Security and Trust
How we keep your business and your clients' data safe, and the providers we rely on to run Leadhand.
Last updated 22 July 2026
We know your Leadhand account holds the details that run your business - your clients, your jobs, your quotes and your invoices. This page explains how we protect that data and which providers we use. It supports our Privacy Policy, and in this page Leadhand, we, us and our mean Leadhand Pty Ltd (ABN 37 699 652 072).
Encryption
Data sent between your browser or the field app and Leadhand is encrypted in transit using TLS (HTTPS). Data we store, including your database records and uploaded files, is encrypted at rest by our infrastructure providers. Payment card details are handled directly by Stripe and are not stored on our systems.
Access controls
- Access to your data inside the app is controlled by roles and permissions, and is separated by business so one customer cannot see another's data.
- We limit internal access to production systems to the people who need it to run and support the service, and we use the access controls our providers offer.
- You control who in your team has an account and what they can do. Remove access promptly when someone leaves your business.
Data hosting and location
Your account data and the information you store about your clients are held in our database, which is hosted in Australia (Sydney). We have kept your core business data onshore on purpose.
Some of the other providers we use process limited data outside Australia: Stripe (payments), Resend (email), Vercel (website hosting and CDN), PostHog (analytics), Google Ads and Meta (advertising measurement). This is set out in the overseas-disclosure section of our Privacy Policy. We take reasonable steps to ensure our providers handle data consistently with the Australian Privacy Principles.
Backups and reliability
Our infrastructure providers maintain regular backups of the database so we can recover from a failure. We still recommend you export and keep your own copy of important data, as set out in our Terms of Service.
Sub-processors
We use a small set of trusted service providers (sub-processors) to run Leadhand. Each one only handles the data it needs to provide its service to us, under its own security and contractual obligations.
| Provider | What they do | Location |
|---|---|---|
| Supabase | Database, authentication and file storage | Australia (Sydney) |
| Stripe | Subscription billing and card payment processing | United States |
| Resend | Transactional and notification email delivery | United States |
| Vercel | Application hosting and content delivery (CDN) | United States |
| PostHog | Product analytics and marketing attribution | United States |
| Google Ads | Advertising delivery and conversion measurement | Global |
| Meta | Facebook and Instagram advertising and conversion measurement | Global |
We may add or change sub-processors as the product develops. If we add or change a material sub-processor, we will update this list and give reasonable advance notice (at least 30 days for a material change) so you can raise any concern.
Reporting a security issue
If you believe you have found a security vulnerability or have a security concern, please email us at support@leadhand.com.au with the details. We take reports seriously and will work with you in good faith to confirm and fix genuine issues. Please give us a reasonable chance to address a problem before disclosing it publicly.
Data breach response
If we become aware of a data breach that is likely to result in serious harm, we will act in line with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth), including notifying affected individuals and the Office of the Australian Information Commissioner where required.
Contact us
For any security or trust question, email support@leadhand.com.au.
Leadhand Pty Ltd
ABN 37 699 652 072
Queensland, Australia
Questions about this policy? Email us at hello@leadhand.com.au. Leadhand Pty Ltd, ABN 37 699 652 072, Queensland, Australia.