Effective August 20, 2026
If you only take the free digest: the email address you type into the signup box, and a short note of where you arrived from — a referring site or campaign tag, if there was one. No card, no name, nothing else.
If you buy a one-time list, that sale runs through Stripe. Stripe takes the payment and passes us the email address and name given at checkout, which product was bought, the amount, the state you typed in the checkout question, and Stripe's own session and customer IDs. We store that so we can build your file, email it to you, and show later exactly what you ordered.
If you take a monthly subscription, that runs through Stripe. Stripe takes the payment and passes us your email address, the name on the checkout, the amount and currency, the states you typed in, and Stripe's customer ID and subscription ID. We store those two IDs on purpose: they are how a cancellation or a failed payment gets matched back to the right person. Without them someone could cancel and keep receiving sheets, or ask to stop and keep being charged.
We never see or store a card number. Card details are handled entirely inside Stripe and never reach our server. Our website sets no tracking cookies and runs no analytics scripts.
We use your email address to send you the newsletter and alerts you signed up for. That's the whole list.
We never sell or rent your email address. We share it only with the suppliers needed to run the service: Resend, which delivers our mail; Stripe, which processes payments; and Google and Comcast, which receive our daily off-site backup of the subscriber database. The live list sits on our own server and is backed up every morning. One exception, stated plainly: if this business is ever sold or merged, the subscriber list may transfer with it — the new owner will be bound by this same policy, and you'll always have the one-click unsubscribe. Emails are delivered through Resend (our email provider), which processes your address solely to deliver our mail.
Our web server keeps an access log, the way nearly every website does. One line of JSON per request, holding your IP address, the time, the full address of the page or file you asked for, the response we sent, your browser's User-Agent string, and the Accept-Language header your browser volunteers. An IP address is personal data under the CCPA and the GDPR, so it belongs on this page rather than buried in a config file.
We use it for one thing: keeping the site up, and seeing when something is broken or being probed. We do not build a profile from it, we do not join it to your email address or your order, and we do not share it with anyone.
How long we keep it. The log rotates by size, not by date. When the live file reaches 10 MB it is rolled up and compressed, we keep the five most recent rolled files, and the server deletes any rolled file older than 90 days. So the honest answer is that retention depends on how busy the site has been, with 90 days as the outer limit — rather than a tidy figure we do not actually enforce.
Every email our systems send you — the weekly digest, and the sheets if you are a paying member — carries a one-click unsubscribe link plus a confirmation, and one click stops all of it. Cold outreach is different: we write those by hand, to business addresses published on company websites, and they carry no link because there is no list to remove you from yet. Reply with anything at all and we add you to a do-not-email list, which is checked before any further message is written. If you'd also like your address erased from our records entirely, email us and we'll delete it within a few days.
The practice records in our digests, samples and paid files come from the CMS National Provider Identifier registry (NPPES), a public U.S. government database anyone can download for free. We compile those public records into lists and we sell them to businesses that want to reach newly registered practices. Saying only that the data "comes from" the registry would leave out the part that matters most to the people in it.
This section is for authorized officials, not buyers.
What is published about you. We hold organizations only. Every individual-practitioner record is dropped before anything is stored, so we never sell an individual provider. But an organization's registration names a real human being: the authorized official who signed it. That means a row can carry your first name, last name and title, next to the organization's name, NPI, specialty, business phone and street address. Where a practice registered from home, that address is a home address. We know that, which is why this section exists.
Where every field comes from. All of it is what the practice itself reported to CMS, passed through unchanged. Nothing is added from any other source: no purchased data, no data broker, no scraped web data, and no email addresses — the federal registry does not publish them, so we have none to sell. The only thing that is ours is a single extra column of quality flags, worked out from that same federal file (for instance, that a phone number is not dialable, or that one number answers for several businesses).
What you can do about it. The registry is the source, so the change that sticks is made there: update your NPI record with CMS at nppes.cms.hhs.gov and the correction flows into every file we build afterwards. But pointing you at a federal agency is not an opt-out, so there is a real route here too. Email leads@freshmedleads.com and a person will answer. Tell us what is wrong, or that you would rather not be in our files, and we will correct your row or stop including it in the files we build from then on. That covers this website too — if your record appears in a public sample or proof page on freshmedleads.com, say so and we will take it off, normally within one working day. It is done by hand, so give us a few days for the files.
What we cannot do, said honestly. We cannot delete or hide your public federal record — only CMS can change that. We cannot recall a file already delivered to a buyer. And we cannot stop anyone else who downloads the same free CMS file from holding the same information. If you are in California, or in the EU or UK, and want to exercise a privacy right, write to the same address and say so. We will treat it as such and reply.
FreshMedLeads is a brand operated by LEADTHEM LLC, a Michigan limited liability company.
leads@freshmedleads.com
LEADTHEM LLC, 5707 Red Arrow Hwy #108, Stevensville, MI 49127