Open Profile InMail is live , reach 100+ extra prospects per seat, at no InMail cost FREE CHANNEL See how it works
Pricing Log in
Get Started Free Book a Demo
Data Flows

What Quicklead receives, stores and sends on

Written for the person doing your vendor review. Every field we take in, where it is held, which components touch it and exactly what crosses the boundary into your systems.

Hosting: DigitalOcean, United States Entity: India TLS 1.2+ and AES-256

Last reviewed September 2026

Inbound

What Quicklead receives

SourceDataHow it arrives
Your teamAccount details, billing contact, workspace and seat configurationEntered in the app
Your LinkedIn accountYour own profile, connections, sent invitations and inboxYour authenticated session, operated on your instruction
Prospect LinkedIn profilesName, headline, current company and role, location, industry, summary, education, skills, languages, profile URL and pictureRead from profiles your campaign targets
Email FinderWork email, and in some records a business phone number and company domainLooked up in Quicklead’s own contact database by profile URL
Your prospectsReplies, acceptance events and message historyReceived into the Smart Inbox
Your CSV or Sales Navigator importWhatever columns you uploadFile upload
Your CRM, if connectedContact records, where you enable contact importOAuth connection
Fields worth flagging to your reviewer Some Email Finder and imported records can carry a personal rather than a business phone or email, and profile records can include date of birth where an individual has published it on LinkedIn. We hold those fields because the source exposes them, we do not require them, and they are removable on request.
At rest

Where it is stored

StoreWhat lives thereLocation
Managed MySQLAccounts, teams, workspaces, plans, integration configuration, credit historyDigitalOcean, United States
MongoDBPer-workspace prospect records, campaigns, connections, inbox, notes, pipelines, the Email Finder datasetDigitalOcean, United States
Object storageUploaded files, exports and attachmentsDigitalOcean, United States
Message queueIn-flight campaign and sync jobs, transientQuicklead-operated
BackupsEncrypted database snapshotsSame region as the source

Each customer workspace has its own prospect, campaign and connection collections. Workspaces are isolated from one another, and agency accounts can isolate each client further.

HubSpot

Exactly what moves between Quicklead and HubSpot

The most common question in a security review, so here is the precise answer rather than a general one.

Permissions Quicklead requests

Two OAuth scopes, and no others:

crm.objects.contacts.read
crm.objects.contacts.write

Quicklead therefore cannot access deals, tickets, companies, quotes, marketing email, workflows, forms, files, reporting, settings or your HubSpot users. If the consent screen shows anything beyond those two scopes, do not approve it and tell us.

Direction of travel

Quicklead → HubSpot. Event-driven. Nothing is sent unless you subscribe the integration to that event type, and you choose which of the four events are enabled.

HubSpot → Quicklead. Contact records only, and only if you switch on contact import. With it off, the connection is write-only.

Tokens are stored encrypted, refreshed automatically, and revoking the app in HubSpot stops the flow immediately.

Field sent to HubSpotWhat it isWhen
Campaign nameWhich Quicklead campaign the event came fromEvery subscribed event
Event typeAccepted invitation, positive reply or negative replyEvery subscribed event
First and last nameThe prospect’s name as shown on LinkedInEvery subscribed event
LinkedIn profile URLThe prospect’s public profile linkEvery subscribed event
Message sentThe outreach message your user sentReply and acceptance events
Reply receivedThe full text of the prospect’s replyReply events
Sentiment flagWhether Quicklead classified the reply as positive or negativeReply events
Sending account identifierThe public identifier of your user’s own LinkedIn profileEvery subscribed event
The one to brief your Head of Risk on Reply text is included in the payload. Whatever a prospect writes back is written into your HubSpot contact record. That is normally desirable, but it means prospect-authored free text crosses into your CRM, so it belongs in your own ROPA.
Other destinations

Everywhere else data can leave

All of these are off by default. Each one is enabled by you, per workspace.

DestinationWhat it receivesEnabled by
Zoho CRMThe same event payload as HubSpotOAuth connection you authorise
ZapierThe full event payload to your catch hookA Zapier hook URL you provide
SlackEvent notifications to a channel you chooseA Slack webhook you provide
Custom webhookThe event payload to any endpoint, with your own headers or bearer tokenA URL you configure
Google SheetsExported contact rowsGoogle OAuth you authorise
CSV / Excel exportWhatever you choose to exportYou, in the app
FAQ

Data flow questions

Contacts, and nothing else. The OAuth connection requests two scopes, crm.objects.contacts.read and crm.objects.contacts.write. That grants no access to deals, tickets, companies, marketing email, workflows, files, reporting or your HubSpot users.
Yes, to the systems you connect it to. If you enable the HubSpot, Zoho, Zapier, Slack or webhook integration for reply events, the reply text is included in the payload so it lands in your CRM. That is usually the point, but it should be a deliberate choice, so we state it here rather than in a footnote.
Yes. AI Messages, AI ICP Scoring and the classification features are optional. With them disabled, no prospect data is sent to OpenAI or OpenRouter at all.
Export everything at any time from the app. On account closure, workspace data is deleted within 30 days, backups age out on their own cycle, and invoices are retained where tax law requires it.

Need the architecture diagram?

We will send the full data-flow document, the network diagram and our completed CAIQ, usually within two business days.

No credit card required · Full product trial · Cancel any time