LeadGuard by UpWeb, Legal Centre
Privacy Policy
- Responsible entity:
- UpWeb Pty Ltd
- Document:
- privacy, v1.0
- Effective:
- 2026-07-15
- Last updated:
- 2026-07-15
LeadGuard by UpWeb helps service businesses discover and monitor the pathways on their websites that turn visitors into enquiries. This policy explains what information we collect through the LeadGuard website, the public scan flow, the dashboard and the LeadGuard site tag, and how we use, share, retain and protect it.
1. At a glance
- LeadGuard collects account details, site configuration, hashed abuse-prevention identifiers, visitor and pathway activity from customer websites, billing state (through Stripe), support content and service logs.
- The LeadGuard site tag does not record the values people type into forms on customer websites. It does not capture names, email addresses, phone numbers, passwords, payment-card details or message contents entered into those forms.
- LeadGuard does not sell personal information and does not share personal information for cross-context behavioural advertising.
- You can access, correct or delete your information by contacting us. See Privacy Requests.
2. Who operates LeadGuard
LeadGuard is a product and trading brand operated by UpWeb Pty Ltd (ABN 85 613 036 918, ACN 613 036 918), located on the Central Coast, New South Wales, Australia. LeadGuard is not a separate legal entity. In this policy, “LeadGuard”, “we”, “us” and “our” refer to UpWeb Pty Ltd trading as LeadGuard.
3. Scope
This policy applies to the LeadGuard public website, the anonymous public scan flow, account creation and authentication, the authenticated dashboard, the LeadGuard site tag as installed on customer websites, Pathway Monitoring, Conversion Insights, alert delivery, support tickets and chat, and subscriptions billed through Stripe.
4. Our roles
For account, billing, support and abuse-prevention data, LeadGuard acts as the controller (or the equivalent role under Australian Privacy Principles or US-state privacy laws).
For visitor and pathway activity collected through the site tag on a customer's website, LeadGuard acts as a processor (or service provider or contractor) on behalf of that customer. The customer is the controller for that data and is responsible for the notices and any consent controls that apply on its own website.
5. Information we collect
The categories of information we collect include:
- Account and contact details. Email address, display name and any account name you set.
- Authentication information. Password hashes and session tokens managed by our authentication provider, or identifiers returned by Google when you sign in with Google.
- Site and account configuration. The website addresses you connect, site public keys, preview and setup tokens, and integration status.
- Public scan information. The URL you submit, the normalised domain, an HMAC-hashed IP address, an HMAC-hashed anonymous browser identifier and an HMAC-hashed user-agent string, and the results of the scan.
- Visitor and pathway activity from customer websites. Where the LeadGuard tag is installed, we receive pseudonymous visitor and session identifiers, page URLs and titles, referrers and UTM campaign parameters, device and browser information, and pathway views and interactions such as form starts, submit attempts, phone or email clicks, booking clicks and confirmed conversions. See Site Tag and Visitor Data for the full list.
- Monitoring records. Evidence collected when we synthetically check that a customer pathway is still reachable, including check outcomes and issue history.
- Alert and delivery records. The email address a notification is sent to and provider message identifiers used for deliverability tracing.
- Support content. Messages, ticket subjects and file attachments you send to us. Attachments are stored in a private bucket and are only accessible through short-lived signed URLs.
- Billing information. A Stripe customer identifier, subscription identifier, subscription status and audit records of Stripe webhook events. Payment-card details are entered directly into Stripe and are not received by LeadGuard.
- Service and security logs. Application and security logs used to keep LeadGuard reliable and safe.
We recognise that pseudonymous identifiers can, in combination with other information, be personal information under some privacy laws. We treat them with the same care as directly identifying data.
6. What the site tag does not collect
The current LeadGuard site tag does not capture the names, email addresses, phone numbers, addresses, passwords, payment-card details, message contents or other field values that people type into forms on customer websites. Account, billing and support forms on the LeadGuard website itself do collect the details you intentionally submit to us.
7. How we collect information
We collect information directly from you (for example, when you create an account, submit a support ticket or buy a subscription), automatically through your interactions with the LeadGuard dashboard, and, where a customer has installed our site tag on its website, from visitors to that website on the customer's instruction.
8. Why we use information
- Provide, secure and improve LeadGuard.
- Perform public website scans and prevent abuse of that feature.
- Detect, monitor and alert on customer lead pathways.
- Deliver service and support communications.
- Bill for subscriptions and handle related administration.
- Meet legal, regulatory and contractual obligations.
10. International processing
Our subprocessors may process information outside your country of residence. See Subprocessors for each provider and its processing region.
11. Subprocessors
The current list is at Subprocessors.
12. Retention
We generally retain information as follows:
- Public scans and preview attempts: 30 days.
- Hashed abuse-prevention and rate-limit records: 30 days.
- Visitor, session and lead-event data: 180 days.
- Monitoring runs and checks: 12 months.
- Resolved issues and alert history: 12 months after resolution or last activity.
- Support tickets, messages and attachments: 24 months after ticket closure.
- Billing, invoice and tax records: 7 years where required.
- Legal acceptance records: 7 years after the account relationship ends.
- Security and audit logs: 90 days.
- Active account data after an approved deletion request or account closure: we aim to delete within 30 days, subject to legal, billing, security, fraud-prevention and dispute requirements.
Provider-managed backups may retain deleted data for up to 35 additional days before routine overwrite.
13. Security
We use industry-standard controls to protect information. See Security for a list of verified practices.
14. Your rights
Subject to your local law, you may have rights to access, correct, delete, restrict or object to the processing of your personal information, to receive a portable copy, and to withdraw consent. See Privacy Requests to make a request.
15. Australian privacy complaints
If you are in Australia and are not satisfied with our response to a privacy concern, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.
16. EU and UK customers
LeadGuard does not actively market to customers in the European Economic Area or the United Kingdom at initial publication. Customers who require EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or other transfer terms should contact team@upweb.com before using LeadGuard for visitor tracking that requires those terms.
17. Direct marketing
LeadGuard does not currently operate a marketing email programme. Service and transactional messages (account, alerts, billing and support) will continue where necessary to provide the service and are separate from marketing communications. If we introduce marketing email in future, we will identify the sender, provide a working unsubscribe option in each message and honour opt-outs promptly.
19. Minimum age
LeadGuard is a business tool and is not directed to children. The minimum age to hold an account is 18.
20. Changes to this policy
We may update this policy from time to time. The effective and last-updated dates are shown at the top. Material changes will be notified through the service or by email.
Contact
Questions about this document can be sent to the LeadGuard team.
- Entity: UpWeb Pty Ltd (ABN 85 613 036 918, ACN 613 036 918).
- Trading as: LeadGuard by UpWeb.
- Location: Central Coast, New South Wales, Australia.
- All enquiries (privacy, security, legal, support): team@upweb.com.
- Legal notices: may be sent electronically to team@upweb.com.
