Privacy Policy
Last updated: 9 September 2026
This Privacy Policy explains how Leadr (“Leadr”, “we”, “us”) collects, uses, discloses, and safeguards information when you use the Leadr application and website at https://goshark.space (the “Service”). Leadr is a multi-tenant WhatsApp Business CRM: a shared inbox, contact and pipeline manager, broadcast tool, and automation builder for businesses and agencies that communicate with their own customers over the WhatsApp Business Platform.
1. Who is the data controller
For personal data about our own account holders (the people who sign up for Leadr), Leadr is the data controller. For the end-customer data that a Leadr customer imports or receives through their connected WhatsApp Business Account — such as their customers’ phone numbers and message content — the Leadr customer is the controller and Leadr acts as a processor on their behalf.
2. Information we collect
Account & workspace data
- Your name, work email, and a securely hashed password.
- Your organization / workspace name, team members you invite, and their roles.
- Configuration you enter: tags, pipeline stages, message templates, automation flows, product catalog, and orders.
WhatsApp Business Platform data
- The WhatsApp Business Account (WABA) ID, phone number ID, business name, quality rating, and messaging limit reported by Meta for the number you connect.
- An access token issued by Meta that lets Leadr send and receive messages on your behalf. Tokens are stored per-organization and used only to operate the Service for that organization.
- Inbound and outbound message content, timestamps, delivery/read status, and the profile name and phone number of the people your customers message with. This content is processed to provide the shared inbox, CRM, campaign reporting, and automation features you use.
Technical data
- IP address, browser type, pages viewed, and timestamps in server logs, kept for security and troubleshooting.
- A single essential session cookie (a signed JWT) that keeps you logged in. We do not use advertising or third-party tracking cookies.
3. How we use information
- To create and operate your account and workspace.
- To send, receive, route, tag, and store WhatsApp messages, run the automations you configure, and report on campaign delivery.
- To authenticate you and keep the Service secure.
- To provide support and respond to your requests.
- To monitor, maintain, debug, and improve the Service, and to detect and prevent abuse.
- To comply with legal obligations and enforce our Terms of Service.
We do not sell personal data, and we do not use the contents of your customers’ WhatsApp messages for advertising or to train machine-learning models.
4. Legal bases (EEA/UK users)
Where the GDPR or UK GDPR applies, we process personal data on the basis of: performance of a contract (operating the Service you signed up for); legitimate interests (securing the Service, preventing abuse, improving our product); consent where required; and compliance with legal obligations.
5. Sharing and sub-processors
We share data only with the service providers needed to run Leadr:
- Meta Platforms, Inc. — the WhatsApp Business Cloud API, which transmits your messages. Your use of a connected number is also subject to the WhatsApp Business Messaging Policy and Meta’s terms.
- Vercel Inc. — application hosting and content delivery.
- Neon Inc. — managed PostgreSQL database hosting.
We may also disclose information if required by law, to protect our rights or users’ safety, or in connection with a merger or acquisition (with notice to you).
6. International transfers
Our providers may process data in the United States and other countries. Where required, transfers rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
7. Data retention
We keep account and workspace data for as long as your account is active. Message and conversation data is retained to provide the inbox and reporting features until you or your workspace owner delete it, or until the account is closed. After account closure we delete or anonymize personal data within 90 days, except where we must retain it to comply with law, resolve disputes, or enforce our agreements. Server logs are retained for up to 30 days.
8. Security
Data is encrypted in transit (TLS). Passwords are stored only as salted hashes. Access to production systems is restricted to authorized personnel. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. Workspace owners can edit or delete most data directly in the app. For other requests, contact us at support@goshark.space. If Leadr processes data as a processor on behalf of a customer, we will refer your request to that customer.
10. Children
The Service is not directed to children and is not intended for anyone under 16. We do not knowingly collect personal data from children.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified through the Service or by email. The “Last updated” date above reflects the latest revision.
12. Contact
Questions or requests about this policy or your data: support@goshark.space.