Privacy Policy
Last updated: 15 July 2026
Pipeline Signals is a product of CatchLead Ltd ("CatchLead", "we", "us"), a limited company registered in England and Wales. Pipeline Signals provides advertising attribution and conversion-measurement software for businesses and marketing agencies using the HighLevel platform. This policy explains what we process, why, and your rights.
Who we are
The data controller/processor for the service is CatchLead Ltd, a limited company registered in England and Wales (company number 17079928, registered office: 124 City Road, London, EC1V 2NX, United Kingdom), trading as Pipeline Signals. Contact: privacy@pipelinesignals.io.
Two roles: controller and processor
For data about our own customers (agency account holders, billing, support), we act as a data controller. For data about our customers' leads and contacts processed through the product, we act as a data processor on the documented instructions of the business that installed the app — that business is the controller. A Data Processing Agreement is available on request.
What we process as a processor
- Ad click identifiers (e.g. fbclid, gclid, wbraid, gbraid, ttclid, msclkid) and UTM parameters captured on our customers' marketing pages.
- Hashed contact identifiers: email addresses and phone numbers are normalized and SHA-256 hashed before storage. We do not store raw emails or phone numbers in our attribution database.
- CRM pipeline events: stage names, deal values and timestamps from the customer's HighLevel account.
- Consent state supplied by the controller, which we forward with every event.
Where it goes
On the controller's instruction, we transmit conversion events (hashed identifiers, click IDs, event names and values) to the advertising platforms the controller has connected: Meta Platforms, Google, and/or TikTok, under those platforms' data terms. We support platform mechanisms for restricted processing (e.g. Meta Limited Data Use, Google consent signals).
Google user data
When a customer connects a Google Ads account to Pipeline Signals via Google sign-in, we receive and process the following Google user data: the list of Google Ads accounts the signed-in user can access (account IDs and names, used solely so the customer can choose a destination account), the conversion actions of the selected account (which we list and create so conversion events have a destination), and OAuth tokens authorising these operations.
Sharing, transfer and disclosure: we do not sell Google user data, and we do not share, transfer, or disclose it to any third party, with these narrow exceptions: (1) our hosting sub-processor (Railway, listed below), on whose infrastructure the data is processed and stored encrypted; (2) Google itself, when delivering the customer's own conversion events to the Google Ads account the customer selected; and (3) where disclosure is required by law. No Google user data is used for advertising by us, shared with data brokers, or used to build profiles.
Storage, retention and deletion: OAuth tokens are encrypted at rest (AES-256-GCM) and deleted immediately when the customer disconnects Google or uninstalls the app. Account and conversion-action metadata is deleted with the connection. Customers may also request deletion at any time via hello@pipelinesignals.io.
Pipeline Signals' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Sub-processors
Cloudflare (network/CDN), Railway (application hosting and database), and the ad platforms named above when instructed. A current list is available on request.
Cookies and the capture script
Our capture script stores ad click identifiers in first-party storage (a cookie and localStorage) on our customers' websites for up to 90 days, solely for attribution. It sets no third-party cookies and does no cross-site tracking. Obtaining any legally required consent for this storage is the responsibility of the website operator (the controller), and our script can be loaded conditionally on consent.
Retention
Attribution records are retained while the customer's subscription is active and deleted within 90 days of uninstall or on verified request. Event delivery logs are retained for 13 months for troubleshooting and audit.
Security
Data in transit is encrypted with TLS. Credentials and API tokens are encrypted at rest with AES-256-GCM. Access is limited to personnel who need it to operate the service.
Your rights
If you are a lead or contact of one of our customers, please direct requests (access, deletion, objection) to that business; we will assist them as processor. If you are our direct customer, contact us at the address above. UK/EU residents may lodge complaints with their supervisory authority (in the UK, the ICO).
Changes
We will post updates to this page and note the revision date above.