Privacy Policy
Last updated 11 September 2026
Gatedleads is a tool for building gated content pages that capture leads. This policy sets out, in plain terms, exactly what personal data the service handles, why it handles it, where it is kept, who else touches it, how long it stays, and how to get a copy or have it removed. It covers two groups of people: account holders (people who sign up and build pages) and page visitors (people who land on a page an account holder has published and enter their email to unlock the content behind it).
Who runs Gatedleads and how to contact us
Gatedleads (“we”, “us”) is an independent software service operated from the United Kingdom. For any privacy question, or to ask for a copy or deletion of your data, email hello@gatedleads.com.
Under UK data protection law we are the data controller for account-holder data (the accounts we run and bill). For the leads captured through an account holder’s published pages, the account holder decides what to collect and why, so they are the controller for those records and we act as their data processor, handling that data on their behalf and on their instructions.
What we collect from account holders
- Email address. Used to identify your account, sign you in, and send you service email. It must be unique to one account.
- Password. Only if you sign up with email and password. It is stored as a one-way bcrypt hash; the plain password is never written to disk and we cannot read it back.
- Google Sign-In data. If you choose “Continue with Google”, your Google email address, name, and profile picture URL. This is set out in full in the Google Sign-In section below.
- Display name. An optional name you can set for your account.
- Branding images. A logo and favicon you can optionally upload to show on your published pages. These are downscaled in your browser and stored as small image data on our database, not in a separate file store.
- Page content. Everything you put into the pages you build: headlines, body text, images, links, colours, SEO title and description, and page settings such as whether to collect a visitor’s name or require email confirmation.
- Billing identifiers (Pro only). If you upgrade, the payment itself is handled by Stripe on Stripe’s own pages. Stripe collects and stores your card details; Gatedleads never sees or stores a card number. We store the Stripe customer ID, the subscription ID, and your current plan so we know what you have access to. Invoices shown in the app are read live from Stripe.
- Sign-in metadata. The time of your most recent sign-in, and whether your email address has been verified.
Google Sign-In
Signing in with Google is optional; you can also use an email address and password. If you do use it, this is exactly what happens.
The scopes we request
When you choose “Continue with Google” we ask Google for three standard OpenID Connect scopes: openid, email, and profile. We request nothing else. We ask for no access to Gmail, Drive, Calendar, Contacts, or any other Google product, and no offline or background access — the sign-in is a one-time exchange that happens while you are on the page.
What those scopes give us
From Google’s user-info endpoint we receive your email address, whether Google has verified that address (sign-in is refused if it has not), your name, and the URL of your Google profile picture. We store your email address, your name (as your account display name, if your account does not already have one), and the profile picture URL (as your avatar, again only if one is not already set). We never receive or store your Google password. We do not store any Google access token or refresh token: the short-lived token returned during sign-in is used once to read the details above and is then discarded.
What we use it for
This data is used solely to create your Gatedleads account, to match you to that account and sign you in on later visits, and to fill in your display name and avatar. Your email address then serves as your account’s contact address for service email, exactly as it would for an account created with email and password. It is not used for any other purpose.
What we do not do with it
We do not sell it. We do not share it with any third party beyond the infrastructure needed to run Gatedleads — our server host, and our email provider when we send service email to your address, both of which are listed in the sharing table below. We do not use it for advertising, to build a profile of you, or to train any AI or machine-learning model.
Revoking access
You can remove Gatedleads’ access to your Google account at any time at myaccount.google.com/permissions. That stops any future Google sign-in. On its own it does not delete the email address, name, and picture URL already stored on your Gatedleads account — to remove those, delete your account (see Getting a copy of your data, or having it deleted below).
How long we keep it
The email address, display name, and profile picture URL are held as ordinary fields on your account for as long as the account exists. If the account is deleted they are deleted with it, along with every page, lead, and analytics record tied to the account. We keep no separate or backup copy of your Google profile data outside that account record.
Our use of data received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
What we collect from visitors to a published page
- The email address a visitor types into the unlock form, plus their name if the page owner turned name collection on. This is the lead the page exists to capture, and it is passed to the account holder who owns that page.
- A traffic source label. A short text tag describing where the visit came from (for example a UTM value carried in the link the visitor followed). It is stored with the lead and the page view so the page owner can see which channels work.
- Page views. Each visit to a published page is counted, with the traffic source label and a timestamp. No name, email, or IP address is stored against a page view — it is a running count, not a visitor log.
- Pending submissions (double opt-in). If the page owner requires email confirmation, the submitted name, email, source, and a one-time confirmation token are held in a separate pending list and a confirmation email is sent. Nothing is recorded as a real lead, and no notification or webhook fires, until the visitor clicks the link. Pending entries that are never confirmed are deleted automatically after 7 days.
- Session analytics and recording. Every Gatedleads page — the marketing site, the app, and every published page — loads a script from a third-party service called SiteBehaviour (served from a DigitalOcean CDN). It records interaction data such as mouse movement, clicks, scrolling, the pages viewed, and approximate device and browser type, and can replay a visit as a session recording so the page owner and Gatedleads can see how pages are used and fix problems. Form field contents are masked in recordings. It is not used to build advertising profiles. This is disclosed in the footer of every published page with a link back to this policy.
Your IP address is read momentarily to rate-limit form submissions and sign-in attempts so the service cannot be flooded. It is held only in memory for that check and is never written to the database.
Why we use this data
- To run the service: to authenticate you, build and serve your pages, and store the leads those pages capture.
- To show analytics: so an account holder can see views, leads, conversion rate, and traffic sources for their own pages.
- To send transactional email: a welcome email when you sign up; a notification to the page owner each time a lead is captured; a confirmation email to the visitor when a page uses double opt-in; team invitations; and billing email from Stripe.
- To forward leads you ask us to forward: if a Pro account holder sets a webhook URL on a page (for example a Zapier or Make hook), each new lead from that page is sent to that URL.
- To keep the service secure and working: rate limiting, abuse prevention, and error monitoring.
The legal bases we rely on under UK GDPR are: performance of a contract (running your account), legitimate interests (keeping the service secure, understanding how pages are used, preventing abuse), and consent where it is required. A page visitor’s data is processed on the instructions of the account holder whose page captured it.
Where the data is stored
Gatedleads runs on a single virtual private server rented from Hostinger, in the United Kingdom. The database is PostgreSQL running on that same server; the application, the database, and any backups all sit within that one UK environment. Passwords are stored only as bcrypt hashes. Server error logs are written to a file on the same machine and may contain a request path and IP address for debugging; they are not an analytics store and are pruned over time.
Who else we share it with
We use a small number of third parties to run the service. We do not sell personal data, and we do not share it with anyone outside this list except the account holder whose page captured a given lead.
| Third party | What it does | What it receives |
|---|---|---|
| Stripe | Takes payment and manages the Pro subscription | Your email and card details (entered on Stripe’s own pages), and subscription status |
| Resend | Delivers our transactional email | The recipient’s email address and the contents of that message |
| SiteBehaviour | Page analytics and session recording on every Gatedleads page | Interaction events and approximate device and browser information |
| Hostinger | Hosts the server the whole service and database run on | All stored data, as the infrastructure provider |
| Optional “Continue with Google” sign-in | Exchanges your email, name, and profile picture URL when you use it | |
| A webhook URL the account holder chooses (e.g. Zapier) | Receives new leads, only if a Pro account holder configures it on a page | The lead’s name, email, source, page, and timestamp |
Primary storage is in the UK. Some of the providers above (Stripe, Resend, Google, and any webhook endpoint an account holder chooses) may process data outside the UK, including in the United States. Where that happens the transfer is covered by the provider’s standard safeguards, such as the UK International Data Transfer Agreement, the EU Standard Contractual Clauses, or an adequacy decision.
How long we keep it
- Free plan: leads and page-view records more than 30 days old are deleted automatically by a daily job. Export your leads to CSV from the dashboard at any time before then if you want to keep them.
- Pro plan: leads and analytics are kept for as long as the account stays active, with no automatic time limit (the analytics screens show up to the last 365 days).
- Unconfirmed double opt-in submissions: deleted automatically 7 days after they are submitted.
- Account data: kept while the account exists. Closing an account deletes the account and every page, lead, and analytics record attached to it.
Getting a copy of your data, or having it deleted
If you are in the UK or EEA you have the right to access, correct, delete, restrict, or port your personal data, and to object to processing we base on legitimate interests. To use any of these rights:
- Account holders: email hello@gatedleads.com from your account address. We will provide an export or delete the account, and everything tied to it, within 30 days. Self-serve account deletion and export inside the app are on the roadmap; until then this email route is how it is done.
- Page visitors: if you gave your email to a page built on Gatedleads and want it gone, use the Request data removal form. Your request comes straight to Gatedleads with a one-click delete that removes your name and email from that page’s lead records and from the pending list — you do not have to contact the page owner. The form does not confirm back to you by email, so that it cannot be used to find out which pages hold a given address. You can also email hello@gatedleads.com.
You also have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk.
Cookies and local storage
Gatedleads does not set advertising or tracking cookies. It uses your browser’s local storage for a few essentials: your sign-in token, which account you are viewing if you belong to more than one, your light or dark theme choice, whether the sidebar is collapsed, and — on a published page — which A/B headline variant you were shown and whether you have already unlocked that page, so it stays consistent for you. The SiteBehaviour script may set its own storage to recognise a returning session for analytics; it is not used for advertising.
Children
Gatedleads is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children.
Changes to this policy
If we change this policy in a way that materially affects how we handle your data, we will update the date at the top and, for account holders, email you before the change takes effect. Continuing to use the service after that date means you accept the updated policy.
Contact
Questions, requests, or complaints: hello@gatedleads.com.