Privacy Policy

Last updated: 2026-10-02

This policy describes how Wannalead collects, uses, and protects personal data when you use the Wannalead web application, API, and tooling (the "Service"). Wannalead is operated by THOLEX ("we", "us"), a French SASU registered with the Toulon Trade and Companies Register (RCS) under number 104 753 967, whose registered office is at 2 impasse des Myrtes, 83320 Carqueiranne, France. THOLEX is the data controller for the processing described in this policy. The Wannalead browser extension has its own dedicated policy: Extension Privacy Policy.

Data we collect

  • Account data. Your name and email address, either from Google sign-in or from the email address you provide, plus workspace and settings data you create in the product.
  • Billing data. Subscription and payment status. Payments are handled by Stripe; we never see or store full card numbers.
  • Marketing attribution. PostHog captures UTM parameters from tagged links and associates them with page views and later product events. We remove query parameters from page URLs before sending them.
  • Product analytics. PostHog receives page paths without query parameters, selected product events, an anonymous browser session identifier, and your internal user ID after sign-in. We do not send form contents, API keys, LinkedIn responses, or message text. Session replay and automatic click capture are off, and we respect the browser Do Not Track setting.
  • LinkedIn session and request data. When you connect the extension, we receive LinkedIn authentication status (presence flags and a non-reversible hash of the session cookies — never the cookie values themselves) and the LinkedIn responses needed to fulfil the requests you make through the Service.
  • Usage and log data. API requests, job history, technical logs, and metadata (IP address, browser and extension versions) used to operate and secure the Service.

How we use your data

  • to provide, operate, and secure the Service;
  • to process payments and manage your subscription;
  • to communicate with you about your account, security, and product updates;
  • to diagnose problems and improve the product.

We do not sell your personal data, and we do not use it for third-party advertising.

LinkedIn data — per-user boundary

Every LinkedIn request is fulfilled from your own LinkedIn session, bounded by what your account can already see and do. Data obtained through your session is used only to provide the Service to you. We do not pool, cross-reference, or resell LinkedIn data across users, and we do not perform cross-account lookups.

Subprocessors and hosting

We rely on a small number of service providers to run the Service, each processing data only as needed for their function:

  • Convex — application backend and database;
  • Stripe — payment processing;
  • Google — optional sign-in (OAuth);
  • PostHog — website and product analytics;
  • OVHcloud — server hosting (European Union).

Data retention

We keep your data for as long as your account is active and as needed to provide the Service. When you delete your account, we delete your personal data within a reasonable period, except where we must retain records to comply with legal obligations (for example, billing records).

Historical attribution records from our previous system are scheduled for deletion after 90 days, session attribution after 30 days, and daily campaign totals after 395 days.

Security

Data is transmitted over encrypted connections (TLS) and stored with access restricted to what is needed to operate the Service. LinkedIn cookie values are never logged or stored by us.

Your rights

Depending on where you live (including under the GDPR if you are in the European Union), you have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact us at the address below. You may also lodge a complaint with your local data protection authority (in France, the CNIL).

Cookies

The Service uses cookies strictly necessary for authentication and session management. PostHog keeps its analytics identifier in browser session storage. We do not use third-party advertising cookies.

Changes to this policy

We may update this policy from time to time; changes are reflected in the "Last updated" date above. For material changes we will notify you by email or in-product.

Contact