← Back to home
🔒 Privacy

Privacy Policy

Last updated: July 26, 2026

Who are we?

SprintLead, a sole proprietorship, operates the Site sprintlead.io. Data controller: GDPR contact form. Requests relating to data protection are processed via this form.

Data collected

Account data : email, first name, last name, password (bcrypt hashed, never in plain text)

Usage data : searches carried out, leads consulted, emails generated (to improve the service)

Payment data : processed by Stripe (we never store your credit card data)

Professional prospect data : identity or trading name, professional contact details, website, location, public signals, source, outreach history, objections and opt-outs

Support and chatbot : messages sent, voluntarily provided email address, feedback, and technical data needed to follow up the request

Navigation data : internal audience measurement and, if configured, PostHog, only after your consent; minified paths without URL parameters

Purposes of processing

PurposeLegal basis
Provision of serviceExecution of the contract
BillingLegal obligation
Product improvementLegitimate interest
Marketing communicationsConsent

Data sharing

Your data is never sold. Subcontractors:

Stripepayment, PCI-DSS certified
Vercelapplication hosting and content delivery network
Supabasemanaged database, EU (eu-west-1)
OpenAIAI generation — instructions and fields selected by the user may contain professional data; no systematic anonymization is promised
GooglePlaces API and Gmail API — requests needed for the service
Resendtransactional and verification email delivery, when configured
Inngestdeferred-task orchestration, when configured
PostHogaudience measurement only after consent, when configured

Use of Google Data / Use of Google User Data

SprintLead lets users connect their Gmail account to send personalized emails from the application. By default, we request the gmail.send, which allows emails to be sent on the user’s behalf from their own Gmail account. Synchronizing replies and delivery failures requires separate consent for the gmail.readonly. This restricted scope is not currently requested from public users: the feature remains unavailable until Google verification is confirmed.

Without that separate consent, SprintLead does not read the inbox. Whengmail.readonlyis enabled, targeted queries look for replies and bounce notices related to outreach messages; the metadata and content needed for the reply thread may then be stored in SprintLead. They are limited to threads initiated or explicitly tracked by SprintLead.

SprintLead's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the requirements of Limited Use.

Concretely:

Gmail data is never used for advertising

Gmail data is never sold

Gmail data is never used to train AI models

Gmail data is never transferred to third parties, except to provide and improve the service to the user, or when required by law

No human reads your Gmail data, unless you explicitly agree to it or require security

English

SprintLead's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We only request the gmail.send scope by default, used to send emails composed by the user from their own connected Gmail account. Reply and delivery-failure synchronization requires a separate grant of the gmail.readonly scope. This restricted scope is not currently requested from public users; the feature remains unavailable until Google verification is confirmed. Without that grant we do not read the inbox. When enabled, targeted queries find replies and bounce notices related to outreach messages, and the response thread data needed by the product may be stored only for threads initiated or explicitly tracked by SprintLead. Google user data is not used for advertising, sold, or used to train AI models.

Data Protection and Google User Data Security

We implement technical, organizational, and security measures designed to protect Google user data, including data processed through the Gmail API scopes gmail.send and, when separately authorized, gmail.readonly. Google user data is used only to provide user-facing email sending, reply synchronization and deliverability protection requested by the user. Public reply synchronization is currently disabled pending Google verification.

Encryption in Transit

All data transmitted between the user's browser, our application, our servers, and Google APIs is protected using secure communication protocols, including TLS/SSL. We require encrypted HTTPS connections for authentication, authorization, API requests, and any transfer of Google user data.

Encryption at Rest

OAuth access tokens, refresh tokens, authentication credentials, and other sensitive identifiers stored by our systems are encrypted at rest using AES-256 encryption or an equivalent industry-standard encryption mechanism. These credentials are stored only for the purpose of maintaining authorized access necessary to provide the service requested by the user.

Access Control and Human Review

Access to Google user data is strictly limited to automated processing required for operation of the service, specifically to send emails initiated or authorized by the user and, after separate authorization, synchronize related replies and delivery failures. SprintLead personnel do not access, read, review, or manually process Google user data, email content, recipients, or related message data, except when the user expressly requests technical support and such access is necessary to resolve the support request.

Data Retention and Deletion

Temporary data processed for email-sending operations is retained only for the period necessary to perform the requested service, maintain security, troubleshoot delivery issues, or comply with applicable legal obligations. Users may revoke the application's access to their Google Account at any time through their Google Account permissions page. Users may also request permanent deletion of their data at any time by contacting us through the contact details provided in this Privacy Policy.

Google API Services User Data Policy Compliance

SprintLead's use and transfer of information received from Google APIs strictly complies with the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising purposes, do not sell Google user data, do not use Google user data to create or enhance user profiles for unrelated purposes, and do not transfer Google user data except as necessary to provide or improve the user-facing functionality of the application, comply with applicable law, or protect the security and integrity of the service.

Your rights (GDPR)

You have the rights of access, rectification, erasure, portability, opposition and limitation. To exercise them:

Contact: GDPR contact form · Response within 30 days.

Shelf life

Account dataSubscription duration + 3 years
Payment data10 years (accounting obligation)
Technical logs12 months
Prospects professionnelsDuring the outreach relationship, then for 3 years after the last contact or collection; objections are kept in a suppression list
Conversations d’assistanceFor as long as needed to handle the request and secure the service, followed by deletion or anonymization according to the request and applicable obligations

Cookies

Internal audience measurement and, if configured, PostHog are only enabled after you consent. URL parameters, sensitive pages and account identifiers are excluded from this collection. No Google Analytics. No Meta Pixel.

International transfers

Supabase hosts the database in the European Union. Vercel and OpenAI are providers established in the United States; when personal data is transferred to them, the applicable contractual mechanisms, in particular the standard contractual clauses, govern these transfers in accordance with Article 46 of the GDPR.

Contact & complaint

For any questions relating to your personal data: GDPR contact form

You can also file a complaint with the CNIL: cnil.fr (online form available on their website).