Lead Generation
UpLead
Rest of world Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 2 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by UpLead, LLC · www.uplead.com
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
UpLead, LLC is a California entity selling a credit-based contact database with real-time email verification, a 200M+ leads headline and a 95% accuracy figure. Its clearest strength is pricing transparency, where scores cluster at 6 with one 5: Essentials at $99 per month for 170 credits, Plus at $199 per month for 400 credits, additional credits at $0.60 and $0.50 per credit, and a stated use-it-or-lose-it expiry. Its weakest criterion is visitor identification, scored 1 to 2: buyer intent data is marketed but gated to the custom-priced, annual-only Professional plan, and we found no public information on how intent is tracked or on a consent position for German traffic. Data coverage and prospecting compliance cluster at 4, sovereignty at 3. The judges genuinely split on CRM sync and export, scored 4 to 6, over the Professional-only bi-directional sync and terms that restrict export, and on data provenance, scored 2 to 3, where a named legitimate-interest basis and opt-out form stand against no published source categories.
Speaks for it
- Tier prices with credit allowances are published, with additional credits priced at $0.60 and $0.50 per credit.
- Native integrations with fifteen CRMs plus 1,500+ apps through Zapier are documented, with real-time CRM enrichment and a three-tier API.
- Suppression-list uploads for emails, phone numbers and company URLs sit alongside 50+ search filters and technographics.
- Standard contractual clauses cover EU, UK and Swiss transfers, with an Article 27 representative (EDPO) appointed.
- A $0 free trial provides 5 credits over 7 days, and monthly plans carry no contract or long-term commitment.
Held against it
- We found no public information on coverage by country, including DACH or EU volumes, or on any re-verification cadence behind the freshness ranking.
- We found no public information on where contact data is sourced, on a balancing test, or on notice to people added to the database.
- Buyer intent data sits behind the custom-priced, annual-only Professional plan, with no published tracking mechanics or consent position.
- The captured pages give different positions on refunds, and on export and retention of data after termination.
- Personal information is stored on servers in the United States by a California-contracting entity, and we found no public information on EU hosting, ownership, or a subprocessor and data-partner list beyond the named analytics tools.
Best for
- You buy contacts by the credit and want tier prices, top-up rates and expiry rules published before signing.
- You work from an established CRM and need native push to Salesforce, HubSpot and thirteen other systems plus Zapier.
- You need suppression lists for emails, phone numbers and company URLs plus 50+ filters to control which contacts reach your campaigns.
Avoid if
- You need country-level coverage figures for Germany, Austria or Switzerland before committing; only whole-database figures are published.
- Your procurement requires EU data residency; the captured pages state that personal information is stored on servers in the United States.
- You expect to keep exported data after cancelling; the terms require destroying all data within seven days of termination.
The scores
Coverage, accuracy & freshness
Show reasoningHide reasoning
How this is scored
How much of the target market the database actually covers — judged on DACH and EU coverage as much as North American — and what the vendor documents about verification and refresh, because accuracy claims cannot be checked from outside.
0 — No stated coverage, no refresh cadence, no verification method; accuracy asserted as a percentage with nothing behind it.
3 — Headline record counts for the whole database, thin or unstated European coverage, and no description of how often records are re-verified.
5 — Coverage stated per country or region including DACH, email verification described, a stated refresh cadence, and firmographics beyond name and domain.
8 — Coverage broken down by country, industry and data type (email, direct dial, mobile), verification method and refresh cadence documented, company data drawn from official registers where available, and a bounce or credit-back guarantee with stated terms.
10 — The vendor is accountable for its data: per-country coverage and accuracy methodology published, every field carrying a last-verified date visible to the user, register-sourced company data, and credit-back terms that make inaccuracy the vendor's cost rather than the buyer's.
The SDR Team Lead
A 200M+ lead count with a 95% accuracy claim, real-time verification as you search, and a promise to refund bounces is roughly what my team measures by, but everything is a whole-database headline — I found no public information on coverage by country, so I cannot tell whether my DACH patch is deep or thin, and there is no stated re-verification cadence for the phone numbers my SDRs dial. 1 2
The RevOps Manager
A 200M+ headline count, a 95% accuracy figure, real-time email verification and firmographic plus technographic filters are public, but coverage is stated for the database as a whole only. I found no public information on country-level coverage for DACH or Europe, on a re-verification cadence beyond ranking by freshness, or on the terms behind the bounce refund claim. 1 2
The Data Protection Officer
The headline is 200M+ leads, AI-verified as you search and ranked by freshness, with a 95% data accuracy figure, but we found no public information on per-country coverage including DACH or on any re-verification cadence behind the freshness ranking. The homepage promises refunds for bounces and poor data while the license terms state all fees are non-refundable — the captured pages give different positions, so the credit-back terms are not firm enough to make inaccuracy the vendor's cost. 1 4
The ABM Marketer
The homepage gives a 200M+ leads headline, real-time email verification described as happening as I search, a 95% accuracy figure and refunds for bounces — that's a verification story, but everything is a whole-database number. We found no public information on coverage per country, DACH or EU presence, or how often records are re-verified, so I cannot tell how many of my German and Austrian targets this database actually holds. 1
The DACH Sales Director
A single '200M+ leads' headline with a bare '95% data accuracy' claim is the classic US-database pitch, and nothing on the pages breaks coverage down for Germany, Austria or Switzerland — for a Mittelstand pipeline that silence is the first disqualifier. Real-time email verification and freshness ranking are described, and a bounce refund is promised, but I found no public information on the terms of that refund or on any refresh cadence, so there is nothing to hold the vendor to. 1 2
The Skeptic
A 200M+ leads headline with real-time email verification standing behind the 95% accuracy claim, and firmographics go well past name and domain with fifty-plus filters and 16K+ technology data points. But we found no public information on per-country coverage — nothing on DACH or EU volumes — and no refresh cadence; "ranked by freshness" is the only statement about the age of records, and the bounce refund is a one-line promise with no published terms. 1 2
Data sources & lawful basis
Show reasoningHide reasoning
How this is scored
Where the personal data in the database comes from and on what legal basis it is processed — as evidenced on the vendor's own pages. Covers Art. 6(1)(f) legitimate interest, the Art. 14 notice to the people in the database, and whether they can find, object to and remove their record.
0 — No statement of where contact data comes from or on what legal basis; "GDPR-compliant" asserted without explanation, and no way for a listed person to object.
3 — Sources described in general terms ("public sources", "partners"), legitimate interest named without any balancing, and an opt-out request form as the only route for data subjects.
5 — Source categories named (registers, company websites, contributory networks, licensed partners), legitimate interest stated as the basis for EU records, a dedicated privacy notice for the people in the database, and a self-service opt-out or removal process.
8 — The above plus an Art. 14 notification practice described (people informed when added), contributory or browser-extension collection disclosed as such, a legitimate-interest assessment summarised publicly, and EU records handled differently from US records where the law differs.
10 — Provenance is traceable per record: the source and collection date available for each contact, Art. 14 notices sent and documented, the balancing test published, objections honoured across the whole dataset and suppressed permanently, and no data sourced by scraping behind logins or from contributors' address books without their contacts' knowledge.
The SDR Team Lead
The privacy policy states legitimate interest as the basis for its business profiles and gives listed individuals an opt-out form, with an EU representative and standard contractual clauses for EU transfers — but I found no public information on where the contact data actually comes from, no balancing test, and no notice practice for the people added to the database. 3 4
The RevOps Manager
Legitimate interests are named as the basis for Business Profile Data and listed people get an opt-out form with a one-month response commitment. We found no public information on where the contact data is sourced, on any balancing summary, or on an Art. 14 notification practice for the people in the database. 3 4
The Data Protection Officer
The privacy policy names legitimate interests as the basis for Business Profile Data and gives listed individuals an opt-out form to access or delete their record, which is at least a named basis and a route for data subjects. But we found no public information on where the contact data is actually sourced, on any balancing for that interest, on an Art. 14 notification practice for people added to the database, or on a dedicated privacy notice aimed at those people. 3
The ABM Marketer
The privacy policy says Business Profile data is processed on legitimate interests and offers people in the database an opt-out form to access or delete their record. We found no public information naming the source categories the contacts come from, no balancing test, and no practice of notifying individuals when they are added — for a database I would be cold-emailing from, that thinness matters. 3
The DACH Sales Director
Legitimate interest is named for the business profiles, listed individuals get an opt-out form, and standard contractual clauses plus an EU representative stand behind the transfers — the bare minimum, and nothing more. I found no public information on where the contact records actually come from: no source categories, no register sourcing, no Art. 14 notification practice, and no balancing summary anywhere on the captured pages. 3 4
The Skeptic
The privacy policy names legitimate interests as the basis for Business Profile Data and gives listed people an opt-out form plus a do-not-sell link, which is the bare minimum a data subject needs. Beyond that we found no public information on where the contact data comes from — no source categories, no Art. 14 notification practice, no balancing test, and no per-record source or collection date. 3 4
Visitor identification & intent signals
Show reasoningHide reasoning
How this is scored
Identifying companies behind website visits and surfacing buying intent — scored on what is identified (company or person), how the tracking works, and whether the vendor states that its script needs consent under §25 TDDDG and how it behaves without it.
0 — No visitor identification or intent data, or person-level identification of EU visitors with no statement of legal basis.
3 — Reverse-IP company identification with a cookie-setting script, no statement about consent, and match rates claimed without method.
5 — Company-level identification with filters, visit history per company, a stated position that the script requires consent where it sets cookies, and a consent-mode or cookieless option.
8 — Company-level only for EU traffic by design, cookieless operation documented, integration with common consent management platforms, intent topics or page-level signals with the source of third-party intent data named, and alerts routed to owners.
10 — Identification that survives a DPO review: no personal data of visitors stored, the TDDDG and GDPR position published and specific, third-party intent data sourced from a named co-op or panel with its consent basis stated, and scoring on intent that the user can trace back to the underlying visits.
The SDR Team Lead
Buyer intent is marketed hard — find customers actively looking to buy, intent signals in the API — but I found no public information on how visitors or intent are identified, whether any script sets cookies, what the consent position is for German traffic, or where the intent data is sourced from. 1 2
The RevOps Manager
Buyer intent data is gated to the top plan and intent signals are advertised through the API, but we found no public information on how companies or visitors are identified, whether a script sets cookies, or the consent position for EU traffic. A DPO review would have nothing to work from. 1 2
The Data Protection Officer
Buyer intent data appears in the homepage copy, the API description and the Professional plan, but we found no public information on any website-visitor identification, on how intent is measured, on the source of third-party intent data, or on a consent position under §25 TDDDG — which is the first thing I look for before any tracking script is allowed to fire. 1 2
The ABM Marketer
Buyer intent data appears as a Professional-plan feature and the homepage promises customers actively looking to buy, but we found no public information on company-level visitor identification, how any tracking works, the consent position under German tracking rules, or who supplies the intent data. Nothing published would let me tell which of my named accounts is actually in market, never mind route an alert to the account owner. 1 2
The DACH Sales Director
Buyer intent data is advertised on the homepage and locked into the custom-priced Professional plan, but we found no public information on how companies are identified, on any tracking script, or on a consent position for the German telecom-privacy rules. An intent claim with no mechanics and no named data source is nothing a DACH data-protection officer would sign off. 1 2
The Skeptic
Buyer intent data is sold as a Professional-tier feature and delivered through the API, but we found no public information on how the signals are tracked, whether any script runs on the buyer's site, or what the consent and German telemedia-law position is. The intent claim comes without method, which is exactly the claim I can't check from outside. 1 2
Prospecting workflow & outreach rules
Show reasoningHide reasoning
How this is scored
Search, list building and outreach — and whether the product helps the buyer stay within UWG §7 and the GDPR once the list exists, rather than leaving the legal risk entirely with the customer.
0 — A search box and an export button; nothing on the pages about what the buyer may lawfully do with the contacts.
3 — Filters on firmographics and job title, saved lists, and a terms clause making the customer solely responsible for compliance.
5 — Advanced filters including technographics and triggers, company-level lists and alerts, a global suppression or do-not-contact list, and guidance on cold outreach rules in the main EU markets.
8 — The above plus country-aware handling (for example flagging German contacts where cold calls and emails require consent), phone numbers checked against national do-not-call registers where they exist, and opt-outs from outreach synced back to the database.
10 — Compliance is part of the workflow: outreach channels restricted or flagged per country and contact type by default, suppression shared across the whole account and every export, the Art. 14 notice supported at first contact, and a documented record of how each contact entered the buyer's pipeline.
The SDR Team Lead
On the workflow side my reps get 50+ filters, technographics across 16K data points, and suppression uploads for emails, phone numbers and company URLs — that is real prospecting muscle — but I found no public information on country-aware handling of German contacts, checks against do-not-call registers, or EU cold-outreach guidance, even though the vendor also sells a done-for-you cold email service. 1 2 4
The RevOps Manager
Advanced filters including technographics and suppression uploads for emails, phone numbers and company URLs are on the public tiers, but customers are designated independent controllers bound to CAN-SPAM, TCPA and GDPR. I found no public information on cold-outreach guidance for the main EU markets, country-aware flagging, or do-not-call register checks, so the legal risk lands entirely on the buyer. 1 2 3 4
The Data Protection Officer
There are 50+ search filters with technographics on higher tiers and a genuine suppression-list upload covering emails, phone numbers and company URLs, which does help a buyer keep people out of campaigns. But we found no public information on guidance for cold-outreach rules in the main EU markets, on country-aware flagging of German contacts, or on checks against national do-not-call registers — notable given the vendor also sells a done-for-you cold email service of its own. 1 2 4
The ABM Marketer
Fifty-plus filters including technographics, advanced filters on the Plus plan, and suppression uploads for emails, phone numbers and company URLs make a workable list-building engine, and the terms name the GDPR alongside CAN-SPAM and the TCPA. We found no public information on country-aware outreach flags, do-not-call register checks, or guidance on German consent rules for cold calls and emails — the legal risk of working the list stays with me. 1 2 4
The DACH Sales Director
Uploadable suppression lists for emails, phone numbers and company URLs, fifty-plus filters and technographics are genuinely useful workflow features. But the vendor offers a done-for-you cold email service while I found no public information on outreach-rule guidance for Germany or any other EU market, no country-aware flags, and no screening against do-not-call registers — and the policy seats customers as independent controllers carrying that risk alone. 1 2 3
The Skeptic
Advanced filters, technographics and suppression uploads for emails, phone numbers and company URLs give the buyer real list control, and the terms bind the customer to CAN-SPAM, TCPA and GDPR. But we found no public information on cold-outreach guidance for the EU markets, country-aware flagging of German contacts, or do-not-call register checks — the legal risk after export sits entirely with the customer. 1 2 4
CRM sync, enrichment & export
Show reasoningHide reasoning
How this is scored
Getting the data into the systems where sales works — CRM sync, enrichment of existing records, API — and what happens to exported data, and to the buyer's access to it, when the subscription ends.
0 — Manual CSV export only; no CRM integration and no API.
3 — A one-way push to one CRM, CSV export, and no statement on whether exported data may be kept after cancellation.
5 — Native sync with the major CRMs including field mapping and deduplication, enrichment of existing CRM records, and a documented API with stated limits.
8 — Bidirectional sync with scheduled re-enrichment, update and deletion propagated when a record changes or a person objects, webhook or API access with credit costs per call published, and data retention rights after cancellation stated plainly.
10 — The vendor treats the buyer's CRM as the system of record: objections and corrections propagated into synced records automatically, full change history per field, a versioned API with a deprecation policy, and exit terms that say exactly which data the customer may keep and for how long.
The SDR Team Lead
Native connections to Salesforce, HubSpot and the rest of my stack, CRM enrichment, a documented API in three tiers, and bi-directional sync on the Professional plan cover most of the sync story, though I found no public information on field mapping, deduplication or API limits. The captured pages describe export differently — the pricing page says a credit unlocks a contact for download or CRM export, while the terms require destroying all data within seven days of termination — so what my reps may keep after cancellation reads as an obligation rather than an exit right. 1 2 4
The RevOps Manager
Fifteen native CRM connections, contact-level export, enrichment and a documented three-tier API are real plumbing, with bidirectional sync reserved for the annual professional plan. I found no public information on field mapping, deduplication or whether objections propagate into synced records, and the terms order destruction of all data within seven days of termination while also containing a clause restricting printing, downloading or exporting the Data. 1 2 4
The Data Protection Officer
Native integrations with fifteen CRMs plus 1,500+ apps by Zapier, real-time CRM enrichment, an API offered in three tiers and bi-directional CRM sync on the top plan are all evidenced; we found no public information on field mapping, deduplication, or API rate limits and credit costs per call. On the end of the relationship the license terms require destruction of all data within seven days of termination and prohibit printing or downloading, while the FAQ confirms Excel CSV downloads — the captured pages give different positions on what the customer may keep after cancellation. 1 2 4
The ABM Marketer
The product pages show fifteen native CRM integrations plus Zapier, CRM enrichment, bi-directional sync on the Professional plan, CSV export and a documented API in three tiers; the license terms, meanwhile, prohibit printing, downloading or exporting the data and require destruction of everything within seven days of termination, so the captured pages give different statements on what a buyer may keep. We found no public information on field mapping, deduplication, API rate limits, or the credit cost of an API call. 1 2 4
The DACH Sales Director
Fifteen native CRM integrations, CSV export, enrichment and tiered APIs read well on paper, though bi-directional sync is reserved for the custom-priced Professional plan. I found no public information on field mapping, deduplication or API limits, and the captured pages give different signals on export rights — the pricing page invites CSV downloads while the terms state data shall not be printed, downloaded or exported — with destruction of all data required within seven days of termination. 1 2 4
The Skeptic
Native integrations with fifteen CRMs, real-time CRM enrichment, bi-directional sync on the Professional plan and a documented three-tier API put this solidly above a one-way push. But we found no public information on field mapping, deduplication, API limits or per-call credit costs, and the captured pages give different positions on export and retention: the pricing page says a credit unlocks download and CRM export, while the terms prohibit download or export of the data and require destruction of all data within seven days of termination. 1 2 4
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where a database of EU residents' personal data is held, who the contracting entity and controller are, and which subprocessors see it. Independently sourced by the sovereignty pipeline; weighted heavily here, because the product itself is personal data about people who never chose the vendor.
0 — Non-EU vendor and contracting entity, hosting unstated, subprocessors unnamed, and EU residents' contact data processed outside the EU with no stated transfer basis.
3 — Non-EU contracting entity with an EU representative under Art. 27, or EU hosting offered while enrichment, support or AI processing stay non-EU.
5 — EU contracting entity and EU hosting as standard, but parts of the chain — data partners, enrichment sources, tracking infrastructure — are non-EU without an explained safeguard.
8 — EU contracting entity and controller, EU hosting on named infrastructure, subprocessor and data-partner list published, and any non-EU transfer named with its legal basis.
10 — Sovereign end to end and evidenced: vendor, controller, hosting, data partners and every subprocessor European, certification published, and a DPA covering both the customer's data and the database records the customer exports.
The SDR Team Lead
A California LLC storing the database on US servers with US analytics vendors in the chain means the EU residents in this database are processed outside the EU; the appointment of an EU representative and standard contractual clauses for EU transfers matches the Article 27 pattern, but I found no public information on data residency options, ownership, or a full subprocessor and data-partner list. 3 4
The RevOps Manager
A California entity under California law stores personal information on US servers, with EDPO appointed as the Art. 27 representative for the EU and standard contractual clauses covering EU, UK and Swiss transfers — the minimum footprint. We found no public information on EU hosting, ownership, or a data-partner and subprocessor list beyond the site analytics services Google Analytics and Hotjar. 3 4
The Data Protection Officer
UpLead, LLC contracts under California law, states that the personal information it collects is stored on servers located in the United States, and has appointed EDPO as its Article 27 GDPR representative with standard contractual clauses available — the classic non-EU arrangement under which EU residents' contact data is processed outside the EU. We found no public information on EU hosting, on a European contracting entity or controller, or on a published subprocessor and data-partner list beyond the analytics tools named in the privacy policy. 3 4
The ABM Marketer
A California entity storing personal information on servers in the United States, with an Article 27 EU representative appointed, standard contractual clauses for EU transfers, and two US analytics subprocessors named. We found no public information on EU hosting options, ownership, or a complete subprocessor and data-partner list — EU contacts I export would sit in a US-processed chain. 3 4
The DACH Sales Director
UpLead, LLC contracts under California law, stores personal information on servers in the United States, and answers with an Article 27 representative plus standard contractual clauses for EU, UK and Swiss transfers — the textbook non-EU setup, and nothing beyond it. No EU hosting option appears on the pages, and beyond website analytics names like Google Analytics and Hotjar I found no published subprocessor or data-partner list for the database chain itself. 3 4
The Skeptic
A California entity contracting under California law, with the privacy policy stating that personal information is stored on servers in the United States; the EU presence is an Article 27 representative (EDPO) plus standard contractual clauses, which is precisely the non-EU-with-representative setup. The only named subprocessors are website analytics (Google Analytics, Hotjar) rather than anything in the data chain, and we found no public information on EU hosting or on the data partners themselves. 3 4
Pricing transparency
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the real annual cost from public pages alone — including credits per email, phone number and mobile, credit expiry, seat pricing, visitor-identification tiers and the API — in a category where the unit of billing is often invented by the vendor.
0 — No public prices at all; every tier is a sales conversation.
3 — A monthly headline exists, but what a credit buys, whether credits expire, or the cost of an additional seat is unstated — the invoice is unknowable.
5 — Tier prices public with credit allowances given, but at least one commonly needed piece (mobile numbers, extra seats, API access, CRM sync) is unpriced or behind a sales call.
8 — Every tier priced publicly with credits per data type, credit expiry and rollover, per-seat costs, overage rates, minimum term and VAT treatment stated.
10 — Complete price computability: the annual invoice derivable for a given number of seats, exported contacts by data type, identified companies and API calls, with every credit cost and the refund rule for inaccurate data published.
The SDR Team Lead
Most of the invoice is computable: public monthly and annual prices with credit allowances, additional credits at $0.60 or $0.50, rollover explicitly use-it-or-lose-it, and terms stating auto-renewal with a 60-day cancellation notice and non-refundable fees. What I cannot price from the pages is the team — every tier below Professional shows one user with no per-seat cost published — nor API access or VAT treatment, which sit behind a custom quote. 2 4
The RevOps Manager
Essentials and Plus are priced publicly with credit allowances, a one-credit-equals-one-contact definition, use-it-or-lose-it expiry and additional credit rates, and monthly plans carry no long-term commitment. The top plan is a sales conversation with custom seats and credits, and we found no public information on per-seat costs, VAT treatment or API call pricing. 2 4
The Data Protection Officer
Monthly and annual prices, credit counts per tier, the credit definition (one contact unlocking email and mobile direct dial), additional-credit rates and the use-it-or-lose-it expiry are all public, which is more than this category usually publishes. The Professional tier with buyer intent data, seats beyond one user and API access sit behind a sales conversation, and we found no public information on VAT treatment. 2 4
The ABM Marketer
The two published tiers are priced monthly and annually with credit allowances, no-rollover expiry, additional credits at $0.60 per credit on Essentials and $0.50 per credit on Plus, and renewal mechanics spelled out; the homepage promises refunds for bounces while the terms state all fees are non-refundable, and the captured pages give different statements. The Professional tier — the only one with buyer intent data and full API access — is fully custom-priced, and we found no public information on extra-seat costs or VAT treatment, so the annual invoice for the plan I would actually need is not computable. 1 2 4
The DACH Sales Director
The two public tiers are honest: $99 per month for 170 credits, $74 per month billed annually for 2,040 credits, additional credits at $0.60 and $0.50, no rollover, and one credit buys a contact with email and mobile direct dial. But every public tier is capped at one user, the Professional plan carrying API access, buyer intent and bi-directional sync is annual-only and 'let's talk', and I found no public information on VAT treatment — so the annual invoice for a ten-seat team is not computable from public pages. 2 4
The Skeptic
Tier prices with credit allowances are public, additional credits are priced at $0.60 and $0.50 per credit, credit expiry is stated bluntly (use it or lose it, no rollover), and the 60-day cancellation notice with automatic renewal is documented. But seats beyond the single user shown per plan, API pricing and the entire Professional tier sit behind a sales call, VAT treatment is unstated, and the captured pages give different positions on refunds — the homepage promises refunds for bounces and poor data while the terms state all fees are non-refundable. 2 4 1
European sovereignty — proven facts
2 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Incorporated in US ⚠ unverified | 0/3 pts | 3 Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | US by default ⚠ unverified | 0/3 pts | 3 Report an error |
| Subprocessors | Not determined | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 22 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Legal entity. Registered as a California LLC but no registry or HRB number is given; the country appears only via the state designation and the address block.
- Weak sourcing — Data residency. Statement sits in the privacy policy's International Transfers section; no EU hosting option is offered anywhere in the excerpts, though SCCs are offered for onward transfers.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 16 pricing facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 6 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 5 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 integrations fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 product fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 subprocessors fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (10)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage www.uplead.com Checked 22 Sep 2026 Details →
- 2 Pricing page www.uplead.com Checked 22 Sep 2026 Details →
- 3 Privacy policy www.uplead.com Checked 22 Sep 2026 Details →
- 4 Terms of service www.uplead.com Checked 22 Sep 2026 Details →
- 5 Coverage, accuracy & freshness — found from sitemap www.uplead.com Checked 1 Oct 2026 Details →
- 6 Coverage, accuracy & freshness — found from sitemap www.uplead.com Checked 1 Oct 2026 Details →
- 7 Data sources & lawful basis — found from sitemap www.uplead.com Checked 1 Oct 2026 Details →
- 8 Prospecting workflow & outreach rules — found from sitemap www.uplead.com Checked 1 Oct 2026 Details →
- 9 CRM sync, enrichment & export — found from sitemap support.uplead.com Checked 1 Oct 2026 Details →
- 10 CRM sync, enrichment & export — found from sitemap support.uplead.com Checked 1 Oct 2026 Details →