Legal

Privacy Notice

What this Service collects, what it does not collect, and what happens when a HubSpot account disconnects. This notice applies specifically to the IV-LEAD Email Signatures public generator and HubSpot app. It sits alongside the IV-Lead Privacy Policy; where the two differ for this Service, this notice governs.

Last updated: 31 August 2026

The short version

  • The public generator creates the signature in your browser. The signature fields you type and the rendered signature HTML are not transmitted to IV-LEAD.
  • When an organisation connects HubSpot, IV-LEAD stores the limited account, brand, security, and rollout records described below. Team Health reads roster names and work email addresses from HubSpot when needed for display, but does not persist those roster fields in the application database.
  • The app requests one read-only HubSpot scope, settings.users.read, plus the baseline access HubSpot grants every app. It cannot read contacts, companies, deals, or mailboxes, and it cannot change HubSpot data or settings.
  • IV-LEAD does not insert tracking pixels or use generated signatures to measure opens, clicks, or recipients. Remote images can still cause ordinary request metadata to reach the relevant image host when an email client loads them.
  • IV-LEAD does not sell personal data or use it for advertising, behavioural profiling, or automated decision-making.

1. Who we are

The Service is provided by Chen Yehoshua, trading as IV-Lead (איי וי ליד), an Israeli licensed sole proprietor (עוסק מורשה), business number 037107026, of Rothschild Blvd 25, Tel Aviv, Israel ("IV-Lead", "we", "us").

IV-Lead is a trade name, not a separate company. The legal person providing the Service is Chen Yehoshua. Our controller and processor roles for different categories of data are explained in section 2.

We have not appointed a Data Protection Officer. Privacy questions, rights requests, and complaints can be sent to support@iv-lead.com.

2. Our roles: controller and processor

The role depends on why the data is processed:

  • For the connected organisation's HubSpot roster, brand kit, and per-user rollout status, the HubSpot account holder determines the purpose of the processing and acts as controller. IV-Lead processes that data on its documented instructions as processor, subject to the Data Processing Addendum.
  • For IV-Lead's own service administration, terms-acceptance evidence, security audit records, infrastructure security, support correspondence, and legal compliance, IV-Lead acts as controller.

If you are an employee or contractor of a connected organisation and want to exercise a right concerning its roster or rollout data, contact that organisation's HubSpot administrator first. IV-Lead will assist the organisation as required and will handle any data for which IV-Lead is controller directly.

3. Using the public generator without connecting HubSpot

The generator assembles the signature locally in your browser and copies the result to your clipboard. The application does not transmit the signature fields you type or the rendered signature HTML to IV-Lead, and it creates no IV-Lead account for you.

The acceptance control presented before copying a signature is evaluated in the browser and is not sent to IV-Lead. The interface font is served from IV-Lead's own hosting and does not contact Google Fonts.

As with any website, Cloudflare may process ordinary request and security metadata, such as an IP address, browser user-agent, requested path, and timestamp. IV-Lead does not use that metadata for advertising or to build behavioural profiles.

4. Data handled when a HubSpot account connects

The following table describes the principal records used by the connected app.

DataPurpose
Encrypted HubSpot access and refresh tokens, the granted scope list, and the HubSpot user ID of the installerMaintain the connection and make the permitted roster requests
HubSpot account ID, connection status, language, and connection timestampsIdentify the connected account and its current state
Company brand kit - company name, website, LinkedIn URL, English and Hebrew postal addresses, two brand colours, default template, and permitted social networksApply one company standard across the team
Per-user rollout record - HubSpot user ID, language, template, renderer version, generated or confirmed state, target email client, confirmation time, and whether a test email was self-confirmedShow rollout progress and support troubleshooting
Terms acceptance record for the connected app - HubSpot account ID, HubSpot user ID, document versions or content hashes, and acceptance timestampRecord the organisation's and user's acceptance of the exact legal terms presented
Security audit log - account and user identifiers, action, target, success or failure, reason code where applicable, and timestampSecurity, troubleshooting, abuse investigation, and legal compliance
Short-lived security records - hashed OAuth state valid for 20 minutes and hashed builder launch tokens valid for 5 minutes and single-usePrevent request forgery and link hijacking

To complete a connection and launch the builder, the app also uses a signed connection-receipt cookie valid for 5 minutes and a signed generator-session token valid for 10 minutes. These are security credentials, not advertising identifiers.

When Team Health is opened, the app reads names and work email addresses from HubSpot to render the roster for an authorised super admin and to calculate aggregate rollout totals. Those roster fields are processed in memory and are not written to the IV-Lead application database.

5. What we do not store or access

  • No signature content persisted by the application. The app does not save names, job titles, phone numbers, email addresses, photo URLs, social links, credential badges, meeting links, or other fields entered in the builder. Information that a person voluntarily includes in support correspondence is handled as support correspondence under section 12.
  • No rendered signature HTML persisted by the application.
  • No uploaded signature images. User photos, logos, and banners are referenced by URLs supplied by the user. Generated signatures may also reference contact-icon images supplied by IV-Lead and hosted on IV-Lead's HubSpot-hosted web assets.
  • No mailbox access. The app does not access, read, send, scan, or inspect messages or mailboxes.
  • No contact, company, or deal records. The app does not request the HubSpot scopes needed to retrieve those objects.
  • No tracking pixels. IV-Lead does not insert recipient-specific or message-specific tracking identifiers into the contact-icon URLs and does not use them to measure opens, clicks, or recipients.
  • No persisted roster names or work email addresses. Stored rollout records use HubSpot's internal user ID.
  • No analytics, advertising, session-recording, or in-app customer-messaging tools.

6. Remote images in generated signatures

A generated signature can contain remote images: images hosted at URLs supplied by the user and shared contact-icon files hosted for IV-Lead. When a recipient's email client loads a remote image, the relevant image host may receive ordinary request metadata such as the recipient's IP address, user-agent, timestamp, and requested file. Some email clients block or proxy remote images.

IV-Lead's contact-icon URLs are shared static asset URLs and are not unique to an account, user, message, or recipient. IV-Lead does not use image requests to identify recipients or measure engagement. The organisation or user supplying another image URL is responsible for the privacy and availability of that external host.

7. Why we process data and the applicable legal basis

For roster, brand-kit, and rollout data processed on behalf of a connected organisation, that organisation determines the legal basis and gives IV-Lead documented instructions. IV-Lead processes the data only to provide, secure, support, and terminate the connected app, as described in the Data Processing Addendum.

Where IV-Lead acts as controller, the purposes and bases are:

  • Providing and administering the Service - performance of the Terms and IV-Lead's legitimate interest in operating the Service requested by the user or organisation.
  • Recording acceptance of the Terms - performance and administration of the contract and IV-Lead's legitimate interest in retaining proportionate evidence of acceptance.
  • Security, fraud prevention, and troubleshooting - IV-Lead's legitimate interest in protecting the Service, connected accounts, users, and IV-Lead.
  • Support and privacy correspondence - performance of the Terms, IV-Lead's legitimate interest in supporting users, and compliance with legal obligations.
  • Legal compliance and claims - compliance with law and IV-Lead's legitimate interest in establishing, exercising, or defending legal claims.

IV-Lead does not rely on consent for these core activities. Disconnecting stops future HubSpot access but does not replace the rights described in section 15.

For the purposes of Israel's Privacy Protection Law, the data described in this notice is collected and used only for the stated Service, security, support, contractual, and legal purposes and is handled through the providers identified in section 10.

8. The HubSpot permission we request

The app requests one read-only HubSpot scope: view users and their permissions (settings.users.read). It is used to retrieve the account roster, verify that a caller belongs to the connected account, and verify super-admin status before individual Team Health data, brand-kit changes, or disconnection are permitted.

The scope does not allow the app to change users or settings, and it does not grant access to contacts, companies, deals, marketing email, one-to-one email, or mailboxes. HubSpot displays the requested permission before the installing user approves the connection. The app manifest also declares HubSpot's baseline oauth scope, which every HubSpot app is granted and which confers no access to data.

9. Strictly necessary cookie and browser credentials

  • Connection-receipt cookie: signed, restricted to the connected page, and valid for 5 minutes.
  • Generator-session token: signed, held in browser memory, and valid for 10 minutes.

These credentials are used only for security and navigation. The Service does not use analytics or advertising cookies.

10. Providers, external services, and international handling

  • Cloudflare, Inc. - application hosting, database, request handling, security observability, and point-in-time database recovery. The application uses Cloudflare infrastructure and requests may be routed through Cloudflare's global network.
  • HubSpot, Inc. - OAuth authentication, the user-roster API, and delivery of IV-Lead-owned contact-icon files hosted in IV-Lead's HubSpot web assets.
  • Google LLC - Google Workspace for support and privacy email. Google is not used to deliver the application's font.

IV-Lead is established in Israel, which the European Commission recognises as providing an adequate level of data protection. Providers may process data in additional countries. Where an applicable transfer requires safeguards, IV-Lead relies on the transfer terms and safeguards in the relevant provider agreement, including the European Commission's Standard Contractual Clauses where applicable.

This list reflects the providers and external services used for the Service as of the date above. Changes involving a processor are handled under the Data Processing Addendum.

11. Team Signature Health visibility

Individual Team Health information is limited to a verified HubSpot super admin of the connected account. A super admin can see each roster member's work name, work email address, language, template, and whether the person marked a signature as generated or confirmed as installed. Other verified account users can see aggregate rollout totals only, without names, email addresses, or individual status.

  • The status is self-reported. The app cannot inspect a mailbox and does not claim that a signature is actually in use.
  • No user can see another person's signature content or the personal fields typed into the builder.
  • The purpose is to coordinate a company signature rollout. It is not attendance or productivity monitoring and should not be used as such.
  • The app presents a short notice before a user first records a rollout status. The connected organisation remains responsible for providing any employee notice required by its law, policies, or employment arrangements.

12. Retention

DataRetention
OAuth sign-in stateUsable for 20 minutes. The stored value is hashed and the expired row is removed by the security cleanup within 24 hours.
Builder launch tokenUsable for 5 minutes and single-use. The stored value is hashed and the expired row is removed by the security cleanup within 24 hours.
Connection-receipt cookie5 minutes.
Generator-session token10 minutes in browser memory; not persisted as a reusable raw token in the application database.
Encrypted HubSpot OAuth tokensFor as long as the app is connected. Usable credentials are destroyed on disconnect.
Account record, brand kit, and rollout recordsWhile connected and for no more than 30 days after disconnect, unless erased sooner on a verified request or retained where law requires.
Minimal connected-app terms-acceptance recordUp to 7 years after the later of acceptance or termination, solely to administer the agreement and establish, exercise, or defend legal claims, unless applicable law requires a different period.
Security audit logUp to 12 months from creation and, after disconnect, no later than 90 days after disconnect, unless a longer period is reasonably required to investigate a specific incident, prevent abuse, or establish or defend a legal claim.
Support and privacy correspondenceUp to 24 months after the last substantive contact, unless a longer period is required by law or for an active dispute.
Cloudflare request and security metadataAccording to the active Cloudflare service configuration and provider limits. IV-Lead does not export it into a separate analytics or advertising system.

Cloudflare's current Workers Free database service provides point-in-time recovery covering a rolling 7-day period. After live-database deletion, earlier copies may therefore remain in recovery history for up to a further 7 days before ageing out. IV-Lead keeps no separate application-database backup outside Cloudflare.

13. Disconnecting and deletion

A HubSpot super admin can disconnect the app from its Settings page. On disconnect:

  • the stored refresh token is overwritten and the access token is deleted;
  • IV-Lead requests token revocation from HubSpot;
  • future access to the HubSpot account is blocked; and
  • the account is placed into the deletion workflow described in section 12.

To request earlier deletion of remaining live-database records, email support@iv-lead.com. IV-Lead will verify the request, remove the records it controls, and confirm completion. Recovery copies then age out within the rolling 7-day period described above.

14. Security

  • HubSpot OAuth tokens are encrypted before storage using authenticated encryption.
  • The application does not intentionally write OAuth token values, signature fields, or rendered signature HTML to its own logs.
  • Traffic uses HTTPS.
  • OAuth state and builder launch tokens are stored hashed, expire in minutes, and launch tokens are single-use.
  • The signature preview runs in a sandboxed frame.
  • Customer data is isolated by the account taken from a verified session rather than from browser-supplied account input.
  • Automated tests cover tenant isolation, including a simulated cross-tenant replay attempt.

No system is perfectly secure. Suspected vulnerabilities or incidents should be reported to support@iv-lead.com.

15. Your rights and privacy complaints

Depending on the law that applies, you may have rights to access, correct, export, erase, object to, or restrict processing of personal data, and rights concerning solely automated decisions. IV-Lead makes no solely automated decisions about individuals.

Send a request or complaint to support@iv-lead.com. IV-Lead may ask for information reasonably needed to verify identity and authority.

IV-Lead will respond without undue delay. Where EU or UK data-protection rules apply, IV-Lead will normally respond to a rights request within one month and will explain within that first month if a lawful extension is required. IV-Lead does not charge for ordinary rights requests.

For a data-protection complaint, IV-Lead will acknowledge receipt within 30 days, investigate appropriately, keep the complainant informed where needed, and communicate the outcome without undue delay.

If you are in the EEA or UK and remain dissatisfied, you may complain to the relevant supervisory authority. In Israel, you may contact the Privacy Protection Authority.

16. Children

The Service is designed for business and professional use. It is not directed at children, and IV-Lead does not knowingly collect personal data from children through the Service. If you believe a child has provided personal data to IV-Lead, contact support@iv-lead.com.

17. Changes to this notice

If the Service's data practices change, IV-Lead will update this notice and the date above. Where a material change affects connected accounts, IV-Lead will also provide notice through the Service, the associated HubSpot account contact route, or another reasonable channel before the change takes effect where practicable.

18. Contact

Privacy questions, requests, and complaints: support@iv-lead.com.