VineskillsSign in

Privacy policy

How this app handles data

Last updated July 21, 2026

What this app does

The Lead Docket Conversions App connects a law firm's Lead Docket account to its Google Ads account. When a lead in Lead Docket reaches a status the firm counts as a conversion, Lead Docket notifies this app, and the app reports that conversion to Google Ads so the firm's advertising can optimize toward real outcomes.

The app is operated by Vineskills for the firms we work with. Each firm decides which of its leads are reported and to which Google Ads conversion action.

What we collect and why

From Lead Docket webhooks: when a firm's Lead Docket sends us a lead, we read it in memory and keep only what conversion reporting needs: the Lead Docket lead ID, a one-way hash (SHA-256) of the lead's email address and phone number, the Google click ID (GCLID) if one was captured, and timestamps. The rest of the webhook, including the lead's name and any raw contact details, is discarded immediately and never written to storage.

From firm users: the name, work email, and password of the people a firm authorizes to sign in. Passwords are handled by our authentication provider and are never visible to us.

From Google: when a firm connects its Google Ads account, Google gives us a token scoped to sending conversion data on the firm's behalf. We store that token encrypted and use it for nothing else.

Operational records: delivery receipts and processing statuses (sent, confirmed, failed) for each conversion, plus standard server logs. These contain lead IDs and status codes, not contact details.

How the data is used

One purpose: reporting the firm's conversions to Google Ads through Google's Data Manager API. Hashed identifiers exist so Google can match a conversion to an ad click. We do not sell data, share it with advertisers other than the firm's own Google Ads account, use it to build profiles, or use it for any purpose beyond operating this service.

How long we keep it

Hashed identifiers and click IDs are kept only while a conversion is being delivered. Once Google confirms or rejects it, they are deleted from the record. What remains afterward is the delivery history: lead ID, status, and timestamps, which the firm sees in its dashboard.

If a delivery fails without a definitive answer from Google, the hashed fields are kept so the conversion can be retried or replayed, then removed once it resolves.

Who processes it

The service runs on infrastructure from Vercel (hosting) and Supabase (database and authentication), and sends conversion data to Google's Data Manager API at the firm's direction. Operational notifications to our team (for example, a failed delivery) go through Slack and contain lead IDs and statuses, never contact details. Each of these providers processes data under its own security and privacy commitments.

Security

All traffic is encrypted in transit. Google access tokens are encrypted at rest with keys held outside the database. Database access is restricted so a firm's users can only ever see their own firm's records, and webhook credentials are never readable from a browser.

The firm's role

Each firm remains responsible for its own relationship with its leads and clients, including having a lawful basis to share lead contact details with its advertising platforms. This app acts on the firm's instructions as a processor of that data.

Your choices

A firm can disconnect its Google Ads account at any time from its dashboard, ask us to pause or delete its account entirely, or ask what data we hold about it. Individuals whose data was processed through a firm's account should contact that firm first, since the firm controls the data; we will support whatever the firm needs to honor the request.

Changes and contact

If this policy changes in a way that matters, we will note it here with a new date. Questions, requests, or concerns: leaddocket@vineskills.com.