LeadCat CRM

Privacy Policy

Last updated: September 10, 2026

Version 1.2

LeadCat is a product of Staminal Technologies Private Limited.

This Privacy Policy explains how STAMINAL TECHNOLOGIES PRIVATE LIMITED (CIN: U62013TN2023PTC165254) collects, uses, stores, and protects information when businesses use LeadCat CRM ("CRM", "Service", "we", "our", or "us").

The CRM is built for businesses that want to capture customer enquiries from Instagram, Facebook, YouTube, website, walk-in, phone, referral, manual entry, and imported lead sources into one follow-up dashboard.

For customer lead and enquiry data, the subscribing business normally decides why the data is collected and how it is used, and STAMINAL TECHNOLOGIES PRIVATE LIMITED processes that data to provide the CRM on the business's instructions. For CRM account, billing, service security, and platform-operation data, STAMINAL TECHNOLOGIES PRIVATE LIMITED determines the purposes described in this Policy.

1. Information We Collect

Depending on how a business uses the CRM, we may process the following information:

2. Meta, Instagram, and Facebook Data

When a business connects Instagram or Facebook, the CRM receives only the data that the business authorizes through Meta permissions and webhooks. This may include Instagram direct messages, Instagram comments, Facebook Page messages, Facebook comments, lead identifiers, sender/page/account metadata, and related timestamps.

We use this information to create or update leads, detect duplicate events, show message history, classify enquiries, suggest human-reviewed replies, and help the business follow up with customers. We do not use Meta data for unrelated advertising, profiling, or sale to third parties.

2A. Google and YouTube Data

LeadCat uses YouTube API Services. When an authorized business user connects a YouTube channel through Google OAuth, we access the connected channel's identifier and name, selected video identifiers and titles, and comments on those videos. Comment data includes comment identifiers, text, author display names and channel identifiers where available, and publication timestamps. We store encrypted OAuth access and refresh tokens on our servers to maintain the authorized connection. LeadCat does not receive or store your Google password.

We use this data to validate video ownership, capture matching enquiries as leads in the business workspace, prevent duplicate processing, and display comment and reply activity. When the business explicitly enables automatic public replies, LeadCat sends its configured reply text to YouTube as the connected channel. These replies are publicly visible on YouTube. Replies are optional; authorized workspace users can disable them or pause capture in Integrations. The requested YouTube permission also covers operations such as editing or deleting videos; LeadCat's comment integration does not perform those operations.

Captured information is available to authorized users of the owning workspace and to service providers needed to host, secure, back up, and operate the service as described below. Configured replies are shared with YouTube and its viewers. We do not sell Google or YouTube data or use it for unrelated advertising. Google's handling of data is described in the Google Privacy Policy.

Connection, automation, and captured lead records remain stored until removed through the applicable deletion process described in Sections 7 and 8. Disconnecting YouTube in LeadCat removes the stored access and refresh tokens and stops further authorized capture and replies; it does not erase historical leads, activity, or replies already published on YouTube. In addition to requesting deletion from LeadCat, you can revoke its Google access at any time through Google Account permissions. Use our Data Deletion Instructions to request removal of stored YouTube data, or contact director@staminal.in with privacy questions or complaints.

LeadCat uses browser storage to maintain your signed-in session and a short-lived cookie to bind the Google authorization flow to the browser that started it. Following links to Google or YouTube opens their services, which are governed by their own privacy and cookie practices.

3. How We Use Information

4. AI Assistance and Replies

The CRM may generate lead classifications and suggested reply text to assist business users. Suggested replies are intended for review by the business before use. The CRM should not make final pricing, discount, stock, delivery, warranty, or availability commitments unless the business has explicitly configured and approved that information.

5. Data Sharing

We do not sell customer enquiry data. We may share information only in these cases:

6. Security

We use HTTPS, tenant separation, role-based access control, password hashing, encrypted integration tokens, server-side access controls, and backup procedures to protect CRM data. No method of transmission or storage is completely secure, but we take reasonable steps to reduce unauthorized access and exposure.

7. Data Retention

Lead and workspace records are retained while the business account is active, unless an authorized deletion request is completed. To reduce unnecessary duplication, our standard operational schedule redacts raw social-message and webhook payloads after 30 days, old completed background-job payloads after 30 days, expired authentication secrets after 30 days, and raw billing-provider payloads after 90 days. Security and access-audit records are normally kept for 365 days, with a minimum 180-day security-log period. IP address, user-agent, and request-ID metadata attached to legal acceptance evidence is normally redacted after 365 days. The minimized acceptance record, including the signer, business, document version, document hash, acceptance wording, authority confirmation, and acceptance time, may be retained while the contract is active and afterwards where reasonably required to establish the agreement, resolve disputes, or comply with law. Contact details attached to a closed deletion request are redacted after three years, while a minimized completion record is retained to support backup-restoration controls.

A legal hold, fraud or security investigation, payment dispute, or a statutory accounting/tax obligation may require selected records to be kept longer. In that case we minimize the retained data and restrict its use to that purpose. Deleted data may remain in access-controlled backups until the applicable backup rotation expires and is not used for ordinary CRM operations.

8. User Choices and Deletion

Businesses can disconnect integrations by removing saved integration credentials from the CRM or revoking app access from the connected platform. Disconnecting revokes the CRM's stored credentials but does not by itself erase historical leads. Authorized workspace, integration, and lead deletion requests are verified, tracked to a due date, and completed only after database and stored-media deletion steps finish. Requests can be submitted using our Data Deletion Instructions.

9. Children's Data

The CRM is intended for business use and is not directed to children. Businesses should not knowingly submit data from children unless they have the required legal basis and consent.

10. Changes To This Policy

We may update this Privacy Policy as the Service evolves. The updated version will be posted on this page with a revised "Last updated" date.