EZ Leads LLC — Privacy Policy

Effective Date: October 5, 2026 | Version: 1.29

1. Introduction

This Privacy Policy explains how EZ Leads LLC (“EZ Leads,” “we,” “us”) collects, uses, discloses, and protects information in connection with our platform, services, websites, APIs, and related products (collectively, the “Service”). This Policy applies to information about our account holders (“Users”) and to information our Users provide to us about their own leads and contacts.

This Policy is incorporated into our Terms of Service.

2. Information We Collect

2.1 Information You Provide When You Create and Use an Account.

  • Account identifiers: name, business name, email address, password, phone number.
  • Billing information: billing name, billing address, payment-method details (processed by our payment processor; we do not store full card numbers).
  • Identity and business information necessary for A2P 10DLC registration, brand vetting, and number verification.
  • Communications and content you submit through the Service, including support requests, messages composed in our messaging interfaces, and configuration settings.

2.2 Information About Your Leads and Contacts. When you upload, import, or input leads into the Service, you provide us with information about those individuals, which may include name, phone number, email address, mailing address, demographic information, communication history, consent attestations, and notes you record. This information is provided by you and is treated as Your Data under our Terms of Service.

2.2A Health and Financial Information About Your Leads. To quote and apply for life insurance, you may record a financial inventory for a lead. It can include health information (date of birth, height and weight, tobacco or nicotine use, medical conditions and diagnoses, medications, hospitalizations, and family medical history) and financial information (income, mortgage and debts, existing coverage, beneficiaries, and monthly budget). This is sensitive information. It is collected by you, from the lead, for the purpose of quoting and applying for coverage they asked about; we process it only to provide the Service to you. It is visible to you, to any team member or virtual assistant you authorize, and to platform administrators for support and security; it is not used for advertising, not sold, and not used to train models. Until September 16, 2026 the inventory also offered fields for government and financial identifiers for the applicant and for a second applicant: Social Security numbers, driver's license numbers and their expiration dates, and bank account details (bank name, routing number, and account number). Those fields were removed from the Service on that date and we no longer collect them; a carrier application asks for them directly. Values recorded before that date are no longer displayed anywhere in the Service and are being deleted from our systems; until they are, they are held under the same terms as the rest of the inventory. If you sell or transfer a lead through the Service, only the information that arrived with the lead moves with it; the health and financial answers you recorded — the identifiers included — do not.

Two features read that health information: the medication lookup, which matches a drug name you type against a built-in reference list, and the underwriting engine, which applies carrier rules to the answers on the record to estimate a rate class. Both run on our own systems against data we hold; neither sends the health answers to a third party, and neither runs unless you ask for it. A third, the View Quote link on the inventory, opens the Insurance Toolkits quoting tool when you click it and passes it the lead's age, sex, state, whether they use tobacco, and a face amount — the inputs a quote needs, never the lead's name, contact details, or any other health answer. A fourth, Suggestions from calls, works only on a call that was recorded and transcribed: it sends the new lines of the transcript, with the current answers in the inventory fields it can fill (among them medications, surgeries, tobacco use, height, weight, and income), to Anthropic, our AI provider, which proposes values together with the words each one came from. Nothing is written to the inventory unless you accept it. The only purpose of all four is to quote, underwrite, or complete the record for the person it describes. We do not use this information for advertising, profiling, or model training, on any platform.

2.3 Communications Metadata. When you send or receive SMS messages or voice calls through the Service, we collect metadata about those communications, including phone numbers involved, timestamps, message content, call duration, call status, recording status, the transcript of a recorded call where call transcripts are on, and delivery information. A call recorded since October 5, 2026 also has a redacted copy of its recording and transcript (Section 4.6).

2.3A AI Receptionist Calls. An agent can turn on an AI receptionist. It is off unless the agent turns it on. When it is on, it answers the agent's calls that come in after hours or that nobody picks up, and it tells the caller at the start that it is an AI assistant. Telnyx runs it: Telnyx converts what the caller says to text, a language model hosted by Telnyx writes the replies, and Telnyx speaks them. To do this it is given the agent's first name and office name and, when the calling number matches one of the agent's leads, the caller's first name. It can take a message — the caller's name, a callback number, why they called, and a good time to call back — and it records a caller's request not to be called or texted again. Telnyx keeps the transcript of the conversation, and we keep a copy with the message on the call's record, so the agent can read them. These calls are not recorded. The receptionist does not book appointments and does not read the agent's Google Calendar.

2.4 Automatically Collected Information. When you use the Service, we automatically collect:

  • Device and browser information (browser type, operating system, screen resolution, language).
  • Log information (IP address, access times, pages viewed, referring URLs).
  • Usage information (features used, actions taken, performance and error data).
  • Cookies and similar technologies (see Section 7).

2.5 Information from Third Parties. We may receive information about you, and about the people you communicate with, from third parties, including:

  • Identity verification providers used for A2P 10DLC registration.
  • Payment processors confirming transactions.
  • Advertising platforms reporting on campaigns you run (e.g., Meta, Google).
  • Communications providers reporting on message and call delivery (Telnyx, and Twilio for accounts not yet moved to Telnyx).
  • Caller-name and line-type information for an incoming call from a number that matches none of your leads, where you turn on Look up unknown callers. It comes from Telnyx's number-lookup service, is saved on that call's record, and is reused for up to 30 days rather than looked up again.

2.6 Meta (Facebook) Integration Data. When you connect your Meta account to the Service via OAuth, we collect:

  • Your Meta user ID and OAuth access token (stored encrypted)
  • Ad account information (account IDs, account names, currency, time zone)
  • Campaign data (campaign names, status, budgets, performance metrics)
  • Lead form data and submissions you collect through Meta lead-generation campaigns
  • Ad performance metrics (impressions, clicks, spend, conversions)

We access this data only when you explicitly authorize us through Meta's OAuth flow. Each User connects their own Meta account independently; we never access other Users' Meta data. You can revoke this connection at any time through your EZ Leads account settings or your Meta business settings.

2.7 SMS / Text Messaging Consent Data. Two consents are collected separately when a consumer submits a licensed agent's lead form (a Meta/Facebook Lead Ad form or an EZ Leads web landing page). Submitting the form with a phone number is the consumer's agreement to be contacted by that agent about the specific request they submitted — individual, conversational messages such as confirming the request, answering coverage questions, or scheduling a call. Recurring automated marketing text messages (for example, quotes and offers) are governed by a separate, optional consent checkbox that is unchecked by default; checking it is never a condition of submitting the form. Marketing texts are sent only where marketing consent exists — given on the form, given later by texting START, or obtained by the agent outside the Service and documented by the agent, who attests to and is solely responsible for the validity of such consent. For EZ Leads web landing-page submissions we record SMS consent, including the consent language shown, a timestamp, the IP address, and the page URL. For Meta Lead Ad forms, the consent checkbox and its disclosure are presented on Meta's form at the point of submission, and we record the consumer's response when our systems receive it from Meta. Consumers may reply STOP at any time to opt out of all text messages, or HELP for help.

We do not sell, rent, or share consumer mobile phone numbers or SMS opt-in consent with third parties or affiliates for their own marketing or promotional purposes. SMS opt-in information is used solely to enable the single licensed agent the consumer contacted to text them about the request they submitted; it is never transferred to any other party for marketing.

Transfers between licensed agents on the platform. A User may transfer a lead record, including the consumer's phone number, to another licensed agent on the platform. The consumer's SMS opt-in consent does not travel with it. Consent under the TCPA names the party who holds it, so a receiving agent may not text or call on a transferring agent's consent record: the Service will not list or transfer a lead that is contactable only under the transferring agent's own consent, and after any change of owner it re-derives that lead's contactability against consent and screening evidence that names the receiving agent. What moves with the lead is the consumer's own inquiry — the form they submitted and when — which is the receiving agent's own basis to respond to it. No transfer is ever to a third party or affiliate for their own marketing; every party to one is a licensed agent using this Service under these terms.

2.8 Google Calendar Integration Data. A User (licensed agent) may optionally connect their Google Calendar to the Service to book appointments with their leads. When a User authorizes this connection via Google's OAuth consent flow, we request the calendar.events.owned scope (connections made before September 8, 2026 were granted the calendar.events scope and keep working) and use it for three purposes only. First, to create, update, and cancel the events that the User schedules through the Service on their own calendar — appointments with their leads and, for a team manager, recurring one-on-one meetings with the agents on their team. Second, to show which times are already taken when the User, or a person the User has given access to their account (such as an assistant), books an appointment: while the booking window is open, we read the start and end times of the events on the User's own calendar for the days shown, up to three months ahead, whether each one marks the User as busy, and whether the User declined it. For the booking window we do not read an event's title, description, location, or attendees, and we do not store these times — they are used to mark times as busy on screen and then discarded. Third, to show the User their own calendar next to their appointments on the Service's Calendar page: for the days on screen, from three months back to three months ahead, we read each event's title, start and end time, whether it marks the User as busy, whether the User declined it, and a link to open it in Google Calendar, plus the event's identifier, used only so that an appointment booked through the Service is not shown twice. A person the User has given access to their account (such as an assistant) sees only the busy times on that page, never the titles; for them we do not read the titles at all. We do not store any of this; it is shown on screen and then discarded. In none of these reads do we read an event's description, location, or attendees. We do not otherwise read, store, display, or process events on the User's calendar that the Service did not create. We store the OAuth refresh and access tokens needed to act on the User's behalf, the identifier of the connected calendar, and, for each appointment booked through the Service, the created event's identifier and links (event ID, event link, and Google Meet link where applicable). When the User asks the Service's in-app AI assistant about their appointments, or asks it to book, move, or cancel one, the assistant — which runs on Anthropic's models (Section 4.1) — is given that appointment's details, including its event link and Google Meet link, so it can answer the User; Anthropic does not use data it receives through its API to train its models. Apart from that, we do not sell, rent, or share Google Calendar data with any third party. A User can revoke this access at any time by disconnecting Google Calendar in Settings → Connections or from their Google Account permissions page; upon disconnection we delete the stored tokens.

2.9 Gmail Integration Data. A User may optionally connect their own Gmail account so that the email steps of their follow-up workflows send from their own address, with replies arriving in their own inbox. When a User authorizes this connection via Google's OAuth consent flow, we request the gmail.send scope together with the basic identity scopes (openid, email) and use them solely to (a) send the emails that the User's own workflows compose to the User's own leads, from the User's Gmail address, and (b) learn which Gmail address was connected, so we can show it to the User and use it as the sender. This is send-only access: we do not request, and cannot obtain, access to read, search, modify, or delete anything in the User's mailbox. We store the OAuth refresh and access tokens needed to send on the User's behalf, the connected Gmail address, and, for each email sent through the Service, our own record of that email (recipient lead, subject, body, Gmail message identifier, and delivery status) as part of the User's lead communication history. Every email sent this way carries the User's identity, the User's business address where on file, and a one-click unsubscribe link, and the Service stops emailing a lead who unsubscribes or whose address bounces. We do not sell, rent, or share Gmail data with any third party. A User can revoke this access at any time by disconnecting Gmail in Settings → Connections or from their Google Account permissions page; upon disconnection we delete the stored tokens.

2.10 Google Ads Integration Data. A User may optionally connect their Google Ads account. When a User authorizes this connection via Google's OAuth consent flow, we request the Google Ads API scope and store the OAuth refresh and access tokens for the connection together with the Google Ads account identifiers the User provides. We access Google Ads on the User's behalf only to attribute the User's leads to their own Google Ads campaigns and to report conversions from those leads back to the User's own Google Ads account, and for no other purpose; we do not change the User's campaigns, ads, budgets, or billing. We do not sell, rent, or share Google Ads data with any third party. A User can revoke this access at any time by disconnecting Google Ads in Settings → Connections or from their Google Account permissions page; upon disconnection we delete the stored tokens.

2.11 Sign in with Google. A User may create or sign in to their account with Google. In that case Google provides us the basic profile information the User agrees to share on Google's consent screen (name, email address, and profile picture), which we use only to create and authenticate the User's account. Signing in with Google grants no access to the User's Google Calendar, Gmail, or Google Ads; those are separate, optional connections described in Sections 2.8 through 2.10. Google's consent and permission screens identify the Service by its product name, EZPZ.

Google user data and the Limited Use requirements. EZPZ's use and transfer to any other app of information received from Google APIs — for every Google integration described in Sections 2.8 through 2.11 — will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Google Workspace APIs (Google Calendar and Gmail) will adhere to the Google User Data Policy, including the Limited Use requirements. In particular:

  • We use Google user data only to provide and improve the features described in Sections 2.8 through 2.11, each of which the User turns on and can turn off.
  • We never use Google user data, or anything derived from it, for advertising — including retargeting and personalized or interest-based advertising — or to determine anyone's creditworthiness or for lending.
  • We never sell Google user data, and never transfer it to data brokers, information resellers, or advertising platforms.
  • We transfer Google user data only: to the service providers named in Section 4.1 that host and run the Service for us, and, for Google Calendar, to Anthropic as described in Section 2.8 — in each case only to provide the features described above; where necessary for security, such as investigating abuse; to comply with applicable law; or as part of a merger, acquisition, or sale of assets, and then only with the User's prior, explicit consent.
  • We do not use Google user data — raw, aggregated, anonymized, or derived — to develop, improve, or train generalized or non-personalized AI or machine-learning models, and we do not transfer it to any third-party AI service that uses it to train its models.
  • No person at EZ Leads reads Google user data unless the User has asked us to for specific data (for example, to troubleshoot a support request), it is necessary for security purposes such as investigating abuse, or it is required by law.
  • Google user data is protected in transit and at rest. Every connection to Google and to our database is encrypted with TLS. The OAuth tokens that let the Service act for a User are additionally encrypted in our database with AES-256-GCM, under a key held outside the database, and only our server-side code can read them — never a browser, including the User's own. Access to production systems is limited to the personnel who operate the Service.
  • How long we keep Google user data, and how to have it deleted, is set out under “Google user data” in Section 6.

2.12 Usage Analytics and Diagnostics. We measure how the Service is used so we can fix what is broken and improve what is not. Three providers do this, and each sees a different, limited thing:

  • Product analytics (PostHog): which pages and features you open, in what order, and whether an action succeeded, tied to your account identifier. It also keeps session replays: a reconstruction of how each page drew and responded to you (its layout, your clicks and scrolling, and any errors), with every piece of text and every input masked, and every image replaced by a blank placeholder, in your browser before anything is sent, so no name, number, message, answer, or photo is ever part of one. Replay does not run on the pages consumers use (agents' landing, referral, business-card, and credentials pages) or in our iOS app, and PostHog's automated tools, including AI, may review masked replays to find pages that broke or frustrated someone. Lead names, phone numbers, message content, call recordings, and financial inventory answers are not part of what we ask it to collect, and you can turn it off entirely in Settings (see Section 7).
  • Traffic and performance measurement (Vercel Analytics and Vercel Speed Insights): page views and page-load timings, with no identifier that we can tie back to you.
  • Error reporting (Sentry): the technical details of a crash or failed request, with personal data stripped before it is sent.

Product analytics is on by default and you can turn it off at any time, on any device, in Settings → Security & privacy → Usage analytics (Privacy on a phone) . Section 7 explains what turning it off does and what it does not do. None of this data is sold, and none of it is used to advertise to you or to anyone else.

3. How We Use Information

We use information to:

  • Provide, operate, maintain, and improve the Service.
  • Process payments and manage subscriptions.
  • Register your business for A2P 10DLC, provision communication numbers, and configure third-party providers on your behalf.
  • Deliver, route, and report on SMS messages and voice calls you originate.
  • Communicate with you about your account, the Service, updates, and security matters.
  • Provide customer support and respond to inquiries.
  • Detect, investigate, and prevent fraudulent, abusive, unauthorized, or illegal activity.
  • Comply with legal obligations and enforce our Terms of Service.
  • Conduct analytics and research to understand how the Service is used and to improve it, including in aggregated and de-identified form.
  • Show, on our homepage, a short list of recent deals closed by agents on the Done-for-you plan: the agent's first name with the client's state, the product line, the annual premium, and the days from lead to close — never the client's name or contact details — unless the agent turns it off in Settings → Security & privacy (Privacy on a phone).

We do not sell information about our Users or their leads.

4. Disclosure of Information

We disclose information to:

4.1 Service Providers and Subprocessors. We use third-party service providers to operate and improve the Service. Our current providers include:

  • Supabase (database hosting and authentication)
  • Vercel (application hosting and performance monitoring)
  • Telnyx (SMS and voice communications, phone numbers, call recording and call transcripts of recorded calls where an agent enables them — Telnyx's own speech-to-text engine transcribes the audio — and 10DLC messaging registration; and, when an agent turns it on, the AI receptionist: Telnyx's AI assistant answers that agent's after-hours and unanswered calls — Telnyx converts the caller's speech to text, a language model hosted by Telnyx writes the replies, Telnyx speaks them, and Telnyx keeps the conversation transcript so the agent can read it. No recording of these calls is kept. See Section 2.3A)
  • Twilio (SMS and voice communications for accounts not yet moved to Telnyx)
  • AssemblyAI (redaction of call recordings — after a recorded call ends, its recording is sent to AssemblyAI, which transcribes it and returns a copy of the audio with Social Security numbers, bank account and routing numbers, payment card numbers, security codes and expiration dates, and dates of birth bleeped out, and a transcript with those details removed. Nothing is sent for a call that is not recorded, and nothing is sent during a call. Once we have stored the copies, we ask AssemblyAI to delete its transcript. See Section 4.6)
  • Resend (transactional and notification email)
  • Vapi (AI voice calling — switched off for every account since September 18, 2026; when on, call audio and transcripts)
  • OpenAI (speech and language models behind AI voice calls and assistant features, where applicable)
  • ElevenLabs (text-to-speech for AI voice features, where applicable)
  • TCPA Litigator List (screening of phone numbers against known litigator and do-not-call risk lists before outreach)
  • Stripe (payment processing; and, for agents who sell leads through the marketplace, payouts through Stripe Connect, including the identity and bank-account verification Stripe performs for them)
  • Meta Platforms (advertising integration, where you choose to use it)
  • Google (Sign in with Google, and the Google Calendar, Gmail, and Google Ads integrations, where you choose to use them; also browser speech recognition — when you choose to talk to a voice feature such as the AI assistant or the Sales Trainer in Chrome or Edge, the browser sends that microphone audio to Google’s speech service to turn it into text. The microphone is only ever open while you have started a voice session yourself, we never listen in the background, and the audio does not pass through or get stored on EZLeads servers)
  • Sentry (error monitoring)
  • PostHog (product analytics — see Section 2.12; you can turn this one off in Settings, see Section 7)
  • Anthropic (AI features, where applicable, including the in-app AI assistant — which can see the Google Calendar details of an appointment described in Section 2.8 — and Suggestions from calls, which reads the transcript of a recorded call to propose Financial Inventory entries — see Section 2.2A)
  • TypeSafe AI (classification of the content of text messages a lead sends to an agent, so the platform can tell what a reply means — for example a wrong number, a request to stop, a question, or a suggested time. It returns a label and a confidence, never written text, and it is bound not to train models on what it receives. It does not decide whether you have consented to be contacted: a request to stop is honored by our own keyword rules, as described in Section 13. It also classifies the text of bug reports and feature requests users send us, with email addresses and phone numbers removed first, so we can sort and route them — for example which part of the app a report is about, or whether it asks how to do something. For these too it returns labels and a confidence only, never written text, and does not train models on them)
  • Plaid (bank account connections in the Palisade Zenith portal, and only for a user who links their own account there; we receive no bank data about leads or about any other third party)
  • Upstash (rate limiting on public forms; it sees opaque request keys, never message or form content)
  • Apple (Sign in with Apple, and the Apple Push Notification service that delivers alerts to our iOS app — for users of that app only; see Section 14)
  • Discord (deal announcements in an agency's private server, for agents whose agency uses them — the agent's name and profile picture, the carrier and product, the annualized premium, and the lead type; never a client's name)

These providers process information on our behalf and are contractually required to handle it in accordance with this Policy and applicable law.

4.2 Legal Compliance and Protection of Rights. We may disclose information when we believe in good faith that disclosure is necessary to:

  • Comply with applicable law, regulation, legal process, or governmental request.
  • Enforce our Terms of Service.
  • Detect, prevent, or address fraud, security, or technical issues.
  • Protect the rights, property, or safety of EZ Leads, our Users, or others.

4.3 Business Transfers. If EZ Leads is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will require the recipient to honor this Policy or notify you of any material changes.

4.4 With Your Consent. We may disclose information with your direction or consent. Two integrations send lead information to another company only when you use them: submitting a closed policy to MyPolicyPal for bonus processing sends the client's name, phone number, email address, date of birth, and state with the policy's carrier, product, face amount, annual premium, effective date, and policy number, and your NPN; and opening a quote in the Insurance Toolkits quoter sends the rating inputs described in Section 2.2A.

4.5 Meta Conversions API (Advertising Measurement). A User may connect their own Meta (Facebook) advertising account to the Service by entering their own pixel or dataset ID and their own Conversions API access token. Where a User has done so, and only for that User's own leads, we send Meta an event each time the User changes a lead's stage, so that Meta's Lead Center can report the outcome of the ad the lead came from. The event carries the Meta lead identifier, the stage, and SHA-256 hashed forms of the lead's email address, phone number, first and last name, date of birth, state, and ZIP code; hashing lets Meta match the event to the person who submitted the ad form, so it does not make the disclosure anonymous. Meta is not acting as our service provider for this export, so we treat it as “sharing” for cross-context behavioral advertising as the CCPA defines that term. Nothing is sent for a User who has not connected an account, and we receive no payment for it.

4.6 Live Call Supervision and Call Review. Anyone in an agent's agency can listen to the agent's live calls, and can play the agent's recorded calls and read their transcripts. A manager above the agent in the agency's hierarchy, or an administrator of that agency, can also speak to the agent alone, speak to both people on the call, or take the call over. Someone who only listens is not shown to the agent; the agent sees who has joined whenever someone speaks to them alone, speaks to both people on the call, or takes the call over. Within an agency this is on for every agent and has no switch. Platform staff outside the agent's agency may join only while the agent allows it in their settings (allowed by default). Supervision follows the same one-party rule as recording (Section 6): no one joins a call when the agent or the consumer is in an all-party-consent state, and no notice is played. A call need not be recorded to be supervised; for a consumer, this means a call with an agent may also be heard live, or played back later, by others in that agent's agency.

On a call recorded since October 5, 2026, only the person who was on the call and the account owner can play the original recording or read the original transcript. Anyone else who may review the call, such as a virtual assistant, a manager above the agent, or an administrator of that agency, gets only the redacted copy described in Section 4.1, with Social Security numbers, bank and payment card details, and dates of birth removed; the rest of the conversation is unchanged. Recordings made before that date play as before.

We do not sell personal information to third parties for money, and apart from the Meta Conversions API export described in Section 4.5, we do not share it for cross-context behavioral advertising. To opt out of that sharing, see Your Privacy Choices.

5. Information About Your Leads

You provide us with information about your leads in order to use the Service to communicate with them. We process that information on your behalf and in accordance with your direction.

Your leads are other people. Almost everything the Service holds is information about someone who is not our account holder: the consumers you record as leads. You decide what to collect about them, what to record, and who on your team can see it, and you are the party those people dealt with. We hold that information for you and act on your instructions about it; we do not use it for our own purposes, we do not sell it, and we do not contact your leads for our own reasons.

Recipients of communications you send through the Service may exercise privacy rights directly with you, since you are the party that collected their information and originated the communication. We will assist you in responding to such requests as required by applicable law, but we do not maintain direct relationships with your leads.

You are responsible for providing any notices to your leads required by applicable privacy law and for obtaining any consents required for the communications you send through the Service.

If you are a consumer whose information an agent holds in the Service: the agent you dealt with collected your information and is the party to contact about it. Where an agent recorded health or financial details you provided for an insurance quote (Section 2.2A), those details are held for that agent, are not sold, and are not used for advertising. You can ask the agent, or us at privacy@myezleads.com, to access, correct, or delete them; see Section 9 and our Consumer Health Data Privacy Policy. Texting STOP to any message sent through the Service stops texts from that sender, and that opt-out is kept even if the agent later deletes your record.

To have your record deleted, email privacy@myezleads.com with the phone number or email address the agent has for you, or ask the agent directly. We acknowledge within ten business days and respond within 45 days (Section 9); where the agent is the party that collected your information, we forward the request to them and assist them in carrying it out. Two things deliberately survive a deletion, because the law requires it and because they exist to protect you: the record that you opted out, so the same number is never contacted again, and the five-year consent evidence described in Section 6.

6. Data Retention

We retain information for as long as your account is active and for a reasonable period thereafter to comply with our legal obligations, resolve disputes, enforce our agreements, and maintain backup or archival copies. Specific retention periods vary based on the type of information and the purposes for which we hold it. Deleting your account is different: the end of this Section says what a deletion removes, and the two kinds of record it keeps.

Communications metadata (message and call records, including message content) is retained for the duration of your account and deleted with it. Call recordings follow their own, shorter period below.

By category, and stated plainly:

  • Call recordings and transcripts. Kept for one year from the call, then deleted: first the audio, which the telephony provider that captured it holds, then our record of where it was, and the transcript with it. If the account is deleted before then, the deletion deletes the audio at that provider, and the transcript and our record of the recording go with it, at once. Recordings made through our previous telephony provider are deleted when that account is closed. Recording is off for every account unless you turn it on, and it only runs where both parties are in a one-party-consent state — the agent's one-time acknowledgement is their consent, and no notice is played. If you want a particular recording or transcript removed, ask us and we will remove it. The redacted copy of a recording and its redacted transcript (Section 4.6) are kept with the recording and deleted with it, on the same schedule.
  • AI receptionist transcripts. Our copy of the transcript, and the message the receptionist took, are kept for the lifetime of the account and deleted with it. Telnyx keeps its own copy of the transcript on its own schedule. There is no recording of these calls to keep (Section 2.3A).
  • Text message content and call logs. Kept for the lifetime of the account, and deleted with it. While the account exists they are the record of what was said to a consumer and when, which is what a messaging or telemarketing complaint is answered with.
  • Lead records. Kept for the lifetime of the account, or until you delete the lead. Deleting a lead removes its record and its related rows; the two exceptions are named below. Deleting the account deletes every lead it holds, and only the consent and opt-out records below outlive them.
  • Google user data. The OAuth tokens for a Google Calendar or Gmail connection are kept while the connection is active and deleted when the User disconnects it in Settings → Connections or deletes their account; if the User revokes access from their Google Account instead, the tokens are cleared the next time the Service tries to use them and Google reports the access revoked. The busy times read to show open times while booking are never kept, and the events read to show the User's calendar on the Calendar page are never kept either; nothing else on the User's calendar is read or kept (Section 2.8). The event identifiers and links of appointments booked through the Service, and our record of each email sent through Gmail, are part of the lead's record and follow it (see Lead records above). A User can ask us at any time to delete the Google user data we hold, as Section 9 describes.
  • Billing records. Invoices, payments and the subscription history are kept for as long as tax, accounting and payment-dispute rules require, including after an account is closed or deleted. The card itself is never stored by us; Stripe holds it.
  • Usage analytics and error reports. Kept on each provider's own retention schedule (Section 2.12) and expired by them automatically.
  • Backups. Database backups are taken daily by our hosting provider. A deleted record can persist in a backup until that backup expires on the provider's schedule; backups are not restored into the live system except to recover from a disaster, and a deletion is re-applied if they are.

Health and financial intake about leads (Section 2.2A) is kept while the lead is active. Where a lead never became a client, the platform is built to clear the recorded health and financial answers after a period of inactivity set in our retention policy (the lead's contact record itself is not affected); until that period is set, the answers are kept for as long as the lead record itself is kept. Intake recorded for a lead who purchased coverage is kept with the transaction record for the lifetime of the account, and deleted with it.

Consent and opt-out records. Records of consent to be contacted and of opt-outs (STOP requests, do-not-contact requests) are kept for at least five years, as the Telemarketing Sales Rule requires, including after the related lead or account is deleted. When a lead record is deleted, the phone number's opt-out is retained as a suppression entry so that the same number is not contacted again if it is later re-imported into that account. Deleting an account does the same for every lead it held: each consent and opt-out record is kept, with the phone number it covers, for five years, and each opt-out stays on the suppression list. A suppression entry records an opt-out given to one account and applies to that account; it is not a platform-wide do-not-call registry and does not bind other agents.

When you delete your account. Deleting your account (Settings, under Legal & support) deletes your profile, your leads and their health and financial intake, notes, text messages, call logs, call recordings and transcripts, workflows and automations, saved views and the files you uploaded. Three kinds of record are kept after the account is gone, because the law requires them: billing records, for as long as tax, accounting and payment-dispute rules require; the consent and opt-out records of your leads, as described above; and the forms you signed — each lead upload, purchase and landing page — together with the sign-in record they are attached to. That sign-in record is not an account: nobody can sign in to EZLeads with it, and it holds no leads, no messages and no phone number. If you also use Palisade Zenith, that account stays on the same sign-in and is unaffected. A deleted record can remain in a backup until that backup expires, as described above.

You may request deletion of information about your account by following the procedures in Section 9, subject to our retention obligations.

7. Cookies and Similar Technologies

We use cookies, local storage, and similar technologies to authenticate Users, remember preferences, measure performance, and detect abuse. You can configure your browser to refuse cookies, but some features of the Service may not function properly if you do. We do not use advertising cookies and we do not permit cross-site tracking of you by anyone. Our Cookie Policy lists each cookie we set by name.

Turning product analytics off (how to withdraw consent). Product analytics is on by default, which this Policy discloses rather than assumes: an account created under this Policy is treated as consenting until you say otherwise. To withdraw that consent, open Settings → Security & privacy and turn Usage analytics off. On a phone and in our mobile app the same switch is under Settings → Privacy. It takes effect immediately. No explanation is required and nothing else about your account changes.

With it off, we stop sending product-analytics events and session replays (PostHog) and page-view events (Vercel Analytics) for you on that device. Three things deliberately continue, because none of them builds a profile of you and the Service is not operable or maintainable without them: the cookies that keep you signed in and remember your preferences; error reporting, which tells us that something broke so we can fix it; and the page-load timings Speed Insights samples, which carry no identifier of any kind. If your browser sends a Do Not Track signal, our product analytics honours it and collects nothing, whatever this switch says.

The choice is stored in a cookie on the device you set it on, so clearing your cookies resets it to the default and setting it on one device does not set it on another.

8. Security

We implement reasonable administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction. These include encryption at rest and in transit for sensitive data, row-level access controls, scoped credentials, and audit logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

If we become aware of a security incident that affects your information, we will notify you as required by applicable law.

9. Your Rights and Choices

Depending on where you live, you may have certain rights regarding information about you, which may include the right to access, correct, delete, or port your information, and to object to or restrict certain processing. To exercise these rights, contact us at privacy@myezleads.com. We may need to verify your identity before responding.

Your choices, and where each one lives. These are controls you operate yourself, inside the Service, without writing to us:

  • Usage analytics: Settings → Security & privacy (Privacy on a phone). Turn it off to withdraw consent to product analytics; see Section 7 for exactly what stops.
  • Delete your account: Settings, under Legal & support. Deleting removes your account and the data described in Section 6, except the billing records, the opt-out and consent records, and the signed forms and sign-in record that Section 6 says survive.
  • Call recording: Calls, and Settings → Phone. Recording is off unless you turn it on, and it never runs where either party is in an all-party-consent state. Call transcripts have their own switch beside it. You can turn either off at any time.
  • AI receptionist: Settings → Phone → Calling. It is off unless you turn it on, and you can turn it off at any time (Section 2.3A).
  • Notifications: Settings → Account. Email, daily digest and account-notification texts are each their own switch; replying STOP to an account text also stops it.
  • Disconnect an integration: Settings → Connections. You may revoke the Meta, Google Calendar, Gmail, or Google Ads connection at any time; we delete the stored tokens on disconnection.

California residents: Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), you have the right to know what personal information we collect, use, disclose, and sell or share; the right to delete personal information; the right to correct inaccurate personal information; the right to opt out of the sale or sharing of personal information; and the right not to be discriminated against for exercising your privacy rights. We do not sell personal information for money. The one disclosure we treat as “sharing” is the Meta Conversions API export described in Section 4.5. To opt out of it — or to send us a Global Privacy Control signal, which we honour as an opt-out request on its own — use Your Privacy Choices. To exercise any of these rights, contact us at privacy@myezleads.com. You may also designate an authorized agent to make a request on your behalf.

Washington, Nevada, and Connecticut residents — consumer health data: The health information described in Section 2.2A is “consumer health data” under the Washington My Health My Data Act, Nevada SB 370, and the Connecticut Data Privacy Act. We collect it only with the consent of the person it describes, given to the agent at the time of an insurance quote; we do not sell it; and we do not share it except with the agent who collected it, their authorized team, and the service providers that host the platform. You may withdraw consent, and access or delete that data, by contacting the agent or privacy@myezleads.com. Our separate Consumer Health Data Privacy Policy sets this out in full.

How we handle requests. We acknowledge a request within ten business days and respond within 45 days (extendable once by 45 days where the law allows, with notice). Where the data was collected by an agent, we forward the request to that agent and assist them; we may verify your identity by confirming the phone number or email the record holds. Deletion does not remove the retained opt-out or consent records described in Section 6.

10. Children's Privacy

The Service is not directed to children under 18, and we do not knowingly collect personal information from children under 18. If we learn we have collected information from a child under 18, we will delete it.

11. United States Only

The Service is intended for use only within the United States. We do not target or knowingly accept information about individuals located outside the United States. If you access the Service from outside the United States, you do so at your own risk and you consent to the transfer of your information to the United States, which may have different data-protection rules than your home country.

12. Changes to This Policy

We may update this Policy from time to time. Material changes will be communicated through the Service or via email to the address on file. The “Effective Date” at the top of this Policy reflects the most recent revision. Your continued use of the Service after the effective date constitutes acceptance of the revised Policy.

13. SMS Communications

13.A SMS Messages EZ Leads Sends to Users (Account Notifications)

EZ Leads offers Users the ability to receive SMS (text message) notifications related to their account activity. This Section 13.A governs SMS messages that EZ Leads sends to you about your account.

By providing your phone number and opting in to SMS notifications within your account settings, you expressly consent to receive text messages from EZ Leads. These messages are strictly transactional and may include:

  • New lead alerts
  • Account status notifications
  • Carrier-vetting or compliance updates
  • Other activity related to your use of the Service

Transactional SMS messages may reference information submitted through your marketing campaigns, including lead details such as contact names and phone numbers, for the purpose of enabling timely follow-up.

Message frequency varies depending on your account activity.

Message and data rates may apply.

No Marketing SMS. EZ Leads does not send marketing or promotional messages to its Users via SMS. All EZ Leads-originated SMS messages to Users are transactional.

Opt-Out. You can opt out at any time by replying STOP to any message. You will receive a confirmation message and will no longer receive SMS messages from EZ Leads unless you opt in again.

Help. For assistance, reply HELP to any message.

Privacy. SMS consent and phone numbers collected for SMS notification purposes are used solely to provide the requested services. We do not sell, rent, or share your phone number or SMS consent information with third parties or affiliates for marketing or promotional purposes.

13.B SMS Messages Sent by Agents to Consumers Through the Service

Licensed insurance agents who use the Service may send SMS messages to consumers who personally submitted a quote request — most on a Meta (Facebook/Instagram) Lead Ad form, some on the agent's EZ Leads web landing page. This Section 13.B describes how EZ Leads handles information about those consumers in connection with SMS messaging.

Brand. Each agent messaging program operates under the name of the individual licensed agent (or their agency) identified in the on-form consent disclosure — that named agent is the registered brand of the program's messaging campaign. This Privacy Policy applies to every such program conducted through the Service, and it is linked both from the opt-in form itself and from each program's public opt-in documentation page.

Consent. Two consents are collected separately on the lead form. Submitting the form with a phone number is the consumer's agreement to be contacted about the specific request they submitted; individual, conversational replies about that request are sent on this basis. Recurring automated marketing texts (for example, quotes and offers) are governed by a separate, optional consent checkbox that is unchecked by default; the disclosure is displayed in full at the point of submission, identifies the licensed agent who may contact the consumer, and checking it is never required to submit the form. Marketing texts are sent only where marketing consent exists — given on the form, given later by texting START, or obtained by the agent outside the Service and documented by the agent, who attests to and is solely responsible for the validity of such consent. For web landing-page submissions, EZ Leads records each consent with a timestamp, IP address, page URL, and the version of the consent language displayed, and retains these records, including after opt-out. For Meta Lead Ad form submissions, EZ Leads records the consumer's checkbox response as received from Meta.

Message content and frequency. Messages are individual, conversational follow-ups regarding the insurance quote the consumer requested and — only where marketing consent exists — occasional marketing texts such as updated quotes and offers. Message frequency varies. Message and data rates may apply.

Opt-out and help. Consumers may opt out at any time by replying STOP to any message; opt-outs are honored immediately and enforced at the platform level, preventing all further SMS to that number. Consumers may reply HELP for assistance.

No sharing of mobile information. Consumer phone numbers, SMS consent records, and text-messaging originator opt-in data are used solely to deliver the communications the consumer requested. We do not sell, rent, share, or otherwise distribute consumer phone numbers or SMS opt-in information with third parties or affiliates for marketing or promotional purposes.

14. Mobile Application

This Section covers our iOS application, EZPZ CRM, which is a companion to the web service described everywhere else in this Policy. It signs you in to the same account, shows the same data, and is governed by this same Policy. Everything below applies only if and when you use it.

What the app collects that the website does not. One thing: a push notification token issued by Apple for the copy of the app on your device. We store it against your account and use it only to deliver the alerts you have turned on (a new lead, an inbound text, a missed call). It identifies a device installation, not a person, it carries no message content, and deleting the app or turning notifications off ends its use. The alerts are delivered through the Apple Push Notification service.

Device permissions, asked for at the moment they are used. The microphone, the camera and Face ID (or Touch ID) are requested only when you start the thing that needs them: the microphone for a call, the call recorder, or a practice session with the sales trainer; the camera for taking a photo to attach to a record; Face ID to unlock the app if you turn the lock on. Face ID is checked by iOS on the device and never leaves it. The app does not ask for your contacts and does not ask for your location.

We do not track you across other apps or websites. The app contains no advertising SDK and no cross-app tracking, and we do not link what you do in it to data collected about you by other companies for advertising. The usage analytics described in Section 2.12 measure our own app only, and the switch in Section 7 turns them off there exactly as it does on the web.

Deleting your account from the app. Settings, under Legal & support, inside the app itself. It is the same deletion described in Sections 6 and 9, with the same retention exceptions.

Nothing is bought inside the app. The app contains no purchasing of any kind and collects no payment information of any kind.

15. Contact

Questions about this Privacy Policy or our handling of information may be directed to:

EZ Leads LLC
Attn: Privacy
8688 E Raintree Dr
Scottsdale, AZ 85260
Email: privacy@myezleads.com

Effective 2026-10-05 · Version 1.29