TL
TrueLead
ES ← Back to home

TrueLead Privacy Policy

Last updated: September 22, 2026 Effective date: September 22, 2026

This document is a template prepared for Sareli Labs S.A.S. and must be reviewed by a licensed attorney in the relevant jurisdictions (including the EU/EEA, Mexico, and California) before publication.

1. Introduction and Scope

TrueLead ("TrueLead", "we", "us", or "our") operates the website at https://trueleadapp.com/ and provides a business-to-business software-as-a-service platform (the "Service") that offers real-time email and phone number validation through a web dashboard and a REST API. Our customers submit their own contact lists to the Service so that those email addresses and phone numbers can be validated (for example: syntax checks, domain/MX-record checks, disposable-email detection, mailbox verification, carrier detection, line-type detection, and international-format normalization). TrueLead is not a lead-generation, scraping, or contact-discovery service; we do not supply contact data to our customers.

This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data, and the rights available to you under:

  • the EU/EEA General Data Protection Regulation ("GDPR"),
  • Mexico's Ley Federal de Protección de Datos Personales en Posesión de los Particulares ("LFPDPPP"), and
  • the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA").

Two-track scope — please read this carefully

We process personal data in two distinct roles:

Track A — Data of our customers and website visitors (we act as the "data controller" / "responsable"). This covers information about the people who visit our website, create a TrueLead account, use the dashboard or API, pay for a subscription, or contact us for support. This Privacy Policy governs Track A processing in full.

Track B — "Submitted Data" (we act as the "data processor" / "encargado"). "Submitted Data" means the email addresses and phone numbers belonging to third parties that our customers upload or transmit to the Service for validation. For Submitted Data, the customer is the data controller and TrueLead is the data processor. We process Submitted Data only on the documented instructions of the customer, solely to provide the validation Service, and never for our own purposes. Track B processing is governed primarily by the Data Processing Agreement ("DPA") between TrueLead and the customer, supplemented by Section 6 of this Policy.

If you are an individual whose email address or phone number was validated through TrueLead by one of our customers, please direct your privacy requests (access, rectification, deletion, objection, etc.) to that customer, who is the controller of your data. We will assist our customers in responding to such requests as required by the DPA.


2. Who We Are (Controller Identity)

The data controller / responsable for Track A processing is:

  • Name / Denominación: Sareli Labs S.A.S.
  • Registered address / Domicilio: Zapopan, Jalisco, Mexico, Mexico
  • Contact email: hola@trueleadapp.com
  • Website: https://trueleadapp.com/
Action item: The operator must insert the legal entity name and registered address before publication. No EU/UK representative has been appointed yet (see Section 9.6).

3. What We Collect (Track A)

3.1 Account data

When you register for a TrueLead account we collect only:

  • Email address (used as your login identifier and for service communications), and
  • Password (stored only in hashed form by our authentication provider, Amazon Cognito; we never see or store your plaintext password).

We do not collect your name, company name, or other profile data at signup.

3.2 Billing data

Paid subscriptions are billed in Mexican pesos (MXN) through our payment processor, Stripe, Inc. When you subscribe, your payment card details are entered directly into Stripe's systems; TrueLead never sees, receives, or stores full card numbers. We receive from Stripe only limited billing metadata, such as: last four digits of the card, card brand, expiry date, billing status, transaction identifiers, subscription plan, and amounts paid. The 14-day free trial does not require a card.

3.3 Usage and API logs

When you use the dashboard or API we automatically collect:

  • API key identifiers and authentication events;
  • request metadata (timestamps, endpoints called, response codes, volume of validation requests);
  • IP address and user-agent (browser/device information) associated with requests;
  • account activity logs (logins, CSV uploads, validation job history — i.e., job IDs, counts, and status, not the underlying third-party contact data itself, which is covered in Section 6).

3.4 Diagnostic and error data (Sentry)

The application uses Sentry (Functional Software, Inc., United States) for error and performance monitoring. If an error occurs, Sentry may automatically capture technical diagnostic data such as your IP address, browser type and version, device/OS information, URLs visited within the app, and error stack traces. We use this data solely to detect, diagnose, and fix defects and to maintain the security and performance of the Service.

3.5 Support and other communications

If you contact us (for example, at hola@trueleadapp.com), we collect your email address, the content of your message, and any information you choose to include, and we retain the correspondence to handle your request and for record-keeping.

3.6 Website visitors

Our public landing page sets no first-party cookies and uses no analytics or advertising pixels. The page loads fonts and stylesheets from third-party content delivery networks (Google Fonts and Tailwind CDN); as with any web request, your IP address and browser user-agent are transmitted to those providers when the resources are fetched. See our Cookie Policy for full details.


4. How We Use Your Data and Legal Bases (GDPR)

The table below maps each processing purpose to the categories of personal data involved and the legal basis under Article 6 GDPR.

#PurposeCategories of personal dataLegal basis (Art. 6(1) GDPR)
1Create and manage your account; authenticate youAccount data (email, password hash); login logs(b) Performance of a contract
2Provide the validation Service (dashboard, API, bulk CSV validation)Account data; usage/API logs(b) Performance of a contract
3Process subscription payments and manage billing (via Stripe)Billing metadata from Stripe; account email(b) Performance of a contract; (c) Legal obligation (tax/accounting)
4Provide customer support and respond to inquiriesSupport communications; account email(b) Performance of a contract; (f) Legitimate interests (responding to requests)
5Maintain security, prevent fraud and abuse, enforce rate limitsIP addresses, API logs, authentication events(f) Legitimate interests (network and information security; Art. 6(1)(f), Recital 49)
6Error and performance monitoring (Sentry)Diagnostic data (IP, browser/device, error traces)(f) Legitimate interests (service reliability and debugging)
7Comply with legal obligations (tax, accounting, lawful requests)Billing metadata; account data; logs(c) Legal obligation
8Send service-related communications (verification emails, billing notices, security alerts, material changes)Account email(b) Performance of a contract; (c) Legal obligation
9Send optional product updates or marketing emails, if anyAccount email(a) Consent, or (f) Legitimate interests for existing customers (soft opt-in where permitted); you may opt out at any time

We do not engage in automated decision-making or profiling that produces legal or similarly significant effects concerning you.

Legitimate interests balancing

Where we rely on legitimate interests (items 4–6), we have balanced our interests in operating a secure, reliable service against your rights and freedoms, and we apply data-minimization measures (e.g., limited log retention, no advertising use, no sale of data). You may object to processing based on legitimate interests as described in Section 9.


5. Purposes under the LFPDPPP (Aviso de Privacidad — Mexico)

For users in Mexico, this section serves as the aviso de privacidad integral required by the LFPDPPP and its Regulations.

Identidad y domicilio del responsable: Sareli Labs S.A.S., con domicilio en Zapopan, Jalisco, Mexico. Contacto: hola@trueleadapp.com.

5.1 Finalidades primarias (obligatorias)

  • Crear, administrar y autenticar su cuenta de TrueLead;
  • Proveer el Servicio de validación de correos electrónicos y números telefónicos (panel web, API, validación masiva por CSV);
  • Procesar pagos y administrar su suscripción a través de Stripe;
  • Atender solicitudes de soporte técnico y aclaraciones;
  • Cumplir obligaciones fiscales, contables y legales aplicables;
  • Enviar comunicaciones transaccionales del Servicio (verificación de cuenta, avisos de facturación, alertas de seguridad, cambios relevantes en los términos o en este aviso).

5.2 Finalidades secundarias (no obligatorias)

  • Monitoreo de errores y desempeño de la aplicación mediante Sentry;
  • Envío de comunicaciones comerciales o de mercadotecnia sobre productos y actualizaciones de TrueLead (solo si usted no se opone).

Si usted no desea que sus datos personales sean tratados para las finalidades secundarias, puede manifestarlo en cualquier momento escribiendo a hola@trueleadapp.com. La negativa para el uso de sus datos en finalidades secundarias no será motivo para negarle el Servicio.

5.3 Datos personales que recabamos

Correo electrónico de la cuenta; contraseña (almacenada únicamente en forma cifrada/hash por Amazon Cognito); datos de facturación proporcionados por Stripe (nunca el número completo de la tarjeta); datos de uso y bitácoras (dirección IP, navegador, registros de API); datos de diagnóstico (Sentry); y contenido de comunicaciones de soporte. No recabamos datos personales sensibles.

5.4 Transferencias de datos personales

Sus datos personales son transferidos y almacenados en infraestructura ubicada en los Estados Unidos, específicamente con los encargados y terceros descritos en la Sección 7 de este aviso (Amazon Web Services, Stripe, Sentry, Google Fonts/Tailwind CDN). Dichas transferencias son necesarias para la prestación del Servicio conforme al artículo 37 de la LFPDPPP y/o cuentan con su consentimiento tácito al usar el Servicio, salvo que la ley exija consentimiento expreso, en cuyo caso lo solicitaremos por separado.

5.5 Medios para ejercer derechos ARCO y revocar el consentimiento

Usted tiene derecho de Acceso, Rectificación, Cancelación y Oposición (ARCO) respecto de sus datos personales, así como a revocar el consentimiento que haya otorgado y a limitar el uso o divulgación de sus datos. Para ejercer estos derechos:

  1. Envíe una solicitud al correo hola@trueleadapp.com con el asunto "Derechos ARCO", indicando: su nombre, el correo electrónico registrado en su cuenta, el derecho que desea ejercer, y una descripción clara de su solicitud, acompañada de documentos que acrediten su identidad.
  2. Daremos respuesta en un plazo máximo de 20 días hábiles contados a partir de la recepción de la solicitud, conforme a la LFPDPPP, y, de resultar procedente, la haremos efectiva dentro de los 15 días hábiles siguientes.
  3. Para revocar su consentimiento o limitar el uso/divulgación, utilice el mismo medio; la revocación puede implicar que no podamos seguir prestando el Servicio.

5.6 Medios para actualizar sus datos y cambios al aviso

Puede actualizar su correo electrónico desde la configuración de su cuenta o escribiéndonos. Cualquier cambio a este aviso de privacidad será comunicado a través del correo registrado y/o un aviso visible en el sitio web, conforme a la Sección 12.


6. Submitted Data — Processing on Behalf of Customers (Track B)

When our customers upload or transmit third-party email addresses and phone numbers for validation ("Submitted Data"), TrueLead acts solely as a data processor under the GDPR (Art. 28), an encargado under the LFPDPPP, and a service provider / contractor under the CCPA/CPRA. Our handling of Submitted Data is as follows:

  • Instructions only. We process Submitted Data only on the customer's documented instructions (i.e., to perform the requested validation), as set out in the DPA and the customer's configuration of the Service.
  • Transient, purpose-limited processing. Submitted Data is processed to perform the requested validation checks (syntax, domain/MX, disposable-domain detection, mailbox verification, carrier/line-type lookup, format normalization) and to return the validation results to the customer. Processing is transient and limited to what is necessary to provide the Service.
  • No enrichment, no sale, no secondary use. We do not enrich, combine, profile, sell, rent, share, or otherwise monetize Submitted Data; we do not use it for advertising; we do not use it to build or augment any database of contacts; and we do not disclose it to third parties except to the sub-processors listed in Section 7 strictly as needed to operate the Service.
  • Retention and deletion. Submitted Data and validation results are retained only for as long as needed to provide the Service and as configured by the customer (e.g., availability of job results in the dashboard), and are deleted or returned in accordance with the DPA upon termination of the service or upon the customer's documented instruction, subject to short backup/log cycles described in Section 8.
  • Assistance with data-subject requests. As noted in Section 1, individuals whose data appears in Submitted Data should contact the relevant customer (the controller). We will reasonably assist customers in fulfilling access, deletion, objection, and other data-subject requests relating to Submitted Data, as required by the DPA.

For full details (security obligations, sub-processor authorization, audit rights, breach notification, international transfer safeguards, and deletion timelines), please refer to the Data Processing Agreement, available upon request at hola@trueleadapp.com.


7. Sub-Processors and Third-Party Recipients

We use the following sub-processors and third-party service providers:

ProviderRole / serviceLocationData involved
Amazon Web Services, Inc. (S3, CloudFront, API Gateway, Cognito)Hosting, storage, content delivery, API infrastructure, user authenticationUnited States (us-east-1)Account data (email, password hash), Submitted Data in transit/at rest, logs, IP addresses
Stripe, Inc.Payment processingUnited StatesBilling metadata; card details are entered into and processed by Stripe directly
Sentry (Functional Software, Inc.)Error and performance monitoringUnited StatesDiagnostic data: IP address, browser/device information, error traces
Google Fonts (Google LLC)Web font delivery (landing page)United States / global CDNVisitor IP address and user-agent at page load
Tailwind CDN (Tailwind Labs / CDN provider)Stylesheet delivery (landing page)Global CDNVisitor IP address and user-agent at page load

Notes:

  • Google Fonts / Tailwind CDN: when you load our landing page, your browser requests font and stylesheet files from these CDNs, which necessarily transmits your IP address and browser user-agent to the provider. Google's processing is governed by the Google Privacy Policy (https://policies.google.com/privacy). These requests involve no cookies set by us; see our Cookie Policy.
  • We do not sell personal data and do not share it with advertisers or data brokers.
  • We may also disclose personal data if required by law, regulation, legal process, or enforceable government request, or to protect the rights, property, or safety of TrueLead, our customers, or others.
  • In the event of a merger, acquisition, or sale of assets, personal data may be transferred as part of the transaction, subject to the protections described in this Policy; we will notify you before your data becomes subject to a different privacy policy.

8. Retention Schedule

Data categoryRetention period
Account data (email, password hash)Life of the account; deleted or anonymized within 90 days after account closure, except as needed to comply with statutory (e.g., tax/accounting) obligations
Billing metadataFor the duration of the subscription and thereafter for the statutory limitation periods applicable to tax and accounting records (under Mexican law, generally 5 years)
Usage / API logs90 days for operational logs; up to 12 months for security-relevant logs, after which they are deleted or anonymized
Sentry diagnostic dataPer our Sentry configuration, 90 days, then deleted or aggregated
Support communicationsUp to 24 months after resolution of the inquiry, unless a longer period is needed for legal claims
Submitted Data and validation results (Track B)Only as long as needed to provide the Service and per the customer's configuration; deleted or returned per the DPA upon instruction or termination, subject to backup cycles of up to 30 days
Consent/opt-out records (marketing)For as long as needed to demonstrate compliance

Bracketed periods must be confirmed against actual system configuration before publication.


9. Your Privacy Rights

You can exercise any of the rights below by emailing hola@trueleadapp.com from the email address associated with your account (or otherwise verifying your identity). We respond within the timeframes required by applicable law (GDPR: one month, extendable; LFPDPPP: 20 business days; CCPA/CPRA: 45 days, extendable).

9.1 GDPR rights (EU/EEA users)

  • Right of access (Art. 15): obtain confirmation and a copy of your personal data.
  • Right to rectification (Art. 16): correct inaccurate or incomplete data.
  • Right to erasure (Art. 17): request deletion ("right to be forgotten"), subject to legal retention obligations.
  • Right to restriction of processing (Art. 18).
  • Right to data portability (Art. 20): receive your data in a structured, commonly used, machine-readable format.
  • Right to object (Art. 21): object to processing based on legitimate interests, and to direct marketing at any time.
  • Right to withdraw consent (Art. 7(3)): where processing is based on consent, withdraw it at any time without affecting prior lawfulness.
  • Right not to be subject to solely automated decision-making with legal or similarly significant effects (Art. 22) — we do not engage in such processing.

9.2 LFPDPPP rights (Mexico — derechos ARCO)

Access, Rectification, Cancellation, and Opposition; revocation of consent; and limitation of use or disclosure, exercisable as described in Section 5.5 above.

9.3 CCPA/CPRA rights (California residents)

Categories of personal information collected (in the preceding 12 months): identifiers (email address, IP address); commercial information (subscription plan, transaction records via Stripe); internet or other electronic network activity information (API logs, device/browser data, diagnostic data); and professional or employment-related information only if you volunteer it in support communications. We collect this information for the business purposes described in Sections 4–5 and retain it per Section 8.

Sources: directly from you; automatically from your use of the Service; and from our payment processor (Stripe).

Disclosure for business purposes: to the service providers listed in Section 7.

  • No sale; no sharing for cross-context behavioral advertising. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising purposes. We have not done so in the preceding 12 months. We do not knowingly collect, sell, or share personal information of consumers under 16.
  • Right to know/access: request the categories and specific pieces of personal information we have collected about you.
  • Right to delete: request deletion, subject to statutory exceptions.
  • Right to correct: request correction of inaccurate personal information.
  • Right to opt out of sale/sharing: not applicable, as we do not sell or share personal information.
  • Right to limit use of sensitive personal information: not applicable; we do not collect sensitive personal information as defined by the CPRA.
  • Non-discrimination: we will not discriminate against you (including by denying service, charging different prices, or providing a different level of quality) for exercising any CCPA/CPRA right.
  • Authorized agents: you may designate an authorized agent to submit requests on your behalf; we may require verification of the agent's authority and your identity.

9.4 Verification

To protect your data, we verify requests by matching them against the email address on file and may request additional information proportionate to the sensitivity of the request.


10. International Data Transfers

Our infrastructure is located in the United States (AWS us-east-1), and our key sub-processors (AWS, Stripe, Sentry) are US-based. Personal data of EU/EEA and Mexican users is therefore transferred to and processed in the United States.

  • EU/EEA transfers: where we transfer personal data from the EEA to the United States or other third countries without an adequacy decision, we rely on appropriate safeguards under Chapter V GDPR, in particular the European Commission's Standard Contractual Clauses (SCCs) (Module 2 controller-to-processor or Module 3 processor-to-processor, as applicable) incorporated into our agreements with sub-processors and into our DPA, supplemented where necessary by additional technical and organizational measures (e.g., encryption in transit).
  • Mexico: transfers are made as described in Section 5.4 and in accordance with the LFPDPPP.
  • You may request a copy of the applicable transfer safeguards (redacted as needed) by emailing hola@trueleadapp.com.

11. Security Measures

We implement technical and organizational measures appropriate to the risk, including:

  • Encryption in transit (TLS/HTTPS) for all connections to the website, dashboard, and API;
  • Authentication via Amazon Cognito with hashed password storage and API-key-based access to the API;
  • AWS infrastructure with its physical, network, and operational security controls;
  • Access controls limiting personnel access to personal data on a need-to-know basis;
  • Session tokens stored in browser localStorage (strictly necessary for authentication — see Cookie Policy);
  • Error monitoring (Sentry) to detect and remediate incidents.

No method of transmission or storage is 100% secure. If we become aware of a personal data breach affecting your data, we will notify you and the competent authorities as required by applicable law.


12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified by email to the address registered on your account and/or by a prominent notice on the website before they take effect. The "Last updated" date at the top indicates the latest revision. For Mexican users, changes to the aviso de privacidad will be communicated through these same channels.


13. Cookies

Our use of cookies and similar technologies is described in our separate Cookie Policy. In short: our website currently sets no first-party tracking or advertising cookies, and the only browser storage we use is strictly necessary for authentication.


14. Marketing Communications and Opt-Out

We may send you service-related communications (verification, billing, security, policy changes); these are not marketing and cannot be opted out of while you maintain an account. Any optional product-update or marketing emails include an unsubscribe link; you can also opt out at any time by emailing hola@trueleadapp.com. We honor opt-outs promptly.


15. Children's Privacy

The Service is intended for business users aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us personal data, contact us at hola@trueleadapp.com and we will delete it.


16. Contact and Complaints

  • Contact / data protection requests: hola@trueleadapp.com
  • Controller: Sareli Labs S.A.S., Zapopan, Jalisco, Mexico
  • EU/EEA: you have the right to lodge a complaint with your local data protection supervisory authority (a list is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en).
  • Mexico: you may file a complaint or procedure for the protection of ARCO rights before the competent transparency and personal-data-protection authority (the Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI) or its successor authority responsible for personal data protection in the private sector). Consult https://home.inai.org.mx/ or the current competent authority for details.
  • California: you may also contact the California Privacy Protection Agency (https://cppa.ca.gov/) or the California Attorney General regarding your CCPA/CPRA rights.

EU representative — action item

Action item (GDPR Art. 27): TrueLead has not appointed a representative in the EU/EEA. Because the Service is offered to users in the EU/EEA and their data is processed in the United States, the operator must assess whether the Art. 3(2) GDPR extraterritorial scope applies and, unless an exemption applies, appoint an EU representative and update this Policy with the representative's name and contact details before publication.

Template notice: This document is a drafting template and does not constitute legal advice. It must be reviewed and adapted by a licensed attorney qualified in the applicable jurisdictions before publication or use.

© 2026 TrueLead — Sareli Labs S.A.S., Zapopan, Jalisco, Mexico.
hola@trueleadapp.com
Terms Privacy Cookies DPA Refunds Acceptable Use