Who we are
Me2Leads is a mobile application and website published by De Bouana SARL, a private limited company registered in Luxembourg. As the publisher we act as data controller within the meaning of Article 4(7) of the EU General Data Protection Regulation (Regulation 2016/679, “GDPR”).
Data we process
We collect only what is strictly required to make Me2Leads useful. The table below summarises every category, where it lives, and whether you can turn it off.
| Category | Examples | Where it lives |
|---|---|---|
| Account | Full name, email, hashed password, optional profile photo, plan tier, session token, last sync timestamp. | On your device + EU hosted storage (always synced). |
| Contacts you capture | First and last name, job title, company, phone, email, source, two project + budget fields, interest, free-text notes, tags, status (hot / warm / cold), capture method, avatar colour, business-card photo. | Encrypted database on your device. Synced to a remote database only for Premium / Business users. |
| Reminders | Start & end datetime, repeat frequency, note, action (call / sms / whatsapp / email), priority, completion flag, list of linked contact ids. Important reminders may be added to your device calendar if you allow it. | Encrypted database on your device. Synced to a remote database only for Premium / Business users. |
| Interactions & audit log | Type of action (call / sms / whatsapp / email / note / edit), timestamp, and a small payload — for edits we store a field-level diff so you can see who changed what. | Encrypted database on your device. Synced to a remote database only for Premium / Business users. |
| Photos | Your profile picture and contact pictures, stored as profile_pictures/<userId>/… and contact_pictures/<userId>/…. |
Local files. Optional cloud storage when sync is enabled. |
| Organization data | Org name, 8-character invite code, member roles (admin / member), per-member privileges (can_edit / can_create / can_view_reminders), member status. Only when you create or join a Business org. | Local + Remote database. |
| In-app notifications | Title, body, scheduled time, reference id, read status — used by reminder push notifications and the in-app feed. | On-device notification queue (WorkManager / flutter_local_notifications). |
| Payments | Tier, transaction id and renewal state returned by in_app_purchase. We never see your card, payment method providers handle it. |
Receipt id stored against your account row; Your payment information remains with you and the payment method providers. |
| Technical metadata | App version, basic device class and last sync timestamp transmitted with sync requests so we can keep migrations correct. We do not embed a third-party crash-analytics SDK. | App logs & account row. |
| Website analytics | Page visits, country, referrer, basic device class — only if you accept cookies. | Google Analytics 4. See Cookies. |
Why we process it
- Provide the service. Run the app, store and sync your contacts, fire reminders, log interactions, and let you reach a contact in one tap.
- Account & security. Verify your email, hash your password, rotate session tokens on logout or password change, and detect abuse.
- Billing. Activate Premium or Business, recognise the receipt from Apple, Google or PayPal, and invoice your team for the Business plan.
- Support. Answer the messages you send through the contact form, by email or on WhatsApp.
- Improve the product. Use aggregated, non-personal signals (app version, OS class, last-sync timestamp) to fix bugs and prioritise features. We do not embed a third-party analytics or crash-reporting SDK in the app.
- Comply with the law. Honour GDPR requests, accounting obligations, and lawful requests from authorities.
Legal basis
We rely on the following legal bases (Article 6 GDPR), depending on the activity:
- Performance of a contract — running your account, syncing, billing, providing support. This covers the bulk of what the app does.
- Legitimate interest — keeping the service secure, preventing fraud and abuse, and aggregating anonymous usage to make the product better. We weigh it against your rights and freedoms before relying on it.
- Consent — for non-essential cookies on the website and any optional marketing email. You can withdraw consent at any time without it affecting prior processing.
- Legal obligation — accounting records, VAT, and responses to lawful requests from EU and Luxembourg authorities.
Storage & encryption
On your device
Contacts, reminders, interactions and notifications live in a local database. Phone numbers and emails are persisted as encrypted blobs and their master key is unique per user.
Your password is never stored. We keep a salted hash, plus a session token that is rotated on every logout and password change so a leaked old token is useless.
In the cloud (Premium & Business only)
If you enable sync, encrypted blobs are upserted to our database operated by De Bouana SARL. Photos are uploaded to a secured server. Sync runs in two modes: explicit push / pull from the Sync screen, and live-writes. Free-tier accounts only push their account row (so multi-device login works), no contacts, reminders, interactions or photos.
Transport & credentials
All traffic between the app and our servers travels over a secure connection. Internal service credentials are obfuscated.
Who we share with
We rely on a small number of vetted sub-processors. Each one is bound by a Data Processing Agreement and the EU Standard Contractual Clauses where data crosses borders.
| Sub-processor | Purpose | Region |
|---|---|---|
| Apple App Store | iOS distribution and in-app purchases via in_app_purchase. | Ireland (EU) |
| Google Play | Android distribution and in-app purchases via in_app_purchase. | Ireland (EU) |
| Google ML Kit | On-device OCR for business-card scanning. Text recognition runs locally — the captured image never leaves the phone. | On-device |
| Mobile Scanner | QR-code reading via the device camera. Decoded locally. | On-device |
| Device calendar | add_2_calendar integration that lets you push important reminders to your phone calendar. We never see the calendar entry itself. | On-device |
| WorkManager / Local Notifications | Schedules and fires reminder push notifications from the device. No remote push server is involved. | On-device |
| Managed database host | Cloud sync of account. For Premium / Business: contacts, reminders, interactions and organization data. | EU (operated by De Bouana SARL) |
| Cloud image storage | Storage of profile and contact pictures, namespaced per user. | EU (operated by De Bouana SARL) |
| SMTP provider | Sends email-verification and password-reset codes. | EU |
| Google Analytics 4 | Anonymised website analytics (cookie-gated). Property ID G-WG04RLCPSC. | EU/US (SCCs) |
| CookieHub | Cookie consent banner on the website. | EU (Iceland) |
We do not sell, rent, or trade personal data, and we do not embed any third-party advertising or fingerprinting SDK in the mobile app.
Retention
- Account data: Kept for the lifetime of your account. Deleted from our cloud upon clicking on the Delete Account button; backups are rotated within 90 days.
- Contacts & reminders: Kept as long as you keep them. Local data lives on your device; cloud copies are removed when you disable sync, change tier, or delete the account.
- Photos: Removed from cloud storage upon account deletion.
- Billing records: Retained for 10 years as required by Luxembourg accounting law.
- Support tickets: Kept for up to 24 months for service-quality and dispute purposes.
- Web analytics: Anonymised, retained for 14 months in Google Analytics.
Your rights under GDPR
Under Articles 15 to 22 GDPR you have the following rights, exercisable free of charge:
- Access — get a copy of the data we hold about you.
- Rectification — correct anything that is inaccurate. Most fields are editable directly inside the app.
- Erasure — wipe individual contacts, your account, or your full cloud footprint at any time.
- Restriction & objection — limit or object to specific processing, including legitimate-interest cases.
- Portability — export your contacts to CSV or TXT from the Import / Export screen, on any tier.
- Withdraw consent — revoke marketing or non-essential cookies without affecting prior processing.
- Lodge a complaint — with the Luxembourg Commission Nationale pour la Protection des Données (CNPD) or with the supervisory authority of your country of residence.
To exercise any of these rights, write to contact@me2leads.com. We reply within 30 days, or 60 days if the request is complex.
Cookies on this website
This website uses a minimal set of cookies, managed through CookieHub. The categories are:
- Strictly necessary session, language preference (
me2leads.lang) and cookie-consent state. Set without consent — required for the site to work. - Analytics Google Analytics 4 (
_ga,_ga_*) — measures traffic and behaviour. Set only after you accept. - Marketing none. We do not run advertising or retargeting cookies.
Open the cookie panel at any time via the floating CookieHub button to change your preferences.
Children
Me2Leads is a professional tool. The service is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has created an account, write to us and we will delete it.
Changes to this policy
When we make a material change, we update the version number and the “Last updated” date at the top of this page, and notify active users by email or in-app banner at least 30 days before the change takes effect. The previous version remains available on request.
Contact & DPO
For any privacy question, request, or complaint: