Security
What we hold, and what we do with it.
Answering your phone means holding some genuinely sensitive things: a customer's name, their phone number, their home address, and a recording of them saying they cannot get into it. This page says plainly where that goes.
Effective 21 July 2026. We will say what changed when this is revised.
The data we hold, and why it matters more than most
Most software that stores a customer list is storing names and emails. A locksmith call is different. Taken together, our records amount to a list of addresses where someone recently could not get in, with a time and a phone number attached. We would rather say that out loud than let you discover it.
Specifically, for each call we keep:
- The caller’s phone number, and their name if they gave it.
- The service address, and the coordinates it resolved to.
- A transcript of the conversation.
- An audio recording, where recording applies.
- What the agent decided, and the price and time it quoted.
Where it lives
All of it is stored in the United States, with the single exception noted below. Data is encrypted in transit, and encrypted at rest by the managed services that hold it. We do not run our own servers or our own storage.
One lookup leaves the country. The routing service that works out real driving time is a Netherlands company, so the service address, or its coordinates, is sent there on every service-area check. We would rather name that than let it sit unmentioned in a subprocessor list.
Everyone else who touches the data is named on the subprocessors page, including the ones we have not switched on yet.
Who can read it
Access to production data is limited to the people who operate LeadLatch, and today that is a very short list. It is used to run the service, to investigate a problem, and to check call quality. It is not browsed.
The database enforces per-shop access rules, so one shop’s records are not reachable from another shop’s session. We are still tightening the internal permissions used by the service that handles live calls, which today runs with broader database access than it needs. That work is in progress and we would rather tell you than describe the end state as if it were finished.
How long we keep it
Transcripts are kept as the durable record of what was said, because that is what lets you settle a disagreement about a quote months later. Audio recordings are treated as short-lived and are deleted on a schedule unless the shop saves a specific one.
We are deliberately not printing exact durations here yet. A number on this page is a promise, and we would rather set that once, properly, than publish something we later have to walk back. If you need a specific retention commitment in writing before you sign up, ask and we will put it in your agreement.
You can ask us to delete a shop’s data, or a specific call, and we will.
Payments
When billing goes live, card details will be handled entirely by Stripe on their own hosted checkout. Card numbers will never reach our servers, which keeps an entire category of risk off our side of the line.
What we do not do
- We do not sell your data, or your callers’ data, to anyone.
- We do not share it with advertisers, and the site sets no cookies and needs no consent banner.
- We do not use your call content to train our own models.
- We do not listen to calls for entertainment or curiosity.
What we are not claiming
LeadLatch is early, and a security page is a bad place to be vague. So, explicitly: we are not SOC 2 certified, we do not publish an uptime guarantee, and we have not had an external penetration test. Larger competitors have some of these. If a certification is a hard requirement for you, we are not the right fit yet, and we would rather say so now than during procurement.
Telling you when something goes wrong
If data we hold is exposed, we will tell the affected shops directly and promptly, with what happened and what we are doing about it. We would rather commit to that plainly than quote a number of hours we have never had to meet.
Reporting a problem
If you have found a security issue, please tell us before telling anyone else, and we will work with you. Use the contact form and say it is a security report; it gets looked at the same day.