Privacy Policy
Last updated September 7, 2026
Relay connects Meta Lead Ads accounts to instant SMS notifications the moment a new lead comes in. This policy explains what information we collect, how we use it, and the choices you have, whether you're the business running the ads, or someone designated to receive lead alerts on their behalf.
Who this applies to
Three different people interact with Relay, and this policy covers all of them: account owners (the business that signs up and connects Meta ad accounts), notify contacts (whoever's phone number is set to receive lead alerts for a given Page (often the account owner themselves, sometimes a teammate or client), and who can text the assistant to check their own lead count), and leads (people who fill out a Meta Lead Ads form; their information passes through our systems so the relevant notify contact can be notified, but they never log in or interact with Relay directly).
Information we collect
Account information: business name, owner name, owner email and phone number, password (stored as a one-way hash; we never store or have access to the plain-text password), default country, and time zone.
Billing information: if you're on a paid subscription, our payment processor, Stripe, collects and holds your name, billing address, and payment method details in order to charge your subscription. We never see or store your full card number. Only Stripe does, under its own PCI-compliant systems. On our side, we keep only your subscription plan and billing status.
Notify contact information: the business/Page name for each connected Meta ad account, and the phone number designated to receive lead alerts for that Page.
Lead information: when someone submits a Meta Lead Ads form, we receive whatever fields that form collects (typically name, phone number, and email) directly from Meta, using the account owner's own connected access token. We use this only to notify the relevant notify contact; the lead is never texted or contacted by Relay itself.
Message content: the text of SMS messages we send (lead alerts, reminders, AI assistant replies) and receive (replies to the AI assistant), along with delivery status and timestamps.
Consent and technical records: to comply with Canada's Anti-Spam Legislation (CASL), we keep a record of consent for every phone number we send to, including the IP address the number was registered from. Since that number is usually entered by someone else (a business owner adding a client or team member's number), we also text the number itself a one-time confirmation request before sending anything further. Reminders, lead alerts, or any assistant message only begin once that number's own owner replies YES.
How we use information
- To deliver lead-alert text messages the moment a connected form gets a submission.
- To power the optional AI assistant: account owners can text it to create, edit, or delete personal reminders, or check lead counts; notify contacts can text it to check their own lead count only.
- To register and maintain CASL consent records for every number we message.
- To operate account login, the dashboard, and customer support.
- To detect, prevent, and investigate fraud, abuse, or security issues.
Data isolation between notify contacts
Each notify contact's leads, message history, and AI assistant conversation are scoped strictly to their own registered phone number. One notify contact's data is never visible to another's, and this is enforced in how our system queries data, not left to chance.
Who we share information with
- Our SMS provider, to deliver text messages and maintain CASL consent records. They receive the phone number and message content necessary to send each text.
- Our AI provider (Google), when the AI assistant is used. The content of that conversation is sent to Google's API to generate a response.
- Our payment processor (Stripe), for paid subscriptions. They receive your name, email, billing address, and payment method details necessary to process your subscription.
- Infrastructure providers that host our application and database, under standard hosting agreements.
- We do not sell personal information, and we do not share it with anyone for their own marketing purposes.
Data retention
We keep account, lead, and message data for as long as the account is active, so the dashboard's lead log and AI assistant conversation history stay useful. Records of individual delivery and billing events from our SMS and payment providers are automatically deleted after 30 days. They're used to process messages and subscription changes as they happen, and only need to be kept briefly afterward for troubleshooting. If you want your account or data deleted, contact us at info@relaylead.ca and we'll take care of it.
Security
Sensitive credentials (Meta access tokens) are encrypted at rest. Passwords are hashed, never stored in plain text. All traffic to Relay is encrypted in transit. No system is perfectly secure, but we design with the assumption that a breach anywhere shouldn't expose more than it has to, including scoping every notify contact's data so it can never leak sideways to another one.
Your choices
- Any phone number can opt out of receiving texts at any time by replying STOP, as required under CASL.
- Account owners can access or correct their information from the Settings page at any time.
- To request access to, correction of, or deletion of your information (including if you're a lead whose information passed through Relay), contact the business that used Relay to reach you, or email us directly at info@relaylead.ca.
Children's privacy
Relay is intended for business use and is not directed at children. We don't knowingly collect information from anyone under 16.
Changes to this policy
If we make material changes to this policy, we'll update the date at the top of this page. Continued use of Relay after a change means you accept the updated policy.
Contact us
Questions about this policy or how your information is handled? Email us at info@relaylead.ca.