Mon - Sat: 9:00 AM - 6:00 PM
Pacific Time (Los Angeles)
Call: 844-376-2274
24/7 Nationwide Service
LIVEJoin Demo Call
Interactive Training Session

Privacy Policy

How LeadLocate collects, uses, shares, protects, and retains personal information, including the dealership records and consumer data our subscribers put into the platform.

Last updated July 26, 2026

Every section below has its own address. Use the link button beside a heading to copy a direct link to it.

Privacy Notice#

The main notice, covering the website, the CRM, and the mobile apps.

PLEASE READ THIS PRIVACY NOTICE (THIS PRIVACY NOTICE) CAREFULLY BEFORE USING THIS SITE AND THE SERVICE TO UNDERSTAND HOW DOTNET HOLDINGS LLC DBA LEADLOCATE COLLECTS, USES AND PROTECTS INFORMATION AND DATA COLLECTED THROUGH THE SERVICE. This Privacy Policy is intended to cover all visitors to this website, all subscribers to lists or newsletters whether paid or unpaid, all members or affiliates whether paid or unpaid, and all customers. LeadLocate (LeadLocate, we, us, or our) respects the privacy of all individuals who visit this website (the Site), and utilize any of the products or services we provide through the Site (collectively, the Service). This website is not lawfully accessible to persons under the age of 18 or who are otherwise covered by the provisions of the Child Online Privacy Act of 1998 (COPA). If you are under the age of 18 you must leave this site immediately. Fraudulent use of this website may make you subject to civil or criminal sanctions. Acceptance of the terms of this Privacy Policy is a portion of the consideration required for your right to visit the website. If you do not accept these terms, you have no right to visit this site and you are fraudulently using this site. WHEN YOU VISIT THE SITE OR USE THE SERVICE, YOU AGREE TO BE BOUND BY THIS PRIVACY NOTICE AND LEADLOCATE’S TERMS OF USE leadlocate.com/sales-leads/terms-of-service. BY USING THE SERVICE, YOU ARE AGREEING TO OUR COLLECTION AND USE OF ANY INFORMATION YOU PROVIDE CONSISTENT WITH THIS PRIVACY NOTICE, AND TO BE BOUND BY THIS PRIVACY NOTICE AND THE TERMS. IF YOU DO NOT AGREE TO THE TERMS OF THIS PRIVACY NOTICE OR THE TERMS, YOU ARE NOT PERMITTED TO ACCESS THE SITE OR USE THE SERVICE. THIS PRIVACY NOTICE IS EFFECTIVE AS OF JANUARY 1st, 2019. WE MAY MAKE CHANGES OR IMPROVEMENTS TO THE SITE, SERVICE AND/OR THIS PRIVACY NOTICE AT ANY TIME, WITHOUT NOTICE. ANY MODIFICATIONS MADE WILL BE EFFECTIVE IMMEDIATELY UPON THE POSTING OF THE MODIFIED PRIVACY NOTICE ON THIS SITE. BY CONTINUING TO ACCESS THE SITE OR USE THE SERVICE AFTER ANY CHANGES ARE MADE, YOU ARE ACCEPTING AND AGREEING TO THE CHANGES. YOU AGREE TO REVIEW THE POSTED PRIVACY NOTICE EACH TIME YOU ACCESS THE SITE OR USE THE SERVICE SO THAT YOU ARE AWARE OF ANY MODIFICATIONS MADE TO THIS PRIVACY NOTICE.

What types of information do we collect?#

a. Information Provided By Your Dealer/Referring Business - When you express interest in a vehicle on your dealer’s website, your dealer may provide us with certain information that you provided to them, which may include, without limitation, your name, email address, mailing address, telephone number, vehicle of interest, past and present vehicle ownership, financial information, including without limitation, vehicle financing, and payoff information, birthdate, and employment information so that we can contact you directly with a personalized link to our Site. Your dealer’s sharing of that information will be subject to its own privacy policy, so we encourage you to review the privacy policy posted on your dealer’s website.

b. Information You Provide to Us - When you provide information in order to be contacted about a vehicle or otherwise engage with the Service, you may be asked to provide certain personally identifiable information, such as your name, email address, mailing address, and telephone number. You may also provide us with information about your automotive preferences.

You may also choose to create a profile of the vehicle(s) you currently own. Each profile that you create will contain whatever information you elect to include.

c. Information Automatically Collected Through Technology - Information regarding your use of the Service may be collected and/or aggregated through the use of automated methods, which may mean that it will not be obvious to you that information is being collected. This automatically-collected information may include non-personally identifiable information, such as: your computer’s or mobile device’s IP address or other unique identifier, your domain server, your type of computer or mobile device, your type of web browser, your type of operating system, your Internet Service Provider or mobile carrier, emails you open and links you click on within those emails, and statistical information regarding the pages on the Site that you visit, and the items that you view and interact with within the Service.

d. Information Collected Using Cookies and Other Technologies - Various technologies are used to automatically collect information, such as cookies, local shared objects, web beacons and short URLs (generally referred to as Tracking Technologies). Cookies are small identifiers sent from a web server that are stored on your device for the purpose of identifying your browser or storing information or settings in your browser. Local shared objects, sometimes known as Flash cookies, may be used to store your preferences or display content based upon what you have viewed on various websites to personalize your visit. A web beacon, also known as an Internet tag, pixel tag or clear GIF, links web pages to web servers and their cookies. A short URL can track the clicks a link receives. When we refer to Tracking Technologies, we are including all current and similar future technologies. We also may use screen recording technology to record your session for fraud prevention and to quality assurance proposes.

We may use one or more Tracking Technologies on our Site, and other websites and mobile applications that may not be ours. Tracking Technologies may be used by us and others, on our behalf and on their own behalf, to transmit information to you or about you and connect information about you from different sources, websites, devices, and mobile applications. The Service does not currently recognize automated web browser tracking method signals, such as do not track instructions.

You can change your privacy preferences regarding the use of cookies and certain other technologies through your browser, including blocking all cookies; however blocking all cookies may affect your use of our Service and other websites and services online, and may prevent you from using all the features and elements of our Service and other websites and services.

e. Combined Information - We may combine information that you provide to us with information we receive from our affiliates and other sources, as well as with other information that is automatically collected. The combined information may include information about your use of the Site and Service, your use of other websites, devices and mobile applications, and information from our affiliates and other sources. We will use this combined information in order to personalize and enhance your experience on the Site.

How Do We Use the Information We Collect?#

We may use the information we collect for the following purposes:

a. for everyday business purposes, such as providing products and services you request, and providing customer support;

b. to contact you via email, SMS, and/or telephone;

c. to personalize the types of information presented on the Site, including recommended vehicles and relevant values and/or offers for cars that you would like to research and/or trade in;

d. to communicate about, and administer your participation in, special events, programs, surveys, contests, sweepstakes and other offers or promotions;

e. to evaluate and improve our business, including without limitation, developing new products and services and analyzing the effectiveness of products, services, applications and websites;

f. to perform data analyses, including market and consumer research, trend analysis, demographic analysis and financial analysis;

g. to deliver content correlating to your interests and browsing and usage history, both within our Site and on other websites and applications;

h. to diagnose and address technical and service problems; and

i. to comply with applicable legal requirements and our policies.

With Whom Do We Share Information?#

We do not sell or otherwise share information about you that we collect or receive, except as described below:

a. Affiliates and Manufacturers. Information collected, including personally identifiable information, may be shared with our affiliates, auto dealers and/or auto manufacturers, who will use that information in accordance with their own privacy policies. For example, if you are interested in a particular listing of a car presented on the Site, information about you may be shared with our affiliates.

b. Our Service Providers. We may engage third parties to provide part or all of the Services offered through or in connection with the Site on our behalf. We require such providers to maintain your information in confidence and to use the information only to perform the services specified by us in a manner consistent with this Privacy Notice.

c. Corporate and Asset Transactions. If we sell all or substantially all of our business or sell or transfer all or a material part of our assets, or are otherwise involved in an acquisition, merger, sale, reorganization or similar event, as part of the transaction, we may transfer all information we have collected and stored, including personal information, related to the portion of the business or assets sold or transferred, to the party or parties involved in the transaction.

d. Other. We may access or disclose information, including personal information, to: (i) protect or defend our interests and the legal rights or property of LeadLocate (DotNet Holdings LLC) and our affiliates; (ii) protect the rights, interests, safety and security of users of the Service or members of the public; (iii) protect against fraud, for risk management purposes or otherwise to maintain the integrity and safety of the Service; and/or (iv) comply with applicable law or legal process.

How Do We Protect Your Information?#

LeadLocate has and will maintain security measures we deem reasonable and appropriate to secure your personally identifiable information against inadvertent, unauthorized or illegal loss, destruction, disclosure, access or use. Although LeadLocate will use various technologies and tools to protect your PERSONALLY IDENTIFIABLE INFORMATION, no method of securing data is foolproof or completely effective, and data transmissions, communications or stored data MAY BE LOST, DESTROYED OR IMPROPERLY OR UNLAWFULLY DISCLOSED, ACCESSED OR USED. Thus, although LeadLocate takes COMMERCIALLY reasonable measures to protect your PERSONALLY IDENTIFIABLE INFORMATION, WE DO not and cannot guarantee that your PERSONALLY IDENTIFIABLE INFORMATION will remain private or secure.

Your Choices#

- You are entitled to make certain choices about how we communicate with you.

a. You may choose not to provide personal information, though that will inhibit our ability to personalize the Site for you and send you certain information or alerts that may be of interest to you.

b. If you do not want to receive marketing emails from us, you can follow the “unsubscribe” link provided at the bottom of those emails or change your communication preferences on the Site under “Manage Account”.

c. As mentioned above, there are ways to limit the information collected through technology by blocking cookies, though some of the features of the Service may not work if you decide to do so.

California Privacy Rights#

Under California law, if you are a resident of California, you are entitled to ask us for a notice describing what categories of personal information we share with third parties or corporate affiliates for their direct marketing purposes. In response to your written request, we will identify the categories of information shared, if any, and will include a list of the third parties and affiliates with which it was shared, as well as their addresses. If you want to submit such a written request, please submit it by email to support@leadlocate.com or by U.S. mail at the address set forth below.

Access and Correction#

You can contact us by sending an email to support@leadlocate.com explaining how you would like to modify your personal information and/or preferences. You agree to promptly notify us if your information changes or is inaccurate.

Third Party Sites#

If you reach the Site using a link or from another web site or search engine, or go to another site from the Site, information about your visit to the Site may be collected by the other website or search engine, and will be subject to the privacy policy of that site. You are encouraged to review the privacy policy of each of those sites or search engines.

IN NO EVENT WILL LEADLOCATE (DOTNET HOLDINGS LLC) BE LIABLE, DIRECTLY OR INDIRECTLY, TO ANYONE FOR ANY DAMAGE OR LOSS ARISING FROM OR RELATING TO ANY USE, CONTINUED USE, OR RELIANCE ON ANY LINKED THIRD PARTY SITE, OR ANY LINK CONTAINED IN A LINKED SITE, OR THE PRIVACY PRACTICES OF ANY LINKED SITE.

U.S. Jurisdiction#

You should be aware that the United States and other countries have not harmonized their privacy laws and regulations. This Privacy Notice is intended only for residents of the United States and individuals who agree to be subject to U.S. law. If you are accessing the Site or using the Service outside of the United States, you agree to the privacy protections set forth in this Privacy Notice and agree to be subject to U.S. law.

Disputes#

As part of the consideration that the LeadLocate requires of the Visitor to view, use, or interact with this site, Visitor agrees to use binding arbitration for any claim, dispute, or controversy (CLAIM) of any kind (whether in contract, tort or otherwise) arising out of or relating to this purchase, this product, including solicitation issues, privacy issues, and terms of use issues.

Arbitration shall be conducted pursuant to the rules of the American Arbitration Association, which are in effect on the date a dispute is submitted to the American Arbitration Association. Information about the American Arbitration Association, its rules, and its forms are available from the American Arbitration Association, 335 Madison Avenue, Floor 10, New York, New York, 10017-4605. Hearing will take place in the city or county of the Seller.

In no case shall the Visitor have the right to go to court or have a jury trial. Visitor will not have the right to engage in pre-trial discovery except as provided in the rules; you will not have the right to participate as a representative or member of any class of claimants pertaining to any claim subject to arbitration; the arbitrator’s decision will final and binding with limited rights of appeal.

Updates#

We may make changes or improvements to the Site, Service and/or this Privacy Notice at any time, without notice. Any modifications made will be effective immediately upon the posting of the modified Privacy Notice on this Site. By continuing to access the Site or use the Service after any changes are made, you are accepting and agreeing to the changes. You agree to review the posted Privacy Notice each time you access the Site or use the Service so that you are aware of any modifications made to this Privacy Notice.

Contact Us#

If you have questions about the Service or need further assistance, please send an email to legal@leadlocate.com or written notice to:

DotNet Holdings LLC

Attn: LeadLocate

1401 21st St Ste 14270

Sacramento, CA 95811

Fax: 866-429-5707

Back to contents

Cookies and Tracking Technologies#

What we set in your browser, why, and how to turn it off.

Cookies allow a website to remember your preferences, improve the user experience and tailor the advertisements you see to those that are most relevant to you. Cookies are sent back to the originating site on each subsequent visit or to another site that recognizes the cookie. We also use other forms of technology that serve a similar purpose to cookies and which allow us to monitor and improve our sites and apps. We use these in connection with cookies to help operate our websites and emails and collect information about online activity. When we talk about cookies in this Policy, this term includes these similar technologies.

Why Do We Use Cookies?#

Cookies have five different functions and we use cookies for the purposes listed below:

Strictly necessary cookies are used to allow you to navigate this website or mobile app and use its features such as accessing secure areas of the website or making a reservation. These cookies expire at the end of your session.

Performance cookies collect information about how you interact with this website or mobile app and are used to improve your experience. They don’t contain personal information that can be used to identify you. We use these cookies to measure the performance of this website or mobile app such as gathering information about the number of visitors, testing designs, and ensuring a consistent look and feel is maintained. All information these cookies collect is aggregated and therefore anonymous. These cookies expire in 7 days.

Functional cookies allow this site or mobile app to remember choices you make and provide enhanced and more personal features such as storing your login account and language or geographic preferences. The information these cookies collect may be anonymized and do not track your browsing activity on other websites. The duration of these cookies varies but all expire within 2 years.

Advertising cookies are used to deliver advertisements that are more relevant to you. Third parties that serve ads on our behalf use cookies to help select the ads that are displayed to you and ensure that you do not see the same ads repeatedly as well as to measure the effectiveness of advertising campaigns. These cookies expire in 2 years.

Social Media Cookies are used when you share information using a social media sharing button or “like” button on this site or mobile app, or when you engage with our content on or through a social site such as Facebook. These cookies expire in 1 year.

Some newer web browsers incorporate "Do Not Track" features. Our websites may not currently respond to "Do Not Track" requests or headers from these browsers. To learn more about your options for not having this information used by certain service providers, visit Cookie Consent Tool. Opting out of this practice does not opt you out of being served to advertise - you will continue to receive generic ads.

For more information on how we process your personal data and to exercise your rights in relation to your personal data please consult our Privacy Policy.

How Can You Manage Cookies?#

Session cookies are used for your current browser session and will expire after you close your browser. Persistent cookies are used to enhance your experience between website visits and will remain on your computer until you delete them or until they reach their set expiry date. You always have the ability to manually delete cookies.

If you are viewing our content via a web browser, you can change your cookie preferences and withdraw your consent at any time using our Cookie Consent Tool. If you are using our mobile apps, you can change your preferences in the analytics settings in the app.

You may also set your browser to block all cookies or to indicate when a cookie is being set, although our services may not function properly if your cookies are disabled. To find out how to control or disable cookies within most browsers, consult the "Help" section of your browser or device or visit www.allaboutcookies.org.

Back to contents

California Privacy Notice#

Supplements the Privacy Notice for California residents under the CCPA and CPRA.

This privacy notice for California residents will take effect on January 1, 2020.
This California Privacy Notice (“Notice”) is for California residents and supplements our Privacy Policy. It explains how we collect, use, and share your Personal Information and how to exercise your rights under the California Consumer Privacy Act (“CCPA”). When we say “Personal Information” in this Notice, we mean information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with you. Personal Information does not include information that is aggregated or information that cannot be reasonably linked to you.

How we collect, use, and share Personal Information#

To provide the products or features offered by LeadLocate (“Products"), we must process information about you, including Personal Information, whether or not you are registered or logged in. Subject to the limitations we describe in our Privacy Policy, we may share your Personal Information for business purposes with strict restrictions on how our partners can use and disclose the data we provide, at your direction, or in ways otherwise in accordance with the CCPA.

The best way to learn about the kinds of information we collect and how we use it is to review our Privacy Policy. Here is a summary of the CCPA-related categories of Personal Information we may have collected about you over the past 12 months, depending on how you use our Products, as well as how we use it and with whom we may have shared it.

Categories of Personal Information we collect may include:

Identifiers

Data with special protections, if you choose to provide it

Commercial information, if you choose to provide it

Photos and face imagery that can be used throughout LeadLocate

Internet or other electronic network activity information, including content you view or engage with

Location-related information, including precise device location

Audio or visual information, including photos and videos, if you or others choose to provide it

Professional or employment information, if you choose to provide it

Education information, if you choose to provide it

Financial information, if you choose to provide it

Information derived from other Personal Information about you, which could include your preferences, interests, and other information used to personalize your LeadLocate account or final consumer data set.

Examples of how Personal Information is used include:

Providing, personalizing, and improving our Products

Facilitating transactions, providing measurement, analytics, advertising, and other business services

Promoting safety, integrity, and security

Communicating with you

Researching and innovating products or services

To perform other business purposes

Parties with whom your information may be shared include:

People and accounts you share and communicate with

People and accounts with which others (clients or employees) share or reshare data

Apps, websites, and third-party integrations on or using our Products

New owners in the event of a change of ownership or control of all or part of our Products or their assets changes

Partners, including partners who use our analytics services, advertisers, measurement partners, partners offering goods and services in our Products, vendors and service providers, and researchers and academics

Law enforcement or other third parties in connection with legal requests

Sources of Personal Information#

We receive Personal Information from the information that you and others provide, your device(s), and from our partners. The categories of sources from which we’ve collected or received Personal Information include:

We collect the content, communications, and other information you provide when you use our Products, including when you sign up for an account, create or share content, and message or communicate with others. We collect information about the people, pages, accounts, data, and 3rd party products or services you are associated with, and how you interact with them across our Products, such as the people you communicate with or the entities you are a part of. We also collect information about how you use our Products, including data we serve on and off LeadLocate, such as the types of data content you engage with, the features you use, the actions you take, the people or accounts you interact with, and the time, frequency, and duration of your activities.

We may also receive and analyze content, communications, and information about you that other people provide when they use our Products or post on word-wide-web, such as when posters show up in your lead feeds, send a message to you, or upload, sync, or import your or 3rd party contact information.

We collect information from and about the computers, phones, connected TVs, and other web-connected devices you use that integrate with our Products, and we combine this information across different devices you use.

We may receive information from other LeadLocate companies or affiliates for business purposes that help us provide you with an innovative, relevant, consistent, and safe experience across all LeadLocate Products or Services you use. We also process information about you across LeadLocate for these purposes, as permitted by applicable law, and in accordance with their terms and policies.

Client partners, account holders, advertisers, app developers, and publishers and other partners can send us information for business purposes through variety of LeadLocate account business tools they use, including our plug-ins, data import, form submissions, WWW data harvesting, APIs and SDKs, or tracking codes. Any partnering entity car provide information about your activities on and off LeadLocate, including information about your device, websites you visit, posts you make on www, public data/web links, things you do on their services, and purchases or transactions you make. We also receive information about your online and offline actions, and data from third-party data providers who have the rights to provide us with your information. Partnering entities receive your data when you visit or use their services or through third parties they work with. Any identifying information that you have posted on the World Wide Web can and might be collected by us.

How can you exercise your rights provided under the CCPA?#

Under the CCPA, you have the following rights:

Right to Know: You have the right to request that we disclose to you the Personal Information we collect, use, or disclose, and information about our data practices

Right to Request Deletion: You have the right to request that we delete your Personal Information that we have collected from you

Right to Non-Discrimination: We will not discriminate against you for exercising any of these rights.

To exercise your “right to know” or your “right to request deletion,” use the form to the right of the screen.

Please note that to protect your information and the integrity of our Products, we may need to verify your identity before processing your request. In some cases, we may need to collect additional information to verify your identity, such as a government-issued ID.

Under the CCPA, you may exercise these rights yourself or you may designate an authorized agent to make these requests on your behalf. We may request that your authorized agent have written permission from you to make requests on your behalf and may need to verify your authorized agent’s identity.

If you have additional questions about this Notice or how to exercise your rights under the CCPA, please contact us at legal[at]leadlocate.com.

Back to contents

Mobile Messaging Privacy Notice#

How phone numbers, consent records, and message content are handled. Opt-in data is never shared, sold, or rented to anyone.

This Privacy Notice describes how LeadLocate collects, uses, retains, and discloses mobile phone numbers, opt-in data, and message content in connection with its SMS and RCS Business Messaging program operated from +1 (844) 376-2274. It supplements the LeadLocate Site Privacy Policy. Effective date: May 21, 2026. Brand: LeadLocate. Sender: +1 (844) 376-2274. Support: help@leadlocate.com.

Headline commitment#

All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

To restate the same commitment in plain language: we do not share, sell, rent, lease, or otherwise distribute mobile phone numbers, opt-in data, or message content collected for the LeadLocate messaging program to third parties or affiliates for marketing or promotional purposes. Phone numbers and consent information collected for this program are used only to deliver the messages described in our Opt-In Policy and to fulfill our obligations to the consumer as their service provider.

What we collect#

  • Mobile phone number. Provided by the consumer through our public sign-up application, a signed written agreement, or a recorded verbal opt-in.
  • Opt-in record. The date, time, IP address, and a copy of the consent language the consumer ticked or agreed to.
  • Message content and metadata. The body of each message sent or received, the Twilio Message SID, sender and recipient address, delivery status (queued, sent, delivered, read, failed), and any error codes returned by the carrier.
  • Opt-out events. The date and time the consumer replied STOP or any equivalent keyword, and the resulting suppression record.
  • How we use it#

  • To deliver the messages the consumer consented to (see our Opt-In Policy for the message-type list).
  • To honor opt-out requests across the entire Messaging Service sender pool, so opt-out on the RCS sender also suppresses SMS and MMS fallback messages.
  • To respond to support inquiries, fraud reports, or carrier audits.
  • To meet legal, regulatory, audit, and dispute-resolution obligations, including CTIA and FCC requirements.
  • For internal analytics on aggregate delivery quality (for example, delivery rates and error code distributions). This data is never combined with marketing profiles or shared externally.
  • Who we share it with#

    We share the minimum necessary data with the following categories of service providers, all of whom are contractually bound to use the data only to provide the messaging service to LeadLocate:

  • Twilio, Inc. Our SMS, MMS, and RCS Business Messaging carrier of record and a sub-processor of Google for RCS.
  • Google LLC. As the operator of RCS Business Messaging infrastructure, when the recipient message is delivered over RCS.
  • Mobile carriers. AT&T, Verizon Wireless, T-Mobile®, Sprint, U.S. Cellular®, Cricket, Boost Mobile, MetroPCS, Google Fi, and other US wireless carriers, only as required to deliver the message to the consumer handset.
  • To restate the carrier-required commitment more narrowly: all of the categories of data we collect for this program exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties, excluding aggregators and providers of the Text Message services (Twilio, Google, and the mobile carriers above) that are needed to actually deliver the message.

    We do not provide phone numbers, opt-in lists, or message content to any other third party for marketing, advertising, retargeting, audience-building, list-rental, or data-broker purposes. We will disclose data only when required by valid legal process (for example, a subpoena or court order), or when reasonably necessary to investigate fraud, protect rights, or prevent serious imminent harm.

    Retention#

    Opt-in records, opt-out records, and message delivery logs are retained for the longer of (a) four (4) years from the date of the event or (b) the period required by applicable law and CTIA or carrier audit requirements. Message bodies may be purged earlier where retention is not required for support, billing, or audit purposes.

    Your choices#

  • Opt out at any time by replying any of STOP, STOPALL, UNSUBSCRIBE, CANCEL, END, or QUIT to +1 (844) 376-2274.
  • Help. Reply HELP or INFO for support contact information.
  • Access and deletion. Consumers may request a copy of, correction of, or deletion of their personal data on file with us by emailing help@leadlocate.com. We honor verified requests under applicable US state privacy laws, including CCPA, CPRA, VCDPA, CPA, CTDPA, and UCPA.
  • Security#

    We maintain commercially reasonable administrative, physical, and technical safeguards designed to protect personal data against unauthorized access, alteration, disclosure, or destruction. Mobile phone numbers and opt-in records are stored in encrypted databases hosted in our US data center, accessible only to authorized LeadLocate personnel.

    Children#

    The LeadLocate messaging program is not directed to children under 18. We do not knowingly collect personal data from any individual under 18. If you believe a minor has provided us with their phone number, contact us at help@leadlocate.com and we will delete the record.

    Changes to this notice#

    LeadLocate may update this Messaging Privacy Notice from time to time. The effective date at the top of this page reflects the most recent update. Material adverse changes will be notified to enrolled consumers at the mobile number on file.

    Contact#

  • Email: help@leadlocate.com
  • Phone: +1 (844) 376-2274
  • Web: https://leadlocate.com
  • LeadLocate operates from the United States of America. This Messaging Privacy Notice applies to the LeadLocate sender +1 (844) 376-2274 and the LeadLocate RCS Business Messaging agent associated with that number. It does not govern messaging traffic that LeadLocate subscribers send to their own customers from their own LeadLocate-provisioned phone numbers. Those programs are governed by each subscriber own privacy notice.

    © 2026 LeadLocate®.

    Back to contents

    SMS and RCS Opt-In Policy#

    Exactly how a person consents to receive text messages from us, and how they stop.

    How customers and prospects consent to receive text messages from LeadLocate at +1 (844) 376-2274. This page documents the opt-in flow, what messages we send, message frequency, costs, and how to opt out. Effective date: May 21, 2026. Brand: LeadLocate. Sender: +1 (844) 376-2274. Support: help@leadlocate.com.

    About LeadLocate#

    LeadLocate is a US business-to-business sales-prospecting platform and CRM used by automotive dealerships and independent automotive sales professionals. Our subscribers use LeadLocate to manage their own customer relationships. The LeadLocate messaging program described on this page is the company-to-customer program operated by LeadLocate itself for its own subscribers and prospective subscribers. This program is separate from any messaging traffic our subscribers send to their own customers through the platform.

    How consumers opt in#

  • The consumer visits our public website at https://leadlocate.com and clicks Sign Up or Start Free Account, which loads our sign-up application at /sales-leads/new_account.
  • The consumer enters their business name, full name, US business address, email address, and a US mobile phone number capable of receiving text messages. Phone numbers are server-side validated to confirm they are US mobile lines. Landline numbers and non-US numbers are rejected.
  • Directly above the Submit button, the consumer ticks a separate, clearly labeled SMS and RCS consent checkbox that is unchecked by default. The checkbox label names LeadLocate by brand, identifies the message types the consumer will receive, states that message frequency varies, states that message and data rates may apply, instructs the consumer to reply HELP for help and STOP to cancel, and links to this Opt-In Policy, the Messaging Terms, and the Messaging Privacy Notice.
  • After the consumer ticks the SMS consent checkbox, completes Google reCAPTCHA, and clicks the Submit button, LeadLocate sends an automated welcome and account activation message from +1 (844) 376-2274 to the mobile number the consumer provided. This is the first SMS or RCS message that consumer will receive from the program. The consumer may also receive follow-up onboarding messages, billing and account notices, and support replies.
  • No phone number is messaged unless the owner of that number personally submitted it through the form, or, where applicable, through a recorded verbal opt-in during a live sales conversation with our team or through a written agreement signed by the consumer. Consent to receive messages is not required as a condition of any purchase.
  • What messages we send#

  • Account notifications. Welcome and activation messages, password resets, billing receipts, payment failures, subscription changes, and scheduled maintenance notices.
  • Customer support. Conversational replies to questions the consumer texts in to the LeadLocate sender, scheduling a support callback, or follow-up after a support ticket.
  • Service notices. Product changes, security advisories, training reminders, and notices required by law or by our terms.
  • Conversational sales. When a prospect requests a demo through our website or by calling our number, our sales representatives reply by text and continue the conversation by text when the consumer responds.
  • We do not send sweepstakes, lottery, age-gated, adult, cannabis, firearms, hate speech, or other CTIA SHAFT category content from this sender.

    Message frequency, cost, and carriers#

    Message frequency varies based on the consumer relationship with us. A typical onboarding flow is 3 to 5 messages in the first week, then occasional account and support messages thereafter. Msg & data rates may apply per the consumer mobile carrier plan. LeadLocate does not impose any additional charge on the recipient for messages we send.

    This program is operated using Twilio Programmable Messaging and Twilio RCS Business Messaging. RCS messages are delivered through carrier RCS Business Messaging where the recipient device and network support it. On devices or networks without RCS support, messages automatically fall back to SMS or MMS. Carriers are not liable for any delayed or undelivered messages.

    How to opt out at any time#

    The consumer can opt out at any time by replying any of the following keywords (case-insensitive) to +1 (844) 376-2274:

    STOP  STOPALL  UNSUBSCRIBE  CANCEL  END  QUIT

    The consumer will receive one final confirmation message:

    You have been unsubscribed from LeadLocate messages and will not receive further messages. Reply START to resubscribe.

    All further messages from this sender are then suppressed for that mobile number, including SMS and MMS fallback messages from this Messaging Service. Twilio Advanced Opt-Out is enabled on the assigned Messaging Service, so the suppression applies across the entire sender pool, not just the RCS sender.

    HELP keyword#

    Replying HELP or INFO returns:

    LeadLocate support: visit https://leadlocate.com or call 844-376-2274. Msg & data rates may apply. Reply STOP to unsubscribe.

    Resubscribing#

    Replying START, UNSTOP, or YES resubscribes the user and returns:

    You are resubscribed to LeadLocate messages. Reply HELP for help, STOP to unsubscribe.

    Mobile data privacy promise#

    We do not share, sell, rent, or otherwise distribute mobile phone numbers, opt-in data, or message content to third parties or affiliates for marketing or promotional purposes.

    Phone numbers collected through the opt-in described here are used only to deliver the message types listed above and to fulfill our obligations to the consumer as their service provider. See the full Messaging Privacy Notice for details, including our exact no-sharing language for messaging originator opt-in data.

    Contact#

    Questions about this Opt-In Policy or the LeadLocate messaging program can be sent to:

  • Email: help@leadlocate.com
  • Phone: +1 (844) 376-2274
  • Web: https://leadlocate.com
  • LeadLocate operates from the United States of America. This Opt-In Policy applies to the LeadLocate sender +1 (844) 376-2274 and the LeadLocate RCS Business Messaging agent associated with that number. It does not govern messaging traffic that our subscribers (dealerships and salespeople) send to their own customers from their own LeadLocate-provisioned phone numbers. Those programs are governed by each subscriber own opt-in policies.

    © 2026 LeadLocate®.

    Back to contents

    Information Security Program#

    The controls behind the promises above. This is the packet we provide for security diligence and financial services partner review.

    Policy Overview#

    LeadLocate is a customer relationship management, lead management, communications, reporting, and dealer workflow platform operated by DotNet Holdings LLC DBA: LeadLocate. The platform handles business customer information, end-user contact information, lead details, communication metadata, and, where enabled by a customer and consented to by the consumer, financial account, identity, income, statement, enrichment, and verification data retrieved through authorized financial data providers.

    This Information Security Policy establishes the administrative, technical, and operational controls used to preserve the confidentiality, integrity, availability, and privacy of data processed by LeadLocate. The policy is written for diligence review by banks, lenders, financial technology partners, data providers, security reviewers, customers, and auditors. It intentionally avoids publishing sensitive implementation details, secrets, IP addresses, credentials, and architecture diagrams that could weaken security.

    Organization

    DotNet Holdings LLC DBA: LeadLocate

    Primary Security Contact

    compliance@dotnetholdings.com

    Effective Date

    April 24, 2026

    Review Cadence

    At least annually and upon material system, vendor, or regulatory change

    TLS 1.2+

    Encryption at Rest

    MFA for Critical Systems

    Least Privilege

    Vulnerability Remediation SLA

    Data Retention Controls

    Information Security Contacts#

    Security notices, diligence requests, vulnerability reports, privacy requests, and incident communications should be sent to the monitored compliance mailbox below. The mailbox is reviewed by General Counsel and authorized operations resources responsible for security, privacy, and platform reliability.

    Name

    Title

    Email

    Responsibility

    General Counsel

    General Counsel

    compliance@dotnetholdings.com

    Primary resource for information security, privacy, compliance diligence, vendor risk, and security exceptions.

    Security Assurance Matrix#

    The table below maps common bank, lender, fintech, and data-provider security diligence questions to LeadLocate's current security practice and supporting documentation location in this policy packet.

    Area

    Question

    LeadLocate Response

    Supporting Detail

    Governance

    Security contact information

    Provided

    General Counsel, compliance@dotnetholdings.com. See Section 2.

    Governance

    Documented and operationalized information security policy

    Yes

    This document is LeadLocate's Information Security Policy and describes operational controls for identifying, mitigating, and monitoring risks.

    Identity and Access

    Access controls limiting access to production assets and sensitive data

    Centralized identity and least privilege

    Production access is restricted to authorized personnel, managed through named accounts, role-based access, least privilege, logging, and review.

    Identity and Access

    MFA for consumers before financial data connection or identity verification

    Yes

    Consumer financial data and identity verification workflows require an authenticated, MFA-verified session before a consumer can connect financial accounts or complete sensitive verification steps. Screenshot evidence can be attached separately when a reviewer requests visual evidence.

    Identity and Access

    MFA for critical systems that store or process consumer financial data

    Yes

    Critical administrative, hosting, source control, and production access paths require MFA and are limited to authorized personnel.

    Infrastructure

    TLS 1.2 or better between clients and servers

    Yes

    LeadLocate uses HTTPS with valid certificates and requires TLS 1.2 or better for client-server communications involving sensitive data.

    Infrastructure

    Encryption of consumer financial data at rest

    Yes

    Consumer financial, identity, income, statement, and verification data is encrypted at rest. Tokens, secrets, and sensitive financial values are not stored in plaintext.

    Vulnerability Management

    Vulnerability scans and patching for employee/contractor machines and production assets

    Yes

    LeadLocate performs vulnerability monitoring and applies remediation based on severity-defined SLAs.

    Privacy

    Privacy policy for applications where financial data connections are deployed

    Yes

    Published at https://leadlocate.com/sales-leads/privacy-policy.

    Privacy

    Consumer consent for collection, processing, and storage

    Yes

    Financial data connections are presented only in consent-based workflows, and consumers authorize the specific institution connection, data sharing, and use case before data is accessed.

    Privacy

    Defined and enforced data deletion and retention policy

    Yes

    See Section 11, Data Retention and Disposal Policy.

    Governance and Risk Management#

    LeadLocate maintains an operational information security program appropriate to the size, complexity, and risk profile of the business. The program is overseen by company leadership and implemented through policies, procedures, technical controls, vendor management, access governance, vulnerability management, incident response, and periodic review.

    Security Objectives

  • Protect the confidentiality of customer, consumer, financial, and operational data.
  • Maintain the integrity of LeadLocate systems, lead records, communications, reports, workflows, and financial data integrations.
  • Maintain appropriate availability of production systems through monitoring, backups, operational response, and change controls.
  • Limit access to sensitive data to authorized personnel with a documented business need.
  • Collect, use, retain, and dispose of personal information in accordance with applicable law, customer instructions, and stated privacy commitments.
  • Continuously improve the security program based on incidents, threat intelligence, vendor changes, product changes, and compliance requirements.
  • Risk Identification and Review

    Security and privacy risks are identified through architecture review, code review, production monitoring, vulnerability scans, dependency updates, vendor diligence, customer feedback, incident review, and legal or regulatory changes. Risks are evaluated based on likelihood, potential business impact, sensitivity of data involved, exploitability, compensating controls, and remediation complexity.

    Material risks are assigned to a responsible party and tracked to remediation, acceptance, transfer, or mitigation. High-impact risks involving consumer financial data, authentication, encryption, tenant isolation, production access, or external integrations receive priority review.

    Policy Review and Exceptions

    This policy is reviewed at least annually and when there are material changes to LeadLocate products, financial data integration scope, hosting environment, authentication model, vendor relationships, data processing activities, or applicable legal requirements. Exceptions must be documented, time-bound, risk accepted by General Counsel, and remediated or renewed before expiration.

    U.S. Compliance Alignment#

    LeadLocate's security and privacy program is designed to support common U.S. requirements and diligence expectations for organizations handling consumer financial data, personal information, identity verification information, income information, statements, and related enrichment or fraud-prevention signals. Applicability depends on the customer, product configuration, data source, contract, and the role LeadLocate plays in the workflow.

    Requirement or Framework

    LeadLocate Alignment

    Policy Coverage

    GLBA Safeguards Rule

    Maintains administrative, technical, and operational safeguards for customer information, including access controls, encryption, risk review, vulnerability management, incident response, and vendor oversight.

    Sections 4 through 12

    GLBA Privacy Rule and customer notice obligations

    Uses consumer notice, consent, purpose limitation, privacy-policy publication, and data-retention controls for financial data workflows.

    Sections 10 and 11

    FTC Act, unfair or deceptive acts or practices

    Requires accurate public security statements, appropriate safeguards, limited use of data, and incident response for suspected unauthorized access.

    Sections 1, 4, 8, 10, and 12

    FCRA, where applicable

    Where data is used for eligibility, underwriting, employment, tenant screening, or another regulated consumer-report purpose, LeadLocate supports customer-required permissible purpose, use limitation, access restriction, retention, and deletion controls. Customers remain responsible for their own adverse action and end-user legal obligations unless contractually assigned otherwise.

    Sections 6, 8, 10, and 11

    State privacy laws, including CCPA/CPRA where applicable

    Supports notice, consent, data minimization, deletion, access restriction, purpose limitation, and service-provider style processing obligations when required by contract.

    Sections 10 and 11

    State data breach notification laws

    Maintains incident triage, containment, investigation, documentation, and notification procedures for suspected unauthorized access to protected personal information.

    Section 12

    Bank, lender, and fintech vendor-risk expectations

    Provides documented governance, MFA, least privilege, TLS, encryption at rest, vulnerability management, secure development, data retention, vendor oversight, and evidence checklist controls.

    Sections 2 through 13

    Scope note: This policy is a security and privacy control document. It is intended for partner diligence and operational compliance support. Workflow-specific legal requirements are reviewed with counsel and addressed in the applicable customer agreement, data processing terms, consent language, and workflow configuration.

    Identity and Access Management#

    LeadLocate applies least privilege, role-based access, named user accountability, and MFA to limit access to production assets and sensitive data. Shared production access is avoided wherever practical. Access is granted based on job responsibility, reviewed periodically, and removed when no longer needed.

    Least Privilege

    Users receive only the access required for their role and assigned work.

    Named Accounts

    Production and administrative actions are attributable to authorized users.

    MFA

    Critical systems and financial data workflows require MFA controls.

    Access Review

    Privileged access is periodically reviewed and removed when no longer justified.

    Session Protection

    Authenticated areas use session controls to reduce unauthorized access risk.

    Tenant Isolation

    Application authorization checks restrict users to their permitted company data.

    Consumer MFA Before Sensitive Financial Workflows

    For financial account, income, identity, statement, and verification workflows, LeadLocate requires the consumer to be in an authenticated and MFA-verified flow before sensitive steps are presented. This reduces the risk that a person without appropriate control of the account or session can initiate a financial institution connection or identity verification event. Where supported by the user's device and browser, phishing-resistant factors such as passkeys, biometrics, or platform authenticators are preferred.

    Administrative MFA

    Access to critical systems that store, process, transmit, deploy, back up, or administer consumer financial data requires MFA. This includes administrative application access, hosting/control panel access, source control, vendor administration consoles, and privileged infrastructure tools. Administrative access is not granted to general users and is limited to authorized personnel.

    Account Lifecycle

  • Access requests must have a business justification and role assignment.
  • Privileged access is limited to personnel who require it for operations, security, support, or maintenance.
  • Access is removed or disabled upon role change, termination, vendor offboarding, or loss of business need.
  • Credential sharing is prohibited for production and security-sensitive systems.
  • Passwords, API keys, provider credentials, tokens, private keys, and secrets must not be sent through insecure channels or stored in plaintext.
  • Infrastructure and Network Security#

    LeadLocate uses layered controls to protect production systems and sensitive data. Controls include HTTPS, certificate management, managed hosting protections, network restrictions, system hardening, vulnerability monitoring, logging, backups, and administrative access controls.

    Encryption in Transit

    LeadLocate uses HTTPS with valid certificates for web application traffic and requires TLS 1.2 or better for client-server communications involving sensitive data. Plain HTTP is not used for transmission of consumer financial data. Financial data provider API communications are made over encrypted channels and follow the provider's production security requirements.

    Encryption at Rest

    Consumer financial, identity, income, statement, enrichment, and verification data is encrypted at rest. Access tokens, secrets, and sensitive financial values are protected using encryption, restricted storage locations, and access controls. Backups containing sensitive data are subject to the same retention, access, and disposal requirements as production data.

    Network and Host Protections

  • Production systems are administered by authorized personnel only.
  • Administrative access paths are restricted and protected by MFA where supported.
  • Unnecessary services are disabled or removed where practical.
  • Security updates are applied based on severity and operational risk.
  • Logs are used to support troubleshooting, anomaly review, security investigation, and auditability.
  • Backups are maintained to support recovery from accidental deletion, corruption, operational failure, or security incidents.
  • Financial Data Handling#

    and Controls

    LeadLocate treats consumer financial, identity, income, statement, enrichment, and verification data as highly sensitive. The platform only requests, processes, and stores data necessary to provide the specific product feature authorized by the consumer and enabled by the customer.

    Data Minimization

    Financial data workflows are designed to request only the product scopes and data elements needed for the business purpose. LeadLocate does not request consumer financial institution credentials directly from the consumer, does not ask consumers to provide bank passwords directly to LeadLocate, and does not sell consumer financial data.

    Consent and Authorization

    Consumers authorize financial account connections, identity checks, document parsing, income verification, enrichment, and fraud review through the applicable consent and permission flow. LeadLocate records or relies on the consent event and uses the resulting tokens, account data, documents, verification data, or derived results only for the authorized workflow. If a consumer withdraws consent or requests deletion, LeadLocate follows the retention and deletion procedure in this policy, subject to legal, fraud prevention, dispute, accounting, or security obligations.

    Token and Secret Protection

  • Provider client secrets, API keys, access tokens, and refresh tokens are treated as secrets.
  • Secrets are never committed to public source code repositories or shared in plaintext support channels.
  • Secrets and tokens are encrypted or stored in restricted secret storage appropriate to the environment.
  • Access to financial data provider credentials is limited to authorized personnel with a business need.
  • Suspected exposure of a credential or token triggers incident response, rotation, and review.
  • Use Limitation

    Financial data is used only to deliver the consumer-permissioned LeadLocate function, support the customer relationship, meet compliance obligations, prevent fraud or abuse, troubleshoot integration issues, and maintain security. It is not used for unrelated advertising, resale, or non-consented secondary purposes.

    Secure Development and Vulnerability Management#

    LeadLocate applies secure development practices to reduce security defects before deployment and to remediate vulnerabilities after discovery. The program covers application code, dependencies, server software, employee and contractor machines, and production assets.

    Secure Development Practices

  • Security-sensitive changes receive review for authorization, tenant isolation, input validation, output encoding, access control, logging, error handling, and data exposure.
  • Secrets must not be hard-coded into application code or committed to repositories.
  • Production changes are scoped, tested, and deployed in a manner designed to minimize service disruption.
  • Customer and consumer data is not used in local development unless needed for support or testing and protected appropriately.
  • New integrations that handle sensitive data are reviewed for privacy, security, data flow, and vendor risk before production use.
  • Vulnerability Scanning and Patch SLAs

    LeadLocate performs vulnerability monitoring and scanning for production assets and employee or contractor machines. Identified vulnerabilities are evaluated and remediated according to severity, exploitability, exposure, and data sensitivity.

    Severity

    Target Remediation SLA

    Examples

    Critical

    As soon as practicable, target within 7 calendar days

    Known exploited remote code execution, exposed secret, authentication bypass, active compromise indicator.

    High

    Target within 30 calendar days

    Privilege escalation, sensitive data exposure, serious dependency issue, externally reachable high-risk service.

    Medium

    Target within 60 calendar days

    Moderate dependency vulnerability, configuration weakness with compensating controls, limited exploitability issue.

    Low

    Target within 90 calendar days or scheduled maintenance

    Low-risk hardening item, informational finding, defense-in-depth improvement.

    Remediation Verification

    Remediation may be verified through patch confirmation, configuration review, code review, retesting, vulnerability scan results, log review, or vendor attestation. Exceptions require a documented compensating control and risk acceptance.

    Data Retention and Disposal Policy#

    LeadLocate maintains a defined and enforced data retention and disposal policy for personal information, customer data, lead data, operational records, logs, backups, and consumer financial data. The goal is to retain data only for as long as it is needed to provide services, support customers, comply with legal obligations, resolve disputes, prevent fraud or abuse, maintain security, and operate the business.

    Retention Principles

  • Data is retained for the shortest practical period consistent with service delivery, customer instructions, legal obligations, security needs, and operational continuity.
  • Consumer financial, identity, income, statement, enrichment, and verification data is retained only for the authorized purpose and removed or de-identified when no longer required.
  • Deletion requests are evaluated promptly and completed unless retention is required for legal, fraud prevention, dispute, security, billing, accounting, backup integrity, or other legitimate obligations.
  • Backups are retained for limited recovery windows and age out through normal backup rotation.
  • Data subject to legal hold, investigation, fraud prevention, abuse prevention, or active dispute may be retained until the hold or need is resolved.
  • Data Category

    Typical Retention

    Disposal Method

    Consumer financial, income, and statement data

    Only as long as needed for the consumer-authorized feature, customer support, legal, fraud prevention, or security purpose.

    Delete, revoke access where applicable, de-identify, or cryptographically render inaccessible according to system capability.

    Provider tokens and secrets

    Only while the integration or consumer-authorized connection remains active and needed.

    Revoke, rotate, delete encrypted records, and invalidate application references.

    CRM lead and customer records

    Retained while the customer account is active or as needed for business records, support, legal obligations, and customer instructions.

    Delete, archive, anonymize, or export and remove upon verified customer request where permitted.

    Application logs and security events

    Retained for troubleshooting, monitoring, fraud prevention, incident investigation, and auditability.

    Rotate, expire, aggregate, or securely delete according to operational retention windows.

    Backups

    Retained for disaster recovery and operational resilience according to backup rotation schedules.

    Automatic expiration, secure deletion of backup media, or destruction by hosting/vendor process.

    Vendor, billing, and compliance records

    Retained as required for tax, accounting, legal, contract, audit, and business purposes.

    Secure deletion or archival disposal after retention need expires.

    Deletion Request Procedure

  • Receive deletion request through the application, customer support, or compliance@dotnetholdings.com.
  • Verify the requester's authority to request deletion for the relevant account, company, or consumer data.
  • Identify systems, records, financial data connections, identity verification records, backups, vendors, and logs reasonably in scope.
  • Delete, de-identify, restrict, or export and remove the applicable data unless a valid retention exception applies.
  • Document completion, exception, or denial reason as appropriate.
  • Financial data deletion: If a financial data connection or verification workflow is terminated or no longer needed, LeadLocate will stop using the associated data, remove or revoke stored tokens where applicable, and delete or de-identify retained consumer financial data except where legally or operationally required to retain it.

    Incident Response#

    and Monitoring

    LeadLocate maintains an incident response process for suspected or confirmed security events affecting production systems, customer data, consumer financial data, credentials, vendor integrations, or availability. The process is designed to contain events quickly, preserve evidence, restore service, communicate appropriately, and reduce the likelihood of recurrence.

    Incident Response Phases

  • Identify: Receive signal from monitoring, alerts, support reports, vulnerability disclosures, logs, vendors, or employees.
  • Triage: Assess severity, affected systems, data sensitivity, active exploitation, customer impact, and regulatory or contractual obligations.
  • Contain: Disable compromised credentials, isolate affected components, block malicious activity, rotate keys or tokens, and restrict access as needed.
  • Eradicate and recover: Patch defects, remove unauthorized access, restore affected services, verify integrity, and monitor for recurrence.
  • Notify: Provide required notifications to customers, partners, regulators, financial data providers, or consumers according to applicable law and contract.
  • Improve: Document lessons learned, update controls, strengthen monitoring, and track remediation items to closure.
  • Security Event Monitoring

    Logs and operational signals are reviewed to support troubleshooting, anomaly detection, abuse prevention, and incident investigation. Sensitive operational logs are restricted to authorized personnel and retained according to the data retention policy.

    Evidence Checklist#

    for Partner Diligence

    This page is intended to be printed or saved as the primary Information Security Policy and Data Retention and Disposal Policy documentation. Banks, lenders, data providers, and financial technology partners may request screenshots or additional records for MFA, encryption, vulnerability management, privacy, or incident response evidence. Screenshots should be attached separately when visual proof of a live control is requested.

    Evidence Item

    Status

    Recommended Attachment or Link

    Information Security Policy

    This page

    Print or save this document as PDF using the button at the top.

    Data Retention and Disposal Policy

    Included

    Section 11 of this document.

    Consumer MFA screenshot before financial data connection

    Attach screenshot

    Capture the consumer-facing MFA step before a financial account connection, identity verification, income verification, document parsing, or similar sensitive workflow is opened.

    Administrative/critical system MFA screenshot

    Attach screenshot

    Capture the MFA requirement for the administrative or critical system used for sensitive financial data operations.

    Privacy Policy URL

    Available

    https://leadlocate.com/sales-leads/privacy-policy

    Management Attestation#

    DotNet Holdings LLC DBA: LeadLocate attests that it maintains a documented and operational information security program designed to identify, mitigate, and monitor information security risks relevant to its business and to protect consumer data handled through financial account, identity, income, statement, enrichment, document parsing, fraud review, and verification workflows.

    LeadLocate further attests that it will review and remediate partner-identified gaps in its security practices as applicable after completion of security diligence.

    Policy Contact

    General Counsel

    DotNet Holdings LLC DBA: LeadLocate

    compliance@dotnetholdings.com

    Version and Approval

    Version: 1.0

    Effective date: April 24, 2026

    Approved by: General Counsel

    Next review: April 24, 2027 or earlier upon material change

    LeadLocate Information Security Policy | Public diligence copy | Questions: compliance@dotnetholdings.com

    Back to contents