Privacy Policy
Last updated 10 September 2026
This policy explains what data Gatedleads collects, why, where it is kept, and how to get a copy of it or have it deleted. Gatedleads is a tool for building gated content pages that capture leads. Two groups of people are covered here: account holders (people who sign up and build pages) and page visitors (people who land on a page an account holder has published and enter their email to unlock content).
Who runs Gatedleads
Gatedleads (“we”, “us”) is an independent software service operated from the United Kingdom. For any privacy question, or to request a copy or deletion of your data, email hello@gatedleads.com. For UK data protection purposes, we are the data controller for account-holder data, and a data processor acting on an account holder’s instructions for the leads captured through that account holder’s pages.
Data collected from account holders
- Account details: your email address, and a password (stored only as a one-way hash, never in plain text). If you sign in with Google, we receive your email address and, if Google provides them, your name and profile image.
- Profile: an optional display name.
- Branding assets: a logo and favicon you optionally upload, stored as image data on our server and shown on your published pages.
- Page content: the headlines, text, images, links, and settings you put into the pages you build.
- Billing data (Pro): if you upgrade, payment is handled by Stripe. Stripe collects and stores your card details; Gatedleads never sees or stores a card number. We store the Stripe customer and subscription identifiers Stripe returns so we can tell which plan you are on.
- Sign-in metadata: the time of your last sign-in, and whether your email has been verified.
Data collected from visitors to a published page
- The email address a visitor enters to unlock gated content, and their name if the page owner turned on name collection.
- A traffic source label (for example a UTM value from the link the visitor followed), used for the page owner’s analytics.
- Page views: a count of visits to each page, with the traffic source and a timestamp. No name, email, or IP address is stored with a page view.
- Unconfirmed submissions: if a page uses double opt-in, the submitted name and email are held in a pending list, along with a one-time confirmation token, until the visitor clicks the confirmation link. Unconfirmed entries are deleted automatically after 7 days.
- Session analytics and recording: every published page loads a script from SiteBehaviour (sitebehaviour-cdn.fra1.cdn.digitaloceanspaces.com). It records anonymised interaction data, mouse movement, clicks, scrolling, the pages viewed, and approximate device and browser information, and can replay a visit as a session recording so the page owner and Gatedleads can see how pages are used and fix problems. It is not used to build advertising profiles. Form fields are masked in recordings. This is disclosed on every published page with a link back to this policy.
Your IP address is used momentarily to rate-limit form submissions and is not written to the database.
How the data is used
- To provide the service: authenticate you, build and serve your pages, and store the leads they capture.
- To show account holders analytics for their own pages (views, leads, conversion rate, traffic sources).
- To send transactional email: a welcome email on sign-up, a notification to the page owner when a lead is captured, a confirmation email to the visitor when a page uses double opt-in, and billing-related email from Stripe.
- To send a page owner’s new leads to a webhook (for example Zapier) if that owner has configured one.
- To keep the service secure and working: error monitoring, rate limiting, and abuse prevention.
The legal bases we rely on under UK GDPR are: performance of a contract (running your account), legitimate interests (security, product analytics, preventing abuse), and consent where required. A page visitor’s data is processed on the instructions of the account holder whose page captured it.
Who processes data on our behalf
| Processor | Purpose | Data shared |
|---|---|---|
| Stripe | Subscription billing for the Pro plan | Email, card details (collected by Stripe directly), subscription status |
| Resend | Sending transactional email | Recipient email address and message content |
| SiteBehaviour | Page analytics and session recording on published pages | Anonymised interaction and device data |
| Hostinger | Server hosting | All stored data (as the infrastructure provider) |
| Optional “Sign in with Google” | Email address, and name and profile image if provided | |
| A webhook endpoint you choose (for example Zapier) | Forwarding new leads, only if an account holder configures it | Lead name, email, source, page, timestamp |
We do not sell personal data, and we do not share it with anyone other than the processors above and, for leads, the account holder whose page captured them.
Where data is stored
The Gatedleads database (PostgreSQL) runs on a virtual private server provided by Hostinger, located in the United Kingdom (Manchester, England). Backups, if taken, are held in the same region.
International transfers
Primary storage is in the UK. Some processors listed above (for example Stripe, Resend, Google, and any webhook endpoint an account holder configures) may process data outside the UK, including in the United States. Where that happens, the transfer is covered by the UK International Data Transfer Agreement, the EU Standard Contractual Clauses, an adequacy decision, or a comparable safeguard offered by that provider.
Data retention
- Free plan: leads and page-view records older than 30 days are deleted automatically each day. You can export your leads to CSV at any time before then.
- Pro plan: leads and analytics are kept for as long as the account is active, with no time limit.
- Unconfirmed double opt-in submissions: deleted automatically 7 days after submission.
- Account data: kept while the account exists. If you close your account, account data and all pages, leads, and analytics tied to it are deleted.
Your rights
If you are in the UK or EEA you have the right to access, correct, delete, restrict, or port your personal data, and to object to processing based on legitimate interests. To exercise any of these:
- Account holders: email hello@gatedleads.com from your account address. We will action deletion or provide an export within 30 days. Self-serve account deletion and export are on the roadmap; until then this email route is the way to do it.
- Page visitors: if you gave your email to a page built on Gatedleads and want it removed, use the data removal request form. Your request goes to Gatedleads with a one-click delete that removes your email and name from that page’s lead records; you do not need to contact the page owner yourself. You can also email hello@gatedleads.com.
You also have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk.
Cookies and local storage
Gatedleads uses browser local storage, not tracking cookies, for essentials: your sign-in token, your light or dark theme choice, and, on a page using A/B headline testing, which variant you were shown so it stays consistent. The SiteBehaviour script on published pages may set its own storage to recognise a returning session for analytics; it does not use that data for advertising.
Children
Gatedleads is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children.
Changes to this policy
If this policy changes in a way that materially affects how we handle your data, we will update the date at the top and, for account holders, email you before the change takes effect. Continued use after that date means you accept the updated policy.
Contact
Questions, requests, or complaints: hello@gatedleads.com.