Legal

Privacy Policy

How Find New Customer handles personal data — both advertiser account data and the customer data in our market databases.

Version 1.0 · Effective 1 January 2026

1. Two kinds of personal data

This policy covers two distinct relationships, and it is important to keep them apart.

  • Advertiser data — the personal data of the people who register and use an advertiser account. We are the controller of this data.
  • Customer data — the contact records held in our India, USA and Europe market databases, used to introduce advertisers to potential customers. Our role and legal basis here are set out in section 4 and in the Data Source Policy.

2. Advertiser data we process

  • Identity and contact: name, business email, phone number, country.
  • Business profile: business name, website, type, industry, a description of what your business does, target markets, timezone.
  • Billing: billing country, currency, billing address, tax registration where supplied, invoices and payment status. Card details are handled by our payment provider and are never stored by us.
  • Account activity: sign-in times, actions taken in the platform, IP address (hashed where used for security), and audit records of administrative changes.
  • Connected mailboxes: the mailbox address, provider account identifier and OAuth tokens, encrypted at rest. We do not store mailbox passwords.

3. Why we process advertiser data

PurposeBasis
Providing the platform and your subscriptionPerformance of a contract
Billing, invoicing and tax recordsLegal obligation and contract
Security, abuse prevention and audit loggingLegitimate interests
Service notifications about your account and campaignsContract
Product improvement surveys and marketing emailConsent, withdrawable at any time

4. Customer data in our market databases

Our market databases contain business contact records used to introduce advertisers to potential customers. We process this data only where we are permitted to do so, and we apply the controls described below regardless of jurisdiction.

  • Advertisers never receive bulk access. There is no export, no download and no enumeration endpoint.
  • An advertiser is not told how many customers exist for any category, state or city.
  • Contact details are shown to an advertiser only for a customer who engaged with that advertiser’s campaign.
  • An address that unsubscribes is suppressed for that advertiser immediately. An address that hard-bounces or complains is suppressed platform-wide.
  • Any individual can ask us for access to, or deletion of, their record through the Data Rights pages. We verify identity before acting on a deletion request.

5. Tracking in campaigns

Links in advertiser campaigns are rewritten to signed tracking links so a click can be attributed to a campaign and a recipient. We deliberately collect the minimum needed for that.

  • We record the campaign, the advertiser, the market, an internal recipient reference, the link, and the time of the click.
  • We record a coarse user-agent family (for example "ios" or "chrome") and a hashed IP address. We do not store raw IP addresses against clicks.
  • We do not place tracking pixels for open tracking.
  • Email addresses never appear in tracking URLs.

6. Sharing

  • Infrastructure and database hosting (Supabase / PostgreSQL).
  • Payment processing (Razorpay), which receives the billing data needed to take payment.
  • Your own connected email provider (Google or Microsoft), which sends your campaigns.
  • Professional advisers, and authorities where we are legally required to disclose.
  • We do not sell personal data.

7. International transfers

The platform operates across India, the USA and Europe, and data may be processed outside your country. Where personal data protected by European law is transferred, we rely on appropriate safeguards including Standard Contractual Clauses. [Confirm the transfer mechanism and hosting regions with counsel before launch.]

8. Retention

Retention periods are configured per record type and reviewed by the operator. Current defaults:

Record typeDefault retention
Click and delivery events3 years
Allocation history3 years (must exceed the 180-day no-repeat window)
Bounce and suppression records7 years — retained as evidence of suppression
Audit logs7 years
Invoices and billing recordsAs required by tax law
Advertiser account dataFor the life of the account, then per retention rules

9. Your rights

Depending on where you are, you may have rights to access, correct, delete, restrict or object to the processing of your personal data, to portability, and to withdraw consent. Advertisers can exercise most of these from account settings or by emailing support@findnewcustomer.com.

If you are in our customer database rather than an advertiser, use the Customer Data Request page. We verify identity before acting on deletion, because acting on an unverified request is itself a privacy risk.

10. Security

  • Role-based access control and row-level security in the database.
  • OAuth tokens and provider credentials encrypted at rest with AES-256-GCM.
  • Secrets held in environment configuration, never in source control.
  • Audit logging of administrative actions.
  • Rate limiting on authentication, tracking and upload endpoints.

11. Contact

Privacy enquiries: support@findnewcustomer.com. Postal: [Legal entity name], [Registered address]. [Appoint and name a Data Protection Officer or EU/UK representative if required.]

Questions about this document? Email support@findnewcustomer.com. For billing matters, support@findnewcustomer.com.