This Privacy Policy explains how Next Leads collects, uses, shares and protects personal data when you visit nextleadscrm.com or use the Next Leads application at app.nextleadscrm.com (together, the “Service”). By using the Service you acknowledge this policy. If you do not agree with it, please do not use the Service.
Summary for Sign in with Google. If you sign in with Google, Next Leads receives only your name, email address, profile picture and Google account ID (scopes openid, email, profile). We use them only to create your account and log you in, store them securely in our database, never sell them or use them for ads or AI training, and delete them when you ask. Details in section 3.
1. Who we are
Next Leads (“Next Leads”, “we”, “us”) is a software-as-a-service CRM with a lead finder that searches public business listings on Google Maps. The Service is operated from Brazil. For the purposes of the Brazilian General Data Protection Law (Lei nº 13.709/2018, “LGPD”) and similar laws, we are the controller of the account data described in this policy. You can reach us, including our data protection contact, at contato@sedenir.dev.
2. Information we collect
2.1 Information you give us
- Account information: your name, email address, company (workspace) name, and a password. Passwords are stored only as a one-way cryptographic hash; we never see or store them in plain text.
- Billing information: when you subscribe, the details you enter for invoicing (such as name, company, country, address and tax ID). Card and payment details are entered directly with our payment provider and are not stored on our servers.
- Content you add to the Service: leads, clients, contacts, notes, follow-ups, sales, projects, services and financial records that you or your team members create or import.
- Team invitations: the email address and role of people you invite to your workspace.
- Messages to us: anything you send when you contact support.
2.2 Information from Sign in with Google
If you choose to sign up or log in with Google, we receive your Google account identifier, name, email address, email verification status and profile picture. See section 3 for exactly how we handle this data.
2.3 Information collected automatically
- Session and security data: the IP address and browser user agent associated with each login session, timestamps, failed login attempts and rate-limit counters used to prevent abuse.
- Audit log: a record of important actions inside a workspace (for example, changing a plan, inviting a member or deleting records), with the user, time and IP address.
- Usage counters: how many lead finder queries your workspace used each month, to apply plan limits.
- Server logs: standard technical logs kept for a short period to operate and secure the Service.
We do not use third-party analytics, advertising trackers or social media pixels.
2.4 Public business data from Google Maps
When you run a search in the lead finder, the Service requests public business listings from the Google Maps Platform (Places API) and stores the results in your workspace: business name, address, phone number, website, rating and number of reviews. This information is published by the businesses themselves on Google Maps. Use of these results is also subject to the Google Maps/Google Earth Additional Terms of Service and the Google Privacy Policy.
3. Google user data
Next Leads offers “Sign in with Google” as an optional way to create an account and log in. This section explains, specifically, how the Next Leads application accesses, uses, stores, shares, protects, retains and deletes the data it receives from Google (“Google user data”).
3.1 What Google user data we access
When you choose Sign in with Google, Next Leads requests only these OAuth scopes: openid, email and profile. With them, Google shares with us:
- your Google account identifier (a unique ID number);
- your full name;
- your email address and whether Google has verified it;
- the URL of your Google profile picture;
- the OAuth access token and ID token that Google issues for this sign-in.
We do not request or access your Gmail messages, Google Drive files, Google Calendar, Google Contacts, location history or any other Google service or data.
3.2 How we use Google user data
We use Google user data only to provide the sign-in feature that you chose:
- to create your Next Leads account and your company workspace the first time you sign in;
- to authenticate you on later sign-ins, so you can log in without a password;
- to link your Google sign-in to an existing Next Leads account that uses the same verified email address;
- to show your name and profile picture inside the application, for example in the top bar and to your teammates;
- to send you essential emails about your account (such as security or billing notices) at the email address Google shared.
We do not use Google user data for advertising, retargeting, profiling, credit assessment or selling to data brokers, and we do not use it to develop, improve or train generalized artificial intelligence or machine learning models.
3.3 How we store Google user data
Google user data is stored in our PostgreSQL database, in the record of your user account: name, email, verification status and picture URL in the user table, and the Google account ID, access token and ID token in the linked sign-in record. The database runs on servers hosted by Amazon Web Services in the United States. We do not store Google user data in browser storage, spreadsheets or any other system.
3.4 How we share Google user data
We do not sell, rent or transfer Google user data to third parties. It is shared only:
- with members of your own workspace, who can see your name, email and picture so they can work with you;
- with our infrastructure providers (Amazon Web Services for hosting and Cloudflare for the secure network connection and encrypted backups), which process it only on our behalf to run the Service;
- when required by law or by a valid order from a competent authority, or to protect against fraud or abuse.
3.5 How we protect Google user data
- All traffic between your browser, our servers and Google is encrypted with HTTPS/TLS.
- The database is not exposed to the internet; it is reachable only by the application inside our private server network.
- The application connects to the database with restricted, least-privilege roles, and each company's data is isolated from other companies by row-level security.
- Backups are encrypted before they leave the server and are stored encrypted.
- Only you and the members of your own workspace can see your data in the application; our staff do not access Google user data unless you ask us to (for example, in a support request), it is necessary to investigate security or abuse, or it is required by law.
3.6 How long we keep Google user data and how to delete it
- We keep Google user data only while your Next Leads account exists.
- You can revoke Next Leads' access to your Google account at any time at myaccount.google.com/permissions. After that, you will no longer be able to sign in with Google until you authorize it again.
- To delete your account and all Google user data we hold, email contato@sedenir.dev from the address of your account. We delete the data from our database within 30 days of confirming the request, and encrypted backup copies are erased automatically within a further 30 days, when those backups expire.
3.7 Limited Use
Next Leads' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. How we use information
- To provide the Service: create and secure your account, run your searches, store your workspace content and let your team collaborate.
- To process subscriptions and payments, apply plan limits and send related notices.
- To keep the Service secure: prevent fraud, spam sign-ups, brute-force attacks and other abuse, including through a CAPTCHA on sign-up.
- To send service emails, such as email confirmation, password reset and important account or policy notices. We do not send marketing emails without your consent.
- To provide support and respond to your requests.
- To comply with legal obligations and enforce our Terms of Service.
We do not sell personal data, and we do not use your workspace content for advertising.
5. Legal bases
Where the LGPD, the EU/UK GDPR or similar laws apply, we process personal data on these bases: performance of a contract (to provide the Service you signed up for); our legitimate interests (security, fraud prevention and improving the Service, balanced against your rights); compliance with legal obligations (such as tax and accounting records); and your consent, where required, which you may withdraw at any time.
6. Sharing and service providers
We share personal data only with providers that help us run the Service, under contracts that limit their use of the data to providing services to us:
- Amazon Web Services (AWS) — application and database hosting (United States).
- Cloudflare — secure network connection to the application, website hosting, CAPTCHA (Turnstile) and encrypted backup storage.
- Dodo Payments — subscription checkout and payment processing. Dodo Payments processes your payment details under its own privacy policy.
- Google — Sign in with Google and the Google Maps Platform used by the lead finder.
- Email delivery provider — to send account emails such as confirmation and password reset.
We may also disclose information if required by law or a valid order from a competent authority, to protect the rights, safety or property of our users or of Next Leads, or as part of a merger or acquisition, in which case this policy will continue to apply to your data.
7. International transfers
Our servers are located in the United States, and some providers may process data in other countries. When personal data is transferred outside Brazil or your country, we rely on safeguards permitted by applicable law, such as contractual clauses and the providers' own security commitments.
8. Retention and deletion
- We keep account data and workspace content for as long as your account is active.
- Login sessions expire after 30 days of inactivity.
- Database backups are encrypted and kept for up to 30 days, after which they are deleted automatically.
- You can ask us to delete your account at any time by writing to contato@sedenir.dev from the email address of the account. We will delete your account and your workspace content within 30 days of confirming the request; copies in backups are removed as those backups expire.
- We may keep limited records for longer when required by law (for example, billing records) or to establish, exercise or defend legal claims.
9. Security
We use measures appropriate to the nature of the data, including encryption in transit (HTTPS/TLS), hashed passwords, optional two-factor authentication, database-level isolation between workspaces, least-privilege database roles, rate limiting, an audit log and encrypted backups. No method of transmission or storage is completely secure, but we work to protect your data and will notify you and the competent authorities of any security incident as required by law.
10. Your rights
Depending on where you live, you may have the right to: confirm whether we process your data; access it; correct incomplete or inaccurate data; request anonymization, blocking or deletion; request portability; obtain information about sharing; withdraw consent; and object to processing. Brazilian residents have these rights under article 18 of the LGPD and may also file a complaint with the Autoridade Nacional de Proteção de Dados (ANPD). Residents of the EU/UK may contact their local supervisory authority.
To exercise your rights, email contato@sedenir.dev. We may need to verify your identity before acting, and we will reply within 15 days. Much of your data can also be viewed, edited and exported to CSV directly in the Service.
11. Data you store about others
Leads, clients and contacts you add to your workspace may include personal data about other people. For that data, you (or your company) are the controller and Next Leads acts as an operator/processor on your behalf: we process it only to provide the Service to you. You are responsible for having a legal basis to collect and use it and for respecting the rights of those people, including anti-spam and direct-marketing rules. Requests from those people about data in your workspace should be directed to you; if we receive one, we will forward it to you when possible.
12. Cookies and local storage
The application uses only cookies that are necessary for it to work:
- Session cookie — keeps you logged in (expires after 30 days).
- Two-factor “trusted device” cookie — only if you choose to trust a device (30 days).
- Language cookie (
nl_locale) — remembers your language (1 year).
The website stores your theme and language preference in your browser's local storage. Cloudflare Turnstile, used on the sign-up page, may process technical signals to tell humans from bots. We do not use advertising or analytics cookies.
13. Age requirement
The Service is intended for businesses and professionals and is not directed to anyone under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us and we will delete it.
14. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the date at the top of this page and notify account owners by email or inside the Service before the changes take effect.
15. Contact
Questions, requests or complaints about privacy: contato@sedenir.dev.