Permit Leads › Privacy
Privacy
Permit Leads is run by one person, Hadi Ghaddar, in metro Detroit. This page says what the software actually stores about you, who else it reaches, and what to do if you want it gone.
Last updated 16 August 2026.
What we collect
When you sign up: your email address, a password (stored only as an Argon2 hash — nobody here can read it, including us), your name, and optionally your company, phone number and ZIP code. You also choose the trades and the counties you want leads for.
We also keep a simplified copy of your email address and phone number — punctuation and Gmail dots removed. It exists for one purpose: to notice when the same person takes the free trial a second time. It is not used to contact you and is not shared.
While you use the site: a sign-in session, which is a random token stored in our database and set as a cookie in your browser. The cookie holds the token and nothing else — no name, no email. We store the browser's user-agent string with the session, when you last signed in, and a count of failed sign-in attempts, which is what locks an account after repeated wrong passwords.
Your own work: when you mark a lead called, quoted or won, or type a note on it, that is stored against your account.
Cookies. These marketing pages set none at all. The app at detroitpermitleads.com/app sets two, both strictly functional: the sign-in token described above, and a small random value that lets us check a submitted form came from our own page and not from somebody else's. That second one is set the first time you open a page with a form on it, so it can reach you before you have an account. Neither follows you anywhere, and there is no analytics, no advertising pixel and no third-party script on any page of ours. Paying takes you to Stripe's own page rather than loading Stripe's code into ours.
The permit data itself
The leads are public building-permit records published by cities. They are not information about you, and we do not connect them to you beyond recording which ones we have sent you — so we do not send the same one twice — and which ones you have marked.
Who else sees your data
Stripe handles payment. Card details are entered on Stripe's own page and never reach our server; we never see or store a card number. We send Stripe your email address, an internal account number, and which plan and trade you chose, and we store the customer and subscription ids Stripe gives back, so a payment can be matched to your account.
Google sees two things. Our email is sent through Gmail, so your address and the contents of any message we send you pass through Google's servers. And the owner keeps a private Google Sheet showing how the system is running, which lists each customer's name and email address beside a count of the leads waiting for them. That sheet is shared with nobody else.
Cloudflare sits in front of this website, so it sees the requests your browser makes — including your IP address — before they reach us. Our own web server keeps an access log of requests: IP address, the page asked for, and the time.
That is the complete list. We do not sell personal information, and we do not share it with advertisers, data brokers or lead aggregators.
Where it is stored, and for how long
Everything lives in one small database on a server run by the owner, in his home, in Michigan. Sign-in sessions expire after 30 days. A password-reset link expires after two hours. Everything else is kept for as long as your account exists — there is no automatic deletion, and we would rather say so than imply a schedule the software does not have.
Backup copies of that database are taken nightly and kept on the same server and on the owner's own computer. A backup taken before you asked for deletion will still contain your data until that backup is rotated out, which takes a few weeks.
Getting a copy, or getting it deleted
Email [email protected] from the address on your account and ask. There is no self-service button for this yet, so it is done by hand: your account, your saved leads and your notes are removed from the live database and you get a reply saying it is done. You can ask for a copy of what we hold the same way.
You do not have to have an account to ask us to stop emailing you — say so in a reply to any message and it stops.
Security
Passwords are hashed with Argon2 and never stored in a readable form. The site is served over HTTPS only. The part of the system that serves this website can read the permit data but cannot change it, and the customer database is not reachable from the public internet.
Changes
If this page changes, the date at the top changes with it. Material changes affecting customers will also be emailed.
Contact
Hadi Ghaddar, Permit Leads, metro Detroit · [email protected] · (313) 421-6784