LeadPass

Cookie Policy

Operator: Jose Ramon Leon Rodriguez, a sole trader (jednoosobowa działalność gospodarcza) established in Poland, registered office: Egipska 5/69, 03-977 Warszawa, Poland, NIP: 8992886524, EU VAT: PL8992886524, REGON: 387147849, entered in CEIDG (Centralna Ewidencja i Informacja o Działalności Gospodarczej), contact: legal [at] useleadpass.com (the "Operator", "we").

Last updated: 27 July 2026


1. What this policy covers

This Cookie Policy explains what cookies and similar technologies are used when you visit or use LeadPass (the "Service"), including:

It applies to everyone who loads a LeadPass page in a browser — Customers, Client Users, Leads and casual visitors alike. For details on how we handle personal data more broadly, see our Privacy Policy.

2. What cookies are

Cookies are small text files that a website places in your browser. They let the site remember something between page loads — for example, that you are signed in, or that a form you submitted really came from you. Cookies set by the site you are visiting are "first-party"; cookies set by another domain are "third-party".

3. The cookies we set

We keep our own cookies deliberately minimal. LeadPass sets the following first-party cookies:

Cookie Set by Purpose Duration Category
leadpass-session LeadPass (first-party) Maintains your session: keeping signed-in users authenticated, remembering the identifier of a Lead's in-progress response so an interrupted flow can resume, remembering a visitor's chosen site language, and general security state. The cookie itself contains only encrypted session data; the associated application records are stored on our servers. Expires after 120 minutes of inactivity Strictly necessary
XSRF-TOKEN LeadPass (first-party) Protects forms and in-app actions against cross-site request forgery (CSRF) attacks. Same as the session (120 minutes) Strictly necessary
remember_web_* LeadPass (first-party) Set only if you tick the "Remember me" box when logging in, so you stay signed in across browser sessions. Never set for Leads or visitors who do not log in. Long-lived (framework default; modern browsers cap the effective lifetime at around 400 days) Functional — set at your explicit request

A few honest clarifications:

4. What we do NOT use

As of the date of this policy, LeadPass does not set or operate any of the following:

If a Lead arrives at a public flow page through a link containing marketing parameters (such as utm_source or click identifiers), those parameters are read from the URL and stored with the Lead record for the Customer's reporting. That is not a cookie and does not involve tracking you across sites.

On flows where the operating business has enabled Meta conversion measurement, the application does not store Meta's click identifiers, does not use them for the measurement, and the web server's access logs do not record URL query parameters. The measurement itself — described in the LeadPass Privacy Policy (Section 4.8) for LeadPass's own flows, or in the flow's Lead Privacy Notice for a Customer's flow — is consent-based and uses a cryptographic hash of the email address the Lead types as its only matching key; it sets no cookie and loads no script.

If an automatic-Pass result shows the Customer's configured next-step button, LeadPass can also record the first time the Lead explicitly submits that button. Other result buttons and manually approved Passes are not measured, including when the Lead reached the result screen through an approval email. This is a server-side event attached to that response, not a cookie or browser-storage technology; it does not observe the destination, and the Lead Privacy Notice shown before the response explains it.

5. Third-party services

The third party involved depends on the page and feature being used:

  1. Cloudflare Turnstile (bot protection) — loaded on public flow pages and the registration page when Turnstile is enabled. It processes technical signals such as IP address, browser, device and network/TLS characteristics to assess whether a request is automated. Cloudflare may use cookies or similar storage where technically required by its security service; LeadPass does not use Turnstile for advertising or analytics.
  2. Cloudflare (network delivery and security) — traffic to the deployed Service is routed through Cloudflare, which terminates the public TLS connection and processes request and response traffic to deliver and protect the Service. Depending on the security feature applied to a request, Cloudflare may set a security cookie or use a comparable technology. Cloudflare's current documentation is the source for provider-controlled names, purposes and lifetimes.
  3. Stripe.js and Stripe Elements (payment and billing pages) — loaded only where a user requests subscription, payment-method or billing functionality. Payment credentials are entered directly in Stripe Elements. Stripe may use cookies, local storage and browser/device/network signals for payment delivery, authentication and fraud prevention. These technologies are governed by Stripe's privacy and cookie information and are not used by LeadPass for advertising.

A third party may change the exact name or lifetime of a technology it controls; its current documentation is authoritative for those provider-controlled details.

6. Why LeadPass currently shows no cookie banner

Under Article 5(3) of the ePrivacy Directive (2002/58/EC) and Article 399(3) of the Polish Electronic Communications Law (ustawa z dnia 12 lipca 2024 r. — Prawo komunikacji elektronicznej), consent is not required for cookies that are strictly necessary to deliver a service the user has explicitly requested.

The first-party cookies listed in Section 3 are used to provide or secure functionality requested by the user:

LeadPass does not operate a general consent banner. The only non-essential advertising operation it performs — the Meta ad-conversion reporting described in the Privacy Policy, Section 4.8 — is limited to the flows where that measurement is enabled, and asks for your consent inline on those flows' start screens before any measurement takes place; that consent also covers, to the extent applicable, the ePrivacy consent requirement for any terminal-equipment storage or access involved in ad attribution. LeadPass does not install or read advertising cookies, does not use localStorage or sessionStorage, and does not load Meta pixels or scripts. The storage-access technologies used by LeadPass, Cloudflare/Turnstile and Stripe for the session, security, registration and payment functions are described above. If LeadPass introduces any other purpose requiring prior consent under these rules, it will require an appropriate consent mechanism and an update to this policy.

7. Managing cookies in your browser

You can view, block and delete cookies through your browser settings. Every major browser lets you:

Consult your browser's help pages for instructions (look for "cookies" in the settings of Chrome, Firefox, Safari, Edge or your browser of choice).

Please note: blocking the session, CSRF or security technologies may prevent you from signing in, submitting protected forms or completing a voice flow. Blocking Stripe technologies may prevent payment and billing forms from working. The marketing pages may remain readable without these functions.

8. Changes to this policy

We may update this Cookie Policy from time to time — for example, if we change the cookies the Service uses or if the law changes. When we do, we will update the "Last updated" date above. If a change introduces new categories of cookies or otherwise materially affects you, we will inform users through the Service or by email before the change takes effect.

9. Contact

Questions about this Cookie Policy or our use of cookies: legal [at] useleadpass.com.

If you are a Lead and have questions about how the business that invited you to a flow handles your data, please contact that business directly — it is the controller of your Lead data, as explained in the Privacy Policy.