Skip to contentChat on WhatsApp
SwiftLead - websites, SEO and ads for local businesses

Privacy Policy

Last updated: September 2026

Who We Are

SwiftLead helps local trades and service businesses get more leads online — websites, Google Maps, reviews, Local Services Ads, Google Ads, and Facebook and Instagram advertising. We are operated in the United Kingdom. When we say “we,” “us,” or “SwiftLead,” we mean SwiftLead and its team. You can contact us at james.wilson@swiftlead.co.uk.

What Data We Collect

Information you provide

  • Name, email address, phone number, and website URL when you fill in our contact or audit request forms
  • Business name and monthly ad budget range
  • Any additional information you share with us via email or WhatsApp

Information we collect automatically

  • If you accept optional analytics, pages visited, time on site, and interactions via Google Analytics 4
  • If you accept optional analytics, device type, browser, and approximate location
  • If you accept optional analytics, referral source (how you found our website)

Information from public sources

  • Business data from Companies House (company name, registration number, SIC codes, registered address)
  • Website performance data from Google PageSpeed Insights
  • Business listings from Google Places (address, phone, reviews, ratings)
  • Publicly available contact details from business websites

How We Use Your Data

  • To respond to your enquiry and provide our services
  • To generate website audit reports for prospective clients
  • To send you information about our services (you can opt out at any time)
  • To manage the Local Services Ads, Google Ads, and Facebook and Instagram advertising services you authorise as a client
  • To improve our website and services through optional analytics, when you accept them

Facebook and Instagram Advertising

When a business authorises SwiftLead to manage its Meta advertising, we access the connected business, ad account, Page, advertising assets and performance results. We use this information to prepare and manage authorised campaigns, monitor delivery and report results to that business in its private portal.

For connected Instant Forms, we receive the contact details and answers that a person submits, together with the form, lead, ad and campaign identifiers and submission time. We store the enquiry for the relevant business and notify its verified contact so it can respond. Advertising clicks and form submissions are recorded separately from reviewed, qualified enquiries.

Connection credentials are used by our server and are not included in client portal responses. Enquiry records are stored with Supabase and processed by our Vercel-hosted service. Text notifications use Twilio and include the enquiry details needed by the receiving business. The business receiving your enquiry may also describe its own use of your data in the privacy notice linked from its form.

To request access to or deletion of Facebook or Instagram data held by SwiftLead, email james.wilson@swiftlead.co.uk. Include the business or Page name and the contact details used for the enquiry so we can locate the records and verify your request. Businesses can also revoke SwiftLead's access in their Meta business settings. Revoking access stops future provider access; it does not itself delete records already received. The retention and rights sections below apply to those records.

Calendar Connections and Visit Bookings

When you connect a calendar to SwiftLead Bookings, we access your account identity, calendar list and availability to help you choose calendars and offer visit times. We create, read, update and cancel SwiftLead visit events in the calendar you select. Customers see only available times and their own visit details.

We store encrypted connection credentials, your calendar selections and booking settings. Visit records include the customer's contact details, visit address, time, status and original enquiry reference. Appointment details are shared with the connected calendar provider and with the business and customer through booking updates.

We encrypt Google Calendar access and refresh tokens before storing them using AES-256-GCM. The encryption key is held separately in server-side configuration, and the encrypted credentials are bound to the relevant business. Tokens are handled by our server and are not included in browser responses.

We use HTTPS/TLS when exchanging data with Google. Access to stored connection and booking data is restricted to server-side services, with business-specific access checks and signed private management links. Calendar authorisation uses PKCE, random state values and a secure, HttpOnly callback cookie that expires after ten minutes. Private booking API responses are marked not to be cached and use a no-referrer policy.

Google Calendar data is used to provide the booking features you choose. We do not use it for advertising or to train general-purpose AI models, and we do not sell it. Our use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

You can revoke access in your Google or Microsoft account settings, or revoke the app-specific password used for iCloud. This stops future access; existing visit records and calendar events are not automatically deleted. Contact james.wilson@swiftlead.co.uk to request removal of stored connection or booking data.

Legal Basis for Processing

We process your personal data under the following legal bases (UK GDPR):

  • Consent — when you submit a form on our website, agree to receive communications, or accept optional analytics
  • Legitimate interest — to contact businesses about our services using publicly available information (limited to corporate subscribers under PECR)
  • Contract — to fulfil our obligations when you become a paying client

Cold Outreach (PECR Compliance)

We may contact UK limited companies using publicly available business email addresses. This is permitted under the Privacy and Electronic Communications Regulations (PECR) for corporate subscribers. We only contact limited companies (Ltd, LLP, PLC) — never sole traders or individuals without prior consent. Every email includes a clear opt-out mechanism.

Cookies and Local Storage

Google Analytics is optional and does not load until you accept it. We also use local storage to remember your choice.

Cookie or storage keyPurposeDuration
swiftlead_calendar_connectProtects your calendar sign-in and returns you to your private booking pageUp to 10 minutes
_ga, _ga_*Optional Google Analytics usage measurement, set only after you acceptUp to 2 years
swiftlead_client_google_tag_consent_v1Local storage value that remembers your Accept or Decline choiceUntil you change your choice or clear this site's browser data

After choosing, you can reopen the consent choices at any time with the Cookie settings button on our website. You can also clear this site's data in your browser settings.

Who We Share Data With

  • Google — for optional Analytics when you accept it, managed Ads and Local Services Ads services, and API services
  • Meta — for the Facebook and Instagram advertising, reporting and Instant Form connections authorised by the relevant business
  • Resend — for sending transactional emails
  • Microsoft and Apple — when you choose to connect their calendar services
  • Twilio — for sending transactional text messages
  • Supabase — for storing client, enquiry and booking records
  • Vercel — our website hosting provider
  • Stripe — for payment processing (clients only)

We do not sell your personal data to third parties.

Data Retention

  • Contact form submissions: retained for 2 years or until you request deletion
  • Client data: retained for the duration of our service agreement plus 6 years (legal/tax requirements)
  • Prospect data from public sources: retained for 12 months, then deleted if no relationship established
  • Analytics data: if you accept, retained under the Google Analytics settings in force for this website

Your Rights

Under UK GDPR, you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — ask us to correct inaccurate data
  • Erasure — ask us to delete your data (“right to be forgotten”)
  • Object — object to our processing of your data for marketing purposes
  • Portability — receive your data in a portable format
  • Withdraw consent — at any time, without affecting the lawfulness of prior processing

To exercise any of these rights, email us at james.wilson@swiftlead.co.uk. We will respond within 30 days.

Complaints

If you believe we have not handled your data properly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

Changes to This Policy

We may update this privacy policy from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this page periodically.