Skip to main content
WeLead Lab Call Vladimir

Legal

Privacy Policy

Last updated: September 21, 2026

WeLead Lab ("we," "us," or "our") provides a founder-led growth partnership for local service businesses and operates the website at weleadlab.com. This Privacy Policy explains what personal information we collect through the website, how we use it, and the choices you have. It covers this website only. A paid client engagement is governed by the separate agreement and privacy terms we sign with that client, and the property, geographic and market information used for Territory Intelligence is described at Data practices.

1. Information we collect

Information you provide directly

  • Contact details: Your name, email address, phone number, and anything you write when you use our contact form, email us, or book a call.
  • Booking information: If you schedule a call, the details you provide are handled by our scheduling provider (Cal.com).

Information collected automatically

  • Privacy-friendly analytics: Aggregate pages-visited and referral data via Cloudflare's built-in analytics. This sets no cookies and does not identify individual visitors.
  • Site analytics: Only after you choose Accept all in the privacy bar, public pages load Google Analytics 4, which records page views, the site or campaign that referred you, coarse device details and the actions we mark as conversions (booking, calling, submitting the contact form). It sets the first-party cookies _ga and _ga_8TERPQEXSG, receives your IP address for approximate location (not stored), and runs with Google Signals and ad personalization off. It does not run on the sales dashboard, checkout or contract pages, and it is not loaded when your browser sends a Global Privacy Control signal. See the Cookie Policy for how to block it.
  • Advertising measurement: Only after you choose Accept all in the privacy bar, public pages load the Meta Pixel, which reports the visit and inquiry actions (booking, calling, texting, emailing, viewing pricing) to Meta so we can measure Facebook and Instagram advertising and, if we advertise there, reach people who visited this site. It sets the first-party cookies _fbp and, after a Meta ad click, _fbc, and Meta may set its own cookies on facebook.com domains. Advanced Matching is off: no name, email or phone number is sent. Not loaded on the sales dashboard, checkout or contract pages, nor under a Global Privacy Control signal. See the Cookie Policy for how to opt out.
  • Session recording and heatmaps: Only after you choose Accept all, public pages load Microsoft Clarity, which records page views, scrolling, clicks, mouse movement and the elements you interact with, and aggregates them into heatmaps and session replays that we review to improve the site. It sets the first-party cookies _clck and _clsk (and Microsoft sets its own on clarity.ms), receives your IP address (used for approximate location and then not stored by us) and browser/device details, and masks text typed into form fields before it leaves your browser. It does not run on the sales dashboard, checkout or contract pages, and it is not loaded when your browser sends a Global Privacy Control signal. See the Cookie Policy for retention periods and how to block it.
  • Optional affiliate attribution: With your permission, Partnero records referral visits and a partner identifier to credit introductions to our business. This visitor integration sends URL, referrer, IP address, session and browser/device information; it does not send form submissions, bookings or payments. The attribution window is 90 days. You can decline or withdraw affiliate permission on the Cookie Policy page.
  • Website visitor identification: Every page of this site loads a visitor identification tag from Instantly.ai, which uses RB2B and its partners (including LiveIntent). It reads and sets third-party cookies on those partners' domains and matches your visit against profiles they already hold, so that we may learn which company — and sometimes which person — visited the site, plus an approximate location derived from your IP address. Matching is attempted for United States traffic, succeeds only sometimes, and returns us nothing when a visit goes unmatched. We use it to follow up with businesses that looked at this site. See the Cookie Policy for how to block it, and section 4 below for how to have it deleted.

2. How we use your information

We use the information we collect to:

  • Respond to your inquiry and follow up about working together;
  • Schedule and hold calls you book with us;
  • Operate, secure, and improve the website;
  • Comply with legal obligations.

We do not sell the personal information collected through this website, and we do not use it to train AI models. Our legal bases (where the GDPR applies) are your consent, our legitimate interest in responding to and operating our business, and compliance with legal obligations.

Scope, stated plainly. This section is about information this website collects from its visitors. It is not a statement about the property, geographic and market information used in a paid Territory Intelligence engagement, where files may be supplied to the client who commissioned the work. How that information is sourced, minimized, restricted and deleted is set out at Data practices, and the legal role for a given engagement is established in that client's agreement rather than here.

3. Third-party services

The website relies on the following providers, each under its own privacy policy:

4. Your rights (GDPR / CCPA)

For EEA and UK residents (GDPR)

If you are located in the European Economic Area or United Kingdom, you have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Request correction of inaccurate personal data.
  • Erasure: Request deletion of your personal data ("right to be forgotten").
  • Portability: Receive your data in a structured, machine-readable format.
  • Objection: Object to processing based on legitimate interests or for direct marketing.
  • Restriction: Request that we restrict processing in certain circumstances.

For California residents (CCPA/CPRA)

California residents have the right to:

  • Know what personal information we collect, use, and disclose;
  • Request deletion of personal information we hold about you;
  • Opt out of the sale or sharing of personal information. We do not sell it. However, the website visitor identification described in section 1 involves third-party partners who set their own cookies and match your visit against their own profiles, and the Meta Pixel reports your visit to Meta; under the CPRA and similar state laws either may qualify as "sharing." Neither loads until you choose Accept all in the privacy bar. To opt out, use the Do Not Sell or Share My Personal Information link in the footer of every page and choose Reject all, block third-party cookies, use the partners' opt-outs (linked in section 3), or email [email protected] and we will suppress and delete anything held about your visit;
  • Not be discriminated against for exercising your privacy rights.

Global Privacy Control and other opt-out preference signals

We honor the Global Privacy Control (GPC) signal as a valid request to opt out of the sale or sharing of personal information, as California, Colorado, Connecticut and other state laws require. When your browser or extension sends the signal (Sec-GPC: 1), the visitor identification tag, the Meta Pixel, Partnero, Google Analytics and Microsoft Clarity are not loaded in that browser, whatever you chose or did not choose in the privacy bar, and the page shows "Opt-Out Preference Signal Honored". The signal is per browser: it does not reach other devices, and it does not identify you to us, so it cannot delete data we already hold — email [email protected] for that. Our machine-readable statement is at /.well-known/gpc.json.

To exercise any of these rights, contact us at [email protected]. We will respond within the timeframe required by applicable law (generally within 30–45 days).

5. Data security

We use industry-standard safeguards, including:

  • TLS/HTTPS encryption for all data in transit;
  • Cloudflare's global network with DDoS protection;
  • Minimizing what we collect, and relying on vetted processors (Stripe for payments, Cloudflare for infrastructure) rather than storing sensitive credentials ourselves.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

6. Data retention

We keep the information you send us (such as contact-form messages and booking details) only as long as needed to respond to you, to maintain reasonable business and legal records, and as required by law — then we delete or anonymize it.

7. Contact

Questions about this Privacy Policy or our data practices? Contact us at:

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page and, where appropriate, notify you.