LeadsACE
Services
For Founders & OperatorsHealthcare go-to-market that survives the buying committee. For Clinics & PracticesPatient acquisition that fills the calendar. All ServicesThe full done-with-you and done-for-you menu.Technical Development ↗Product & engineering builds via our partner BitLab.
Mechanisms
01Positioning & Messaging 02LinkedIn Outbound Engine 03Cold Email Infrastructure 04Paid Acquisition 05CRM Build & Migration 06AI Sales / Follow-Up Agent 07Podcast-as-Pipeline 08Marketplace & Niche GTM 09Sales Training & Enablement 10Content Production 11Conversion Funnel & Offer 12Analytics & Growth Modelling See all 12 mechanisms →
Specializations
Med Spas Plastic Surgery Cosmetic Dentistry & Ortho Cosmetic Dermatology Chiropractic Concierge & Longevity Fertility See all specializations →
Case Studies About Book a Growth Audit
Legal

Privacy Policy

What we collect when you visit leadsace.io or talk to us, why we collect it, and what you can ask us to do about it.

Last updated: 3 September 2026
The short version. We do not sell your data and we run no advertising trackers. The site counts visits without cookies and records masked session replays so we can see which pages confuse people. Book a call and your details sit in our CRM so we can follow up. Email hello@leadsace.io and we will delete any of it.

Contents

  1. Who we are and what this covers
  2. Information we collect
  3. Cookies and analytics tools
  4. How we use your information
  5. Our legal bases (UK and EU visitors)
  6. Who we share information with
  7. Please do not send us patient data
  8. How long we keep information
  9. How we protect information
  10. International transfers
  11. Your rights
  12. Do Not Track and Global Privacy Control
  13. Children
  14. Changes to this policy
  15. Contact us

Who we are and what this covers

LeadsACE is an independent growth agency based in Toronto, Canada, working with HealthTech and MedTech companies and with clinics and specialty practices. In this policy, "we" and "us" mean LeadsACE, and "you" means anyone who visits leadsace.io, books a call with us, or corresponds with us.

This policy covers the website and the enquiries, calls and emails that follow from it. Work we do for a client is also governed by the agreement signed with that client. Where this policy and a signed agreement disagree about that client's data, the signed agreement wins.

Questions about anything here go to hello@leadsace.io.

Information we collect

Information you give us

When you book a growth audit or email us, we receive your name, email address, phone number if you provide one, your company, and whatever else you choose to tell us about your business. Bookings run through Calendly, so Calendly receives that information too.

Information collected automatically

  • Your IP address, browser, device type and operating system.
  • Pages you viewed, how long you stayed, and the page or search that sent you here.
  • Approximate location, at city or country level, derived from your IP address. We do not collect precise geolocation.

How you use the pages

We record anonymised session activity: mouse movement, clicks, scroll depth, and where you stop reading. This is done by Microsoft Clarity, described in the next section. Text on the page is masked by default, so the replay shows shapes and interactions rather than readable content.

Calls and meetings

We record and transcribe most video calls so we can write accurate notes and follow up properly. The meeting platform announces recording at the start of the call. If you would rather we did not record, say so and we will turn it off.

Cookies and analytics tools

Three tools touch your browser on this site. Here is all of them, what each one does, and whether it sets cookies.

ToolWhat it doesCookies
Cloudflare Web AnalyticsCounts page views and visits so we know how many real people read a page. It does not use cookies, does not fingerprint your device, and does not follow you to other sites.None
Microsoft ClarityHeatmaps and session replay, so we can see which parts of a page confuse people or get ignored. Page text is masked by default. Data is processed by Microsoft.Yes
CalendlyRuns the scheduling page when you click through to book a call. Calendly sets its own cookies on its own domain, under its own privacy policy.Yes, on calendly.com

We do not run advertising pixels on this site, and we do not use cookies to build advertising profiles or to retarget you elsewhere.

You can block any of this through your browser settings or a content blocker, and the site will work normally without it. Microsoft explains Clarity and its opt-out at privacy.microsoft.com.

How we use your information

  • To answer your enquiry, run the call you booked, and follow up afterwards.
  • To deliver and improve work for clients, and to keep records of what was agreed.
  • To understand which pages are useful and which need rewriting.
  • To send updates you asked to receive. Every marketing email has an unsubscribe link that works.
  • To meet legal and accounting obligations, and to enforce our terms.

We do not use your personal information to train machine-learning models, and we do not make automated decisions about you that produce legal or similarly significant effects.

Our legal bases (UK and EU visitors)

If you are in the United Kingdom or the European Economic Area, we rely on these bases under the GDPR:

  • Legitimate interests, for running and improving the website, understanding traffic, and contacting businesses about services relevant to them. We have weighed this against your interests and use privacy-preserving analytics as a result.
  • Performance of a contract, where we are delivering work you engaged us for, or taking steps you asked for before an engagement.
  • Consent, for marketing email where consent is required. You can withdraw it at any time.
  • Legal obligation, for tax, accounting and record-keeping.

Who we share information with

We do not sell your personal information, and we never have. We share it with the service providers that run our operations, each bound by its own contract to protect it:

ProviderWhy
CloudflareWebsite hosting, security, and cookieless traffic analytics
MicrosoftClarity heatmaps and session replay
GoogleBusiness email and documents
CalendlyCall scheduling
CloseOur CRM, where enquiries and conversation history live
FathomCall recording, transcription and notes

Beyond that, we disclose information only when the law requires it, when we need to establish or defend a legal claim, or if the business is ever transferred, in which case the acquirer inherits the obligations in this policy.

Please do not send us patient data

LeadsACE is a marketing and go-to-market firm. We are not a healthcare provider, and this website is not built to receive protected health information.

Do not send patient names, medical records, or any other protected health information through this website, through a booking form, or by ordinary email. If an engagement genuinely requires us to handle protected health information, we will sign a business associate agreement first and set up an appropriate channel for it. Anything sent to us outside that arrangement, we will delete.

How long we keep information

Enquiries and CRM records are kept while there is an active or realistic business relationship, and for up to three years after our last contact, so that we can pick up a conversation where it left off. Session replays and heatmap data expire on Microsoft Clarity's own schedule, currently around thirty days. Traffic analytics are aggregate and hold no personal identifiers. Records we must keep for tax or accounting reasons are kept for as long as the law requires.

You can ask us to delete your information sooner, and we will unless we are legally required to keep it.

How we protect information

The site is served over HTTPS with HSTS. Access to our CRM, email and call recordings is limited to people who need it, protected by multi-factor authentication, and reviewed when someone stops working with us. Our providers are established vendors with their own security programmes.

No system is perfectly secure, and we will not pretend otherwise. If a breach ever affects your personal information, we will notify you and the relevant regulator as the law requires.

International transfers

We are based in Canada and our providers operate in Canada, the United States and the European Union, so your information may be processed outside your home country. Where information moves out of the UK or EEA, our providers rely on the European Commission's standard contractual clauses or an equivalent approved mechanism.

Your rights

Wherever you live, you can email hello@leadsace.io and ask us what we hold about you, ask us to correct it, or ask us to delete it. We will respond within thirty days, and we will not charge you or treat you differently for asking.

United Kingdom and European Economic Area

You have the right to access, correct, erase, restrict processing of, and port your data, to object to processing based on legitimate interests, and to withdraw consent. You can also complain to your national data protection authority, or to the Information Commissioner's Office in the UK.

Canada

Under PIPEDA you may access the personal information we hold about you and challenge its accuracy. Unresolved complaints can go to the Office of the Privacy Commissioner of Canada.

California

Under the CCPA and CPRA you may request the categories and specific pieces of personal information we collected, request deletion, and correct inaccurate information. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of on that front.

Do Not Track and Global Privacy Control

Browsers send these signals inconsistently and there is still no agreed standard for honouring them, so we do not claim to respond to Do Not Track headers. The point is largely academic here: we run no advertising trackers and sell nothing. If you send a Global Privacy Control signal, treat it as already satisfied by how this site works.

Children

This is a business-to-business website. It is not directed at children, and we do not knowingly collect information from anyone under 16. If you believe a child has sent us personal information, email us and we will delete it.

Changes to this policy

When this policy changes we update the date at the top of the page. If a change materially affects how we handle your information, we will say so prominently rather than quietly editing the text.

Contact us

LeadsACE, Toronto, Ontario, Canada.

Email hello@leadsace.io for anything about this policy, including access and deletion requests.

Our Terms of Service cover use of the website itself.

LeadsACE

Built to Booked. Go-to-market for HealthTech & MedTech.

Services
All 12 mechanisms For clinics & practices Patient acquisition Specializations For founders
The system
The Action Plan Acquisition Machine NTPMA · Product-market fit
Company
Case Studies Blog About Contact
Connect & legal
LinkedIn hello@leadsace.io Privacy Policy Terms of Service
© 2026 LeadsACE. All rights reserved. Privacy · Terms Independent growth agency & go-to-market partner to Bitlab · Toronto · Remote · Worldwide