This Privacy Policy explains how KeyBolt Inc., a New York corporation, doing business as LeadLatch ("LeadLatch," "we," "us," or "our"), handles personal information in connection with our public website, business accounts, support activities, and the LeadLatch Service.
1. Scope and our roles
1.1 Information LeadLatch controls
LeadLatch determines the purposes and means of processing personal information associated with:
- visitors to the public website;
- people who submit contact, demo, or support requests;
- Customer representatives and Authorized Users;
- account administration, authentication, contracting, security, and support; and
- billing contacts and payment administration after billing launches.
For this information, LeadLatch acts as a controller or business under applicable privacy law.
1.2 Caller Data processed for Customers
When LeadLatch handles a call for a locksmith business, the Customer generally determines why the Caller Data is collected and how the Customer uses it. LeadLatch generally processes that Caller Data for the Customer under the Data Processing Addendum. The Customer is responsible for its own privacy notices, legal basis, and relationship with the Caller.
LeadLatch delivers Caller Data to the Customer through the authenticated dashboard, the Customer's designated notification email address and, where an Authorized User has opted in to LeadLatch Operational Alerts, the Customer's designated mobile number by SMS. Those SMS alerts contain the Caller Data needed to return the call, which may include the Caller's name, callback number, service address, described job, and vehicle details, and LeadLatch repeats an alert about the same request until an Authorized User acknowledges it or the request is closed. SMS is not an encrypted channel and is carried by telecommunications providers outside LeadLatch's control; a Customer that does not want Caller Data delivered that way should leave Operational Alerts off and rely on email and the dashboard.
Callers should ordinarily submit privacy requests to the locksmith business they called. Section 12 explains how LeadLatch handles requests it receives directly.
1.3 Information outside this Policy
This Policy does not govern a Customer's independent handling of information after the Customer receives it. It also does not govern third-party websites or services that LeadLatch does not control.
2. Information we process
2.1 Caller Data
Depending on the call and Customer configuration, Caller Data may include:
- caller telephone number and caller-ID information;
- name and contact details provided during the call;
- requested service address and coordinates derived from that address;
- lock, key, vehicle, property, access, and job details;
- call audio, live conversation content, and transcripts;
- qualification results and records of Service tool calls;
- authorized prices, routed drive times, availability, held windows, and Booked Jobs;
- call time, duration, status, provider identifiers, and outcome; and
- technical and security telemetry.
2.2 Customer and Authorized User information
We may process:
- business name, service location, business contact details, and account identifiers;
- Authorized User name, email address, authentication records, and account role;
- service areas, hours, technicians, prices, job types, notification recipients, greetings, and disclosure settings;
- a designated operational-alert mobile number, SMS consent status and history, disclosure version, opt-out or help requests, alert category, message content, and delivery status;
- Order Forms, acceptance records, invoices, credits, and billing information after billing launches; and
- support, security, legal, and other correspondence.
2.3 Website and inquiry information
We may process:
- information submitted through contact or demo forms;
- IP address, user agent, request time, and similar hosting or security metadata; and
- cookieless website analytics describing page use and referral information.
3. Sources
We obtain information:
- directly from Callers during calls;
- directly from Customers and Authorized Users;
- from people who contact us through the website or email;
- from telecommunications carriers and service providers used to deliver the Service; and
- automatically from application, hosting, authentication, and security systems.
4. How we use information
We use information to:
- answer calls and conduct the requested voice interaction;
- determine service-area eligibility using routed drive time;
- communicate Customer-configured prices and availability;
- hold appointment windows and create Booked Jobs;
- send operational email and opted-in SMS notifications to Customers, including the Caller Data needed to return a call, and repeat an unacknowledged SMS alert until an Authorized User acknowledges it or the request is closed;
- authenticate Authorized Users and administer accounts;
- provide support and targeted quality assurance;
- detect, investigate, and prevent fraud, misuse, and security incidents;
- debug, maintain, and improve reliability using operational telemetry;
- administer contracts, credits, invoices, and future billing;
- comply with law and enforce our agreements; and
- respond to inquiries and communicate about LeadLatch.
We do not use identifiable Caller audio, transcripts, addresses, or job details for general product analytics or unrelated marketing. We may use properly deidentified or aggregated data for internal security, reliability, capacity planning, and service analytics and will not attempt to reidentify that data.
5. Cookies and analytics
5.1 Public website
The public marketing site uses Vercel's cookieless analytics. We do not use advertising cookies or cross-site tracking pixels on that surface.
5.2 Authenticated dashboard
The authenticated dashboard uses necessary Supabase authentication cookies to establish and refresh login sessions and enforce access. These cookies are not used for targeted advertising or cross-site tracking.
Hosting and security providers may also create ordinary request logs containing IP address, user agent, time, and requested resource.
6. How we disclose information
We disclose information only as described below:
6.1 Service providers
We use providers for telephony, real-time media, AI processing, databases, authentication, routing, geocoding, application hosting, rate limiting, error monitoring, software delivery, and email notifications. The current providers and their actual data flows are listed in the Subprocessor Register.
Important examples include:
- Telnyx receives telephone numbers, call audio, call metadata, stored recordings, operational SMS content, consent or opt-out commands, and delivery metadata;
- LiveKit transports real-time audio and session metadata;
- OpenAI receives call audio and conversation content for realtime voice processing, and receives call audio sent for post-call transcription;
- Supabase stores account, configuration, call, transcript, and booking information and supplies authentication;
- Geocodio receives service addresses for geocoding;
- TomTom receives origin and destination coordinates for routed drive-time calculations;
- Vercel hosts the website, dashboard, APIs, webhooks, server actions, and recording proxy, so application data may transit its infrastructure;
- Sentry receives diagnostic data and is configured to reduce personal information in error events, but incidental personal information may still appear;
- GitHub Actions currently handles call audio transiently in the recording-ingestion workflow;
- Resend sends Customer notification emails that may contain a Caller phone number, service address, job details, quoted price, and booking window; and
- Upstash processes a salted identifier for public contact-form rate limiting.
Stripe is planned for Customer billing but is not currently processing production billing data for the Service.
6.2 Legal, safety, and corporate events
We may disclose information when reasonably necessary to comply with valid legal process, protect rights or safety, investigate abuse, establish or defend legal claims, or complete a financing, merger, acquisition, reorganization, or asset transfer. Where legally permitted, we will direct a request for Customer-controlled Caller Data to the relevant Customer or notify the Customer before disclosure.
6.3 No sale or targeted advertising
LeadLatch does not sell personal information, share it for cross-context behavioral advertising, or use Caller Data for targeted advertising.
LeadLatch does not sell or share mobile numbers, SMS opt-in data, or SMS consent status with third parties or affiliates for their marketing or promotional purposes. We provide that information only to Telnyx, telecommunications carriers, and service providers as needed to deliver, secure, and support LeadLatch Operational Alerts.
7. AI processing
OpenAI processes live call audio and conversation content to generate voice responses. OpenAI's published API documentation states that API data is not used to train or improve OpenAI models unless the customer affirmatively opts in. LeadLatch has not verified its account-level opt-in, retention-control, or regional-endpoint configuration for publication.
OpenAI's published endpoint table currently distinguishes between the endpoints LeadLatch uses:
/v1/realtimelists no training use, up to 30 days of default abuse-monitoring retention, and no application-state retention; and/v1/audio/transcriptionslists no training use, no abuse-monitoring retention, and no application-state retention.
OpenAI states that legal requirements and safety-retention conditions may create exceptions. Zero Data Retention and Modified Abuse Monitoring require eligibility and account configuration. We will not represent that either control or a United States regional endpoint applies to LeadLatch until the account is verified.
8. Retention
We retain information according to its purpose, sensitivity, contractual requirements, and legal obligations. Current retention behavior is:
| Information | Current retention behavior |
|---|---|
| Unsaved call recordings | A scheduled process selects recordings matched to call records for deletion after approximately 30 days. Recordings not matched to a call record may not be reached by the current process. |
| Call transcripts | Retained without a defined deletion schedule. |
| Booking and call records | Retained in the Customer account without a defined post-termination schedule. |
| Account and contract records | Retained as needed to administer the account, document acceptance, resolve disputes, and comply with law. |
| SMS consent and delivery records | Retained as needed to administer the messaging program, honor opt-outs, document consent, resolve delivery issues, and comply with carrier or legal requirements. |
| Backups | No public maximum has been verified. |
| Provider-side copies | Subject to provider terms, endpoint behavior, legal requirements, and deletion capabilities. |
We may retain information longer when required by law, subject to a documented legal hold, needed to establish or defend a legal claim, or retained by a provider under a disclosed legal or operational exception. Access to retained information remains restricted.
9. Security
We use administrative, technical, and organizational safeguards designed for the nature of the information processed. Current verified controls include:
- server-side dashboard access rather than a browser database client;
- Supabase authentication and necessary session cookies;
- database row-level security for Customer isolation through the dashboard;
- a scoped Postgres role for the voice worker rather than a master administrative credential;
- restricted personnel access for support, operations, security, legal needs, and targeted quality assurance;
- secrets kept outside application source code;
- Sentry configured to reduce personal information in error events; and
- scheduled recording-purge and recording-ingestion processes.
No security measure eliminates all risk. LeadLatch is not SOC 2 certified, has not completed an external penetration test, and does not offer an uptime or incident-response-time SLA.
The DPA security annex contains the binding security commitments for Customer Personal Data. The Security and Data Protection Overview provides additional factual context but is not an SLA.
10. International processing
Provider headquarters do not establish where a particular request is processed or stored. We do not claim that all personal information remains in the United States. Actual processing depends on the provider, Customer plan, configured region, endpoint, and provider subprocessors.
The Subprocessor Register identifies location information only where it has been verified. Optional international-transfer terms will be activated when the facts and applicable law require them.
11. Privacy choices and rights
People may have rights under applicable law to request access, correction, deletion, portability, or information about processing, and to appeal certain decisions or opt out of certain uses. These rights vary by jurisdiction and are subject to verification and legal exceptions.
For personal information LeadLatch controls, submit a request to privacy@leadlatch.org. We may ask
for information reasonably necessary to verify identity and authority. We will not discriminate
against a person for exercising an applicable privacy right.
LeadLatch does not currently use personal information for targeted advertising or sell it, so an advertising opt-out mechanism is not currently offered. LeadLatch does not claim to honor Global Privacy Control for a sale or sharing activity that does not occur. If relevant practices change, we will implement any required preference-signal handling before updating this Policy.
12. Caller requests
LeadLatch generally processes Caller Data for the locksmith business the Caller contacted. A Caller should ordinarily submit a request to that business. If LeadLatch receives a request directly, we will attempt to identify and route it to the relevant Customer and will assist that Customer as required by the DPA and applicable law.
LeadLatch may respond directly when legally required, when the request concerns information LeadLatch controls independently, or when routing is not reasonably possible. LeadLatch does not currently provide a Caller self-service access or deletion portal.
13. Children
The website and dashboard are intended for businesses and are not directed to children. Callers may include minors, and Caller Data may incidentally contain information relating to a minor. We do not knowingly solicit children to create LeadLatch accounts or submit information for LeadLatch's own marketing purposes.
14. Changes to this Policy
We may update this Policy to reflect changes in law, providers, and processing. We will update the version and dates above. Where law requires additional notice or consent, we will provide it before the relevant change takes effect.
15. Contact
- Privacy requests and questions:
privacy@leadlatch.org - Legal notices:
legal@leadlatch.org - Security reports:
security@leadlatch.org - General support:
support@leadlatch.org