This Privacy Policy (the “Policy”) describes how Self Serve Leads (“Company,” “we,” “us,” or “our”) collects, uses, discloses, retains, and safeguards personal information in connection with (a) our website, account portal, and APIs (the “Site”), and (b) the data files and audience-building services we make available to our business customers (collectively, with the Site, the “Services”). This Policy applies to personal information of website visitors, prospective and active customers, and the individuals whose records appear in the audience data we license.
1. Roles
With respect to website visitors and account holders, Company acts as a “business” / “data controller.” With respect to records made available within the Licensed Data, Company acts as a “business” / independent “data controller” of the source dataset and our customers act as independent businesses or controllers from and after delivery. Company is not a “service provider” or “processor” to its customers and does not handle personal data on a customer’s behalf.
2. Categories of Personal Information We Collect
(a) Information you provide directly
- Account information: name, business name, business email, business address, business phone, and login credentials;
- Billing information: billing contact, billing address, and payment-card tokens (full card data is handled by our PCI-DSS-compliant payment processor and is not stored by us);
- Communications: messages you send to support, sales, or compliance and any attachments;
- Compliance attestations: certifications you provide about your intended use of the Licensed Data.
(b) Information collected automatically
- Device and connection data: IP address, user-agent string, browser type, operating system, language, referring/exit URLs, and time-stamped log entries;
- Usage data: pages viewed, features used, downloads initiated, and API calls;
- Cookies and similar technologies: strictly necessary cookies, preference cookies, and limited analytics cookies (see Section 9).
(c) Information within the Licensed Data
The Licensed Data may include business and consumer identifiers such as name, postal address, email address, telephone number, and hashed equivalents suitable for upload to advertising platforms. Records are sourced from third-party data suppliers and self-reported survey/opt-in channels. Company does not collect special categories of personal data (e.g., government identifiers, financial account numbers, precise geolocation, biometric data, or health data) for inclusion in the Licensed Data.
3. How We Use Personal Information
- To provide, operate, secure, and improve the Services;
- To process orders, deliver Licensed Data, and provide customer support;
- To verify customer eligibility, prevent fraud and abuse, and enforce our Terms of Service and Acceptable Use Policy;
- To send transactional and service-related communications;
- To send marketing communications to business contacts where permitted (with an opt-out in each message);
- To comply with law, respond to lawful requests, and protect our legal rights and the safety of users and the public;
- To make Licensed Data available to vetted business customers for the Permitted Use described in our Terms of Service.
4. Legal Bases (for individuals in the EEA/UK)
Where the EU/UK GDPR applies, we process personal information on the bases of (i) performance of a contract, (ii) compliance with legal obligation, (iii) our legitimate interests in operating, securing, and growing our business and in enabling lawful B2B advertising, balanced against the rights and interests of data subjects, and (iv) consent where required. You may object to processing based on legitimate interests as described in Section 7.
5. Disclosure of Personal Information
We disclose personal information only as follows:
- To customers: Licensed Data is made available to vetted business customers solely for the Permitted Use defined in our Terms of Service;
- To service providers / processors: hosting, storage, content delivery, payment processing, analytics, customer support, fraud detection, and professional advisors, in each case bound by written confidentiality and data-protection obligations;
- To data suppliers and partners: for reconciliation, suppression, and compliance verification;
- For legal reasons: to comply with law, valid legal process, or government request; to enforce our Terms; to investigate or prevent fraud, abuse, or harm; or to protect rights, property, or safety;
- In a corporate transaction: in connection with a merger, acquisition, financing, reorganization, or sale of assets, in which case successor entities will be bound by commitments at least as protective as this Policy.
We do not knowingly disclose personal information for any purpose that would constitute a “sale” of personal information of a known minor under sixteen (16) years of age.
6. International Data Transfers
We are based in the United States and our Services are hosted in the United States. If you access the Services from outside the United States, you acknowledge that your information will be transferred to, stored, and processed in the United States and other jurisdictions that may not provide the same level of data-protection rights as your home jurisdiction. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.
7. Your Rights and Choices
Subject to applicable law (including CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, and GDPR/UK GDPR), you may have the right to:
- Know or access the categories and specific pieces of personal information we hold about you;
- Request correction of inaccurate personal information;
- Request deletion of personal information, subject to legal exceptions;
- Opt out of the “sale” or “sharing” of personal information, or of targeted-advertising / cross-context behavioral advertising uses;
- Limit use or disclosure of sensitive personal information (we do not knowingly process sensitive personal information in the Licensed Data);
- Withdraw consent where processing is based on consent;
- Lodge a complaint with a supervisory authority.
To exercise any of the foregoing rights, email privacy@selfserveleads.com or submit a request through our online form. We will verify your identity using reasonable means proportionate to the sensitivity of the request and respond within the time required by applicable law. You may use an authorized agent where permitted. We will not discriminate against you for exercising any privacy right.
Do-Not-Sell / Do-Not-Share / Targeted-Advertising Opt-Out. To request that your personal information not be included in any Licensed Data delivered to customers for custom-audience purposes, submit a request to privacy@selfserveleads.com. We honor Global Privacy Control (GPC) signals received from your browser as a valid opt-out for the browser from which the signal is sent.
8. Data Retention
We retain personal information for as long as necessary to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. Specific retention periods depend on the category of data and applicable legal requirements. When personal information is no longer required, we delete or de-identify it using commercially reasonable measures.
9. Cookies and Analytics
We use a limited set of cookies and similar technologies to operate the Site, remember preferences, secure sessions, and measure aggregate usage. You may manage cookies through your browser settings; disabling certain cookies may impair functionality. We do not use cross-site advertising cookies on the Site for re-targeting consumers.
10. Security
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, alteration, disclosure, or destruction, including encryption in transit, role-based access controls, logging, and least-privilege provisioning. No system is perfectly secure, and we cannot guarantee absolute security.
11. Children
The Services are intended for businesses and individuals at least eighteen (18) years of age. We do not knowingly collect personal information from children under the age of thirteen (13). If we learn that we have inadvertently collected such information, we will delete it.
12. Third-Party Sites and Platforms
The Site may link to third-party websites or platforms. We are not responsible for the privacy practices of those third parties. Once Licensed Data is uploaded by a customer to a third-party advertising platform, that platform’s privacy policy and terms govern the further handling of that data by the platform.
13. State-Specific Disclosures
California (CCPA/CPRA)
In the preceding twelve (12) months, we have collected the categories of personal information identified in Section 2 from the sources identified in Section 2, for the purposes identified in Section 3, and disclosed those categories as identified in Section 5. We disclose business and consumer identifiers to our business customers for the Permitted Use; depending on interpretation, such disclosures may be deemed a “sale” or “share” under the CCPA/CPRA, and California residents may opt out as described in Section 7.
Virginia, Colorado, Connecticut, Utah, and other state laws
Residents of these states may exercise the rights described in Section 7. We will respond within the time required by the applicable state law. You may appeal a denial of your request by replying to our response email.
14. Changes to this Policy
We may update this Policy from time to time. Material changes will be indicated by an updated “Effective Date” at the top of this page and, where required, by additional notice.
15. Contact Us
Privacy questions and rights requests: privacy@selfserveleads.com. Legal notices: legal@selfserveleads.com.