Legal

Privacy

Last updated 28 September 2026 · MapMyLead

This page covers two different groups of people, and they have different rights here: customers who hold an account, and the businesses that appear in leads, who never asked to be in our system at all. The second group is dealt with in section 3, and it is the section most privacy pages leave out.

MapMyLead is the controller for both. Contact: [email protected].

1. If you have an account

We hold your name, email address, a hashed password, your sessions, your credit balance and ledger, the searches you configured and the leads delivered to you. We process it to run the service you asked for (contract), to keep it secure and prevent abuse (legitimate interest), and to meet accounting obligations (legal obligation).

We do not sell it, we do not share it with advertisers, and we do not profile you.

2. Cookies and analytics

One cookie, for your session, set when you sign in. It is strictly necessary, so there is no banner to click. We run no advertising or third-party analytics trackers.

3. If you are a business that appears in a lead

We may hold your business name, address, phone number, website, a published email address, and our own assessment of your site. Where you are a sole trader or the address is a personal one, that is personal data and the following applies to you.

Lawful basis: legitimate interest in business-to-business lead generation, balanced against your interests. We collect only contact details a business publishes for the purpose of being contacted, and nothing behind a login.

Source: commercial map data and your own public website — see data sources.

Recipients: the customer whose search matched you, who then contacts you directly and is responsible for that contact.

Objecting is one email. Write to [email protected] naming the address or number. We suppress it across every account, erase the copies we hold, and block it from ever being delivered again — including to customers whose future searches would have matched you. You do not need an account, a form, or a reason.

4. How long we keep things

Map-derived detail on a lead — address, coordinates, phone, review counts — is erased 30 days after it was collected. The business’s identity and our own assessment are kept so a repeat search recognises a business already delivered rather than charging for it twice.

Account data is kept while the account exists. Ask us to close an account and we anonymise it; the credit ledger is retained, because financial records must be, and it no longer identifies you. Sessions, verification links and rate-limit counters are deleted as they expire.

5. Processors and where data lives

We use a small number of providers to run the service: a hosting provider, a database, a payment processor, an email sender, a map data provider, and a language-model provider used for planning searches and scoring websites. Each is given only what its job requires. Where a provider is outside the EEA, transfers rely on the European Commission’s standard contractual clauses.

Lead scoring sends the business’s public website text and listing fields to the model provider, under that provider’s paid API terms, which do not permit it to be used to train their models. We send no account data with it — not your name, not your email address, and not what you searched for.

6. Your rights

Access, rectification, erasure, restriction, portability and objection, plus the right to complain to your data protection authority. Write to [email protected] and we will answer within a month. A human reads it; there is no ticket system to fight.

7. Security

Passwords are hashed, sessions can be revoked everywhere at once, transport is encrypted, and access to production is limited. API credentials are stripped from anything we log. We run no third-party error-reporting service, so nothing from a failure leaves our own machines. No system is perfect; if a breach affects you, we will tell you.