Privacy Policy
Effective Date: 10 August 2026Introduction
LeadTime ("LeadTime", "we", "our", or "us") operates a notification platform that enables businesses to send automated notifications to their clients and contacts via email, SMS, and WhatsApp. We are committed to protecting your personal information and handling it responsibly in accordance with the Protection of Personal Information Act, 4 of 2013 ("POPIA") and all other applicable South African data protection laws.
This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and your rights as a data subject. By using LeadTime, you agree to the practices described in this policy.
Who This Policy Applies To
This Privacy Policy applies to:
- Registered users of the LeadTime platform ("Users") who create accounts and use our services to send notifications.
- Recipients of notifications sent via the LeadTime platform on behalf of our Users.
- Visitors to our website and related digital properties.
Information We Collect
3.1 Account and Registration Information
When you register for a LeadTime account, we collect:
- Email address
- Referral code (optional) — if provided at registration, we record which authorised sales partner referred you. This is used solely for internal attribution purposes and is not shared publicly.
3.2 Business Profile Information
Your account includes one business profile by default; Standard and Premium subscribers may create additional business profiles. For each business profile you create, we collect:
- Business name
- Phone number
- Email address
- Where configured, connected messaging credentials for that profile (such as a WhatsApp Business phone number/access token or a linked email sending domain), used solely to send messages on your behalf via that profile.
3.3 Recipient Contact Information and Message Logs
In the course of using the LeadTime platform to send notifications, we collect and temporarily store contact information for your notification recipients. This is limited to:
- Email address – only when you choose to send notifications via email.
- Phone number – only when you choose to send notifications via SMS or WhatsApp.
Alongside each message you send, our Analytics page keeps a log entry recording: the recipient's name (where supplied in your spreadsheet), the channel used, the WhatsApp template name (where applicable), the message's status, and, where reported back to us, the timestamps at which it was sent, delivered, read, and replied to. You can view this log, filter it by date, recipient, channel, template, or status, and export it as a CSV or Excel file for your own records; a separate PDF export covers just the accompanying charts and KPI summary, not the log itself. Both are generated on demand for you and are not sent to or shared with any third party.
3.4 WhatsApp Templates and Inbound Messages
Where you send a WhatsApp message using an approved Message Template, the variable values you supply (for example, a customer's name, order number, or estimated delivery date) are transmitted to Meta to populate that template and are not separately stored by LeadTime beyond the request needed to send the message. If you build a template with an image header, the image you upload is transmitted to Meta as part of submitting that template for review and is not separately stored by LeadTime once submitted. Where the Service provides an inbound WhatsApp inbox for your connected WhatsApp Business Account, we receive and store, for each conversation: the customer's WhatsApp number and profile name, the content of messages sent and received, message type, delivery status, and timestamps. Unlike the tiered-retention recipient data described above, this conversation history is retained for as long as your account and the relevant business profile exist, so you can refer back to past customer conversations, and is permanently deleted if you delete your account or the business profile it belongs to.
3.5 Scheduled Messages
If you are subscribed to the Standard tier or above and use message scheduling, we store the recipient's contact detail, the message content, and your chosen send date and time until the message is dispatched. Once a scheduled message has been sent (or cancelled by you), this record is retained only as part of your standard message history, in line with Section 7.
3.6 Uploaded Images
If you use the Uploads feature to send a photo attachment (for example, via WhatsApp), the image you upload is stored in our cloud storage provider (Supabase Storage), in a private location accessible only to your account — it is never made publicly browsable. When you use the image, we generate a temporary link that expires after 24 hours for delivering it. Depending on what you choose to upload, this may include sensitive personal information such as photographs of ID documents; you are responsible for only uploading images you have the right and any necessary consent to share. Uploaded images are retained until you delete your account, at which point they — along with all other account data — are permanently deleted (see Section 7).
3.7 Security and Authentication
We do not store passwords in plain text. All passwords are encrypted using industry-standard hashing algorithms before being stored in our database.
3.8 Payment Information
Payments for LeadTime subscriptions are processed by PayPal. We do not store your credit card or banking details on our systems. All payment data is handled directly by PayPal in accordance with their own privacy policy and applicable financial regulations. If you cancel your subscription to take effect at the end of your billing period, we record that end date so your access continues correctly until then.
3.9 Saved Contact Lists
If you choose to save a list of recipients for reuse in future bulk sends (the Contact Lists feature), that contact data — names, phone numbers, email addresses, and any other spreadsheet columns you included — is stored against your account until you delete the list or your account, rather than being subject to the tiered automatic deletion described in Section 3.3. Only you can view or use lists saved to your account.
3.10 Invoicing, Customer Records, and Shareable Links
If you have the Invoicing add-on enabled on your account, the Invoicing feature stores customer records (name, contact details, address, VAT number where provided) and the invoices, quotes, and credit notes you create for them, retained until you delete the customer record or your account. Where you generate a shareable link for an invoice or quote, anyone with that link can view the document without logging in; we record when a shared invoice/quote is first viewed so you can see that it reached your client. Do not include personal information in an invoice beyond what's needed for the transaction, since a share link is not access-controlled beyond the link itself.
3.11 In-App Notifications
The Service shows you a notification bell covering account events (such as a payment received or a recurring invoice generated) and live account status (such as overdue invoices or missing configuration). Stored notifications are tied to your account, retained until you delete your account, and are never visible to any other user.
3.12 One-Time Verification Codes (OTP)
Where you use the Service to send a WhatsApp one-time verification code (via an Authentication-category Message Template), we store the recipient's phone number and a cryptographically hashed (not plaintext, not reversible) copy of the code, together with an expiry time and whether the code has been used. This is used only to verify that a code entered back matches the one issued to that number, and to enforce a short cooldown between repeated code requests to the same number. These records are retained as part of your account's data until you delete your account, at which point they are permanently deleted along with your other account data.
3.13 Browser Push Notification Subscriptions
If you enable browser push notifications (for example, to be alerted the moment a new WhatsApp message arrives in your Inbox), your browser generates a push subscription — an endpoint URL, encryption keys, and information about the browser/device — which we store against your account so we can deliver a notification to that browser even when LeadTime isn't open. You can disable this at any time from LeadTime's notification bell icon or your browser's own notification settings.
3.14 Blocked/Suppressed Contacts
If you add a contact to your blocked contacts list, or a recipient replies "stop" to a WhatsApp message (which adds them automatically), we store that contact's phone number or email address, which channel(s) it's blocked for, and, where applicable, the reason, so that contact is excluded from your future sends across bulk messages, scheduled messages, and automated reminders.
3.15 AI Assistant (Optional Add-On)
AI Assistant is an optional, separately priced add-on that is not enabled by default and is currently available on request to a limited number of accounts. Where it is enabled for your account, the Service reads the text of each incoming WhatsApp message in your connected inbox and generates a suggested reply, grounded in the business context you write and any documents you upload to your Knowledge Base — either as a draft for your team to review and send, or, if you turn on Auto-send, sent automatically without human review. To generate each reply, the incoming message text, your written business context, and the relevant content of your uploaded Knowledge Base documents are sent to a third-party AI service provider. Knowledge Base documents you upload are stored on our infrastructure and used only to generate replies for your own account; they are never shared with any other LeadTime user. You may also configure escalation phrases that, when matched in an incoming message, skip the AI entirely and flag the conversation for you to handle yourself.
3.16 API Access (Optional Add-On)
API Access is a separate optional add-on, also currently available on request, that lets you generate API keys granting your own external website or system programmatic access to your WhatsApp inbox — to retrieve your conversations and messages, to send replies through LeadTime, to retrieve the list of your business's Meta-approved WhatsApp message templates, and to send a template message to a contact (including outside the 24-hour reply window). A template message sent this way is recorded in your Inbox and Analytics message log like any other send, and is visibly marked as sent via API so it's distinguishable from a message you or a team member typed yourself. Only the key's cryptographic hash is stored on our systems; the plaintext key is shown to you once at creation and cannot be retrieved again. An API key carries the same level of access to your inbox data as your own logged-in account, scoped to your business, and you are solely responsible for keeping it secure. Revoking a key takes effect immediately. We do not access, monitor, or use whatever external system you connect using an API key — the data flow it enables is entirely between your own system and LeadTime.
3.17 Team Management (Premium)
If you invite Team Members to your account (a Premium feature — see Section 5.13 of our Terms of Service), each Team Member's name, email address, and the pages you've granted them are stored against your account until you remove them or delete your account. Data your business already holds — conversations, message history, Analytics, customer/invoice records, and similar account data — is shared with a Team Member to the extent of the pages you grant them; it is not maintained as separate per-person copies. A Team Member accesses this data under their own login credentials, and their use of it is subject to the same obligations as your own under our Terms of Service. Removing a Team Member's access is immediate; it does not retroactively affect data already generated while they had access (e.g. messages they sent remain part of your account's message history).
How We Use Your Information
We use the information we collect for the following purposes:
- To create and manage your LeadTime account.
- To provide, operate, and improve the LeadTime notification platform.
- To send transactional communications related to your account, including billing notifications and service updates, via email.
- To process subscription payments via PayPal.
- To deliver notifications to your specified recipients on your behalf.
- Where you have enabled the optional AI Assistant add-on, to generate suggested or automatic replies to your WhatsApp conversations.
- Where you have enabled the optional API Access add-on, to authenticate and authorise your own connected system's programmatic access to your inbox data.
- Where you use Team management (Premium), to authenticate a Team Member's login and enforce the per-page access you've granted them.
- To comply with our legal obligations under South African law.
- To investigate and resolve disputes or security incidents.
Legal Basis for Processing
We process your personal information on the following legal bases under POPIA:
- Contractual necessity: Processing is required to provide you with the services described in our Terms of Service.
- Legitimate interest: Processing is necessary for the administration, security, and improvement of our platform.
- Legal obligation: Processing is required to comply with South African law.
- Consent: Where we rely on consent, you may withdraw it at any time by contacting us.
Data Storage and Infrastructure
Your data is stored and processed on the following infrastructure:
- Application servers: Google Cloud Run (europe-west1 – Belgium).
- Database: Supabase hosted on AWS eu-central-1 (Frankfurt, Germany).
- File storage: Supabase Storage, on the same infrastructure, for images you upload via the Uploads feature.
While our servers are located outside South Africa, we take reasonable steps to ensure that your information is protected with appropriate contractual and technical safeguards equivalent to the standards required by POPIA. By using LeadTime, you acknowledge and consent to your data being processed in these locations.
Data Retention
We retain your personal information for as long as your account is active and as required to provide you with our services. Specifically:
- Account information (email, business profile details, phone numbers): Retained for the duration of your account and a reasonable period thereafter for legal and administrative purposes.
- Recipient contact information and message logs (including per-message delivery/read/reply status and timestamps): Automatically and permanently deleted once it ages past your subscription tier's Analytics retention window — 1 month after collection on Basic, 12 months on Standard, or 24 months on Premium.
- WhatsApp inbox conversations: Retained for as long as your account and the relevant business profile exist — not subject to the tiered recipient data window above, since this is an ongoing conversation history rather than a one-off send. Deleted immediately if you delete your account or the business profile it belongs to.
- Uploaded images: Retained until you delete your account, at which point they are permanently deleted along with your other account data.
- Scheduled messages: Retained until sent or cancelled; if your account is deleted before a scheduled message is sent, it is removed immediately along with your other account data.
- Saved contact lists: Retained until you delete the list or your account — not subject to the tiered recipient data window above.
- Invoicing data (customer records, invoices, quotes, credit notes): Retained until you delete the relevant record or your account.
- In-app notifications: Retained until you delete your account.
- One-time verification codes (OTP): Hashed codes and their associated phone numbers are retained until you delete your account, at which point they are permanently deleted.
- Browser push notification subscriptions: Retained until you disable browser notifications or delete your account.
- Blocked/suppressed contacts: Retained until you remove the entry or delete your account.
- AI Assistant business context and Knowledge Base documents (accounts with this optional add-on enabled): Retained for as long as the feature remains enabled on your account, or until you delete the individual document or your account.
- API keys (accounts with this optional add-on enabled): Retained until you revoke the key or delete your account; revocation takes effect immediately and cannot be undone.
- Payment records: Retained as required by applicable South African tax and financial laws.
You may delete your account and all associated personal information at any time directly from the Account Settings page within the platform, provided you do not have an active subscription. Upon deletion, all data listed above — with the exception of payment records required by law — is permanently and immediately removed from our systems. This action cannot be undone.
Payment records may be retained beyond account deletion as required by applicable South African tax and financial laws.
Sharing of Information
We do not sell your personal information. We share your information only with the following third-party service providers, strictly for the purposes of delivering our service:
- Mailgun – Email delivery service provider.
- Twilio – SMS delivery service provider.
- Meta (WhatsApp Business Platform) – WhatsApp message delivery, using the WhatsApp credentials configured on your business profile. Where you have an inbound WhatsApp inbox enabled, Meta also relays messages your customers send to your connected WhatsApp number to us via webhook.
- PayPal – Payment processing.
- Google Cloud – Application hosting infrastructure.
- Supabase – Database hosting.
- A third-party AI service provider – AI reply generation, only for accounts with the optional AI Assistant add-on enabled. Incoming message text, your business context, and relevant Knowledge Base document content are sent to that provider to generate a suggested or automatic reply.
Each of these providers is bound by their own privacy policies and applicable data protection laws. We may also disclose your information where required to do so by law, court order, or regulatory authority.
Your Rights Under POPIA
As a data subject under POPIA, you have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate or incomplete information.
- Request deletion of your personal information, subject to our legal obligations.
- Object to the processing of your personal information.
- Lodge a complaint with the Information Regulator of South Africa.
To exercise the right to deletion, you may use the self-service account deletion option in Account Settings, or contact us directly — see our Data Deletion Instructions for the full process. For all other rights, or if you require assistance, please contact us at the details in Section 12. If you are not satisfied with our response, you may lodge a complaint with the Information Regulator of South Africa.
Security
We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, loss, misuse, or disclosure. These measures include password hashing, access controls, and the use of reputable cloud infrastructure providers. However, no system is completely secure, and we cannot guarantee the absolute security of your information.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will notify you by email and update the effective date at the top of this document. Continued use of the LeadTime platform after such notification constitutes your acceptance of the updated policy.
Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or the handling of your personal information, please contact us at: