Lokal Media LLC, doing business as Fresh Leads Marketing (“Fresh Leads,” “we,” “us,” or “our”), operates the Fresh Leads Client Portal (the “Portal”), a web-based platform provided to our marketing services clients for the purpose of managing advertising campaigns, viewing performance analytics, managing customer relationship (CRM) data and customer re-engagement, operating client websites and a consumer customer application, accessing AI-powered tools, and managing billing for optional add-on services.
This Privacy Policy describes how we collect, use, store, share, and protect personal information when you use the Portal. By accessing or using the Portal, you acknowledge that you have read and understood this Privacy Policy.
When your account is created by a Fresh Leads administrator, we collect and store the following: your full name, email address, assigned role (e.g., client owner, staff member), and an optional profile avatar. You do not create your own account — accounts are provisioned by our team during the onboarding process.
We use Supabase Authentication to manage login sessions. When you sign in, we store a secure authentication token in an HTTP-only cookie on your browser, along with your assigned role and client identifier. Passwords are hashed and managed by Supabase — we never store plaintext passwords.
For clients using the Portal, we store business-related information including: your business name, location, advertising platform account identifiers (Google Ads Customer ID, Facebook Ad Account ID), CRM platform identifiers (GoHighLevel Location ID), and POS system connection credentials. Sensitive credentials such as API keys and POS system passwords are encrypted at rest using AES-256-GCM encryption.
The Portal displays aggregate advertising metrics from your Google Ads and Facebook/Instagram Ads accounts. This data includes campaign-level metrics such as impressions, clicks, cost, conversions, click-through rates, cost-per-click, and cost-per-lead. This is aggregate performance data only — we do not import or store the personal information of your individual customers from these advertising platforms.
If you use optional paid features (AI Chatbot or AI Voice Bot), payment processing is handled entirely by Stripe, Inc. We do not store your full credit card number, CVV, or other sensitive payment card details on our servers. We retain your Stripe Customer ID, payment method identifier (for auto-reload functionality if you enable it), and transaction records including amounts, dates, and descriptions for accounting purposes.
If you use the AI Chatbot or AI Voice Bot features, we store conversation transcripts, call metadata (duration, timestamps), and AI-generated analysis (sentiment, summaries). Chatbot conversations are processed by Anthropic (Claude AI). Voice calls are processed by Retell AI. These services receive conversation content to generate responses but do not use your data to train their models. See Section 5 for details on third-party data sharing.
We log activity within the Portal for security and operational purposes, including login timestamps, actions taken (e.g., marking onboarding tasks complete, sending messages), and IP addresses used during authentication for rate-limiting purposes. We do not use third-party analytics or tracking services on the Portal.
The Portal uses the following essential cookies, which are strictly necessary for the Portal to function. We do not use advertising cookies, analytics cookies, or tracking pixels.
Where you connect your laundry point-of-sale (POS) system, CRM (GoHighLevel), and/or enable the customer re-engagement and consumer Customer Application (PWA) features, the Portal retrieves, stores, and processes the personal data of your customers in our databases. This may include their names, email addresses, phone numbers, loyalty/account or card identifiers, account balances, and visit, usage, and spend history. We use this data to build CRM segments, tag and re-engage lapsed customers (with campaigns delivered through your GoHighLevel account), produce analytics, and operate the Customer App.
As to this customer data, you are the data controller and we act as your service provider/processor, handling it solely to provide the Services and only on your instructions. We do not sell it, use it for our own marketing, or share identifiable customer data across clients (we may use aggregated and de-identified data as described in Section 3 below). You are responsible for having the rights, consents, and privacy notices needed to provide this data to us (see also Section 5 of your Marketing Services Agreement). End customers using the Customer Application are covered by a separate, consumer-facing privacy notice presented within that application.
We use the information we collect for the following purposes:
Aggregated and De-Identified Data. We may create and use data that has been aggregated or de-identified so that it cannot reasonably be used to identify you, any individual, or any customer, in order to operate, secure, develop, benchmark, and improve our services, models, and AI features, including across our client base, both during and after your engagement. We do not attempt to re-identify this data or present it in a way that identifies you.
Your data is stored on Supabase-hosted infrastructure (PostgreSQL database) with encryption in transit (TLS 1.2+) and at rest. Sensitive credentials (API keys, POS system passwords) are additionally encrypted using AES-256-GCM before storage.
Payment data is processed and stored by Stripe in compliance with PCI DSS Level 1 standards. We do not store raw credit card numbers on our infrastructure.
Access to the Portal is protected by password-based authentication with rate limiting (5 login attempts per minute per IP address). API endpoints enforce role-based access control — client users can only access their own data, and all administrative actions require verified admin credentials.
While we implement commercially reasonable security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your information.
If we become aware of a confirmed unauthorized acquisition of personal data within our systems, we will notify affected clients without undue delay and cooperate in reasonable mitigation efforts.
We share information with the following third-party service providers who assist us in operating the Portal. Each provider processes data only as necessary to perform their specific function:
Supabase, Inc.
Database hosting, authentication, and data storage. Receives: account data, business information, activity logs.
Stripe, Inc.
Payment processing for AI Chatbot and Voice Bot usage. Receives: payment card details, billing amounts, customer identifiers.
Anthropic, PBC (Claude AI)
AI chatbot conversation processing. Receives: chatbot message content and conversation context to generate responses.
Retell AI, Inc.
AI voice bot call processing. Receives: call audio, phone numbers, and conversation content for voice interactions.
Google (Google Ads API)
Advertising data retrieval. We access your Google Ads account data using authorized credentials to display campaign performance.
Meta Platforms, Inc. (Facebook/Instagram Ads API)
Advertising data retrieval. We access your Facebook Ads account data using authorized credentials to display campaign performance.
GoHighLevel (Highlevel, Inc.)
CRM and customer-messaging platform. We sync your customer contacts and re-engagement tags to your GoHighLevel sub-account, which sends the email/SMS campaigns. Receives: customer names, emails, phone numbers, and segmentation tags.
Laundroworks / Mitechisys
Laundry point-of-sale (POS) system. We retrieve your customers' account and usage data via the POS API to power CRM, re-engagement, and the Customer Application. Receives: API requests authorized by your stored credentials.
Vercel, Inc.
Application hosting and delivery. The Portal is hosted on Vercel's infrastructure.
Resend (Resend, Inc.)
Transactional email delivery. Receives: recipient email addresses and notification content for system-generated emails.
We do not sell, rent, or trade your personal information to third parties for their own marketing purposes.
We may add or replace sub-processors as the Portal evolves. We will post material changes to this list on this page and update the “Last updated” date above.
When you or your customers opt in to receive text messages, we collect the mobile phone number and the associated consent record (the date, time, and method of the opt-in, and the disclosure language shown at the time). We use this information only to send the messages that were signed up for and to meet our legal and record-keeping obligations.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with or sold to any third parties. Sharing with subcontractors who provide support services, such as customer service platforms and message delivery providers, is permitted solely so that the messages you requested can be delivered.
All other categories and sharing practices described in this Privacy Policy, including the sub-processor list above, exclude text messaging originator opt-in data and consent. That information is not shared with, or sold to, any third parties for marketing purposes under any circumstance.
You can stop receiving text messages at any time by replying STOP to any message. Reply HELP for help, or contact us at ryan@freshleadsmarketing.com. Message frequency varies. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. We honor opt-out requests received by any reasonable means, not only the STOP keyword, and we retain consent and opt-out records for at least five years.
We retain your information for as long as necessary to provide the Portal services and fulfill the purposes described in this policy:
Depending on your jurisdiction, you may have the following rights regarding your personal information:
To exercise any of these rights, contact us at info@freshleadsmarketing.com. We will respond to verifiable requests within 45 days.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). We do not sell or share your personal information for cross-context behavioral advertising. You have the right to know what personal information we collect, the right to delete your personal information, and the right to non-discrimination for exercising your privacy rights. To submit a request, email info@freshleadsmarketing.com.
The Portal is a business-to-business platform and is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information promptly.
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by posting a notice within the Portal and updating the “Last updated” date above. Your continued use of the Portal after such changes constitutes your acceptance of the updated policy.
If you have any questions about this Privacy Policy or our data practices, contact us at:
Lokal Media LLC (Fresh Leads Marketing)
Email: info@freshleadsmarketing.com
Website: freshleadsmarketing.com