← Back to LeadLockr

LeadLockr

Privacy Policy

Effective Date: July 20, 2026

1. Who We Are

LeadLockr is operated by Calls From Clicks LLC, an online presence and AI communication platform for home service contractors. This policy covers visitors to leadlockr.ai, contractors who use the LeadLockr platform, and the homeowners and customers who communicate with those contractors through it.

2. Information We Collect

We collect information in three groups:

  • From website visitors and prospects: name, email, phone, and business information submitted through forms or blueprint requests.
  • From contractor clients (platform users): business profile, EIN, service area, the dedicated business phone line we provision, and account login data. Passwords are stored bcrypt-hashed and never in plaintext.
  • From communications routed through the platform: SMS and voice conversation history between a contractor and their customers, voice call recordings and transcripts, lead events, job records, and photo uploads.
  • From accounts a contractor chooses to connect: if a contractor connects their Google Business Profile, we access their business listing, its reviews, and its profile-activity metrics. This is optional and covered in detail in Section 9.

3. How We Use Information

We use information to deliver and operate the service.

  • Build and maintain each contractor's website and listings.
  • Operate the business phone line, the AI receptionist, and missed-call auto-text.
  • Power AI-assisted responses through Lockr.
  • Respond to inquiries and send service-related updates.

We also use anonymized, aggregated patterns across all contractors to improve the platform for everyone. See Anonymized Aggregate Data below.

4. AI Processing

Routine customer messages and unanswered calls may be handled by our AI assistant, Lockr, which uses Claude by Anthropic for reasoning. Under Anthropic's commercial terms, conversation data is not used to train Anthropic's models.

Contractors control whether AI is enabled and can take over any conversation. Voice calls handled by AI are recorded and transcribed, and this is disclosed on the call.

5. SMS & Mobile Privacy

You may receive automated SMS messages from a LeadLockr business number, including replies from an AI receptionist when texting a business and an automated text when a call goes unanswered. Message frequency varies, and message and data rates may apply.

  • Mobile numbers are used only for communications related to your inquiry or service.
  • Mobile information is never shared with third parties for marketing or promotional purposes.
  • Reply STOP to opt out and HELP for help.
  • We do not sell, rent, or share mobile numbers.

6. Anonymized Aggregate Data

Separately from any individual's data, we use anonymized, aggregated signal across all contractors, such as which platforms perform for which trades and which approaches convert in which regions, to improve the platform.

This aggregate signal is not tied to any individual and is not personal data. We do not sell individual data or provide it to third parties to train their AI models.

7. Data Security

We build security into the platform.

  • Data is encrypted at rest.
  • Every Twilio webhook is cryptographically verified.
  • Public forms and intake surfaces are rate-limited.
  • Admin destructive actions are logged to an audit trail.
  • Passwords are bcrypt-hashed.

We are not SOC 2 certified yet and will say so when we are. We do not make vague claims about security. For full detail, see our Trust page.

8. Third-Party Services

We use trusted providers for hosting, email, Twilio for telephony, and Anthropic for AI. These providers process data only as needed to deliver platform functionality. Where a contractor connects their Google Business Profile, Google is also a source of data covered by the additional terms in Section 9.

9. Connected Google Account Data

Contractors can connect their Google Business Profile to LeadLockr. This is optional, and the platform works without it. This section describes exactly what that connection accesses, because data obtained through Google APIs is handled under stricter rules than the rest of this policy.

What we request. A single permission scope: https://www.googleapis.com/auth/business.manage. We do not request access to Gmail, Drive, Contacts, Calendar, or any other Google service. Connecting delegates the access the contractor's own Google account already has. It does not grant LeadLockr access to any profile they cannot already manage.

What we access and store. The Business Profile accounts and locations that Google account manages; for the location the contractor selects, its profile details (business name, phone, website, categories, hours, address or service area, and services); its reviews, including reviewer name, rating, review text, and any existing owner reply; and Google's aggregate profile-activity counts such as calls, website clicks, and direction requests. We store the authorization token that keeps the connection alive, the selected account and location identifiers, and the profile, review, and activity data needed to render the dashboard.

How the token is protected. The Google authorization token is encrypted at rest using authenticated encryption with a dedicated key, kept separate from the keys protecting other credentials on the platform. If stored token data is altered or corrupted, decryption fails closed and the connection is marked as needing reconnection rather than proceeding.

How we use it. Only to deliver features the contractor can see and use: displaying their Presence dashboard and profile health, and, where the contractor uses the review-response feature, drafting and posting replies to their reviews on their behalf. Review text may be sent to Anthropic's Claude to draft a suggested reply; under Anthropic's commercial terms that data is not used to train Anthropic's models. Drafted replies are posted only when the contractor approves them, or where the contractor has explicitly enabled automatic posting for low-risk reviews.

What we never do with it. We do not sell it. We do not use it for advertising or serve ads against it. We do not use it to train generalized AI models. We do not transfer it to third parties other than the service providers necessary to operate the feature, and we do not include Google account data in the anonymized cross-contractor aggregate signal described in Section 6. Human access is limited to authorized LeadLockr personnel, and only for support the contractor has requested, security investigation, or where the law requires it.

Disconnecting and deletion. A contractor can disconnect Google at any time from the dashboard. Disconnecting revokes LeadLockr's authorization with Google and deletes the stored token. Access can also be revoked directly from the contractor's Google Account permissions page. Deletion of the profile and review data retained from the connection can be requested at any time using the contact details in Section 11.

LeadLockr's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

10. Data Retention & Your Rights

You can request access to or deletion of your personal information by emailing support@leadlockr.ai. We complete requests within 30 days except where records must be retained for legal, tax, or security-audit reasons.

Contractor clients can also export their data on account closure. See the Service Agreement for details.

11. Contact

Questions? Contact support@leadlockr.ai.