How Lead Commander handles your data.
Lead Commander is operated by The Meliora Group LLC, an Ohio limited liability company trading as Agency Development Services ("we", "us"). This policy explains what we collect, why, and what we do not do.
It applies to the Lead Commander application and to leadcmdr.com.
1. Who uses Lead Commander
Lead Commander is business software sold to independent insurance agencies. Its users are agency staff and the licensed insurance agents contracted under them. It is not a consumer product and has no public sign-up. Accounts are created by an agency for its own people.
2. Google user data
An agent may choose to connect their Gmail or Google Workspace mailbox. Connecting is optional; Lead Commander is fully usable without it.
The only scope we request
https://www.googleapis.com/auth/gmail.send — permission to send mail as
you.
We also receive the basic openid, email and
profile claims, which tell us the address of the mailbox you connected so we
can show you which account is in use and set the correct From address.
What this means, plainly
- We cannot read your mailbox. The
gmail.sendscope confers no read access. We do not request, and have no technical means of obtaining, the contents of your inbox, your sent mail, your drafts, your contacts, your labels or your attachments. - We do not sync, index, back up or scan any mailbox. There is no inbox synchronisation feature in this product.
- We never send from your account without your action. Mail is sent when you write and send a message, or when you explicitly approve and queue a campaign to your own clients.
What we store as a result
- OAuth tokens — an access token and a refresh token for the connected mailbox, held so we can send on your instruction without asking you to sign in each time. They are stored in our database and are never shared with any third party.
- The address and display name of the connected mailbox.
- Messages you send through Lead Commander — recipient, subject, body, timestamp, and the provider's message identifier — recorded against the lead they concern so the conversation stays on the customer record. This is the message you composed in our application, not anything retrieved from your mailbox.
Limited Use
Lead Commander's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We do not use Google user data to serve advertising. We do not sell it. We do not transfer it to any third party except as strictly necessary to provide the service, to comply with applicable law, or as part of a merger or acquisition where it remains subject to this policy. We do not allow humans to read it, except with your explicit consent for specific messages, where necessary for security purposes such as investigating abuse, or to comply with applicable law.
We do not use Google user data to develop, improve or train generalised or non-personalised artificial intelligence or machine learning models.
3. Replies, and how we handle them without inbox access
Messages sent through Lead Commander carry a Reply-To address at
leadcmdr.com containing a token identifying the conversation. When a
recipient replies, the reply is delivered to us at that address. We record it against the
correct lead and forward it to the agent's own inbox.
We therefore hold the content of replies that recipients send to that address. We hold them because they were addressed to us, not because we have any access to a connected mailbox. An agent who prefers not to have replies pass through us should not use the email features.
4. Other information we hold
- Account data — name, work email address, agency, role, and sign-in records for each user.
- Lead and customer records supplied by the agency or purchased through the platform: prospect name, postal address, telephone number, product interest, and, where the agent records them, date of birth and email address.
- Activity — dispositions, appointments, sales, mileage and route history recorded by agents in the course of their work.
- Operational logs needed to run and secure the service.
Prospect and customer records belong to the agency that holds them. We process them on the agency's behalf. If you are a consumer whose details appear in an agency's book and you want them corrected or removed, contact the agency you dealt with; if you cannot identify it, write to us and we will route your request.
5. Who can see what
An agent's email conversations are private to that agent. Agency administrators can see their agency's leads, production and activity, but cannot read their agents' correspondence. Agencies cannot see one another's data.
6. Where data is held
Lead Commander runs on Cloudflare infrastructure (Workers, D1 and R2). Data is processed in the United States. We use Google's APIs to send mail on your instruction. We do not sell data to anyone, and we do not share it with advertising networks or data brokers.
7. Retention
- OAuth tokens are deleted immediately when you disconnect the mailbox, and are in any case invalidated when you revoke access at your Google Account.
- Messages and replies are retained on the customer record for as long as the agency's account is active, and are deleted within 90 days of account closure.
- Lead and customer records are retained for as long as the agency requires them, and deleted on the agency's instruction or within 90 days of account closure.
8. How to disconnect or revoke
- In Lead Commander: open My Email and choose Disconnect. The stored tokens are deleted.
- At Google, at any time: myaccount.google.com/permissions → select Lead Commander → Remove access.
- To request deletion of your Lead Commander account and the data associated with it, email support@leadcmdr.com. We respond within 30 days.
9. Security
Access to production data is restricted to personnel who need it to operate the service. Traffic is encrypted in transit. We request the narrowest Google scope that does the job — which is why this application can send mail but can never read it.
10. Children
Lead Commander is not directed to anyone under 18 and we do not knowingly collect data from children.
11. Changes
If we change this policy we will update the date below. Material changes affecting how Google user data is handled will be notified to account holders by email before they take effect.
12. Contact
The Meliora Group LLC, trading as Agency Development Services — Ohio, United States.
support@leadcmdr.com