Privacy Policy

What passes through GhostReach, why, and who else touches it. The important part is clause 2: your account data and your lead data have different owners, and that changes who answers for what.

Last updated 20 September 2026

1.Scope

This policy covers GhostReach, a sole proprietorship established in Bangladesh operated by Md Aman Ullah Aman of Palsha, Sarkerpara, Bogura 5800, Bangladesh. Because a sole proprietorship is not a separate legal person, the data controller for your account data is that individual. Below: what personal data passes through the service, why, who else handles it, and what you can ask us to do about it.

2.Two kinds of personal data, with two different owners

This distinction runs through everything below, so it comes first.

  • Your account data — your name, email address, workspace settings, billing records. We decide how this is used, so we are the controller and this policy governs it.
  • Your lead data — the people you choose to contact, and the messages you exchange with them. You decide who they are and what you say. You are the controller; we are your processor and act on your instructions.

Because you are the controller of your lead data, you are responsible for having a lawful basis to contact those people, and for answering their privacy requests. If one of them asks us directly, we will refer them to you and help you respond.

3.What we collect about you

  • Account — email address and a hashed password, or your identity provider’s token. We never store a readable password.
  • Workspace — the names of your workspaces, campaigns, templates and settings, and which team members belong to which.
  • People you invite — the email address and role of each teammate or client you invite, and when they joined.
  • Branding — on white-label plans, the product name, logo, icon, colour theme and custom domain you set.
  • Email preferences — which alerts and summaries you want, and at what hour.
  • Connected accounts — the LinkedIn identities and Sales Navigator contracts you connect, and the session credentials needed to act on them. These are held server-side and are never exposed to your browser.
  • Billing — your plan, seat count, invoice history, account balance and billing email. We take no card details: payments are made to us directly and recorded by hand.
  • Operational logs — what the service did and when: sends, errors, sync results. These make the product debuggable and are what tells you why something did not send.

4.What passes through about your leads

Whatever you upload or collect: name, job title, employer, LinkedIn profile URL, and where you provide it, email address and phone number. Alongside that we store the messages sent and received, the state of each conversation, and the connection requests you send.

We keep a copy of every conversation, so its history stays available even after LinkedIn removes it — for example when a Sales Navigator contract is replaced. It is deleted when you delete it, or when your account is closed (see “How long we keep it”).

To choose between InMail and a connection request, a campaign may check whether a lead’s profile is an Open Profile. That check sends the lead’s public LinkedIn profile address to one of the lookup providers listed below, and nothing else.

Where you switch on lead monitoring, we periodically re-read a lead’s public LinkedIn profile to detect a change of job, title or employer, and store enough of a snapshot to tell that a change happened.

5.Your clients, if you invite them

On plans with the client portal you can invite your own clients to a workspace. A client sees that workspace’s results: campaign figures, and the names and replies of the people who answered. Inviting them is sharing that lead data with them, and it is your decision, made as the controller of that data.

Clients cannot read or change anything else. We hold their email address to let them sign in, and send them only their invitation and each campaign’s final report.

6.Email we send

  • Always — sign-up confirmation, password resets, invitations, invoices and renewal warnings. These are part of running your account.
  • Only while you want them — alerts about replies and problems, the daily summary, and each campaign’s final report. Each person turns these on or off for themselves in Settings.

On white-label plans these emails carry the workspace’s own name and logo. They are still sent by us, from our address.

7.Why we are allowed to process it

  • To perform our contract with you — running your account, sending what you tell it to send, taking payment.
  • Our legitimate interests — keeping the service secure, preventing abuse, and understanding aggregate usage so we can improve it.
  • Legal obligation — keeping tax and accounting records.

For lead data we process on your documented instructions as your processor, and your own lawful basis is the one that matters.

8.Artificial intelligence

The service uses Anthropic’s models for two jobs: classifying whether an incoming reply is positive, and drafting a suggested response for you to review.

  • Only the message text needed for that request is sent.
  • Your data is not used to train models.
  • Drafts are suggestions. Nothing is sent to a lead automatically unless you have explicitly enabled that, and it is off by default.

9.Who else handles it

We use the providers below and no others. We do not sell personal data, and we do not share it for advertising.

ProviderWhat forWhere
UnipileConnects your LinkedIn and Sales Navigator accounts and carries every message, invitation and profile lookup you send through them.European Union
SupabaseThe database, the sign-in system and file storage. Holds your workspaces, campaigns, leads, the full history of your conversations, settings, and the logos and icons you upload.European Union
ResendDelivers email: sign-up confirmation, password resets, team and client invitations, alerts, daily summaries, campaign reports, renewal warnings and invoices. Receives the recipient's address and the message itself, nothing else.United States
VercelHosts and serves the application, and the custom domains white-label workspaces connect for their client portal, including their certificates.Global edge network
AnthropicClassifies replies and drafts suggested responses. Only the message text needed for that request is sent, and it is not used to train models.United States
HarvestAPITells whether a lead's LinkedIn profile is an Open Profile, so a campaign can choose InMail or a connection request. Receives the lead's public LinkedIn profile address only.Not published by the provider
ApifyThe same Open Profile check as HarvestAPI, used when it does not answer. Receives the lead's public LinkedIn profile address only.European Union
ScrapingdogReads a lead's public LinkedIn profile to convert and enrich lists, where you use the profile converter. Receives the profile address only.India

We will update this page before adding a provider that handles customer data, and will email workspace owners if the change is material.

10.International transfers

Some providers above are outside the UK and EEA. Where data moves there we rely on the UK International Data Transfer Agreement and the EU Standard Contractual Clauses, and we keep the database itself in the European Union.

11.How long we keep it

  • While your account is open — your data stays available so the product works.
  • After you close it — 30 days, so an accidental cancellation can be undone, then deleted. Ask and we will delete immediately.
  • Billing records — kept as long as tax law requires, typically six years. These are invoices, not lead data.
  • Operational logs — 90 days.

You can delete a lead, a list or an entire campaign yourself at any time, and it goes immediately.

12.Security

  • Encrypted in transit and at rest.
  • Every table is scoped to a workspace by database row-level security, so one customer’s query cannot return another customer’s rows even if the application has a bug.
  • LinkedIn session credentials are written and read server-side only. They are never sent to a browser.
  • Staff access to customer data is limited to support and is recorded in an audit log.

No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant regulator within the time the law requires.

13.Cookies

GhostReach sets only what it needs to work: a session cookie that keeps you signed in, and a cookie remembering which workspace you were last looking at. Your browser also keeps, on your own device, when you last saw new activity, so the pop-ups only show what is new. There is no advertising or cross-site tracking, and so there is no consent banner to dismiss.

14.Your rights

Depending on where you live you may have the right to access, correct, delete, port or restrict your personal data, to object to processing, and to withdraw consent. To exercise any of them, email [email protected].

We answer within 30 days. We will not charge you or treat you differently for asking. If you are in the UK or EEA and are unhappy with our answer, you may complain to your data protection authority.

15.Children

The service is for business use and is not directed at anyone under 18. We do not knowingly collect data about children, and will delete it if we learn we have.

16.Changes

We will update this page when our processing changes, and email workspace owners when the change is material. The date at the top shows the current version. See also the Terms of Service.

17.Contact

Privacy questions, and data requests:

EntityGhostReach
ProprietorMd Aman Ullah Aman
AddressPalsha, Sarkerpara, Bogura 5800, Bangladesh
RegistrationTrade licence application pending