Legal
Privacy Policy
What this website collects, what a purchase involves, and what the desktop application does on your own machine. Every statement here describes how the software actually behaves.
- In effect from
- 24 August 2026
- Supplied by
- The Website Labs, Croatia, in the European Union
- Contact
- thewebsitelabs@gmail.com
Section 1: Who is responsible
The controller for the personal data described in this notice is The Website Labs, an individual trader established in Croatia, trading as The Website Labs.
- Contact for anything in this notice — thewebsitelabs@gmail.com. We aim to reply within 3 business days.
- Trading address — The trading address is provided on request — write to the support address and it will be sent to you. It is also held by Creem, the Merchant of Record, as part of its own verification.
- Telephone — We do not operate a telephone support line, so there is no number to give. Every contact route on this site is the one email address above; it reaches the person who answers it, and the target is a reply within three business days.
This notice covers two separate things, and the difference between them matters more here than anywhere else on the site: this website, and the LeadCo desktop application that runs on your own computer.
Section 2: What this website collects
Browsing this website — including running the interactive demonstration — does not require you to give us anything, and we do not collect anything about you in order to let you do it. There are no accounts, no login, no newsletter and no tracking script.
- No analytics or advertising provider. No third-party analytics, advertising or session-recording script is loaded on any page. The site records a short list of interaction events — which page was opened, that a demo run was started — in the browser tab’s own memory so that a provider could be connected later. Nothing is transmitted anywhere, and the list is discarded when you close the tab.
- No cookies and no browser storage. This site’s own code sets no cookies and writes nothing to local or session storage. There is no consent banner because there is nothing to consent to. This is a property of how the site is built today; if that ever changes, this notice and the site change with it in the same release.
- The demonstration. It downloads static files from this site and filters them inside your browser. They contain real public business listings captured once in central London, and deliberately no telephone numbers — only whether a listing has one. The area, radius and filters you choose stay in the page and are not sent anywhere.
- Server request logs. Loading any page means your browser makes a request to our hosting provider, Vercel, which records ordinary request data — IP address, timestamp, the page requested, the user-agent string — as part of operating and securing the service. That happens beneath the application rather than in it. Vercel acts as our processor; see its privacy notice.
Section 3: What a purchase involves
Buying a licence is the only part of this site that collects personal data, and it collects one thing: an email address, so that there is a way to reach you about the licence. There is no account to create and nothing else is asked for.
Your card details never reach us. Payment is taken by Creem (Armitage Labs OÜ) on its own secure page. This website has no card field, receives no card number, and stores no payment instrument of any kind.
What we receive from Creem after a payment, and what we do with it:
- Confirmation that the payment settled, with an order reference, a checkout reference and — for a subscription — a subscription reference. These are stored so a purchase can be traced, so a renewal extends the right licence, and so a refund or chargeback can revoke the right one.
- The email address you gave at checkout. It is collected so that we can reach you about this purchase: where licence delivery by email is connected, to send you the licence key and the download links; and in every case, to answer you if you write to us about it. Your key is shown to you on screen the moment the payment is confirmed, so a purchase never depends on an email arriving.
- The licence we issue — its key, the plan, the machine allowance, the expiry and the update window.
We do not keep a list of customer email addresses. The address passes through the fulfilment process at the moment of delivery and is not written to our database. What is written is a one-way keyed digest of it — HMAC-SHA-256 under a secret key held by this deployment and never stored beside the digest. The key is what that gives you: a plain hash of an email address can be undone by hashing a list of addresses and looking for a match, and lists of addresses are easy to come by, whereas a keyed digest cannot be matched that way by anybody who does not also hold the key. So the stored value is enough for support to confirm that a given address bought a given licence, and is not enough — for us, or for anyone who obtained a copy of the database — to reconstruct an address or to build a mailing list from. The address itself is held by Creem, which needs it as the seller of record.
There is no marketing list, no newsletter and no profiling. We will not email you about anything other than your purchase, your licence and your support requests.
Section 4: When you write to us
Support runs by email. If you write to thewebsitelabs@gmail.com, we receive what you send — your address, your message, and anything you choose to include such as an order reference or a licence key — and we keep the correspondence so that a follow-up makes sense and so we have a record of what was agreed about a purchase.
That mailbox is hosted by Google as our email provider. Please do not send passwords, full card numbers or proxy credentials: we never need them and will never ask for them.
Section 5: What the desktop application handles
LeadCo is desktop software. The work happens on your computer, which is the point of the design rather than an incidental detail of it.
- Searches run from your machine, through the proxy account you supply. This website does not run them, has no endpoint that would receive them, and cannot see them.
- Your proxy credentials are entered in the application’s own settings and stay on that machine. We never receive, hold or control your proxy account or its credentials.
- Results, filters and run history are stored locally on your computer. Finished runs are kept for seven days, or the newest two hundred, whichever comes first. Exports are files you create on your own machine, and we have no access to them.
- Licence checks. Where the application checks your licence key with us, that check carries the key and an identifier for the installation, and nothing else. It does not carry your search terms, your results or your exports — there is no route by which they could reach us, and no endpoint here that would accept them.
Business information the application collects about businesses — names, addresses, categories, and where published, contact details — is collected by you, on your machine, from publicly visible listings. For that data you are the controller, not us, and the obligations that come with it are described in section 6 of the Terms and in the Acceptable Use Policy.
Section 6: Who else is involved
These are every third party that touches this service — the whole list, not a selection. Each is here because it is engaged and configured for this service: a live account, a wired-up integration, or an endpoint the software actually calls. Nothing is listed as planned or coming, because a notice that names a provider you cannot yet reach tells you nothing about where your data is.
Engaged and configured is not the same as having processed data about you. Ordering opens soon. Two of the entries above — Creem and Supabase — are reached only by a purchase, so neither has yet received anything about you or about anyone else. For those two, the list states what each receives when an order is placed; it is not a record of what either already holds.
- Creem (Armitage Labs OÜ, Rotermanni 14, Tallinn 10111, Estonia) — Merchant of Record. Takes the payment, handles tax, holds the customer record and operates the customer portal. Your email address, your payment details and the record of the sale. Your card details go to Creem and never to us. See Creem’s privacy notice.
- Vercel — Hosting for this website, and its request logs. Your IP address, the time of the request, the page you asked for and your user-agent string — the ordinary record a web server keeps in order to serve and secure a site. See Vercel’s privacy notice.
- Supabase — The managed Postgres database behind purchases and licensing. Order, checkout and subscription references, the licence we issued, and a one-way keyed digest (HMAC-SHA-256) of your email address. The address itself is not written to it. See Supabase’s privacy notice.
- Google — The mailbox behind our support address. Whatever is in an email you send us and in our reply — your address, your message, and anything you choose to include such as an order reference. It is used for correspondence only. No marketing list, no newsletter and no contact export exists. See Google’s privacy notice.
- OpenFreeMap — The basemap under the demonstration map. Your IP address and which map tiles you looked at. Your browser fetches them itself, so those requests reach the provider directly rather than passing through us. The tiles are built from OpenMapTiles and OpenStreetMap data. No API key, no account and no cookie is involved. See openfreemap.org.
- OpenStreetMap Nominatim (operated by the OpenStreetMap Foundation) — The geocoder inside the desktop application: it answers the Where box, and it names the town under your pin whenever a scrape starts. The coordinates of your pin, or the place name you typed, and the IP address of the machine you run the application on. Your own computer makes that request — it does not pass through us, and it does not go through your proxy either. It carries no search terms, no categories, no filters and no results: a coordinate goes out and a town name comes back. See the OpenStreetMap Foundation’s privacy policy.
- CARTO — The basemap under the desktop application’s own map. Your IP address and which map squares the application drew, which is to say roughly where on the map you are working. As with the geocoder, your computer fetches them itself rather than through us or through your proxy. The tiles are built from OpenStreetMap data. The tile address in the build carries no key, and there is no account behind it. See CARTO’s privacy notice.
- ipify — The address-echo service behind the desktop application’s Test Proxy button: it answers “what address is this request coming from?” so the application can show you the egress address your proxy provider gave you. One request with no payload, sent through the proxy you configured — so the address ipify sees is your provider’s egress address, not your machine’s own. It also sees the application’s user-agent string. Nothing about the call reaches us. Called only when you press Test Proxy, and treated as informational by the application: an ipify outage can never fail the proxy check, and no scrape traffic touches it. See ipify.org.
Creem is an independent controller for the customer record it holds as seller of record, not our processor — which is why a request to erase the email address itself is answered by pointing you at Creem, as section 8 explains. OpenFreeMap is neither: your own browser fetches those tiles, so we never see the request.
Fonts and scripts are served from this site itself: no font or script CDN sees your visit. There is no advertising network, no analytics provider, no chat widget and no tag manager — a provider not named above is a provider that is not there. Where a provider is outside the European Economic Area, transfers are made under the European Commission’s standard contractual clauses or an equivalent approved mechanism.
Section 7: Why we are allowed to hold it, and for how long
- Your purchase and licence records — processed to perform the contract you entered into. Kept for as long as the licence may be relied on, and thereafter for as long as tax and accounting law requires records of a sale to be kept.
- Support correspondence — processed on the basis of our legitimate interest in answering you and keeping a record of what was agreed. Kept for two years from the last message, unless it relates to a purchase, in which case it follows the record above.
- Hosting request logs — processed on the basis of our legitimate interest in operating and securing the site. Retention is set by the hosting provider.
We do not use personal data for automated decision-making that produces legal or similarly significant effects, and we do not sell or rent it to anyone.
Section 8: Your rights
Under the General Data Protection Regulation you may ask us for a copy of the personal data we hold about you; to correct it; to erase it; to restrict or object to how we use it; and to receive it in a portable form. Write to thewebsitelabs@gmail.com and we will respond within one month.
One practical note, because it affects what we can actually do for you. Since we hold your email address only as a one-way hash, an access or erasure request will normally be answered from the order reference or licence key you quote. If you want the address itself removed from the record of the sale, that record is held by Creem as seller of record, and we will tell you how to reach them.
If you think we have handled your data badly, please tell us first — most things are put right in one exchange. You also have the right to complain to a supervisory authority: in Croatia that is the Croatian Personal Data Protection Agency (AZOP), and you may alternatively complain to the authority where you live or work.
Section 9: Changes to this notice
We update this notice when what we do changes — a new provider, a new feature, a change in the law. The version in force is the one published on this page, and the effective date at the top of it is the date that version took effect. A material change is made by publishing a revised version here under a new effective date. We keep no notification list and send no change announcements, so the page itself is the notice — the effective date tells you whether anything has changed since you last read it.
That includes a change materially affecting how we handle data about an existing customer: it is published here, under a new effective date, in the same way as any other change. We do not hold a list of customers to write to — as section 3 explains, the address itself is never stored — so the page is where to look.
Questions about this document, or about anything else: thewebsitelabs@gmail.com. We aim to reply within 3 business days.