytics processor.

7. Security

  • All data transmitted over HTTPS/TLS — unencrypted connections are rejected
  • Passwords hashed using bcrypt via Supabase Auth — we never store or access plaintext passwords
  • API keys stored server-side only — never exposed to the browser or client-side code
  • Row-level security (RLS) enforced at the database layer — users can only access their own data
  • Service role key used only in server-side API routes, never in client bundles

8. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

  • Material changes will be communicated via email at least 14 days before they take effect
  • Minor clarifications may be made without notice
  • The "Last updated" date at the top of this page reflects the most recent revision
  • Continued use of the service after any changes constitutes acceptance of the updated policy

9. Contact

For privacy-specific enquiries including data access, deletion, or portability requests:

  • Data controller: Intelacis LLC
  • Privacy: privacy@raplead.com
  • Support: support@raplead.com
  • Jurisdiction: State of Texas, United States