Leads2Build certification seal

Privacy Policy

Effective date: May 24, 2026 · Last updated: May 24, 2026

1. About this policy

This Privacy Policy explains how Leads 2 Build(“Leads 2 Build,” “we,” “us”) collects, uses, shares, and protects information when you use the Leads 2 Build platform (the “Service”) at leads2build.com and any subdomain or custom domain we host on your behalf.

By creating an account or otherwise using the Service, you confirm that you have read and understood this policy. If you do not agree, do not use the Service.

This policy covers the Service we operate. It does not cover the separate practices of the third-party services we integrate with (QuickBooks Online, GoHighLevel, SmartBuild, Clerk, Supabase, Vercel, and any payment processor). When you connect or use those services through the Service, their own privacy policies also apply, alongside this one.

2. Who we are

Leads 2 Build is a business based in Calgary, Alberta, Canada, with a mailing address at 154 Bridlewood Drive SW, Calgary, Alberta, Canada.

For privacy or data-protection inquiries, contact our privacy team at privacy@leads2build.com.

3. The information we collect

3.1 Information you give us directly

  • Account information — your name, business name, email address, phone number, password (handled by our authentication provider; we do not see it), and the role assigned to you within your organization (admin, sales, project manager, crew lead, worker).
  • Customer and project data you upload or enter — including customer contact information, mailing/site addresses, project specifications, material lists, photographs, signatures, notes, tasks, and any documents you attach (contracts, change orders, intake forms).
  • Billing information — payment card information is collected and handled entirely by our payment processor (see Section 5). We do not store full card numbers on our systems.
  • Communications — messages you send through the in-app messaging features, support requests, and feedback.

3.2 Information from integrated services

When you connect a third-party service to your Leads 2 Build account, we receive the categories of data listed below. You control what gets connected; you can disconnect any integration at any time from Settings → Integrations.

QuickBooks Online (Intuit)

If you connect QuickBooks Online, we access — through Intuit’s Accounting API — the following data categories:

  • Customer records (name, contact, billing/shipping addresses, balance)
  • Vendor and supplier records
  • Items / Products & Services (your catalog, pricing, income-account mapping)
  • Estimates and invoices (line items, totals, status, attachments)
  • Payments received and bills paid
  • Chart of Accounts (for posting transactions correctly)
  • Class / Project / Department records (used for per-job profitability)
  • Company information (company name, country, base currency, plan tier)

We do not access bank-account credentials, your QuickBooks Payments merchant settings, or payroll data. We do not access cardholder data (PANs, CVVs, SSNs, EINs) through QuickBooks. We do not share, resell, or re-disclose QuickBooks customer data to any third party, and we do not use it to train artificial intelligence or machine-learning models. Tokens used to access your QuickBooks data are encrypted at rest using AES-256-GCM authenticated encryption.

GoHighLevel

GoHighLevel is a service we operate in the background to provide CRM, SMS, and email functionality on your behalf. You are not required to have your own GoHighLevel account; where one is used, it is provisioned and managed by us as part of the Service. Through GoHighLevel, we read and (in some cases) write the following on your behalf:

  • Contacts, opportunities, and pipelines
  • Conversations, messages, notes, tasks, and calendar events
  • Media library items (when generating documents)
  • Pipeline stage assignments (we may move opportunities between stages when configured automations fire — for example, when an estimate is approved)

GoHighLevel is also our delivery channel for SMS and email communications (see Section 8). Credentials for the GoHighLevel environment we operate on your behalf are stored encrypted with AES-256-GCM.

SmartBuild

SmartBuild is a separate service that you maintain your own account with. When you connect your SmartBuild account, you authorize us to access, read, and retrieve (pull) your SmartBuild data — job specifications, material lists, labor hours, markup, and pricing — in order to display it in the Service and generate customer-facing estimates. Your SmartBuild credentials are stored encrypted with AES-256-GCM. We do not modify your SmartBuild data — the integration is read-only on the SmartBuild side.

3.3 Information collected automatically

  • Device and browser information — IP address, browser type and version, operating system, screen size, and similar technical signals.
  • Usage information — pages viewed, features used, timestamps, referring URLs, error logs.
  • Cookies and similar technologies — see Section 11.

4. How we use information

We use the information described above to:

  • Provide, maintain, and improve the Service.
  • Authenticate you, prevent unauthorized access, and protect against fraud.
  • Process subscription payments and prevent payment fraud.
  • Synchronize information with the third-party services you have connected (for example, pushing an invoice you created in Leads 2 Build to QuickBooks Online).
  • Send transactional communications (account verification, payment receipts, system alerts).
  • Send service updates and, with your consent, marketing communications you can opt out of at any time.
  • Diagnose problems, monitor performance, and improve reliability.
  • Comply with legal obligations.

The legal bases under applicable EU/UK data-protection law are: performance of our contract with you, our legitimate interests (operating and improving the Service, fraud prevention), your consent (for optional marketing), and compliance with legal obligations.

5. Subprocessors — who we share information with

We use the following subprocessors to deliver the Service. Each is bound by a data-processing agreement consistent with applicable data-protection law. All listed subprocessors are based in the United States. Leads 2 Build itself is based in Canada; when you provide information to the Service, that information is transferred to and processed in the United States by these subprocessors. See Section 12 for additional details on cross-border data transfers.

SubprocessorPurposeLocation
ClerkUser authentication, sessions, organization membershipUnited States
SupabaseApplication database (Postgres), file storage, real-timeUnited States
VercelWeb hosting, edge runtime, build infrastructureUnited States
Intuit / QuickBooks OnlineAccounting data sync — only when you connect itUnited States
GoHighLevel (HighLevel, Inc.)CRM data sync, SMS and email delivery — operated by us to provide the ServiceUnited States
SmartBuild (Post Frame Solver)Construction estimating — only when you connect itUnited States
TwilioSMS and voice delivery, phone number provisioning, A2P messaging registrationUnited States
Mailgun (Sinch)Transactional email delivery and delivery analyticsUnited States
StripeSubscription payment processingUnited States

We may also disclose information when required by law (subpoena, court order, government request) or to protect the rights, property, or safety of our users or the public. If we are involved in a merger, acquisition, or sale of assets, we may transfer information as part of that transaction; we will provide advance notice in that event.

We do not sell your personal information. We do not share customer financial data with any party other than the subprocessors above for the purposes stated. We do not allow any subprocessor to use your data for their own marketing.

6. How we protect information

We maintain a documented, operational information security program — written policies and procedures, technical and organizational controls, and a continuous-improvement cycle under which the program is reviewed at least annually and matured over time. A fuller description is in our Information Security overview. Key safeguards include:

  • Encryption in transit — all traffic between your browser and the Service uses TLS 1.2 or higher.
  • Encryption at rest — third-party-integration credentials (QuickBooks tokens, GoHighLevel API keys, SmartBuild passwords) are encrypted at rest using AES-256-GCM authenticated encryption with a tenant-isolated key envelope. Supabase additionally provides at-rest encryption on the underlying storage.
  • Authentication & MFA — we use Clerk for identity, supporting single sign-on and multi-factor authentication (authenticator-app one-time passwords). MFA is required for accounts that can initiate or authorize payments. Passwords never reach our servers.
  • Multi-tenant isolation — every record in our database is stamped with an organization identifier, and every read and write is scoped server-side to the requesting organization. Cross-tenant access is rejected at the middleware layer.
  • Access controls — application access is gated by role (admin, sales, project manager, crew lead, worker). Internal staff access to production data is limited to debugging and is logged.
  • Audit logging — sensitive actions (invitations, role changes, payment recording, integration credential changes) are written to an immutable audit log.
  • Security incident response — we maintain a written incident response procedure. In the event of a confirmed breach involving your personal information, we will notify affected users and relevant authorities (including Intuit, if QuickBooks data is involved) without undue delay and in accordance with applicable law.

No method of transmission or storage is perfectly secure. We work to apply industry-standard safeguards but cannot guarantee absolute security.

7. Retention and deletion

  • Active accounts — we retain information for as long as your account is active and as needed to provide the Service.
  • Disconnecting QuickBooks — when you disconnect QuickBooks Online from your account, we revoke our OAuth tokens with Intuit and delete the stored tokens from our database within 24 hours. Previously synchronized read-only references (such as the QuickBooks ID stamped on a Leads 2 Build invoice) remain on your records for your own audit purposes; no further data is fetched from QuickBooks after disconnect.
  • Account cancellation — when you cancel your subscription, your account moves into a 30-day export window during which you can download your data. After the export window closes, your account data is deleted from production within an additional 30 days (60 days total from cancellation). Off-site backup snapshots are cleared on rolling 90-day cycles.
  • Deletion requests — you may request deletion of your personal information at any time by emailing privacy@leads2build.com. We respond to verified requests within 30 days. Some information may be retained where required by law (for example, tax records for transactions you have made).
  • Audit logs — security audit logs are retained for at least 12 months and may be retained longer where required by law or for fraud investigation.

8. SMS messaging (A2P 10DLC, TCPA, CTIA)

If you provide your mobile phone number through the Service, you may receive SMS messages from us or from the GoHighLevel sender registered to your organization. We use GoHighLevel as our SMS delivery vendor; GoHighLevel is a registered A2P 10DLC sender with US carriers.

  • Message frequency — message frequency varies based on the campaigns and automations your organization has configured. For transactional messages (account alerts, customer-portal notifications), frequency is event-driven. For marketing or campaign messages, you will be told the expected frequency at the time of consent.
  • Standard rates — message and data rates may apply, as set by your carrier.
  • Opt out at any time — reply STOP to any message to unsubscribe from further SMS from that sender.
  • Help — reply HELP for assistance, or contact the sender directly.
  • Mobile information privacy — your mobile phone number and SMS consent are not sold or shared with third parties for their own marketing. Mobile opt-in data is not shared with third parties or affiliates for marketing purposes.
  • Restricted content — we do not knowingly transmit SMS content involving sex, hate, alcohol, firearms, or tobacco (SHAFT) without explicit additional consent and carrier approval.

If you sign up for SMS through a third-party integration, the third party’s opt-in record and consent apply. We follow consent records received from the source system.

9. Email communications (CAN-SPAM)

We send three categories of email:

  • Transactional — account verification, password reset, payment receipts, invoices delivered through the Service. You cannot opt out of these while your account is active.
  • Service announcements — material changes to the Service, security advisories, downtime notices. Limited and infrequent.
  • Marketing — optional. You can opt out at any time from any marketing email’s unsubscribe link, or by emailing privacy@leads2build.com.

10. Your rights

10.1 General rights

Regardless of where you live, you may:

  • Access the personal information we hold about you.
  • Correct inaccurate information.
  • Request deletion of your personal information (subject to legal exceptions).
  • Withdraw consent for processing that relies on consent.
  • Opt out of marketing communications.
  • Request a copy of your data in a structured, commonly used format.

10.2 California (CCPA / CPRA)

California residents have additional rights, including the right to know what personal information we have collected, the right to delete it (with exceptions), the right to correct it, the right to opt out of sale or sharing of personal information for cross-context behavioral advertising (we do not sell or share personal information for cross-context behavioral advertising), and the right not to be discriminated against for exercising any of these rights.

10.3 EU / UK / EEA (GDPR)

Where the EU or UK General Data Protection Regulation applies, you have rights of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on our legitimate interests. You also have the right to lodge a complaint with your local data protection authority. Our lawful bases for processing are described in Section 4. Where processing is based on consent, you can withdraw consent at any time.

10.4 Canada (PIPEDA)

If you are in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, provincial privacy laws (including British Columbia’s Personal Information Protection Act) govern how we handle your personal information. You have the right to access your personal information, request corrections, and withdraw consent to processing (subject to legal or contractual restrictions). If you have an unresolved privacy concern, you may file a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, for British Columbia residents, with the Office of the Information and Privacy Commissioner for BC (oipc.bc.ca).

10.5 How to exercise your rights

Email privacy@leads2build.com with your request. We will verify your identity before responding. We respond to verified requests within 30 days (or as required by applicable law).

11. Cookies and similar technologies

We use a small number of cookies and similar technologies:

  • Essential cookies — authentication, session management, and security. These cannot be disabled without breaking the Service.
  • Functional cookies — remembering your preferences (such as your last-selected pipeline view).
  • Analytics — first-party usage analytics that help us understand which features are used. We do not use third-party advertising trackers.

Most browsers let you delete or block cookies. Doing so for essential cookies will prevent the Service from working.

12. International data transfers

Leads 2 Build is based in Calgary, Alberta, Canada. The Service’s infrastructure and the subprocessors listed in Section 5 operate from the United States. When you use the Service, your personal information is transferred to, stored in, and processed in the United States. Where required by Canadian (PIPEDA), EU/UK (GDPR), or other applicable law, we rely on standard contractual clauses, the recipient organizations’ privacy commitments, or other lawful transfer mechanisms.

13. Children's privacy

The Service is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it.

14. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and post a notice in the Service at least 30 days before the change takes effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

15. Contact us

Questions, requests, or complaints about this Privacy Policy or our data practices: