Privacy Policy
This Policy explains what personal information GoodLeads processes, where it comes from, how we use and disclose it, and the choices and rights available to the individuals whose information we process. If you want to exercise a right directly, go to Request to Know or Delete My Information or Do Not Sell or Share My Information.
1Who we are
GoodLeads is a business-to-business sales-intelligence service operated by Two Envelopes LLC, a Montana limited liability company ("GoodLeads," "we," "us"). We provide verified contact records on newly formed businesses to other businesses for sales, marketing, and business-development use.
This applies to our website, platform, and data products (the Services, as defined in our Terms of Service). It does not apply to our customers' independent use of data they obtain from us — that use is governed by our Terms and the customer's own privacy practices.
2The information we process, and where it comes from
GoodLeads is built on primary public records. Our starting point for every record is a business's own filing with a U.S. Secretary of State. We then enrich a subset of those records with contact attributes:
- Public business-filing data — business names, registered and principal addresses, registered-agent details, formation dates, entity types, and officer or organizer names, as published by state business registries.
- Business-contact information — names, business or associated addresses, phone numbers, email addresses, and role or title, obtained or verified through third-party data vendors and derived by our own processing.
- Our own inferences and scores — industry classification, reachability and relevance scores, and related signals we generate.
- Customer and website data — account details, billing information, and usage and device data from people who visit our website or use our platform.
Because a newly formed business often has no separate business address, phone, or email yet, some contact information associated with a business is the personal contact information of its owner or principal. We process that information for business-to-business purposes only.
Categories of personal information (CCPA/CPRA)
| Category | Collected? | Sources | Sold or shared? |
|---|---|---|---|
| Identifiers (name, address, email, phone) | Yes | Public SOS filings; data vendors; our inferences | Sold — not shared for ads |
| Professional / employment info (role, business affiliation) | Yes | Public SOS filings; data vendors | Sold — not shared for ads |
| Commercial information (billing) | Customers only | Directly from customers | No |
| Internet / device activity | Website visitors | Automatically, via our website | No |
| Sensitive personal information | No | — | No |
We do not collect biometric, precise-geolocation, health, or other special categories of data, and we do not use personal information to infer sensitive characteristics.
3How we use information
- Build, verify, score, and maintain our business-contact database;
- Provide the Services to our customers, including search, filtering, and delivery of records;
- Operate, secure, and improve our website and platform;
- Process transactions, provide support, and communicate with customers;
- Comply with legal obligations and enforce our Terms.
We do not knowingly collect or use sensitive personal information, information about children, or data for any purpose regulated by the Fair Credit Reporting Act (such as eligibility for credit, insurance, employment, or housing). Our customers are contractually prohibited from those uses.
4How we disclose information
- To customers, as part of the Services — this is the core of what we do;
- To service providers and processors who host, secure, process payments for, or support our platform, under contracts that limit their use of the information;
- To our data vendors, as required to verify and maintain records;
- For legal and safety reasons, when required by law or to protect rights, safety, and our Services;
- In a business transfer, such as a merger, acquisition, or sale of assets.
5Legal basis (EEA/UK)
Where the GDPR or UK GDPR applies, we process business-contact personal data on the basis of our legitimate interests in providing B2B sales-intelligence services and building an accurate business database, balanced against the rights of the individuals concerned. Where we rely on legitimate interests, you have the right to object as described below.
6Your privacy rights and how to exercise them
Depending on where you live, you may have the right to access, delete or suppress, correct, or opt out of the sale of your personal information, to object to or restrict certain processing (EEA/UK), and to not receive discriminatory treatment for exercising these rights.
Request to know, access, correct, or delete your information →
Opt out of sale / do not sell my information →
We will verify your request and respond within the timeframes required by applicable law. When we suppress or remove a record, we also instruct our customers to suppress that record in their own systems, and we honor removal requests that originate from our data vendors. Authorized agents may submit requests on an individual's behalf with proof of authorization. If we decline a request, you may appeal by replying to our response.
7Data retention
- Public business-filing data and business-contact records: retained for as long as the record remains useful to maintain an accurate, current business-contact database, and refreshed or removed as it becomes stale or on request.
- Suppression and removal records: retained indefinitely, as the minimum information necessary to honor a suppression or opt-out going forward.
- Customer account and billing data: retained for the life of the account plus the period required by tax, accounting, and legal-obligation rules.
- Website usage and device data: retained only as long as needed to operate and secure the site.
8Security
We maintain reasonable administrative, technical, and organizational measures designed to protect personal information against unauthorized access, use, or disclosure. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9International transfers
We are based in the United States and process information in the United States. If you access the Services from outside the United States, your information will be processed in the United States, where data-protection laws may differ from those in your jurisdiction.
10State-specific disclosures
Some U.S. states require businesses that handle personal information under certain conditions to register as a "data broker." GoodLeads reviews its obligations under these laws on an ongoing basis as its data coverage changes.
We honor the privacy rights described in Section 6 for residents of all U.S. states that provide them. For state-specific questions, contact us at privacy@goodleads.club.
11Children's information
The Services are directed to businesses and are not intended for children. We do not knowingly collect personal information from children.
12Changes to this Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, where required, provide additional notice.
13Contact us
Two Envelopes LLC (d/b/a GoodLeads)
1001 S Main St, Ste 49 · Kalispell, MT 59901 · USA
Privacy requests: privacy@goodleads.club · General: hello@goodleads.club