Privacy Policy

Kumo Leads — Privacy Policy

Effective date: August 18, 2026

Last updated: August 18, 2026

1. Who we are and what this policy covers

Kumo Communications, LLC, doing business as Kumo Leads ("Kumo," "we," "us"), provides a customer relationship management and lead-routing platform for dealers, manufacturers, and their partners.

This policy covers:

  • kumoleads.com and our other public marketing pages;
  • the Kumo Leads application at app.kumoleads.com and its mobile clients;
  • Kumo Forms, the embeddable lead-capture form our customers place on their own websites; and
  • the Kumo Leads intake API and related integrations.

This policy does not cover our customers' own websites, their own privacy practices, or any other company that receives a lead through a routing arrangement its own operator configured.

2. Two different roles, and why the distinction matters

Kumo handles personal information in two distinct capacities, and your rights depend on which one applies.

As a business (controller), for our own data. Information about our customers' staff — the people who hold Kumo Leads accounts — and about visitors to our marketing site is information we collect and decide how to use. This policy governs it.

As a service provider (processor), for lead data. Information about consumers our customers put into the platform — the people who fill out a form, call a dealership, or are entered by a sales rep — is processed on our customers' instructions, on their behalf. We do not decide what to collect, who it gets routed to, or how long it is kept. Our customer does.

If you are a consumer whose information is in Kumo Leads because you contacted a dealer, the dealer is the business responsible for it. Contact them first. We will help them respond, and Section 10 explains what to do if you cannot reach them.

3. Information we collect

3.1 Account and user information

Collected when a customer's administrator creates an account or invites a user: name, business email address, the organization and location(s) a user belongs to, role and permissions, profile details the user chooses to add, notification preferences, and language preference.

Authentication is handled by our identity provider. If you sign in with a Microsoft work account, we receive your verified email address and basic directory profile from Microsoft. We never receive or store your password.

3.2 Billing information

Billing contact details, billing address (required for sales-tax calculation), plan, subscription quantities, invoices, and payment status.

We do not store payment card numbers. Card details are captured and stored by our payment processor, Stripe, and never traverse or persist in our systems.

3.3 Lead data submitted by our customers

Whatever the customer chooses to collect, which typically includes: first and last name, email address, phone number, postal address and ZIP code, business or company name, the product or service of interest, custom fields the customer defines, notes and call/interaction history recorded by their staff, tasks and appointments, uploaded files and their extracted contents, and order numbers and values.

3.4 Information collected by Kumo Forms

When a Kumo Form is embedded on a customer's website:

  • Nothing is collected until the visitor presses submit. Loading the page, loading the form, and loading form images collect nothing. There is no page-load beacon and no passive tracking. This was verified against the form worker's source code, not assumed.
  • On submission, along with the fields the visitor typed, the form records the visitor's IP address (for spam, fraud, and abuse prevention) and the browser's time zone (so the receiving business knows whether it is a reasonable hour to call).
  • IP address and time zone are personal information under California and most other state privacy laws, and they receive the same treatment as every other field on the record — the same disclosure, opt-out, and deletion handling.
  • Consent checkboxes are recorded as submitted, including the separate SMS consent checkbox where the customer has enabled it.

3.5 Usage, device, and log information

IP address, browser and device type, pages and features used, timestamps, and API request logs. Application errors are reported to our error-monitoring provider and may include the user identifier and request context associated with the error.

3.6 Audit records

The platform maintains a detailed audit log — who viewed, created, changed, assigned, shared, or deleted a record, and when. This exists so that disputes about lead ownership and access can be resolved, and so that privacy-related actions (such as a do-not-sell block or a file being sent for AI processing) have a verifiable trail.

4. How we use information

  • To provide, operate, secure, and support the platform.
  • To route and share leads according to the routing rules our customer configures, and to deliver notifications about them.
  • To run the AI file-processing feature described in Section 6.
  • To authenticate users and protect accounts.
  • To detect, investigate, and prevent fraud, spam, abuse, and security incidents.
  • To bill for the service and calculate applicable taxes.
  • To send service and transactional messages — assignment notifications, invitations, billing notices, security alerts, and product notices.
  • To produce aggregated or de-identified statistics about how the platform is used, in a form that does not identify any individual or customer.
  • To comply with law and enforce our agreements.

We do not use lead data to train machine-learning models, and we do not exchange lead data for monetary consideration. See Section 7 on what "sale" and "sharing" mean under state law, because routing is a subtler question than it first appears.

5. Categories of personal information — state-law disclosure table

Category (CCPA) Examples we handle Source Disclosed to
Identifiers Name, email, phone, postal address, IP address, account ID Consumer via form; our customer; our customer's staff Service providers; other businesses via customer-configured routing
Customer records Contact and address details, order number and value Consumer; customer's staff; uploaded files Service providers; routing recipients
Commercial information Products or services of interest, purchase/order history Consumer; customer's staff Service providers; routing recipients
Internet/network activity Log data, feature usage, request records Automatic Service providers
Geolocation (coarse) ZIP code, time zone, IP-derived region Consumer via form Service providers; routing recipients
Professional information Business name, job role of account users Our customer Service providers
Inferences Lead scoring or status classification Derived Service providers; routing recipients
Sensitive personal information Only where a customer uploads a document containing it — see Section 8.3 Our customer Service providers

We retain each category as described in Section 9.

6. AI processing of uploaded files

Customers can upload files to a lead — a receipt, invoice, quote, photo, or identity document. Where the customer has the feature enabled:

  • The file is sent to Anthropic, our AI sub-processor, to classify the document, extract structured fields (such as an order number or value), and flag whether it appears to contain personal information.
  • Anthropic does not train its models on data submitted through its API. Data may be retained for a limited period for trust-and-safety purposes.
  • Every transmission is written to the audit log as a distinct event, so there is a per-file record of what was sent and why.
  • AI output can be wrong. Extracted values are presented for a human to confirm; they are not treated as authoritative.

7. When information is shared with others

7.1 Sub-processors

We use a small set of vendors to run the service. The current list, with each vendor's purpose and the data it touches, is published at kumosoftware.com/sub-processors and forms part of this policy.

7.2 Lead routing between businesses

The platform's defining feature is that a lead can be routed from one business to another — for example, a manufacturer forwarding an inquiry to the dealer covering that ZIP code.

  • Routing happens only according to rules the sending organization configures. Kumo does not route leads on its own initiative and does not operate a lead exchange or marketplace.
  • Each business is independently responsible for the personal information it receives and for its own privacy disclosures.
  • A receiving business's private working data — its notes, its custom fields — is not visible to the sending business. The only thing that crosses back is a classification of whether the recipient already had a relationship with that consumer.

On "sale" and "sharing" under state law: we do not exchange personal information for money, and in our capacity as a service provider we do not “sell” or “share” personal information as those terms are defined under state privacy laws. Whether a particular routing arrangement constitutes a “sale” or “sharing” as between the sending and receiving businesses depends on the commercial terms between the two businesses, not on our software.

7.3 Do-not-sell and opt-out signals

The platform honors an opt-out from routing and sharing through three independent mechanisms:

  1. The Global Privacy Control browser signal, on any site running a Kumo Form.
  2. Shopify's Customer Privacy API, where a form runs on a Shopify storefront.
  3. A manual do-not-sell flag that can be set at intake or by staff.

When any of these is present, the lead is created but routing and sharing are blocked outright, before any territory matching occurs, and the block is recorded in the audit log. A blocked lead cannot be shared manually either.

7.4 Other disclosures

Legal process and lawful requests; enforcement of our agreements; protection of rights, safety, and security; and a merger, acquisition, or asset sale, in which case we will use reasonable efforts to provide notice before information becomes subject to a different privacy policy.

8. Sensitive information and things not to put in the platform

8.1 Consent for messaging

SMS consent is explicitly captured as a separate checkbox where our customer enables it, and the response is stored with the lead record.

Email consent is not separately captured. The only related record is the consumer's agreement to the customer's own terms and conditions at submission. Neither we nor our customers should describe email consent as separately collected, because it is not.

8.2 Responsibility for consent

Our customers are responsible for the lawfulness of the leads they collect and the messages they send — including TCPA, state mini-TCPA, do-not-call, and CAN-SPAM obligations, and for supplying the terms and privacy links that appear on their own forms.

8.3 Sensitive identifiers

The platform supports uploading identity documents. Where a customer does so, the resulting file may contain sensitive personal information such as a driver's license number. Customers must have a lawful basis for collecting it, and our agreement requires them to limit it to what they actually need. We process such information solely on the customers instructions we do not use it for any independent purpose.

9. How long we keep information

Data Retention
Account and user records For the subscription term, then 30 days after termination
Lead data Until the customer deletes it, or 90 days after termination, then deleted
Uploaded files With the lead record; deleted from object storage on deletion
Audit log 2 years — retained for dispute resolution and compliance evidence
Billing records 7 years, as required for tax and accounting
Backups Purged on a rolling 30-day cycle
Error monitoring 90 days, per Sentry's default retention

10. Your privacy rights

Residents of states with comprehensive privacy laws may have rights to access, correct, delete, and obtain a portable copy of their personal information, to opt out of sale, sharing, and targeted advertising, and to appeal a denial.

For lead data, contact the business you interacted with. They control it. If you do not know which business holds your information, or cannot reach them, write to us at privacy@kumosoftware.com and we will identify the customer and pass the request to them.

For account data, or for information we hold as a business, write to privacy@kumosoftware.com or use our support page.

We will verify your identity before acting, respond within the period the applicable law requires, and will not discriminate against you for exercising a right. An authorized agent may submit a request with proof of authorization.

Deletion requests are handled through an audited process. Where a lead has already been routed to another business, that business holds its own copy and must be contacted separately. We will identify recipients on request.

11. Cookies and similar technologies

The application uses cookies and local storage strictly for authentication, session management, and remembering user preferences. Kumo does not run analytics or advertising tracking pixels on kumoleads.com or within the application.

Kumo Forms sets no advertising or tracking cookies.

12. Security

We protect information with encryption in transit, network-level protection in front of our origin servers, hashed API credentials, per-organization access controls enforced on every read, role-based permissions, and comprehensive audit logging. No system is perfectly secure, and we cannot guarantee absolute security.

13. Children

The service is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child's information has been submitted, contact privacy@kumosoftware.com.

14. Where information is stored

The service is operated in the United States and is intended for U.S. businesses only. If you access it from elsewhere, your information will be transferred to and processed in the United States. We do not currently offer data residency outside the U.S.

15. Changes to this policy

We will post any change here with a new effective date, and will give advance notice of material changes by email or in-app notice 30 days before they take effect.

16. Contact

Kumo Communications, LLC
12927 Cynthia Lane, Clermont, FL 34715
privacy@kumosoftware.com · 1-833-227-9444