Last updated: July 2026
This Privacy Policy explains how LeadOpera LLC, a Colorado limited liability company (“Company,” “we,” “us,” or “our”), collects, uses, and shares information in connection with LeadProof™ and our related websites and services (the “Services”). It should be read together with our Terms & Conditions.
LeadProof handles two categories of data that are treated differently:
(a) Account data — information about the businesses and users who sign up for and operate the Services. For this data we act as the controller.
(b) Consent records — the consumer-consent events that an integrating business captures and asks us to certify and seal on its behalf. For this data the integrating business is the controller and LeadProof acts as a service provider / processor: we process it under the business’s instructions to produce a tamper-evident record, and we do not sell it or use it to build consumer profiles for our own purposes. A consumer who wishes to access, correct, or delete their information should contact the business that collected it; we will assist that business as its processor. See Your choices & rights.
Account & billing. Company name, contact name, email address, authentication identifiers, API keys, credit balance and transaction history, and support communications. Payments are processed by our payment processor (Stripe); we do not receive or store full payment-card numbers.
Consent records (on behalf of integrating businesses). At the moment a consumer consents on an integrating business’s property, the Services may capture: the consent language and form markup presented, the URL and the documents linked from it, the timestamp, the originating IP address, behavioral signals from the session (for example mouse movement, keyboard interaction, pointer events, and time-to-complete), and an anti-bot / anti-fraud assessment. Phone numbers and email addresses provided for later matching are hashed with a secret salt at capture and the plaintext is discarded — we store only the one-way hash, never the raw number or address.
Technical & usage. Standard server and security logs, and cookies strictly necessary to keep you signed in and to run the anti-bot challenge. We do not use advertising or cross-site tracking cookies. See Cookies.
We use account data to provide, secure, bill for, and support the Services. We process consent records solely to perform the certification the integrating business requested — archiving and hashing what was observed, applying a trusted timestamp, scoring trust and fraud signals, and, on request, running verification, drift analysis, or generating evidence packages and attestations. We also use limited data as needed to detect abuse, comply with law, and enforce our Terms. We do not sell personal information.
We share information with vendors that help us run the Services, each under contractual confidentiality and data-protection obligations, and only as needed for their function:
We may also disclose information to comply with law or valid legal process, to protect the rights, safety, and security of our users and the public, or in connection with a corporate transaction (for example a merger or acquisition), in which case we will require the recipient to honor this Policy.
The Services are designed to seal evidence, not to accumulate personal data. Contact identifiers used for matching are stored only as one-way salted hashes; the certification record is a cryptographic seal over what was observed. Where a field is absent, we record its absence honestly rather than substituting a placeholder.
Account data is retained for the life of the account and as required for legal, tax, and audit purposes. Because a certificate’s value is evidentiary, sealed consent records and evidence are retained as directed by the integrating business (for example, for a chosen retention term) and for so long as they may be needed to demonstrate the integrity of a record. Retention on behalf of an integrating business is governed by our agreement with that business.
We use technical and organizational safeguards including encryption in transit and at rest, scoped access controls, cryptographic integrity hashing, and database-level immutability of sealed fields so a certified record cannot be silently altered after capture. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, or to object to or restrict certain processing. For account data, you may exercise these by contacting us at the address below. For consumer consent records, because the integrating business is the controller, please direct requests to that business; we will support the business in responding as its processor. Note that we may retain information where required by law or where a sealed record must remain intact for its evidentiary purpose, and that hashed identifiers are pseudonymous and not reversible by us.
We use only cookies that are strictly necessary: a session cookie to keep you signed in, and cookies set by our bot- mitigation provider to run the human/bot challenge. We do not use advertising, analytics-profiling, or cross-site tracking cookies. You can block cookies in your browser, but the Services may not function correctly without the necessary ones.
We operate in the United States, and our vendors may process information in the United States and other countries. Where required, transfers of personal data are made under appropriate safeguards. By using the Services you understand your information may be processed in the United States.
The Services are intended for businesses and are not directed to children. We do not knowingly collect personal information from children. If you believe a child’s information has been provided to us, contact us and we will take appropriate steps.
We may update this Policy from time to time. Material changes take effect when posted with an updated date; your continued use of the Services constitutes acceptance of the revised Policy.
Questions or privacy requests may be directed to support@leadopera.com, LeadOpera LLC (Colorado, USA).
This Privacy Policy is a working draft and should be reviewed by legal counsel before being treated as final, particularly for use under specific state privacy laws (e.g., CCPA/CPRA), the GDPR, or other regulated contexts.
Terms & Conditions · LeadProof FAQ
LeadProof™ is a proprietary product and service of LeadOpera LLC, a Colorado limited liability company, operated through its independent website. LeadOpera™ and LeadProof™ are trademarks of LeadOpera LLC; wordmark applications pending. Unauthorized use of these marks is strictly prohibited. The consent-certification method used by LeadProof is patent pending. © 2026 LeadOpera LLC. All rights reserved.