Privacy Policy

Last updated: August 16, 2026

GHL Lite ("we", "us", "our") provides a multi-tenant customer relationship management platform. This Privacy Policy explains how we collect, use, store, share, and delete information when you use our website and application at http://localhost:3000.

1. Information we collect

Account and workspace data

Facebook Platform Data

If a workspace administrator connects Facebook Lead Ads, we receive and process Facebook Platform Data on their behalf, including:

We use this data solely to import leads into the connecting workspace's CRM, trigger automations configured by that workspace, and maintain the integration the administrator authorized.

Embeddable forms and hosted pages

When visitors submit our hosted or embedded lead capture forms, we collect the fields enabled by the workspace (such as name, email, and phone) and may store the submitter's IP address for abuse prevention.

2. How we use information

We do not sell Facebook Platform Data or use it for advertising profiles, surveillance, or eligibility decisions prohibited by Meta's Platform Terms.

3. Legal bases and consent

Workspace administrators authorize Facebook integrations through Facebook Login. Lead submitters consent to data collection through the Facebook Lead Ad form or our public forms, as disclosed by the advertiser or workspace owner.

4. Service providers

We use subprocessors to operate the service, including hosting, database, messaging, and email providers. These providers process data only to deliver the service on our behalf and under contractual restrictions. Current categories include cloud hosting (Vercel), database hosting (Neon), SMS (Plivo), email (Resend), and job queues (Upstash).

5. Data retention

We retain data while your account or workspace is active and as needed to provide the service. Facebook access tokens are removed when you disconnect a Facebook Page. Lead data imported from Facebook may remain in your workspace until deleted by a workspace administrator or through a data deletion request.

6. Your rights and data deletion

You may request access, correction, or deletion of your personal data by:

We will confirm deletion requests with a confirmation code and status page when applicable.

7. Security

We use industry-standard safeguards including encrypted transport (HTTPS), access controls, webhook signature verification, and workspace isolation. No method of transmission or storage is 100% secure.

8. Children

Our service is not directed to children under 13 and we do not knowingly collect their data.

9. Changes

We may update this policy from time to time. Material changes will be posted on this page with an updated date.

10. Contact

Questions about this policy or Platform Data: support@yourdomain.com or visit our Support page.