Exactly what we collect, why, who we share it with, and how to exercise your rights.
Last updated: April 27, 2026
Effective: April 27, 2026
At a glance
- We only collect what we need to run the service — no more.
- We do not sell your personal data and we do not show ads.
- All primary infrastructure is hosted in the EU (Hetzner / AWS Frankfurt).
- We set exactly 3 cookies, all strictly necessary. No tracking cookies.
- You can delete your account and all associated data at any time from your profile settings.
- Our Data Protection Officer is reachable at dpo@privacyfetch.com.
PrivacyFetch is a company privacy directory operated from Romania.
We organize the data we collect into the categories below. Each category lists the specific fields, where the data comes from, and the legal basis under the GDPR.
| Field | Source | Legal basis |
|---|---|---|
| Name | You provide it, or from OAuth provider | Contract — Art. 6(1)(b) |
| Email address | You provide it, or from OAuth provider | Contract — Art. 6(1)(b) |
| Password | You set it (hashed with bcrypt, cost factor 12 — we never store or see the plaintext) | Contract — Art. 6(1)(b) |
| Profile picture | From your OAuth provider (Google) | Contract — Art. 6(1)(b) |
When you sign in with Google, GitHub, or LinkedIn, we store a connection record:
| Field | Notes |
|---|---|
| Provider name | google, github, or linkedin-openid |
| Provider user ID | Your unique ID at the provider |
| Access token | Encrypted at rest |
| Refresh token | Encrypted at rest, nullable |
| Scopes | The permissions you granted (e.g. openid, profile, email) |
| Expiry | When the token expires |
Legal basis: Contract — Art. 6(1)(b). Retention: Until you revoke the connection or delete your account.
| Field | Notes |
|---|---|
| Session ID | Random identifier |
| IP address | IPv4 or IPv6 |
| User agent | Your browser's User-Agent string (truncated to 255 characters) |
| Last activity | Timestamp of your last request |
Legal basis: Legitimate interest — Art. 6(1)(f) (security, fraud prevention). Retention: 120 minutes, then automatically swept.
Payments are processed by Stripe. PrivacyFetch never sees or stores your full card number or CVC.
| Stored by PrivacyFetch | Stored by Stripe |
|---|---|
| Stripe customer ID | Full card number |
| Payment method type (e.g. "card") | CVC / CVV |
| Last 4 digits of your card | Billing address |
| Trial end date (if applicable) | Full transaction history |
Legal basis: Contract — Art. 6(1)(b). Stripe is PCI DSS Level 1 certified.
If you use our developer API, each authenticated request is logged:
| Field | Notes |
|---|---|
| Request ID | A unique ULID per request |
| Endpoint and method | e.g. GET /api/v1/companies |
| Status code | HTTP response code |
| Response time | Milliseconds |
| Request / response size | Bytes |
| IP address | Your IP at the time of the request |
| Country code | 2-letter code derived from the Cloudflare CF-IPCountry header |
| User agent | Truncated to 255 characters |
| Cache hit | Whether the response was served from cache |
| Billable | Whether the request counts toward your quota |
Legal basis: Legitimate interest — Art. 6(1)(f) (billing, rate limiting, abuse prevention). Retention: 90 days, then automatically deleted. Aggregated daily rollups (non-personal) are retained indefinitely.
| Field | Notes |
|---|---|
| Notification settings | Which email notifications you opt into (score changes, policy changes, etc.) |
| Digest frequency | How often you receive digest emails (daily, weekly, or off) |
| Saved companies | Which companies you've bookmarked in the directory |
Legal basis: Contract — Art. 6(1)(b).
If you create or join a team:
| Field | Notes |
|---|---|
| Team name | Set by the team owner |
| Membership | Your user ID linked to the team |
| Role | Owner, admin, or member |
| Invitations | Invitee email, role, expiry token |
Legal basis: Contract — Art. 6(1)(b).
If you claim a company profile, we store:
| Field | Notes |
|---|---|
| Verification email | A company domain email you provide (e.g. privacy@example.com) |
| Verification token | A one-time token sent to that email |
| Expiry | Token expires after 24 hours |
Legal basis: Contract — Art. 6(1)(b). Retention: Until verified or expired, then until account deletion.
| Field | Notes |
|---|---|
| Email address | Provided when you sign up for the newsletter or contact form |
| Name | Optional |
| Source | Where you signed up (e.g. landing page, footer) |
This data is synced to Resend, our email delivery provider, so we can send you emails.
Legal basis: Consent — Art. 6(1)(a). You can unsubscribe at any time via the link in any email.
We log changes to certain models (e.g. company profile edits) for accountability:
| Field | Notes |
|---|---|
| What changed | Model type and ID |
| Who changed it | Your user ID |
| Before / after values | JSON diff of modified fields |
| Timestamp | When the change occurred |
Legal basis: Legitimate interest — Art. 6(1)(f) (accountability, debugging). Retention: 365 days.
We want to be explicit about what we don't do:
| Purpose | Data used | Legal basis |
|---|---|---|
| Provide the service (authentication, personalization, features) | Account, connections, preferences, teams | Contract — Art. 6(1)(b) |
| Process payments | Payment data (via Stripe) | Contract — Art. 6(1)(b) |
| Send transactional emails (password resets, claim verification, notifications) | Email address | Contract — Art. 6(1)(b) |
| Enforce API rate limits, detect abuse, and bill usage | API usage logs | Legitimate interest — Art. 6(1)(f) |
| Maintain security and prevent fraud | Session data, IP address | Legitimate interest — Art. 6(1)(f) |
| Monitor for data breaches affecting your email | Email address sent to HaveIBeenPwned | Consent — Art. 6(1)(a) |
| Send newsletter and marketing emails | Contact data (email, name) | Consent — Art. 6(1)(a) |
| Website analytics (when consented) | Anonymized IP, pages visited via Google Tag Manager | Consent — Art. 6(1)(a) |
| Maintain audit trail of data changes | Activity logs | Legitimate interest — Art. 6(1)(f) |
We set exactly 3 cookies, all strictly necessary. We do not set any tracking, advertising, or analytics cookies.
| Cookie name | Purpose | Duration |
|---|---|---|
privacyfetch-session | Maintains your authenticated session | 2 hours |
XSRF-TOKEN | Protects against cross-site request forgery | 2 hours |
cookie_consent | Remembers your cookie consent acknowledgment | 1 year |
For full technical details, see our Cookie Policy.
| Service | Purpose | Data shared | Location | Safeguards |
|---|---|---|---|---|
| Hetzner / AWS | Infrastructure hosting | All stored data | EU (Frankfurt) | Data remains in EU |
| Stripe | Payment processing | Name, email, card details | US | EU SCCs, PCI DSS Level 1 |
| Resend | Email delivery | Email address, name | US | EU SCCs, DPA |
| Google (OAuth) | Authentication | Name, email, profile picture | US | EU SCCs |
| GitHub (OAuth) | Authentication | Username, email | US | EU SCCs |
| LinkedIn (OAuth) | Authentication | Name, email | US | EU SCCs |
| HaveIBeenPwned | Breach monitoring | Email address | AU / US | Consent-gated, minimal data |
| Google Tag Manager | Analytics | Anonymized IP, pages visited | US | Consent-gated (default denied), EU SCCs |
| Bunny Fonts | Font delivery | IP address (ephemeral, not stored) | EU | No PII retained |
These services analyze publicly available company information. They never receive your personal data.
| Service | Purpose | Data shared |
|---|---|---|
| OpenAI | Privacy policy analysis | Company policy text |
| Google Gemini | Policy analysis (fallback) | Company policy text |
| Firecrawl | Web scraping | Company URLs |
| BrandFetch | Logo and branding data | Company domains |
| Serper | Web search | Company names and domains |
| Recraft | Image generation | Prompt text (no personal data) |
Our primary infrastructure is hosted in the European Union (Hetzner and AWS Frankfurt, eu-central-1).
Some third-party services are based in the United States. For each US-based service listed above, we rely on EU Standard Contractual Clauses (SCCs) per GDPR Article 46(2)(c) to ensure your data receives an adequate level of protection outside the EU.
Where a service participates in the EU–US Data Privacy Framework, that provides an additional safeguard.
HaveIBeenPwned is operated from Australia and the United States. We only send your email address to this service if you explicitly enable breach monitoring, and the data is minimal.
| Data category | Retention period | How it's deleted |
|---|---|---|
| User account | Until you delete it | Account deletion cascades to all associated records |
| Sessions | 120 minutes | Automatically swept by the framework |
| Password reset tokens | 60 minutes | Automatically expired |
| OAuth connections | Until revoked or account deleted | Cascade on account deletion |
| API usage logs | 90 days | Automatically pruned |
| API daily rollups | Indefinite | Aggregated and non-personal |
| Activity logs | 365 days | Automatically pruned |
| Breach monitoring cache | 24 hours | Automatically expired |
| Team invitations | Until accepted or expired | Cascade on account deletion |
| Payment data at Stripe | Per Stripe's retention policy | Managed by Stripe |
| Newsletter contacts | Until you unsubscribe | Unsubscribe link in every email, or email DPO |
You have the following rights regarding your personal data. We will respond to any request within 30 calendar days (extendable by 60 days for complex requests, per Art. 12(3)).
You can view your account data in your profile settings. For a complete copy of all data we hold about you, email dpo@privacyfetch.com.
You can edit your name and other profile details directly in your profile settings.
You can delete your account from your profile settings at any time. Deletion immediately cascades to all associated records: OAuth connections, API tokens, API usage logs, activity logs, team memberships, company claims, and cost logs.
Alternatively, email dpo@privacyfetch.com and we will delete your account within 30 days.
We do not currently offer an automated data export feature. You may request a machine-readable export of your personal data by emailing dpo@privacyfetch.com. We are working on a self-service export feature and will update this policy when it is available.
Contact dpo@privacyfetch.com to request that we restrict the processing of your personal data.
You may object to any processing based on legitimate interest (API usage logging, activity logging, security monitoring) by contacting dpo@privacyfetch.com. We will cease the processing unless we demonstrate compelling legitimate grounds.
Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
You may file a complaint with the Romanian supervisory authority:
ANSPDCP B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, București, Romania anspdcp.ro
You may also contact the supervisory authority in your EU member state of residence.
If you are a California resident:
To exercise your rights under the CCPA (right to know, right to delete, right to correct), email dpo@privacyfetch.com. We will not discriminate against you for exercising these rights.
PrivacyFetch is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If we learn that we have collected personal data from a child under 16, we will delete it promptly. If you believe a child under 16 has provided us with personal data, please contact dpo@privacyfetch.com.
We implement the following technical and organizational measures:
No system is 100% secure. We cannot guarantee absolute security, but we are committed to protecting your data with industry-standard practices and to notifying you promptly in the event of a breach affecting your personal data, as required by GDPR Articles 33 and 34.
We may update this policy from time to time. When we make material changes, we will:
Non-material clarifications (e.g. fixing typos, improving readability) may be made without notice.
Previous versions of this policy are available upon request from dpo@privacyfetch.com.
See also: Terms of Service · Cookie Policy
Related legal documents