SLS Leads CRM SLS Leads CRM

SLS Leads CRM

Privacy Policy

How Smart Leading Solutions LLC collects, uses, and protects information in SLS Leads CRM.

Last Updated: September 14, 2026

This Privacy Policy describes how Smart Leading Solutions LLC (“we”, “us”) collects, uses, and shares information in connection with SLS Leads CRM (the “Service”), available at https://leads.smartleading.net/.

1. Who we are

The Service is operated by Smart Leading Solutions LLC (https://smartleading.net/). It is a marketing reporting and client management platform (CRM) for managing clients, leads, tasks, reports, metrics, and marketing integrations for agency and client workspaces.

2. Information we collect

Depending on how the Service is used, we may process:

  • User accounts: name, email address, password hash, role, avatar, and login times.
  • Client records: name, website, contact person, email, phone, logo, notes, and timezones.
  • Tasks associated with client workspaces.
  • Leads: personal information submitted or synced into the CRM, plus campaign, UTM, and platform attribution where available.
  • Report snapshots and performance metrics.
  • Encrypted integration configuration (for example OAuth or API tokens for connected platforms).
  • Audit logs of significant actions in the Service.
  • Branding settings (logos and related display assets).

3. Authentication

Access to the CRM uses email and password login. Password reset is available by email. Roles include Admin, Team Lead, Staff, and Client. The Service does not offer social login into the CRM itself.

4. Integrations and third-party data

Clients may connect integrations including Google Ads, Google Search Console, Google Analytics, Google Business Profile (GBP), Meta, GoHighLevel (GHL), Call Tracking, and Website Forms. OAuth and API tokens for these integrations are stored encrypted. We do not store Google or Meta account passwords.

  • Meta: We sync advertising insights metrics such as spend, impressions, reach, clicks, CTR, CPC, and lead counts derived from ad actions, along with campaign dimensions. New Meta connections request read-oriented scopes: public_profile, pages_show_list, pages_read_engagement, ads_read, and business_management (for asset discovery). Write scopes such as ads_management and pages_manage_ads are not requested for new connections. The Service does not currently store Meta lead form submissions as CRM Lead records from Meta’s lead retrieval API. CRM leads from Meta lead forms are not claimed unless they arrive through other connected paths such as website forms or GHL. Existing Meta connections may retain previously granted scopes until the client reconnects with Meta.
  • Google: Search Console and Analytics use read-only OAuth scopes. Google Ads uses Google’s Ads API scope (adwords), and Google Business Profile uses business.manage; Google does not currently offer narrower read-only equivalents for those products’ APIs. The CRM uses these connections for reporting reads only; platform metrics and related reporting data are stored as described in our metrics inventory.
  • GHL: Contacts may be synced into CRM Leads. Marketplace OAuth uses readonly contact/opportunity/location scopes. Private Integration Tokens must be created with least-privilege readonly scopes by the operator.
  • Website Forms: Form submissions may create CRM Leads. Inbound auth uses an unguessable per-client URL token (treat the webhook URL as a secret).
  • Call Tracking: Sync is currently a stub and does not claim full call-record ingestion.
  • Public reports: Live report links use unguessable tokens and may optionally require a password. Contact fields can be masked or hidden.

5. How we use information

We use information to operate the Service, authenticate users, enforce role-based access and client isolation, sync and display metrics and leads, produce reports, maintain audit trails, and improve reliability and security.

6. Retention

There is no fixed automatic purge schedule for all CRM data. Soft deletes are used for certain records (such as users). Weekly backups retain the latest automatic weekly backup. Deployment versions retain the current version plus 3 previous (max 4). Data is otherwise retained as needed to provide the Service and meet operational requirements.

7. Deletion

User accounts may be soft-deleted. Client records may be hard-deleted by an Admin. Disconnecting an integration clears stored credentials; historical metrics already stored in the CRM are not automatically removed by disconnect alone. Public deletion requests (including Meta’s data deletion callback) do not automatically delete data — an Admin verifies and processes requests. See our Data Deletion page.

8. Security

We apply authentication, role-based access control (RBAC), client isolation, encrypted integration configuration, CSRF protection, security headers, HTTPS as configured via APP_URL, secret redaction in logs and user-facing error paths, and least-privilege OAuth scope requests where the provider allows it. No system is 100% secure; we work to reduce risk and respond to issues appropriately. Compromised CRM credentials or encryption keys could still allow reading of synced data and, for some provider tokens, API access allowed by those tokens.

9. Contact

For privacy inquiries, contact us through our company website: https://smartleading.net/.