PeopleSearchFor Logo Dark Version

Legal

Privacy Policy

Overview

This policy explains what personal data PeopleSearchFor (the "Service") collects, why we collect it, how long we keep it, and the rights you have over it.

PeopleSearchFor is the controller of your personal data. You can contact us about anything in this policy at [email protected].

This policy describes the categories of personal data we collect and the purposes we use them for. Where we make a material change to how we handle personal data, we will update this policy as described in section 10.

1. Data we collect

Account data. Your email address, password (stored hashed, never in readable form), and any name, organisation or profile details you provide. If you belong to a workspace or organisation, we record which accounts belong to it and your role within it.

Billing data. Our payments are handled by Paddle as merchant of record. Paddle collects and processes your payment details, and we do not receive or store your card number. We receive a record of your subscription, plan, billing status, credit allowance and transaction history.

Usage data. Searches you run, the terms you submit, saved runs, projects, exports, credit consumption, and requests made under your account through our API, MCP connections or automated agents you have authorised.

Content you submit. Keywords, seed terms, project and workspace names, lists, notes and similar materials, as described in our Terms of Service.

Forms and communications. If you contact us, request support, subscribe to updates, register interest in a feature, respond to a survey, or otherwise submit a form on our site, we collect the details you enter and our correspondence with you. This typically includes your name, email address and message, and may include other details you choose to provide.

Technical data. IP address, browser and device type, operating system, pages visited, referring pages, interactions with the site, and approximate location derived from IP address. Some of this is collected only where you consent to analytics, as described in section 4.

2. Why we use it, and our lawful basis

We rely on performance of a contract to:

  • create and run your account, and provide the Service to you;
  • take payment, and manage subscriptions, credits and renewals; and
  • respond to your support enquiries and correspondence.

We rely on legitimate interests to:

  • keep the Service secure, and prevent fraud, abuse and misuse;
  • diagnose errors, maintain reliability and improve the Service;
  • respond to enquiries from people who do not hold an account with us; and
  • establish, exercise or defend legal claims.

We rely on consent to:

  • understand how the Service is used, through analytics; and
  • send marketing and newsletters, and to use advertising and measurement technologies.

We rely on legal obligation to meet tax, accounting, regulatory and other legal requirements.

Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights and freedoms, and concluded that it is not. You can ask us for further detail on that assessment.

Where we rely on consent, you can withdraw it at any time. Withdrawing consent does not affect processing carried out before you withdrew it.

3. Who we share it with

We do not sell your personal data.

We share personal data with service providers who process it on our behalf, under contract and only on our instructions. These fall into the following categories:

  • Payments and billing. Currently Paddle, as merchant of record, covering checkout, payment processing, tax, invoicing and related billing communications.
  • Product analytics. Currently PostHog, including session replay where you have consented.
  • Website analytics and advertising. Currently Google Analytics, together with any advertising or measurement platforms we use where you have consented to marketing.
  • Error monitoring and diagnostics. Currently Sentry.
  • Hosting, infrastructure and content delivery.
  • Email delivery, for transactional messages and, where you have consented, marketing.
  • Customer support, forms and communication tools.
  • Data sources and enrichment providers that supply search and related metrics used to produce results.

We may change providers within these categories, or add new ones, as the Service develops. Any new provider is engaged under equivalent contractual protections.

We may also disclose personal data where required by law or regulation, in response to a valid legal request, or to establish, exercise or defend legal claims. We may disclose data in connection with a merger, acquisition or sale of assets, in which case we will tell you before your data becomes subject to a different privacy policy.

Some providers are located outside the UK and EEA. Where personal data is transferred internationally, it is protected by an adequacy decision, or by standard contractual clauses or the UK International Data Transfer Agreement, together with additional safeguards where required.

We use a small number of cookies and similar technologies that are strictly necessary for the Service to work, such as keeping you signed in, maintaining security and remembering your privacy choices. These do not require consent.

Analytics, functional and marketing technologies load only after you have consented. Until you choose, Google Consent Mode is set to denied by default, and PostHog stores data in memory only rather than in cookies. You can change your preferences at any time through the privacy options on our site.

The categories are:

  • Necessary. Always on, and required for sign-in, security and basic functionality.
  • Functional. Remembering preferences and choices you have made, and error monitoring.
  • Performance and analytics. Understanding how the Service is used, including session replay.
  • Marketing and targeting. Advertising, remarketing and measurement, where used.

Where you are signed in, our product analytics identify your account using an internal customer reference. We deliberately send only the domain of your email address, not the address itself. Session replay is enabled only where you have consented to analytics.

Google Analytics is configured with IP anonymisation, and advertising and personalisation storage remain denied unless you consent to marketing.

If we introduce further tools in any of these categories, they will be governed by the same consent controls.

5. How long we keep it

  • Account data. For as long as your account is open, and up to 12 months after closure.
  • Searches, saved runs and content you submit. For as long as your account is open, or until you delete them.
  • Billing and transaction records. Seven years, to meet tax and accounting obligations.
  • Support and other correspondence. Up to three years.
  • Analytics data. Up to 14 months.
  • Error logs and diagnostics. Up to 90 days.
  • Marketing contact details. Until you unsubscribe or withdraw consent.

Where we no longer need personal data, we delete it or irreversibly anonymise it. Backups are overwritten on a rolling basis, so deleted data may persist in backups for a short period before being overwritten. We may keep data for longer where required by law, or where necessary to establish, exercise or defend legal claims.

6. Your rights

Under UK and EU data protection law you have the right to:

  • be informed about how your data is used, which is the purpose of this policy;
  • access a copy of the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased in certain circumstances;
  • restrict how we use your data;
  • object to processing carried out on the basis of legitimate interests;
  • object to direct marketing at any time;
  • receive your data in a portable format, and have it transmitted to another controller; and
  • withdraw consent at any time where we rely on it.

To exercise any of these, email [email protected]. We will respond within one month. There is no charge, unless a request is manifestly unfounded or excessive.

If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk, or to your local supervisory authority if you are in the EU. We would ask that you raise it with us first so we have the chance to put it right.

7. Marketing

Where you have consented, or where you are an existing customer and the law permits, we may send you product updates, newsletters or other marketing by email.

Every marketing email includes an unsubscribe link, and you can opt out at any time through that link, through your account settings, or by contacting us. Opting out of marketing does not stop transactional messages that are necessary to run your account, such as billing notices, security alerts and service announcements.

8. Security

We use HTTPS throughout, store passwords using industry-standard hashing, restrict internal access to personal data to those who need it, and keep payment card data entirely outside our systems by using Paddle as merchant of record.

No service can be completely secure, but we take technical and organisational measures appropriate to the risk. If a breach affects your rights and freedoms, we will notify you and the relevant supervisory authority as required by law.

9. Children

The Service is not intended for anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

10. Changes to this policy

We may update this policy from time to time, including as we add features or change the tools we use. If we make a material change to how we handle personal data, we will tell you by email or through the Service, and update the effective date above. Minor changes, such as naming a new provider within an existing category, will be reflected here without separate notice.

11. Contact

PeopleSearchFor Email: [email protected]

Privacy Policy | PeopleSearchFor