Privacy Policy
Last updated: 30 June 2026
1. Who we are
The LeadChase platform at leadchase.co is operated by LeadChase Ltd, a company registered in England and Wales (company number 17225822), registered office 29 Primrose Avenue, Downham Market, PE38 9GF ("we", "us", "our"). Prior to 18 May 2026 the platform was operated by Jordan Edner as a sole trader; on incorporation of LeadChase Ltd on 18 May 2026, responsibility for the platform and this policy transferred to LeadChase Ltd. For any questions about this policy, contact us at jordan@leadchase.co.
2. What data we collect
- Account information: your name, email address, and agency name when you sign up.
- Payment card details: when you sign up for a free trial or paid subscription, payment card details are collected and stored securely by our payment processor, Stripe, on our behalf. We do not store full card numbers ourselves.
- Candidate CVs (raw PDFs): PDF files uploaded by recruiters for outreach generation. The original PDF bytes are processed in memory only and are not retained. We keep only a SHA-256 hash of the original PDF so we can recognise duplicate uploads of the same file.
- Anonymised CVs (saved-CV library): the redacted text of each uploaded CV, plus a structured candidate profile (skills, achievements, role title) generated automatically from that redacted text. Each candidate's name, email, phone number, and personal URLs are replaced with "Redacted" before storage. These are stored against your user account so you can re-attach a CV to future outreach without re-uploading it.
- Company documents: brochures, case studies, market reports, and similar marketing collateral you upload through Settings. We store the original PDF plus an extracted text summary used to ground AI-generated references in your messages. Visible only to you and your agency.
- Email account access: when you connect Gmail or Outlook via OAuth, we access your inbox solely to send outreach emails on your behalf and to detect replies to those emails. We do not read, store, or process any unrelated inbox content.
- CRM data: job and candidate records passed to LeadChase via your connected CRM (e.g. Bullhorn via webhook integration).
- Outreach activity: records of messages generated, hiring manager details, and company names associated with each outreach session.
- Response tracking: whether a hiring manager replied to outreach, the channel (email or LinkedIn), and screenshots uploaded by you as evidence of a response.
- Placement data: placement fees entered by recruiters, attribution relationships between outreach sessions and placements, and revenue share calculations.
- Usage data: actions taken within the platform and session activity, used to improve the service.
- Browser extension activity (LeadChase Companion users only): when the extension's side panel is open on a LinkedIn page, it reads the visible name, role/headline, profile URL, and (where shown on the page) current company of profiles already rendered on screen. These are sent to LeadChase only when you click Generate or paste them into an outreach session. See section 11 for the full extension data flow.
- Recruiter profile: preferences you set during onboarding and in Settings, and any writing samples you choose to provide to help us match your voice in generated outreach.
- Third-party people data in our shared contact directory: the names, public headlines, public employment data, and (where we have verified one) work email addresses of professional contacts relevant to our customers' work. This information is held cross-tenant in a shared directory described in section 12.
- Personal data exports you upload: if you choose to upload personal data exports from professional networks, LeadChase processes the structured records in that upload to recognise contacts you already know. We do not store the content of any private messages contained in the upload, and any message-content fields are discarded on import.
- Suggestions and insights derived for you: recommendations, rankings, and summaries we calculate from your data combined with the publicly-available information in our shared contact directory. These are generated for you only and are not shared between customers.
3. How we use your data
- To generate personalised outreach messages on your behalf using AI.
- To send emails from your connected inbox when you explicitly approve and initiate sending.
- To detect replies to outreach emails sent through LeadChase.
- To track attribution between outreach activity and placements — we record which companies were contacted, which responded, and which resulted in placements. This attribution proof chain is used for revenue share calculation.
- To calculate and administer revenue share on attributed placements.
- To rank and prioritise contacts relevant to your work based on the information we hold about your network and the publicly-available data in our shared contact directory.
- To surface market and intent signals tied to companies you are tracking, drawn from public sources described in section 13.
- To generate suggestions and insights for you (such as introduction suggestions and contact recommendations), calculated from your own data combined with the publicly-available information described above.
- To capture product-usage analytics so we can measure feature adoption and improve the platform.
- To improve platform features and performance.
- To determine when unlock actions consume credits from your monthly insight-credit allowance, and to record each unlock for billing transparency so the same unlock is never charged twice.
- To monitor publicly-available job-board data and (for users who connect them) connected email and calendar metadata, to detect new job openings and call bookings relevant to your work.
4. Lawful basis for processing
We process your personal data on the following lawful bases under UK GDPR:
- Performance of a contract: to provide the platform services you have signed up for, including account administration, message generation, email delivery, and (where applicable) attribution tracking and revenue share calculation.
- Legitimate interests: for product improvement, security, fraud prevention, and operating the business — balanced against your rights and interests.
- Consent: for any optional features you opt in to (e.g. marketing communications), which you may withdraw at any time.
- Legal obligation: where we must process data to comply with applicable law.
5. Email and CRM access
When you connect your email account (Gmail or Outlook) or CRM (e.g. Bullhorn), we access only the data necessary to provide the service described above. We will never send emails without your explicit approval. We do not share your email or CRM data with any third parties. You can disconnect your email account or CRM at any time from the Settings page.
6. Data sharing and sub-processors
We do not sell your data. We do not share your data with third parties for marketing purposes.
We share personal data with the following sub-processors who act on our behalf, each under appropriate data-processing terms:
- Anthropic — AI inference used for the Service's AI-powered features (US).
- Vercel — frontend hosting and content delivery (global).
- Railway — backend application hosting (EU region).
- Neon — managed PostgreSQL database (EU and US options).
- Stripe — payment processing for paid plans (US).
- EnrichLayer — public professional-profile enrichment (US).
- Google APIs — Gmail integration when you connect a Google email account (regional). Subject to Google's API Services User Data Policy.
- Microsoft Graph — Outlook integration and call scheduling when you connect a Microsoft email account (regional).
- MillionVerifier — email-address pattern verification (US).
- PostHog — product analytics and session recording (EU instance).
In addition, the Service draws on public data sources for the market and signal information described in section 13. These include Companies House, Crunchbase, public job-board APIs (Greenhouse, Lever, Ashby, Workable, Personio, Recruitee, SmartRecruiters), The Org, and public RSS feeds including Google News. We send these sources only non-personal queries (company names and slugs) and receive back publicly-listed information. They are not data processors for your personal data.
All sub-processors are bound by appropriate data-processing terms and process your data only on our instructions.
7. Data retention
- Free Plan accounts: we retain your Free Plan account and its associated data indefinitely while you continue to access the account. We will give you at least thirty (30) days' advance email notice before any policy change that would terminate inactive Free Plan accounts.
- Paid subscription accounts: account data is retained for as long as your subscription is active. On cancellation, your account reverts to the Free Plan and is retained on the Free Plan terms above; you may also request immediate deletion by emailing the address at the bottom of this section.
- Trial accounts (legacy, no longer offered): the provisions in the remainder of this paragraph apply only to historical trial accounts created during the time the trial program was offered. After signup, accounts waited in a pending state until the onboarding call activated the trial. If activation did not occur within fourteen (14) days of signup, the account was automatically cancelled and any payment card details were removed from our payment processor. For activated trial accounts, data was retained for the 14-day Free Trial (starting on the Trial Start Date) plus a 30-day read-only Post-Trial Access Period (44 days total from the Trial Start Date). At the end of the Post-Trial Access Period, the account and all associated data was permanently deleted unless upgraded to a paid subscription. A reminder email was sent at least seven (7) days before deletion. Combined with the pre-activation window, the maximum retention period for a trial account was up to 58 days from signup.
- Raw CV PDFs: discarded after redaction. We keep only a SHA-256 hash of the original PDF to recognise re-uploads of the same file.
- Anonymised CVs (saved-CV library): retained against your user account until you archive them (via the extension CV picker or the web app) or until your account is deleted. Archived CVs are excluded from your library immediately and hard-deleted from the database within 90 days, to allow recovery from an accidental delete.
- Company documents: retained until you delete them in Settings, or until your account is deleted.
- Outreach activity, response records, and placement data are retained to support attribution tracking and revenue share administration.
- Payment card details are retained securely by Stripe for as long as your account is active. You may request deletion of your card details at any time.
- LeadChase Community Network: records in our shared contact directory (described in section 12) are retained while the contact remains active in our customers' work. Tombstone removal via leadchase.co/data-rights or by emailing jordan@leadchase.co takes effect within 24 hours platform-wide and prevents re-import for a minimum of 30 days.
- Personal data exports you upload: the original ZIP/CSV upload is processed transiently and discarded after parsing. The structured records extracted from the upload are retained in your account until you remove them or your account is deleted.
- Market and intent signals: signals tied to companies you watch are retained in your account while you keep watching the company. Aggregated company-level signal data may be retained for longer to support our platform-wide market-intelligence features.
- You may request deletion or export of your account and all associated data at any time by emailing jordan@leadchase.co. Note that deletion of placement records may affect revenue share obligations already confirmed.
8. Your rights under UK GDPR
You have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request erasure of your data (subject to legal obligations).
- Restriction of processing — you may ask us to limit how we use your data in specific circumstances under Article 18 UK GDPR.
- Request portability of your data in a machine-readable format.
- Object to processing based on legitimate interests.
- Withdraw consent — where we rely on your consent, you may withdraw it at any time without affecting the lawfulness of processing that took place before withdrawal.
- Not be subject to solely automated decision-making — LeadChase does not make solely automated decisions that produce legal or similarly significant effects on you. All recommendations, rankings, and suggestions surfaced by the Service are advisory; a human user always decides whether to act on them.
To exercise any of these rights, email jordan@leadchase.co. We will respond within 30 days.
How to ask us to delete your data
If you'd like LeadChase to remove your information from our records, visit leadchase.co/data-rights to submit an opt-out request, or email jordan@leadchase.co with your LinkedIn URL or work email. For records in our shared contact directory, removal takes effect within 24 hours platform-wide as a tombstone that prevents re-import for a minimum of 30 days; in practice we treat tombstones as permanent unless you explicitly ask us to reverse one. We do not modify our customers' own data — if you also want a specific recruitment agency to remove you from their records, please contact that agency directly.
9. Cookies and local storage
We use essential cookies required to keep you logged in (session authentication). Our session replay provider (PostHog) uses localStorage to correlate page visits within a single browsing session. We do not use advertising cookies.
If you use the LeadChase Companion browser extension, the extension stores your access token and a list of recently-seen LinkedIn managers in Chrome's per-extension local storage (chrome.storage.local). This storage is isolated from the websites you visit — LinkedIn cannot read it, and we cannot read your LinkedIn cookies. The token is cleared when you sign out of the extension or disable extension access on your account.
No advertising cookies or third-party tracking cookies are set by LeadChase.
10. Product analytics and session recording
We capture product-usage analytics across the platform — including the authenticated product — to measure feature adoption and improve the service. Events are tagged with your user and agency identifiers so we can understand cohort behaviour. We do not use these analytics for advertising.
When you use our free lead magnet tools (e.g. pages under /tryam), we additionally record your browsing session to understand how visitors interact with the product. These recordings capture page content, mouse movements, clicks, and scrolling — but all form inputs are automatically masked so we never see what you type. Recordings are processed by our analytics provider, PostHog (see their privacy policy). Recordings are retained for up to 30 days and are used solely for product improvement.
11. Browser extension (LeadChase Companion)
The LeadChase Companion is an optional Chrome and Edge extension that lets you build a manager list from a LinkedIn page you are already viewing, in one click, without copy-pasting URLs. It is a clipboard helper — it never clicks LinkedIn UI, scrolls, paginates, sends messages, or modifies the LinkedIn page in any way.
What it reads. When you open its side panel on a LinkedIn profile, company People tab, search-results page, or Sales Navigator page, it reads the visible name, role/headline, profile URL, and (where shown) current company of profiles already rendered on screen. It does not auto-read Recruiter pages — those fall back to a manual paste-in box.
What it does not read. The extension does not read LinkedIn cookies, page HTML, page screenshots, your LinkedIn account credentials, or any LinkedIn private API. It runs in the browser's isolated content-script context and cannot access the page's own JavaScript state.
What it sends to LeadChase. Only the manager details listed above plus your normal session inputs (text brief, CV selections, document selections), sent to leadchase.co when you click Generate. No LinkedIn page content or cookies are ever sent.
What it stores on your device. Your LeadChase access token after you connect, and the last list of managers seen on each LinkedIn tab so the side panel renders instantly when reopened. Both are kept in the browser's per-extension local storage, which is isolated from the websites you visit.
Permissions. The extension requests storage, side-panel, active-tab, and alarms access. It does not request broad tab access, cookie access, network interception, or all-sites access.
Alerts on your other work surfaces. The extension also displays your own saved market-signal alerts as a small, dismissible card on the email and ATS/CRM pages LeadChase supports (Gmail, Outlook, and the platforms you can connect from Settings → Integrations). The card is rendered inside an isolated container that does not read the page underneath, does not modify the page, and does not send the page's URL or contents to LeadChase. It only paints alerts that already belong to your LeadChase account.
Your controls. You can pause the extension on LinkedIn at any time from the side panel settings, or disable extension access for your account entirely from web Settings → Integrations → Browser Extension. Both take effect immediately.
Additional capabilities surfaced in the side panel. The extension also lets you:
- Pick a saved (anonymised) CV from your LeadChase account to attach to outreach you initiate via the extension.
- Add or remove a company from your watch list.
- Display introduction suggestions and market signals in the side panel, drawn from data already in your LeadChase account.
LinkedIn's Terms of Service. LinkedIn's User Agreement prohibits browser extensions that read data from its site. By using the LeadChase Companion, you accept that risk on your own LinkedIn account. We minimise detection surface, but no extension can be guaranteed undetectable. You are shown this disclosure once when you first open the side panel and must explicitly acknowledge it before the extension activates.
12. LeadChase Community Network
LeadChase operates a community data network: customers contribute professional business-card information (names, titles, employers, and work email addresses) and professional relationship links (for example, that two people have worked together), and in return every customer benefits from warm-introduction paths and verified business contact emails drawn from the whole community. Work emails you send to are also verified through our own email-finding process and retained to spare the community repeat lookups. We never take your live hiring leads, the roles you are working, candidate CVs or personal data, the contents of your messages, or personal (non-work) email addresses, and nothing contributed is attributed back to you or your agency.
When the LeadChase Companion extension reads profile metadata on LinkedIn pages you view (name, role/headline, profile URL, employment data), LeadChase records this metadata in a shared directory used to operate the LeadChase service.
The directory stores only the same public profile metadata LinkedIn shows to any logged-in visitor. It does not store private LinkedIn data such as private messages, connection lists, or profile content gated behind LinkedIn's privacy settings. Inclusion in the directory does not by itself indicate any relationship with LeadChase or any LeadChase user.
LeadChase maintains the shared contact directory to record publicly-available information about professional contacts relevant to our customers' work. A contact's record in this directory contains the contact's name, public headline, public employment data, and where we have verified one, a work email address. The same contact may appear in more than one customer's view of LeadChase.
Anything else — including a customer's work inside LeadChase — stays private to that customer and is not shared between customers, except as described in the paragraph immediately below.
Information you provide to the Service about your professional contacts may be used to generate suggestions for users on the same agency account, and may inform suggestions surfaced to other LeadChase customers on a basis that does not identify you or your agency. No private outreach content is shared in this way. You can request the removal of any specific contact via the opt-out described below; removal takes effect across all suggestions generated by the Service.
LeadChase generates suggestions and insights for each customer separately, calculated for that customer from their own data combined with the publicly-available information in the directory. No additional categories of personal data are collected to generate them.
For the shared contact directory specifically, LeadChase acts as a joint controller with our customers (UK GDPR Article 26). We determine the purposes and means of operating the directory; our customers determine which contacts they research and outreach. For all other personal data (account data, customer-scoped contacts, outreach activity), LeadChase remains a processor acting on our customers' instructions.
Participation in the Community Network is part of using LeadChase. Paid agencies may opt out of contributing by emailing jordan@leadchase.co; opted-out agencies retain access to the network but stop contributing. Free accounts contribute as a condition of free access. Individuals may remove their own record at any time via the data-rights process below.
To request removal of your record from the shared contact directory, visit leadchase.co/data-rights to submit an opt-out request, or email jordan@leadchase.co. We will tombstone every record matching that identifier within 24 hours and prevent re-import for a minimum of 30 days; in practice we treat tombstones as permanent unless you explicitly ask us to reverse one. Tombstoning takes effect platform-wide and removes the contact from every suggestion generated by the Service.
13. Market and intent signals
LeadChase aggregates publicly-available information about companies to surface contacts and opportunities relevant to your work. This information is drawn from public news, public-record filings, and similar publicly-listed sources.
Our sources include Crunchbase, Companies House, the public job-board APIs of recruitment software providers, public RSS feeds including Google News, and similar public sources. We send these sources only non-personal queries such as company names; they return publicly-listed information. They are not data processors for your personal data.
We rely on legitimate interests as the lawful basis for this processing. To opt out of being identified in this material as a contact connected to a company, visit leadchase.co/data-rights.
14. Children's privacy
The Service is intended for use by recruitment professionals and is not directed at, marketed to, or intended for use by anyone under the age of 18. We do not knowingly collect personal data from minors. If you believe we may hold data relating to a minor, contact jordan@leadchase.co and we will delete it.
15. Security
All data in transit between your browser, the extension, and the LeadChase backend is encrypted with TLS. Email-account OAuth refresh tokens (Gmail and Outlook) and any stored CRM API keys are encrypted at rest using symmetric encryption with a key held only on our backend servers. Other data is protected by per-tenant row-level security in our PostgreSQL database and by the disk-level encryption applied by our hosting providers. Access to the production database is restricted to the LeadChase backend service and named operators.
16. Changes to this policy
We may update this policy from time to time. For material changes (price changes, intellectual-property clauses, governing law, addition of a sub-processor for a new category of data, or any change to the scope of our shared contact directory), we will give you at least fourteen (14) days' notice by email before the change takes effect. For minor changes (typographical corrections, swaps of sub-processors within the same category, or clarifications), the change takes effect immediately with the "Last updated" date bumped.
17. Contact and complaints
For any privacy-related questions or requests, contact jordan@leadchase.co.
If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
18. California privacy rights (CCPA/CPRA)
This section applies to residents of California and supplements the remainder of this policy. It is provided under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA"). Terms used in this section have the meanings given to them in the CCPA. Where the CCPA applies, it governs our handling of the personal information of California residents.
Notice at collection
The categories of personal information we collect, the purposes for which we use them, the categories of sources from which they are collected, the categories of third parties and service providers to whom they are disclosed, and the periods for which they are retained are described in sections 2, 3, 6 and 7 of this policy. We do not collect or process categories of personal information designated as "sensitive personal information" under the CCPA for the purpose of inferring characteristics about a consumer. We do not use or disclose personal information for purposes materially different from those disclosed in this policy without providing further notice.
Your California rights
Subject to the limitations and exceptions set out in the CCPA, California residents have the right to:
- Know and access the categories and specific pieces of personal information we have collected, the categories of sources, the purposes for collection, and the categories of third parties and service providers to whom it is disclosed.
- Delete personal information we have collected from you, subject to the exceptions permitted by law.
- Correct inaccurate personal information we maintain about you.
- Opt out of the "sale" or "sharing" of personal information, as those terms are defined by the CCPA.
- Limit the use and disclosure of sensitive personal information to the purposes permitted by the CCPA.
- Not receive discriminatory treatment for exercising any of these rights.
Do Not Sell or Share My Personal Information
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, in each case as those terms are defined by the CCPA. We nonetheless make available a means by which you may direct us not to disclose your personal information in any manner that could be construed as a sale or share. To exercise this right, visit leadchase.co/data-rights or email jordan@leadchase.co.
How to exercise your rights
To submit a request to know, delete, correct, or opt out, visit leadchase.co/data-rights or email jordan@leadchase.co. We will confirm receipt and respond within the timeframes required by the CCPA. We will take reasonable steps to verify your identity before acting on a request and may decline to act on a request we are unable to verify to the standard required by law. You may use an authorised agent to submit a request through the same channels; we may require the agent to provide proof of authorisation and may require you to verify your identity directly with us.
The disclosures in this section reflect our practices for the twelve (12) months preceding the "Last updated" date above. We do not knowingly sell or share the personal information of consumers under 16 years of age.