Privacy Policy

Last updated: 30 June 2026

1. Who we are

The LeadChase platform at leadchase.co is operated by LeadChase Ltd, a company registered in England and Wales (company number 17225822), registered office 29 Primrose Avenue, Downham Market, PE38 9GF ("we", "us", "our"). Prior to 18 May 2026 the platform was operated by Jordan Edner as a sole trader; on incorporation of LeadChase Ltd on 18 May 2026, responsibility for the platform and this policy transferred to LeadChase Ltd. For any questions about this policy, contact us at jordan@leadchase.co.

2. What data we collect

3. How we use your data

4. Lawful basis for processing

We process your personal data on the following lawful bases under UK GDPR:

5. Email and CRM access

When you connect your email account (Gmail or Outlook) or CRM (e.g. Bullhorn), we access only the data necessary to provide the service described above. We will never send emails without your explicit approval. We do not share your email or CRM data with any third parties. You can disconnect your email account or CRM at any time from the Settings page.

6. Data sharing and sub-processors

We do not sell your data. We do not share your data with third parties for marketing purposes.

We share personal data with the following sub-processors who act on our behalf, each under appropriate data-processing terms:

In addition, the Service draws on public data sources for the market and signal information described in section 13. These include Companies House, Crunchbase, public job-board APIs (Greenhouse, Lever, Ashby, Workable, Personio, Recruitee, SmartRecruiters), The Org, and public RSS feeds including Google News. We send these sources only non-personal queries (company names and slugs) and receive back publicly-listed information. They are not data processors for your personal data.

All sub-processors are bound by appropriate data-processing terms and process your data only on our instructions.

7. Data retention

8. Your rights under UK GDPR

You have the right to:

To exercise any of these rights, email jordan@leadchase.co. We will respond within 30 days.

How to ask us to delete your data

If you'd like LeadChase to remove your information from our records, visit leadchase.co/data-rights to submit an opt-out request, or email jordan@leadchase.co with your LinkedIn URL or work email. For records in our shared contact directory, removal takes effect within 24 hours platform-wide as a tombstone that prevents re-import for a minimum of 30 days; in practice we treat tombstones as permanent unless you explicitly ask us to reverse one. We do not modify our customers' own data — if you also want a specific recruitment agency to remove you from their records, please contact that agency directly.

9. Cookies and local storage

We use essential cookies required to keep you logged in (session authentication). Our session replay provider (PostHog) uses localStorage to correlate page visits within a single browsing session. We do not use advertising cookies.

If you use the LeadChase Companion browser extension, the extension stores your access token and a list of recently-seen LinkedIn managers in Chrome's per-extension local storage (chrome.storage.local). This storage is isolated from the websites you visit — LinkedIn cannot read it, and we cannot read your LinkedIn cookies. The token is cleared when you sign out of the extension or disable extension access on your account.

No advertising cookies or third-party tracking cookies are set by LeadChase.

10. Product analytics and session recording

We capture product-usage analytics across the platform — including the authenticated product — to measure feature adoption and improve the service. Events are tagged with your user and agency identifiers so we can understand cohort behaviour. We do not use these analytics for advertising.

When you use our free lead magnet tools (e.g. pages under /tryam), we additionally record your browsing session to understand how visitors interact with the product. These recordings capture page content, mouse movements, clicks, and scrolling — but all form inputs are automatically masked so we never see what you type. Recordings are processed by our analytics provider, PostHog (see their privacy policy). Recordings are retained for up to 30 days and are used solely for product improvement.

11. Browser extension (LeadChase Companion)

The LeadChase Companion is an optional Chrome and Edge extension that lets you build a manager list from a LinkedIn page you are already viewing, in one click, without copy-pasting URLs. It is a clipboard helper — it never clicks LinkedIn UI, scrolls, paginates, sends messages, or modifies the LinkedIn page in any way.

What it reads. When you open its side panel on a LinkedIn profile, company People tab, search-results page, or Sales Navigator page, it reads the visible name, role/headline, profile URL, and (where shown) current company of profiles already rendered on screen. It does not auto-read Recruiter pages — those fall back to a manual paste-in box.

What it does not read. The extension does not read LinkedIn cookies, page HTML, page screenshots, your LinkedIn account credentials, or any LinkedIn private API. It runs in the browser's isolated content-script context and cannot access the page's own JavaScript state.

What it sends to LeadChase. Only the manager details listed above plus your normal session inputs (text brief, CV selections, document selections), sent to leadchase.co when you click Generate. No LinkedIn page content or cookies are ever sent.

What it stores on your device. Your LeadChase access token after you connect, and the last list of managers seen on each LinkedIn tab so the side panel renders instantly when reopened. Both are kept in the browser's per-extension local storage, which is isolated from the websites you visit.

Permissions. The extension requests storage, side-panel, active-tab, and alarms access. It does not request broad tab access, cookie access, network interception, or all-sites access.

Alerts on your other work surfaces. The extension also displays your own saved market-signal alerts as a small, dismissible card on the email and ATS/CRM pages LeadChase supports (Gmail, Outlook, and the platforms you can connect from Settings → Integrations). The card is rendered inside an isolated container that does not read the page underneath, does not modify the page, and does not send the page's URL or contents to LeadChase. It only paints alerts that already belong to your LeadChase account.

Your controls. You can pause the extension on LinkedIn at any time from the side panel settings, or disable extension access for your account entirely from web Settings → Integrations → Browser Extension. Both take effect immediately.

Additional capabilities surfaced in the side panel. The extension also lets you:

LinkedIn's Terms of Service. LinkedIn's User Agreement prohibits browser extensions that read data from its site. By using the LeadChase Companion, you accept that risk on your own LinkedIn account. We minimise detection surface, but no extension can be guaranteed undetectable. You are shown this disclosure once when you first open the side panel and must explicitly acknowledge it before the extension activates.

12. LeadChase Community Network

LeadChase operates a community data network: customers contribute professional business-card information (names, titles, employers, and work email addresses) and professional relationship links (for example, that two people have worked together), and in return every customer benefits from warm-introduction paths and verified business contact emails drawn from the whole community. Work emails you send to are also verified through our own email-finding process and retained to spare the community repeat lookups. We never take your live hiring leads, the roles you are working, candidate CVs or personal data, the contents of your messages, or personal (non-work) email addresses, and nothing contributed is attributed back to you or your agency.

When the LeadChase Companion extension reads profile metadata on LinkedIn pages you view (name, role/headline, profile URL, employment data), LeadChase records this metadata in a shared directory used to operate the LeadChase service.

The directory stores only the same public profile metadata LinkedIn shows to any logged-in visitor. It does not store private LinkedIn data such as private messages, connection lists, or profile content gated behind LinkedIn's privacy settings. Inclusion in the directory does not by itself indicate any relationship with LeadChase or any LeadChase user.

LeadChase maintains the shared contact directory to record publicly-available information about professional contacts relevant to our customers' work. A contact's record in this directory contains the contact's name, public headline, public employment data, and where we have verified one, a work email address. The same contact may appear in more than one customer's view of LeadChase.

Anything else — including a customer's work inside LeadChase — stays private to that customer and is not shared between customers, except as described in the paragraph immediately below.

Information you provide to the Service about your professional contacts may be used to generate suggestions for users on the same agency account, and may inform suggestions surfaced to other LeadChase customers on a basis that does not identify you or your agency. No private outreach content is shared in this way. You can request the removal of any specific contact via the opt-out described below; removal takes effect across all suggestions generated by the Service.

LeadChase generates suggestions and insights for each customer separately, calculated for that customer from their own data combined with the publicly-available information in the directory. No additional categories of personal data are collected to generate them.

For the shared contact directory specifically, LeadChase acts as a joint controller with our customers (UK GDPR Article 26). We determine the purposes and means of operating the directory; our customers determine which contacts they research and outreach. For all other personal data (account data, customer-scoped contacts, outreach activity), LeadChase remains a processor acting on our customers' instructions.

Participation in the Community Network is part of using LeadChase. Paid agencies may opt out of contributing by emailing jordan@leadchase.co; opted-out agencies retain access to the network but stop contributing. Free accounts contribute as a condition of free access. Individuals may remove their own record at any time via the data-rights process below.

To request removal of your record from the shared contact directory, visit leadchase.co/data-rights to submit an opt-out request, or email jordan@leadchase.co. We will tombstone every record matching that identifier within 24 hours and prevent re-import for a minimum of 30 days; in practice we treat tombstones as permanent unless you explicitly ask us to reverse one. Tombstoning takes effect platform-wide and removes the contact from every suggestion generated by the Service.

13. Market and intent signals

LeadChase aggregates publicly-available information about companies to surface contacts and opportunities relevant to your work. This information is drawn from public news, public-record filings, and similar publicly-listed sources.

Our sources include Crunchbase, Companies House, the public job-board APIs of recruitment software providers, public RSS feeds including Google News, and similar public sources. We send these sources only non-personal queries such as company names; they return publicly-listed information. They are not data processors for your personal data.

We rely on legitimate interests as the lawful basis for this processing. To opt out of being identified in this material as a contact connected to a company, visit leadchase.co/data-rights.

14. Children's privacy

The Service is intended for use by recruitment professionals and is not directed at, marketed to, or intended for use by anyone under the age of 18. We do not knowingly collect personal data from minors. If you believe we may hold data relating to a minor, contact jordan@leadchase.co and we will delete it.

15. Security

All data in transit between your browser, the extension, and the LeadChase backend is encrypted with TLS. Email-account OAuth refresh tokens (Gmail and Outlook) and any stored CRM API keys are encrypted at rest using symmetric encryption with a key held only on our backend servers. Other data is protected by per-tenant row-level security in our PostgreSQL database and by the disk-level encryption applied by our hosting providers. Access to the production database is restricted to the LeadChase backend service and named operators.

16. Changes to this policy

We may update this policy from time to time. For material changes (price changes, intellectual-property clauses, governing law, addition of a sub-processor for a new category of data, or any change to the scope of our shared contact directory), we will give you at least fourteen (14) days' notice by email before the change takes effect. For minor changes (typographical corrections, swaps of sub-processors within the same category, or clarifications), the change takes effect immediately with the "Last updated" date bumped.

17. Contact and complaints

For any privacy-related questions or requests, contact jordan@leadchase.co.

If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

18. California privacy rights (CCPA/CPRA)

This section applies to residents of California and supplements the remainder of this policy. It is provided under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA"). Terms used in this section have the meanings given to them in the CCPA. Where the CCPA applies, it governs our handling of the personal information of California residents.

Notice at collection

The categories of personal information we collect, the purposes for which we use them, the categories of sources from which they are collected, the categories of third parties and service providers to whom they are disclosed, and the periods for which they are retained are described in sections 2, 3, 6 and 7 of this policy. We do not collect or process categories of personal information designated as "sensitive personal information" under the CCPA for the purpose of inferring characteristics about a consumer. We do not use or disclose personal information for purposes materially different from those disclosed in this policy without providing further notice.

Your California rights

Subject to the limitations and exceptions set out in the CCPA, California residents have the right to:

Do Not Sell or Share My Personal Information

We do not sell your personal information, and we do not share it for cross-context behavioural advertising, in each case as those terms are defined by the CCPA. We nonetheless make available a means by which you may direct us not to disclose your personal information in any manner that could be construed as a sale or share. To exercise this right, visit leadchase.co/data-rights or email jordan@leadchase.co.

How to exercise your rights

To submit a request to know, delete, correct, or opt out, visit leadchase.co/data-rights or email jordan@leadchase.co. We will confirm receipt and respond within the timeframes required by the CCPA. We will take reasonable steps to verify your identity before acting on a request and may decline to act on a request we are unable to verify to the standard required by law. You may use an authorised agent to submit a request through the same channels; we may require the agent to provide proof of authorisation and may require you to verify your identity directly with us.

The disclosures in this section reflect our practices for the twelve (12) months preceding the "Last updated" date above. We do not knowingly sell or share the personal information of consumers under 16 years of age.