Privacy Policy

Last updated: September 18, 2026

This policy explains what data gitmoleads collects, why we collect it, who we share it with, and how you can delete it. It covers gitmoleads.com, the dashboard, the lead pages we host, and the short links behind every QR code. gitmoleads is operated by GITMO LLC. If anything is unclear, email support@gitmoleads.com.

1. If you filled in a form on a business's page

A page that says "Powered by gitmoleads" belongs to the business named at the top of it. What you typed - your name, phone number, email, message - goes to that business so they can get back to you. We store it to deliver it to them. We do not sell it, we do not contact you, and we do not use it for our own marketing. To have it removed, ask the business, or email support@gitmoleads.com and we will remove it and tell them.

2. Information we collect from businesses

  • Account data - your email address, name, business name, and, if you set one, a hashed password. We never store passwords in plain text. You can use the Service for 30 days before giving an email; such an account holds only what you typed into the builder.
  • Codes and pages - the codes you make, where they point, and the text, color, questions, and phone number on your lead pages.
  • Leads - the form submissions your pages receive (section 1), with the time, IP address, and browser user agent of each submission, which we use to stop spam.
  • Team data - the email addresses and roles of teammates you invite.
  • Mailer codes - if we mailed you a printed code, that code is linked in our records to the business name and mailing address we sent it to, so we can tell whether the mailing worked. The account the code opens does not show that to anyone.

3. Information we collect when a code is scanned

When someone scans a code, we record the time, the code, the IP address, the browser user agent, and the referring page, and we set a first-party cookie (section 6) so the business can tell a new visitor from a returning one. IP addresses give approximate location only; we do not collect precise GPS location. If the code points at another website, we add tags to the link (such as utm_source=gitmoleads) so that site's own analytics can tell the visit came from a scan.

4. How we use it

We use this data to run the product: open the right page when a code is scanned, count scans, show leads in the dashboard and email them to the business, send sign-in links, keep accounts secure, and answer support requests.

We do not sell personal data. We do not share it for targeted advertising. We have no advertising partners.

5. Who we share data with

Only service providers that run the product, and only what each one needs:

  • Fly.io - hosting and databases.
  • Resend - transactional email (sign-in links, lead notifications, invites).

Leads are shared with the business whose page collected them, and with the teammates that business has invited. We may also disclose data when the law requires it, or as part of a merger or sale of the business - in which case this policy still applies.

6. Cookies

  • __gml_session - keeps you signed in to your account, including an account you have not saved yet. Lasts 30 days.
  • gl_device - a random id set when a code is scanned, so repeat scans from the same browser count as one visitor. Lasts 5 years. It is not linked to your name and is not shared across businesses' reports.

We use no advertising cookies and no third-party tracking cookies.

7. Retention and deletion

We keep account data, codes, scans, and leads while the account exists. To delete your account and its data, email support@gitmoleads.com - we delete personal data within 30 days, except records we must keep for legal reasons. Deleting a code deletes its scans and leads.

8. Security

All traffic is encrypted in transit (TLS). Passwords and sign-in links are stored only as hashes. Database access is restricted to the systems that need it. No method of storage is perfectly secure - if we learn of a breach that affects your data, we will notify you.

9. Your rights

You can ask us to access, correct, export, or delete your personal data at any time by emailing support@gitmoleads.com. We honor these requests regardless of where you live, including rights under the CCPA and GDPR where they apply. We do not sell or share personal data as those laws define it, so there is nothing to opt out of.

10. Children

gitmoleads is a business tool. It is not directed at children under 13, and we do not knowingly collect their data.

11. Changes and contact

If we change this policy, we update the date at the top; material changes get an email to account holders. Questions: support@gitmoleads.com, or the support page. See also our Terms of Service.