Privacy Policy
Effective date: September 22, 2025 • Last updated: September 22, 2025
1. Introduction
Hookely (referred to as “we”, “us” or “the Service”) operates the Hookely website and related services for B2B lead generation. This Privacy Policy explains what information we collect, how we use and share it, and the choices and rights available to you under applicable laws (for example, the GDPR and CCPA).
Legal name: Hookely • Support: support@hookely.com • Hosting: Frontend on Vercel; backend on Railway. Payments are processed by third parties (PayPal and Binance Pay; Stripe may be added later).
2. Overview of Lead-generation Features
The Service provides two primary lead sources:
- Google Maps leads: users search and collect local business listings (name, address, phone, website, category, and other publicly available business metadata).
- Social media leads: users collect publicly visible online businesses and digital stores from supported platforms.
In addition, the Service offers an email scraper feature (available after you generate Google Maps leads) which attempts to extract publicly listed email addresses associated with gathered leads. The email-scraper is provided as a convenience and is currently free to use. Please read Section 4 and Section 10 for important legal and usage considerations.
3. Information We Collect
3.1 Information You Provide
- Account & Profile: Email address, username, password (stored as a secure hash), optional avatar and profile metadata.
- Generated leads & CRM data: Any leads, notes, tags, labels, or files you create, import, or save in the built-in CRM. This includes lead lists you export (CSV/XLSX) and any attachments you upload.
- Payments & credits: Payment confirmations and transaction metadata (we do not store full card details — payment processors handle sensitive payment data). Your wallet/credit balance and top-up history are recorded for billing and use tracking.
- Support: Messages and attachments you send to our support channels (e.g., support@hookely.com).
3.2 Information Collected Automatically
- Usage data: Pages visited, feature usage (e.g., number of leads generated, scraper usage), timestamps, API calls, and error logs.
- Technical data: IP address, device and browser fingerprints, operating system, and user agent strings.
- Cookies & local storage: Used for sessions, preferences, authentication, and security. See Section 11 for details.
3.3 Aggregated and De-identified Data
We may aggregate or de-identify data for analytics and Service improvement. We do not attempt to re-identify aggregated data.
4. How We Use Information & Your Responsibilities
- To provide, operate, maintain, and improve the Service (including the lead generation, email-scraper, CRM and exports).
- To create and manage accounts, authenticate users, and provide customer support.
- To manage wallet balances, process payments, and provide billing receipts.
- To detect, prevent and respond to fraud, abuse, and security incidents.
- To communicate important Service information (updates, billing notices, policy changes).
User responsibilities: When you use features that collect contact information (for example, the email-scraper or exported lists), you are responsible for ensuring your use of that information complies with applicable law (including data protection, anti-spam and telemarketing laws). We do not guarantee that email addresses or other contact data you obtain through the Service may be used for direct marketing without additional legal bases (such as consent). You agree not to use the Service to send unsolicited or unlawful communications.
5. Feature-Specific Details
5.1 Google Maps & Social Platform Data
The Service helps you collect publicly available business data from Google Maps and supported social platforms. That data is provided by third-party platforms and may change or be removed by those platforms; we are not responsible for third-party data accuracy.
5.2 Email Scraper
The email scraper attempts to extract publicly visible email addresses for leads you generate from Google Maps. This feature is provided as a convenience and may collect personal data. Laws in some jurisdictions restrict scraping or contacting individuals without consent — you must ensure compliance, and you indemnify us for your use of scraped data that violates applicable law. We may log scraper usage to prevent abuse.
5.3 CRM, Exports & Downloads
Leads you save in the built-in CRM are stored in your account and can be exported as CSV and XLSX files. Exported files are available for download; copies of exported data may be retained in temporary storage for a short period to support downloads and backups, unless you delete your account.
6. Payments, Wallet Credits, Free Leads & Refunds
The Service uses a pay-as-you-go model. Supported payment methods currently include PayPal and Binance Pay. When you first sign up you receive 20 free leads credited to your account. Additional leads are charged against your wallet credits.
Credits: Credits remain associated with your account and do not expire while the account is active. If you delete your account, credits are forfeited unless otherwise required by law or our Terms. Refunds are provided only in limited cases (for example, technical failures) and handled according to our Terms & Conditions — refund requests should be submitted within 7 days of the failed transaction when possible.
7. Legal Bases for Processing (GDPR)
- Contract: Processing necessary to provide the Service you requested (account management, lead generation, CRM and exports).
- Legitimate interests: Operating, improving and securing the Service, preventing fraud, and analytics (balanced against your rights).
- Consent: For optional features where we request consent (for example, marketing communications). You may withdraw consent where applicable.
- Lawful obligation: Processing to comply with legal obligations (e.g., financial recordkeeping).
8. Sharing & Disclosure
- Service providers: We share data with providers who help run the Service (hosting, payment processors, analytics, email delivery and support platforms). These vendors process data on our behalf under contractual safeguards.
- Third-party platforms: Data you collect from Google Maps or social platforms is subject to those platforms' terms and we may share necessary metadata with platform APIs.
- Legal requests: We may disclose data to comply with law, respond to legal process, or to protect rights, property, or safety.
- Business transfers: Data may be transferred as part of a merger, sale or acquisition, with notice to users where required.
9. Data Retention & Deletion
We retain personal data as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce policies. Leads and CRM data you create are retained while your account exists and will be deleted upon request or account deletion except where retention is required for legal or legitimate business purposes (fraud prevention, accounting, backups).
10. International Transfers
Our systems and service providers may process data in the United States and other countries. By using the Service, you consent to transfers to jurisdictions with different data protection laws. For users in the EU/UK we rely on appropriate safeguards such as Standard Contractual Clauses when required.
11. Cookies & Tracking
We use cookies and similar technologies to enable sessions, remember preferences, provide analytics, and secure the Service. You can control cookies through your browser settings; disabling certain cookies may impair functionality.
12. Security
We use industry-standard administrative, technical, and physical measures to safeguard data (for example TLS in transit, access controls, password hashing). Despite reasonable safeguards, no method of transmission or storage is completely secure and we cannot guarantee absolute security.
13. Your Rights
13.1 GDPR (EU/EEA/UK)
If you are in the EU/EEA/UK you may request access, correction, deletion, restriction, objection to processing, and data portability where applicable. To exercise your rights, contact us at support@hookely.com with the subject line “Data request”. We may need to verify your identity before fulfilling requests.
13.2 CCPA (California)
California residents may have rights to know, access, and delete certain personal information, and to opt-out of “sale” (we do not sell personal information). Submit requests via support@hookely.com.
14. Children
The Service is not intended for children under 13. We do not knowingly collect personal information from children under 13. If we learn that we collected a child’s information in violation of law we will take steps to delete it. Parents/guardians may contact us to request deletion.
15. Data Processing Addendum (DPA)
Business customers who require a DPA under GDPR may request one by contacting support@hookely.com.
16. Prohibited Uses & Indemnity
You must not use the Service to collect or transmit illegal content, to harass or spam individuals, or to violate any platform provider’s terms. You agree to indemnify and hold us harmless for claims arising from your use of data obtained through the Service that violates law or third-party rights.
17. Changes to this Policy
We may update this Policy from time to time. Material changes will be communicated via the Service or email where feasible. Continued use after changes indicates acceptance of the updated Policy.
18. Contact
Hookely support team • support@hookely.com
Last reviewed: September 22, 2025