Legal
Privacy Policy
This Privacy Policy explains how Vindispensable LLC (“Account Finder”, “we”, “us”) collects, uses, and shares information when you use the Account Finder application and website (the “Service”). Account Finder is a business-to-business prospecting tool; we designed it to collect the minimum personal data needed to operate.
This policy is written for account holders (our customers). Separately, the Service processes information about third-party businesses and individuals that appear in search results (“prospects”). How we handle that data is described in Section 12 and in our standalone Prospect Data Notice.
1. Information we collect
Google account information
You sign in with Google. At sign-in we request only your basic profile: name, email address, and profile picture. If you later choose to export results to Google Sheets, we additionally request permission to create spreadsheets in your Google Drive (see Section 3).
Usage information
- Search parameters you enter (locations, states, filters, brand context) and summary metadata about results.
- A usage ledger of credits granted and consumed, tied to your account email.
- Technical logs (timestamps, request status, and IP address) for reliability, rate limiting, and abuse prevention.
Customer Data you upload or connect
You may upload a spreadsheet (CSV or Excel), connect a Google Sheet, or connect a CRM so that your own accounts appear on the map alongside search results. We store the records you provide — typically business name, address, and optionally phone, email, and any other columns in your file — together with coordinates we derive by geocoding the address. This is your “Customer Data” under the Terms; you own it, and we process it on your behalf to provide the Service.
Customer Data is stored in your own workspace, keyed to your account, and is not visible to other customers of the Service. Addresses are sent to Google's Geocoding API to obtain coordinates. We may derive aggregated, de-identified statistics that cannot identify you, your customers, or any individual (see Terms §8a). Please do not upload special-category or sensitive personal data; the Service is not designed for it. You can export or delete any uploaded dataset at any time from within the Service.
Brand profile
If you create a brand profile, we store the fields and free text you provide and an AI-normalized summary of them. See Section 4 for how this is processed.
Billing information
Payments are processed by Stripe. We receive your subscription status, plan, and billing events; we never see or store your full card number.
We do not knowingly collect data from anyone under 18, and the Service is not directed to children.
2. Legal bases for processing
If you are located in the EEA, UK, or another jurisdiction with a similar framework, we rely on the following lawful bases under Article 6 of the GDPR:
| Processing activity | Data | Lawful basis (GDPR Art. 6) |
|---|---|---|
| Account creation & authentication | Google profile | 6(1)(b) contract |
| Billing & subscription management | Stripe billing/subscription status | 6(1)(b) contract; 6(1)(c) legal obligation (tax/accounting) |
| Search execution & credit metering | Search parameters, usage ledger | 6(1)(b) contract |
| Security, abuse prevention, fraud detection | Technical logs, IP address | 6(1)(f) legitimate interest |
| Customer Data (uploaded/connected) | Whatever you upload | Processor role — the basis is yours; governed by our data-processing terms |
| Prospect / third-party account data | Business and some individual data from public sources and in-house curated datasets | 6(1)(f) legitimate interest (see Section 12 & Prospect Data Notice) |
| AI enrichment (fit scores, rationales, brand normalization) | Search context, brand profile | 6(1)(f) legitimate interest |
| Service-related email | Email address | 6(1)(b) contract (not marketing) |
3. How we use information
- To operate the Service: authentication, running searches, metering credits, exports.
- To provide support and respond to your requests.
- To secure the Service, prevent abuse, and enforce our Terms.
- To send service-related notices (billing, security, material changes). We do not send marketing email without your consent.
We do not sell personal information, and we do not use it for third-party advertising. This is an absolute commitment about selling or renting data as a product — see Section 6 for what it means (and does not mean) if the business itself is ever acquired.
4. AI processing
Some features send your search context — for example, your brand description and free-text brand profile, and venue names — to large-language-model providers to generate fit scores, rationales, outreach drafts, and to normalize your brand profile on save. The providers are Anthropic (primary) and Google (Gemini) as an automatic fallback when the primary is unavailable. We send only what the feature needs; we do not send your Google profile data or Google Drive content to these providers.
Anthropic, our primary AI provider, is contractually committed not to use your data to train its models. Google's Gemini API is used only as an automatic fallback when Anthropic is briefly unavailable, and requests that fail over to it are governed by Google's own API terms, which do not carry the same no-training commitment — so a small share of requests may be subject to Google's standard data-handling terms for that API rather than a guarantee it is never used for training.
Deletion reach. Deleting your brand profile removes our stored copy immediately. Content already transmitted to a provider as part of a completed API call is processed under that provider's own data-use terms and is not separately retrievable by us.
5. Google user data and the Limited Use policy
Account Finder's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- Profile data (name, email, picture) is used only to create and display your session and account records.
- Google Sheets / Drive access is requested only when you click “Export to Google Sheets”, is limited to creating files on your behalf, and can only access files the app itself creates — never your existing Drive files.
- We do not transfer Google user data to third parties except as necessary to provide the feature you requested, to comply with law, or as part of a merger or acquisition with equivalent privacy commitments.
- We do not use Google user data for advertising, and we do not allow humans to read it except with your explicit consent, for security purposes, to comply with law, or where aggregated and anonymized.
- We do not use Google user data to train artificial-intelligence or machine-learning models.
You can revoke Account Finder's access to your Google account at any time at myaccount.google.com/permissions.
6. How we share information — sub-processors
We share personal data only with service providers who process it on our behalf:
| Sub-processor | Purpose |
|---|---|
| Vercel | Hosting |
| Supabase | Database |
| Upstash | Rate limiting |
| Sign-in, Maps/Places, exports you request, Gemini AI fallback | |
| Stripe | Payments |
| Anthropic | AI processing |
| Hunter.io | Business-email contact lookup (outreach reveal) |
We do not sell or rent personal information as a product, and we never will as a matter of routine business — this is separate from, and not weakened by, the paragraph below. We may also disclose information if required by law or to protect rights and safety.
Business transfers. If Account Finder is acquired, merges with another company, or sells substantially all of its assets, personal information may transfer to the successor as part of that transaction, with notice to you. This is a business transfer, not a sale of your data: the data stays attached to the business and the commitments in this Privacy Policy, rather than being detached and sold on its own as a mailing list or dataset — the successor inherits our obligations to you along with the data and cannot simply resell it standalone. This reflects how both US and EU/UK privacy law already treat a whole-business transfer: it is excluded from the definition of a “sale” under the CCPA/CPRA (Cal. Civ. Code §1798.140(ad)(2), see Section 10), and under the GDPR a successor steps into the prior controller's role and obligations rather than receiving data as a fresh, unrestricted disclosure. Any successor must handle your information under this Privacy Policy's commitments, including the promise never to sell it, unless and until you are given notice of a materially different policy under Section 13.
7. Cookies
We use two cookies, both required for the Service to function: a session cookie (authentication; expires when you sign out or your session ends) and a locale cookie (remembers your language choice; expires after 1 year). Neither is used for advertising or cross-site tracking. As strictly-necessary cookies, they do not require your consent under applicable cookie law, so we do not show a cookie banner. If we ever add analytics or third-party tracking, we will update this section and obtain consent where required.
8. Data retention
- Account and usage-ledger records are kept while your account is active and for up to 24 months after, for billing and audit purposes, unless law requires longer.
- OAuth tokens are kept only while your session or grant is active and are deleted when you revoke access.
- Technical logs, including IP address, are retained for a limited rolling window used for reliability and abuse prevention, then deleted.
- Uploaded or connected Customer Data is retained until you delete the dataset or your account. Deletion removes records from active systems promptly and from routine backups within 30 days. On account termination we delete or de-identify Customer Data within 30 days. Aggregated, de-identified datasets that cannot identify you or any individual may be retained (Terms §8a); we commit not to re-identify them.
You can request deletion of your account data at any time (Section 10), and we will delete it except where retention is legally required.
9. International transfers
The Service is operated from the United States, and data is processed on US-based infrastructure. Where we transfer personal data from the EEA, UK, or similar jurisdictions to the United States, we use recognised safeguards — such as reliance on a provider's own EU-US Data Privacy Framework certification where available, or the EU Standard Contractual Clauses incorporated through a provider's own data-processing agreement — as required.
10. Your rights
Depending on where you live (including under the GDPR/UK GDPR and the CCPA/CPRA), you may have rights to access, correct, delete, port, and object to or restrict processing of your personal data. To exercise them, email privacy@accountfinder.app from the address associated with your account. We respond within the timelines required by law, and we do not discriminate against you for exercising your rights.
California (CCPA/CPRA). We do not sell or share your personal information, as those terms are defined by the CCPA/CPRA — a transfer of data to a successor as part of a merger, acquisition, or asset sale is a business transfer, not a “sale,” under the statute (Cal. Civ. Code §1798.140(ad)(2)) and under Section 6 above. If you are a California resident, you can exercise your rights, including any applicable right to opt out of sale or sharing, by emailing privacy@accountfinder.app.
11. Security
We use industry-standard safeguards: encryption in transit (TLS), encrypted storage with our hosting providers, scoped API keys, and access limited to those who need it to operate the Service. No system is perfectly secure; if a breach affecting your personal data occurs, we will notify you as required by law. Report security issues to security@accountfinder.app.
12. Prospect (third-party) data
To provide the Service, we collect and process information about businesses, and in some cases business-registered individuals (such as licensed professionals), from public sources: state and federal licence/registry filings (for example TTB, state ABC boards, professional licence boards, IRS tax-exempt filings, SBA loan records), map/directory listings (Google Places, OpenStreetMap), and USDA/CMS/NCES public datasets, together with proprietary curated datasets we compile in-house from such publicly available information. We combine this with limited AI-generated commentary for our customers, who are sales representatives evaluating whether to contact a business.
For this processing we are the controller (not a processor acting on a customer's instructions), and our lawful basis is legitimate interests (Art. 6(1)(f)) — enabling lawful B2B sales intelligence from publicly available business information, balanced against the rights of the people concerned. We do not make decisions producing legal or similarly significant effects about a prospect, and we do not sell this data. Full detail, including your rights and how to opt out, is in our standalone Prospect Data Notice.
13. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice (for example, by email or an in-app notice) before they take effect. The “Last updated” date above reflects the current version.
14. Contact
Vindispensable LLC
418 Broadway STE N, Albany, NY 12207, USA
Privacy requests: privacy@accountfinder.app
General: hello@accountfinder.app