Privacy policy
Last updated: 27 July 2026
This policy explains what personal data Leaderstamp collects, why, and what you can do about it. It covers leaderstamp.com and the client portal at portal.leaderstamp.com.
What we collect
When you visit the website
Nothing beyond what any web server records. Our host, Hostinger, keeps standard access logs containing IP address, browser type and pages requested, for security and troubleshooting. We do not use analytics, advertising pixels, or any tracking tools.
When you create an account
| What | Why |
|---|---|
| First and last name | To address you properly |
| Email address | Account access, invoices, service updates |
| Company name | To identify the account |
| Website address | It is the thing we work on |
| Password | Stored only as a bcrypt hash. We cannot read it, and neither can anyone who obtains the database |
When you set up your campaign
Target keywords, competitors, your content management system, whether you want us to publish for you or send drafts, an author name, and anything you tell us to avoid. This is business information about your company rather than personal data, but it is stored alongside your account.
While we work for you
Articles, backlinks, technical findings, ranking positions, and performance figures relating to your website. If you grant us access to your Google Search Console, we retrieve traffic statistics for your site.
What we deliberately do not collect
We never store your website passwords, hosting logins, or credentials of any kind in the portal. Where we publish on your behalf, access credentials are held in a separate encrypted credential store used only by our automation, and are never written to the portal database.
We never see or store card details. Payments go through PayPal, who handle the transaction entirely.
Why we are allowed to use it
| Purpose | Legal basis |
|---|---|
| Running your account and delivering the service | Performance of a contract |
| Sending invoices and payment reminders | Performance of a contract |
| Keeping the portal secure, preventing abuse | Legitimate interests |
| Keeping accounting records | Legal obligation |
| Replying when you contact us | Legitimate interests |
We do not send marketing email to portal clients unless you ask us to.
Who else sees it
We do not sell personal data and never will. We share it only with the services needed to run the business:
| Service | What for | Where |
|---|---|---|
| Hostinger | Hosting and email | EU |
| PayPal | Payments | EU and US |
| Fonts, and Search Console data if you grant access | US | |
| Web3Forms | Contact form on the marketing site | US |
| [AI providers, if you use them for content] | Drafting article content | US |
| [SEO data providers, if you use them] | Ranking and keyword data | US |
We may also disclose data if the law requires it.
Data leaving Europe
Some of the services above are based outside the European Economic Area. Where that happens, transfers rely on the European Commission's Standard Contractual Clauses or an equivalent safeguard offered by that provider.
How long we keep it
| What | How long |
|---|---|
| Your account and campaign data | While your account is active, then 12 months |
| Work we produced for you | While your account is active, then 12 months |
| Invoices and payment records | As long as tax law requires, normally 5 to 10 years |
| Login attempt records | 14 days |
| Activity history in your portal | 2 years |
| Support conversations | While your account is active, then 12 months |
Ask us to delete your data sooner and we will, except where we are legally required to keep it.
Your rights
If you are in the EEA or the UK, the GDPR gives you the right to:
- Ask what we hold about you and get a copy
- Have inaccurate data corrected
- Have your data deleted
- Restrict or object to how we use it
- Receive your data in a portable format
- Withdraw consent, where we relied on consent
- Complain to a supervisory authority
Cookies
The marketing site sets no cookies at all. The portal sets a single cookie that keeps you logged in. It contains no personal data, expires when your session ends, and the portal cannot work without it, so no consent banner is required.
The full detail is in our cookie policy.
How we protect it
- Everything is served over HTTPS
- Passwords are hashed with bcrypt and are not recoverable, by us or anyone else
- Uploaded files are stored outside the public web directory and served only after checking who is asking
- Login attempts are rate limited
- Your account data is queryable only within your own account
- Client website credentials are kept out of this system entirely
No system is perfectly secure. If a breach occurs that puts your rights at risk, we will tell you and the relevant authority within 72 hours of becoming aware of it.
Children
This is a business service and is not directed at anyone under 18. We do not knowingly collect data from children.
Changes
If we change this policy we will update the date at the top. If the change is significant, we will email account holders.
info@leaderstamp.com