Privacy Policy
Last updated 2 August 2026
- Who we are and what this covers
- Two different roles: our data and your borrowers' data
- Information we collect
- How we use information
- Borrower data, credit reports and FCRA
- When we share information
- Service providers and subprocessors
- How we protect information
- How long we keep information
- Your privacy rights
- Cookies, analytics and tracking
- Children
- Where data is stored
- Changes to this policy
- How to contact us
1. Who we are and what this covers
LeadClx is loan origination automation software for licensed mortgage professionals. This policy is published by [LEGAL ENTITY NAME], a [STATE] [ENTITY TYPE] ("LeadClx", "we", "us"), whose registered address is [REGISTERED ADDRESS].
It explains how we handle information in connection with the LeadClx website at leadclx.com, the LeadClx application at app.leadclx.com, and any related services (together, the "Services").
LeadClx is a business tool sold to mortgage brokers, loan officers and their firms. We do not sell products to consumers, and we do not have a direct relationship with the borrowers whose information passes through the Services.
2. Two different roles: our data and your borrowers' data
This distinction determines who is responsible for what, so it is worth stating plainly.
| Situation | Our role | What it means |
|---|---|---|
| You visit leadclx.com, join the waitlist, email us, or hold a LeadClx account | We are the controller | We decide why and how that information is used, and this policy governs it directly. |
| Your firm uses LeadClx to process a borrower's loan file | We are a processor acting for your firm | Your firm decides what borrower data enters the system and why. We handle it on your documented instructions, under your agreement with us. Your firm, not LeadClx, is responsible for the notices, consents and permissible purpose required for that data. |
If you are a borrower and want to know how your information is used, contact the mortgage broker or loan officer you are working with. They control that file. We will support them in responding to you, but we cannot act on a borrower's data without their instruction.
3. Information we collect
Information you give us directly
- Waitlist and beta requests. Full name, brokerage name, work email, phone number and team size.
- Account information. Name, work email, phone, role, NMLS number where applicable, and your firm.
- Authentication data. A password or PIN you choose, multi-factor secrets, and the identifier of the hardware security key issued to you. We store credentials in hashed or encrypted form and never in plain text.
- Support and sales correspondence. What you send us when you contact us, including anything you choose to attach.
- Billing details. Where applicable, the contact and payment information needed to invoice your firm.
Information we collect automatically
- Website usage. Aggregate page views and referrers, collected without cookies (see section 11).
- Application logs. IP address, browser and device type, timestamps, and the actions taken in the Services. These are security and audit records: every action in LeadClx is logged to a tamper-evident audit trail.
- Anti-abuse signals. Our forms use Cloudflare Turnstile, which assesses whether a submission is automated.
Information we receive from your connected systems
When your firm connects LeadClx to systems it already uses, LeadClx reads and writes data in those systems using credentials or authorisations your firm supplies. Depending on what you connect, this can include loan files, property data, pricing results, credit report data, documents and CRM records.
4. Borrower data, credit reports and FCRA
Because LeadClx operates on live mortgage files, the data your firm puts into it can be highly sensitive. It may include names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers, income and employment details, asset and liability information, property details, and consumer credit reports.
Consumer reports are handled as a matter of your permissible purpose, not ours. LeadClx does not sell consumer reports and is not a consumer reporting agency. When LeadClx runs or retrieves a credit report, it does so at your direction, using your firm's credentials and your firm's relationship with the credit vendor, under the permissible purpose your firm has established with the borrower under the Fair Credit Reporting Act.
- The Services record consent events, including the type of pull authorised and when it was captured, so your firm has an audit trail. Recording consent in LeadClx is not a substitute for obtaining it.
- Credit report documents are stored encrypted and are accessible only to users your firm has authorised.
- We do not use borrower data to train models, to market to borrowers, or for any purpose of our own beyond providing and securing the Services.
- We never sell borrower data, and we never share it for cross-context behavioural advertising.
5. How we use information
- To provide, operate and maintain the Services, including running the automations your firm configures.
- To authenticate users and protect accounts, including issuing and verifying hardware security keys.
- To detect, investigate and prevent fraud, abuse and security incidents.
- To provide support and respond to your requests.
- To bill your firm and keep the financial records we are required to keep.
- To improve the Services, using aggregate or de-identified operational data rather than borrower records.
- To send service and security notices. These are not marketing and you cannot opt out of them while you hold an account.
- To comply with law and to establish, exercise or defend legal claims.
6. When we share information
We share information only in these circumstances:
- With the systems you connect. LeadClx sends data to and retrieves it from the platforms your firm authorises, because that is the function you are buying.
- With service providers. Vendors who host, secure or support the Services, bound by contract and permitted to use the data only to serve us. See section 7.
- Within your firm. Data is visible to users your firm has authorised, according to the roles your firm assigns.
- For legal reasons. Where required by law, subpoena or court order, or to protect rights, safety or property. Where we are legally permitted to do so, we will notify the affected customer first.
- In a corporate transaction. If we are involved in a merger, acquisition or sale of assets, information may transfer to the successor, which will remain bound by commitments no less protective than these.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
7. Service providers and subprocessors
The main providers involved in delivering the Services:
| Provider | Purpose | Data involved |
|---|---|---|
| Cloudflare | DNS, TLS, DDoS protection, bot mitigation (Turnstile), privacy-preserving web analytics | IP address and request metadata in transit |
| InMotion Hosting | Infrastructure for the marketing site | Website request logs |
| Google Fonts | Web fonts on the marketing site | IP address and browser data when fonts are fetched |
| Loan origination, pricing, credit, telephony and CRM platforms your firm connects | Performing the automations you configure | Whatever the connected workflow requires |
Systems your firm connects are governed by your firm's own agreements with those vendors, not by this policy. A current list of subprocessors is available on request, and customers may ask to be notified of material changes.
8. How we protect information
- Encryption. Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Particularly sensitive fields, including Social Security numbers and dates of birth, receive field-level encryption in addition to disk encryption.
- Dedicated infrastructure. The application runs in a private United States data centre on infrastructure we control, not in shared public hosting.
- Hardware-backed authentication. Access requires a physical FIDO security key together with a PIN. This is mandatory rather than optional, because the Services hold borrower data and act inside your lending systems on your behalf.
- Least privilege. Role-based access control, enforced at the database layer, so users see only what their role permits.
- Audit trail. Every action is recorded with the actor, the record and the time.
- Breach response. If a breach affects your data, we will notify affected customers without undue delay and cooperate with the notifications you are required to make.
No system is perfectly secure, and we do not claim otherwise. We commit to the controls above and to telling you promptly if something goes wrong.
9. How long we keep information
- Borrower and loan data is kept for as long as your firm's account is active, and afterwards for the period your agreement specifies. On termination, we will return or delete it on request, except where law requires retention.
- Account records are kept while the account is active and for a reasonable period afterwards.
- Security and audit logs are kept for a limited period appropriate to investigating incidents.
- Waitlist submissions are kept until we have responded and for a reasonable period afterwards, and are deleted on request.
- Billing records are kept for the period tax and accounting law requires.
10. Your privacy rights
Depending on where you live, you may have the right to access, correct, delete or receive a portable copy of your personal information, to opt out of sale or sharing (we do neither), and not to be discriminated against for exercising these rights. Residents of California and of other states with comprehensive privacy laws have these rights under those laws.
To exercise them, contact us at [email protected]. We will verify your identity before acting and respond within the period the applicable law requires. You may use an authorised agent where the law permits.
If your request concerns borrower data held in a customer's account, we will direct it to that firm, since they control that data. We will assist them in responding.
11. Cookies, analytics and tracking
- The marketing site sets no advertising or tracking cookies. There are no third-party advertising pixels on leadclx.com.
- Analytics. We use Cloudflare Web Analytics, which measures aggregate traffic without cookies and without fingerprinting individual visitors.
- Turnstile. Our forms use Cloudflare Turnstile to block automated submissions. It is a privacy-preserving alternative to conventional CAPTCHA and does not track visitors across sites.
- The application sets strictly necessary cookies to keep you signed in. These cannot be disabled while using the application, because they are what keeps a session secure.
- Fonts. The marketing site currently loads web fonts from Google Fonts, which means Google receives your IP address when the fonts are fetched.
12. Children
The Services are business software for licensed professionals and are not directed to anyone under 18. We do not knowingly collect information from children. If you believe a child has provided us information, contact us and we will delete it.
13. Where data is stored
The Services are operated from the United States and data is stored there. If you access them from elsewhere, you are transferring information to the United States, where privacy laws differ from those in your country.
14. Changes to this policy
We may update this policy as the Services change or the law does. We will revise the date at the top, and for material changes we will notify account holders by email or in the application before the change takes effect.
15. How to contact us
Privacy questions, requests and complaints: [email protected].
Postal: [LEGAL ENTITY NAME], [REGISTERED ADDRESS].
We aim to resolve concerns directly. You also have the right to complain to your state's regulator.