Privacy Policy
Effective date: August 21, 2026 Last updated: August 21, 2026
This Privacy Policy explains how [Company Name], operating [Product Name] (30 N Gould St #42906, Sheridan, Wyoming 82801, US), collects, uses, and shares personal data. It covers two different kinds of people, on purpose, because [Product Name]'s business is not typical SaaS:
- Customers — people who sign up for a [Product Name] account, and the businesses they represent.
- Third-party contacts — individuals whose name, business email, phone number, or social-media profile appears on a website that a Customer scans, and which [Product Name]'s Contact Finder feature surfaces. If you are in this second group, see Section 6 — it is written specifically for you.
1. Who we are
[Company Name] (EIN [EIN]), [company address], is the data controller for the personal data described in this policy, except where we act as a processor on behalf of a Customer (see Section 9). Contact: [support email].
2. Personal data we collect about Customers
- Account data: name, business email, company name, billing country, and authentication details.
- Billing data: invoice details and payment-reference/remittance information you send us to confirm a bank transfer. We do not collect or store full bank account credentials of Customers; we only use Customer-supplied confirmation (invoice number, amount, date) to match payments.
- Usage data: scans run, briefs generated, API calls, IP address, browser/device information, and similar log data.
- Support data: anything you send us by email or through the product.
3. How we use Customer personal data
We use this data to: provide and maintain the Service; process payments and match bank transfers to invoices; approve accounts and API key access; provide customer support; monitor for abuse, fraud, and security issues; and communicate service updates, invoices, and (where you have not opted out and local law permits) relevant product updates.
Our legal bases (where GDPR/UK GDPR applies) are: performance of a contract (providing the Service you signed up for), legitimate interests (security, fraud prevention, service improvement), and legal obligation (tax and accounting records).
4. Sub-processors and where data is hosted
We use the following categories of sub-processor to run the Service. [Confirm and finalize this list with your developer before publishing — this reflects the stack referenced in your product docs as of this draft.]
| Purpose | Provider | Notes | |---|---|---| | Application hosting | Google Cloud Run (GCP) | Serves the [Product Name] web app and workers | | Database | Neon (Postgres) | Stores account, scan, lead, and billing data | | Cache / queues | Redis (Memorystore) | Job queues and session-related caching | | Transactional email | Resend | Sends invoices, account, and notification emails | | Maps discovery | Google Places API | Used when Customer runs Map leads searches | | Payment receipt | Bank transfer rails and/or payment platforms we enable (e.g. Stripe, Airwallex) when live; we do not store full card numbers on our servers when cards are processed by those providers | Matching invoices to remittance / provider settlement | | AI pitch generation | Customer's own connected provider (OpenRouter/OpenAI/Anthropic/xAI), only when Customer supplies their own API key | We do not send your data to an AI provider unless you've connected your own key for this feature |
We require sub-processors to protect personal data under contractual confidentiality and security obligations. An up-to-date sub-processor list can be requested at [support email].
5. International data transfers
We are based in the United States. If you are located in the UK, EEA, Canada, or Australia, using the Service will involve transferring your personal data to the United States and to the countries where our sub-processors operate. Where required, we rely on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum (or equivalent successor mechanisms) for such transfers. [This wording assumes SCCs/IDTA will actually be put in place with each relevant sub-processor — confirm this with counsel/your providers before relying on this sentence; do not publish it if the mechanism isn't actually in place.]
6. If you are a third-party contact surfaced by a scan (important — read this section)
[Product Name]'s core feature scans publicly accessible business websites at a Customer's request and surfaces information appearing on those pages — such as a name, business email, phone number, or social-media link — so the Customer (a marketing agency or similar business) can prioritize and personalize B2B outreach.
If your name, business contact details, or social profile has appeared in a [Product Name] scan result, here is what that means:
- We only extract information that is already publicly published on the scanned page (for example, a "Contact us" or "Team" page, or a public LinkedIn/company profile link). We do not access private accounts, non-public data, or data behind a login.
- Our legal basis for this processing (where GDPR/UK GDPR applies) is legitimate interests — specifically, facilitating legitimate B2B sales outreach between businesses, using only data the underlying website owner chose to publish. We have assessed this against the interests, rights, and freedoms of the individuals concerned and consider it proportionate because: the data is already public, is limited to business contact details, and is not used for any purpose beyond enabling a business message.
- We do not collect or store special-category data (e.g., health, religion, ethnicity, political opinions) and instruct Customers not to attempt to use the Service to do so.
- You can ask us to stop processing your business contact information, or ask what we hold about you, at any time by emailing [support email] with the subject line "Data request" and the URL or company name concerned. We will action opt-out/erasure requests from individuals within the timeframe required by applicable law (generally within 30 days under GDPR/UK GDPR; without unreasonable delay under other frameworks), and will suppress that contact from future scans.
- Because this data is not collected directly from you, Article 14 GDPR (and equivalent UK GDPR provisions) require us to make certain information available to you even without direct contact — this policy, together with the opt-out mechanism above, is intended to satisfy that obligation. [Flag for legal review: depending on your scan volume, you may also need a proactive, not just reactive, transparency mechanism — discuss with counsel.]
7. US state privacy rights (CCPA/CPRA and similar state laws)
If you are a California resident (or resident of another US state with a comparable law), you may have the right to: know what personal information we have collected about you, request deletion, request correction, and opt out of the "sale" or "sharing" of personal information (we do not sell personal information). To exercise these rights, email [support email]. We will verify your request before acting on it.
8. Canada (PIPEDA)
We collect and use personal data in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) principles: accountability, identifying purposes, consent or another lawful basis, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and the ability to challenge compliance. Canadian individuals may contact us at [support email] to request access to, or correction of, their personal information.
9. Australia (Privacy Act / Australian Privacy Principles)
Where the Privacy Act 1988 (Cth) applies to our handling of your personal information, we aim to comply with the Australian Privacy Principles (APPs), including principles on collection, use and disclosure, data quality, security, and access/correction. Australian individuals may contact us at [support email].
10. When we act as a processor for a Customer
Where a Customer imports its own lead lists or CSVs containing personal data of its own contacts, we process that data as a processor on the Customer's instructions, under the terms of the Data Processing Addendum (available on request or at [insert DPA page link]), not as a controller in our own right for that specific data set.
11. Data retention
We retain Customer account and billing data for as long as the account is active and for a reasonable period afterward for legal, tax, and accounting purposes (typically up to 7 years for financial records, consistent with US and equivalent recordkeeping requirements). We retain scan results and third-party contact data for as long as reasonably necessary to deliver the Service, or until an opt-out/erasure request is actioned under Section 6.
12. Security
We use reasonable technical and organizational measures (such as encryption in transit, access controls, and restricted admin approval for new accounts) to protect personal data. No system is completely secure, and we cannot guarantee absolute security.
13. Children
The Service is a B2B product not directed at children, and we do not knowingly collect personal data from anyone under 16.
14. Cookies
See our separate Cookie Policy for details of cookies and similar technologies used on this website.
15. Changes to this policy
We may update this policy from time to time; material changes will be reflected by an updated "Last updated" date and, where required by law, notified to Customers.
16. Contact us / exercising your rights
Email [support email], or write to [Company Name], 30 N Gould St #42906, Sheridan, Wyoming 82801, US. EU/UK individuals also have the right to lodge a complaint with their local data protection supervisory authority (e.g., the ICO in the UK).
This document is a drafting template. Section 6 in particular sits in a genuinely contested area of data-protection law — enforcement against lead-generation and contact-scraping tools has increased in the EU/UK in recent years. Have this policy, and your actual scanning/contact-extraction practice, reviewed by a data-protection lawyer before scaling sales into the UK or EU. It is not a substitute for that review.