Want to access, correct or delete your personal information? Lodge a privacy request and we will respond within 30 days.

Privacy Policy

Effective date: 2 July 2026 | Last updated: 2 July 2026

Ross Clark McFarlane, trading as Pocket Leadz (ABN 13 612 801 409) ("Pocket Leadz", "we", "us", "our") respects your privacy. This Privacy Policy explains how we handle personal information when you use the Pocket Leadz website, web and mobile applications, link-in-bio pages, and related services (the "Service"). It is written to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs"), and with applicable United States state privacy laws. By using the Service, you agree to the handling of personal information described here.

1. Who this Policy covers, and two different roles

This Policy applies to:

(a) Account holders and visitors. Information we handle about our customers, their team members, and visitors to our website and apps. For this information, Pocket Leadz is the responsible entity (the business or controller).

(b) Lead and contact data held on behalf of customers. Our customers use the Service to capture and manage information about their own leads, prospects, and contacts ("Lead Data"). We host and process Lead Data on the customer's behalf and on their instructions, as their service provider or processor. For Lead Data, the relevant customer is the responsible entity. If you are a lead or contact and want to access, correct, or delete your information, or ask why you received a message, contact the business that captured your details. We will help that business respond and will refer you to them where appropriate.

2. What is personal information

Personal information (also called personal data) is information that identifies, relates to, or could reasonably be linked with an identified or identifiable individual.

3. The personal information we collect

Depending on how you use the Service, we may collect:

Account and profile information: name, business name, email address, phone number, role, and login credentials.
Billing information: plan, transaction records, and limited payment details. Card payments are processed by our payment processor, Stripe; we do not store full card numbers.
Content you create: notes, tasks, call logs, voice-to-text notes, tags, comments, social post and ad library entries, and other content you add.
Lead Data: information about your leads and contacts that you or your integrations capture, import, or enter, which may include names, contact details, message and activity history, lead source, and notes.
Communications data: records of messages sent through the Service, including delivery, reply, and unsubscribe events. Message content is sent through your own connected provider accounts (see section 7).
Usage and device information: log data, IP address, device and browser type, app version, features used, and timestamps.
Link-in-bio analytics: views, clicks, lead submissions, and similar metrics.
Cookies and similar technologies: see section 11.

We collect only what is reasonably necessary for our functions and activities.

4. How we collect personal information

We collect personal information directly from you; automatically when you use the Service; from your integrations and inputs (including website and funnel webhooks, Meta lead-ad connectors, link-in-bio forms, and data you import); and from third parties such as our service providers, where lawful. Where we collect personal information about an individual from someone other than that individual (for example Lead Data you import), we rely on you to have given any required notices and obtained any required consents.

5. Why we use personal information

We use personal information to: provide, operate, secure, maintain, and improve the Service; create and manage Accounts and authenticate users; process payments and manage subscriptions; enable messages that you direct through the Service using your own connected providers; provide support; analyse and report on usage and develop features; detect and respond to fraud, abuse, security incidents, and breaches of our Terms; and comply with our legal obligations. We will not use or disclose personal information for an unrelated purpose unless you would reasonably expect it, you consent, or it is otherwise permitted or required by law.

6. Direct marketing

6.1 We may send you information about the Service, including service updates and offers, consistent with applicable law, and every marketing message will include a way to opt out. You can opt out at any time using the unsubscribe facility or by contacting support@pocketleadz.com.

6.2 Messages you send to your own leads and contacts through the Service are sent by you, not by us. You are responsible for consent, identification, and opt-out handling for those messages, as set out in our Terms and under applicable law (including the TCPA and CAN-SPAM Act in the United States and the Spam Act 2003 (Cth) in Australia).

7. Who we disclose personal information to, and your connected providers

7.1 We may disclose personal information to:

Service providers and subprocessors who help us run the Service, under confidentiality and data-protection obligations, including: Supabase (PostgreSQL, United States) and Vercel for hosting and storage; Stripe for payments; and our own server logs (we do not use a third-party analytics provider) for analytics.
Integration partners you choose to connect (for example Meta), to the extent needed to provide the integration you enabled.
Professional advisers such as lawyers and accountants.
Authorities and others where required or authorised by law, to enforce our Terms, or to protect any person's rights, property, or safety.
A buyer or successor in connection with a sale, merger, or reorganisation, subject to this Policy.

7.2 Your own connected providers. You connect and use your own third-party accounts to send messages, including your own SMS provider (for example Twilio) and your own email provider (for example Resend). When a message is sent, the relevant content and recipient details are processed through your account with that provider, under your relationship with them and their privacy terms, not ours. We are not the account holder with those providers.

7.3 We do not sell personal information, and we do not "share" it for cross-context behavioural advertising as those terms are defined under United States state privacy laws.

8. International data handling

8.1 We are based in Australia and serve customers mainly in the United States. Personal information may be stored and processed in Australia, the United States, and in other countries where our providers operate, which may include the United States and Australia.

8.2 Where we disclose personal information across borders, we take reasonable steps to ensure it is handled consistently with this Policy and applicable law, including through contractual protections. For Australian individuals, where APP 8 applies we remain accountable for overseas disclosures except where an exception applies. By using the Service you acknowledge these cross-border transfers.

9. Security of personal information

9.1 We take reasonable administrative, technical, and physical steps to protect personal information from misuse, interference, and loss, and from unauthorised access, modification, or disclosure. These include access controls, two-factor authentication, encryption in transit, restricted staff access on a need-to-know basis, logging, and regular review of our security practices.

9.2 No method of transmission or electronic storage is completely secure. While we work to protect personal information, we cannot guarantee absolute security, and any transmission is at your own risk.

9.3 We take reasonable steps to destroy or de-identify personal information we no longer need, unless we are required to retain it by law or for legitimate backup, security, or dispute-resolution purposes.

10. Data breaches

If we become aware of a data breach involving personal information, we will assess and respond in line with our legal obligations. In Australia, that includes the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth): where a breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner ("OAIC"). In the United States, we will comply with applicable state breach-notification laws. Where a breach involves Lead Data held on behalf of a customer, we will work with that customer to meet applicable obligations.

11. Cookies and analytics

We use cookies and similar technologies to operate the Service, remember your preferences, keep you signed in, measure usage, and improve the Service. You can manage cookies through your browser, although disabling some may affect how the Service works. Where required, we honour recognised opt-out preference signals, including the Global Privacy Control, for browsers that send them.

12. Automated decision-making

We do not use automated processes to make decisions that have a legal or similarly significant effect on individuals. If this changes, we will update this Policy and describe the kinds of decisions made, the kinds of personal information used, and how you can seek review.

13. Health and financial data (HIPAA and GLBA)

13.1 The Service is not, by default, a HIPAA-compliant environment, and we are not a Business Associate unless we have signed a Business Associate Agreement with you. Customers must not submit Protected Health Information to the Service unless such an Agreement is in place. Where a Business Associate Agreement is in place, we handle Protected Health Information in accordance with it and with HIPAA.

13.2 Where a customer is a financial institution subject to the Gramm-Leach-Bliley Act (for example a mortgage broker), that customer is responsible for its own compliance. Where we process nonpublic personal information on a customer's behalf, we do so as a service provider, applying the security measures described in this Policy and in any addendum the parties sign.

14. Your privacy rights and choices

14.1 Everyone. You may ask us to access the personal information we hold about you and to correct it if it is inaccurate, out of date, incomplete, or misleading. Contact support@pocketleadz.com. We will respond within a reasonable period, may need to verify your identity, and in limited circumstances permitted by law may decline a request and give reasons.

14.2 United States residents. Depending on your state, you may have rights to: know and access the categories and specific pieces of personal information we hold; delete your personal information; correct inaccurate personal information; obtain a portable copy; opt out of the sale or sharing of personal information and of targeted advertising; limit the use of sensitive personal information; and not be discriminated against for exercising these rights. Some states also give you a right to appeal a refusal. To exercise these rights, contact support@pocketleadz.com. You may use an authorised agent where the law allows. We will verify your request as the law requires.

14.3 We do not sell or share. We do not sell personal information or share it for cross-context behavioural advertising. We honour the Global Privacy Control signal as an opt-out for browsers that send it.

14.4 Lead Data. If your request relates to Lead Data held on behalf of a customer, we will direct you to, or assist, that customer, who is the responsible entity for that information.

15. Children

The Service is intended for businesses and individuals aged 18 and over. It is not directed at children, and we do not knowingly collect personal information directly from children. If you believe a child has provided personal information to us, contact us so we can address it.

16. Complaints

16.1 If you have a privacy complaint, contact our Privacy Officer at support@pocketleadz.com. We will acknowledge it and aim to resolve it within a reasonable period.

16.2 Australia. If you are not satisfied with our response, you may complain to the OAIC: oaic.gov.au; phone 1300 363 992; post GPO Box 5288, Sydney NSW 2001.

16.3 United States. You may also have the right to contact your state Attorney General. California residents may contact the California Privacy Protection Agency.

17. Changes to this Policy

We may update this Policy from time to time. The current version is always available at https://pocketleadz.com/privacy with its effective date. For material changes, we will take reasonable steps to notify you. Continued use of the Service after a change takes effect means you accept the updated Policy.

18. Contact us

Privacy Officer Ross Clark McFarlane, trading as Pocket Leadz ABN 13 612 801 409 687c Brighton Rd, Seacliff SA 5049, Australia support@pocketleadz.com

This Privacy Policy is provided for general information and is not legal advice. Have it reviewed by a qualified United States privacy attorney and an Australian solicitor before you rely on it.