Legal
Privacy Policy
Last updated: April 26, 2026
1. Introduction
CertLeads.com ("CertLeads", "we", "us") operates a B2B lead-generation service that surfaces newly-registered domains and the public business contact information associated with them. This policy explains what data we collect, why we collect it, how long we keep it, and how you can request access, correction, or removal.
We focus exclusively on business information. We do not target consumers and we do not knowingly collect data about private individuals acting outside a commercial capacity.
2. Data we collect
CertLeads sources data from public, lawful channels:
- Domain registrations — newly-issued certificates observed in public Certificate Transparency (CT) logs. CT logs are operated by Google, Cloudflare, Let's Encrypt and others and are publicly auditable by design.
- Public website metadata — page titles, meta descriptions, detected language, country, platform (e.g. WordPress, Shopify), SEO indicators, and Open Graph thumbnails fetched from a domain's public homepage and a small number of public pages such as
/contactand/about. - Business contact information — generic role-based emails (such as
info@,sales@,contact@), business phone numbers, and links to public social profiles, where these are voluntarily published on the website. - Domain registration metadata — registration date, registrar name, and whether WHOIS privacy is enabled. This is used solely to apply our 180-day freshness gate. Personal WHOIS fields (registrant name, email, phone, organization, country) are stored internally for that verification step and are never exposed in any product surface, export, API response, or CSV download.
- Account data — if you sign up for an account, we collect your email, hashed password, plan, and usage history (reveals, exports, saved searches).
- Payment data — handled directly by Stripe. We store a customer ID and invoice records but do not store full card numbers.
3. How we use the data
- To populate our directory of newly-launched businesses.
- To classify and enrich each lead with category, platform, language, SEO score, and contact-completeness signals.
- To verify that a domain is genuinely newly registered (within the past 180 days) before surfacing it.
- To provide accounts, billing, and customer support.
- To respond to opt-out and removal requests.
- To detect abuse, prevent fraud, and secure our service.
4. Lawful basis for processing
We process business contact information on the basis of legitimate interest in supporting B2B outreach. We have performed a balancing assessment and concluded that:
- The data is already published by the business owner on a public-facing website and is intended to be read.
- The data we expose is limited to business contact details (role-based email, business phone, public social handles) — not personal addresses or identification numbers.
- An easy, free, public opt-out is available at any time at /opt-out, and is respected within seven days across all exports.
For account holders, we additionally process data to perform our contract with you (providing the service you signed up for) and to comply with our legal obligations (tax, accounting, anti-fraud).
5. Data retention
- Lead records — kept while the underlying domain remains active and within scope. Domains older than 180 days from registration are dropped from the freshness pipeline. Inactive or removed domains are archived from the public directory.
- Opt-out records — retained indefinitely so we can prove we honored a removal request and prevent re-ingestion.
- Account data — retained while your account is active. On account deletion, profile and search data are removed within 30 days, with a stub retained for legally-required tax records.
- Logs — operational and security logs are retained for up to 90 days.
6. Country scope
CertLeads lists business metadata (domain, category, and SEO signals) globally. Native business contact details — email and phone — are surfaced only for businesses based in the United States, Canada, Australia, New Zealand, the United Kingdom, Singapore, the United Arab Emirates, and India. We surface and process this B2B contact data under the applicable laws of each market and honor opt-out and removal requests everywhere (see below).
For businesses outside these markets we retain any contact data only for internal analytics, recheck cycles, and quality control. It is never published in our directory, returned via our API, or included in any customer-facing CSV export.
8. Your rights
Subject to applicable law, you have the right to access, correct, port, restrict, or delete personal data we hold about you, and to object to our processing of it.
If you are a business owner and want your domain removed from CertLeads, submit a request at /opt-out. We will confirm receipt within 24 hours and complete removal within 7 days. The opt-out is permanent — once a domain is opted out, it will not be re-ingested in future crawls.
If you are an account holder, you can update your profile from your account settings, export your personal data, or delete your account from the same page. For more complex corrections, email privacy@certleads.com.
You also have the right to lodge a complaint with your local data protection authority.
9. Security
We use industry-standard measures to protect data in transit (TLS) and at rest (encryption). Access to internal systems is restricted to authorized personnel and audited. No system can be guaranteed perfectly secure; we will notify affected users without undue delay in the event of a breach that materially affects them.
10. Children's data
CertLeads is a B2B service and is not directed to children under 16. We do not knowingly collect data about children. If you believe a child has provided us with personal data, please contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top reflects the most recent change. Material changes will be notified to account holders by email at least 14 days before they take effect.
12. Contact us
For privacy questions, data subject requests, or compliance matters, contact us at privacy@certleads.com.
For domain removal requests, please use the dedicated form at /opt-out — it is the fastest route.