The minimum columns are name, contact details, where they came from, the date of first contact, what they asked about, the current status, the date of last contact, and the next action with a date. That last pair is what makes it a system rather than a list. A lead with no next action is a lead you have stopped working without deciding to, and it is where most small business pipelines quietly leak.
Structure it for eventual migration, because you will move it. One row per lead, one piece of information per column, no merged cells, no colour as the only meaning, dates in a consistent format. A spreadsheet built this way exports cleanly into any system later. One built organically does not, and the migration becomes a retyping exercise that delays the decision by months.
Record where they came from on every entry, without exception. Six months of that column is the most valuable marketing data a first year business can own, and it cannot be reconstructed afterward. It will also disagree with your analytics, and the lead is the more reliable source.
Move to a real system when the spreadsheet stops being enough, which is recognisable: more than one person needs to update it, you are missing follow ups because nothing reminds you, or you want to see history without scrolling. Until then this is not a compromise, it is the correct tool at your volume.
Review the list weekly rather than referring to it when something comes up, because a lead tracker read only reactively is a record rather than a tool. Fifteen minutes scanning for anything with no next action, or a next action whose date has passed, recovers work you were unknowingly abandoning. That single habit is most of the difference between a business that follows up and one that intends to, and it does not become easier to adopt once you have software.
Keep it somewhere reachable from a phone, since a substantial share of enquiries arrive when you are not at a desk and a record you cannot update in the moment is one that gets updated inconsistently or not at all. A shared spreadsheet in cloud storage covers this adequately, and the discipline of entering something within the hour matters more than the sophistication of where it goes.