1. Introduction
This Privacy Policy explains how Prospektr™ ("we," "us") collects, uses, stores, and shares information when you use our service at prospektr.co(the "Service"). It applies to information about our customers and to information about the third-party businesses our customers research through the Service.
We aim to keep this policy plain-language. If anything is unclear, email privacy@prospektr.co.
2. What we collect
From you (the customer)
- Account info: email address, name (optional), and profile metadata.
- Workspace settings: business type, target customer types, geographic scope, and quality preferences you configure.
- Billing info: handled by Stripe — we receive only the customer ID, subscription status, and last-four card digits. We never see or store full card numbers.
- Usage telemetry: sign-in timestamps, error logs, and aggregate metrics needed to operate the Service.
About third-party businesses
Prospektr discovers and classifies publicly listed businesses using Google Places and our customers' defined criteria. The data we store about each prospect is information that is publicly available from their website or Google Places listing — name, address, phone, website URL, surfaced email addresses, and our classifier's reasoning. We do not collect personal data about individual employees beyond what they themselves publish.
3. How we use it
- To provide the Service (run searches, classify prospects, send digests).
- To bill you for your subscription.
- To communicate about your account (sign-in links, billing notices, security alerts).
- To improve the Service and our classifier accuracy via aggregated, anonymized usage patterns.
- To comply with legal obligations.
We do not sell your data, train AI models on your Customer Data, or use your data for advertising.
4. Sharing & sub-processors
We use a small set of third-party services to operate Prospektr. These sub-processors receive only the data necessary to perform their function:
| Sub-processor | Purpose | Data shared | Location |
|---|---|---|---|
| Vercel | Application hosting | All Service traffic (transit only; no persistence) | USA |
| Neon | Postgres database | Customer Data + workspace settings | USA |
| Stripe | Subscription billing | Email, name, card details (Stripe-hosted) | USA |
| Resend | Transactional email | Email address + email content (sign-in links, digests) | USA |
| Anthropic (Claude) | Prospect classification | Prospect website text + business name | USA |
| Google Places API | Business discovery | Search query terms (no customer-identifying data) | USA |
We may also disclose information when legally required (subpoena, court order, law enforcement). We will give you notice when permitted by law.
5. Cookies & similar technologies
We use a small number of cookies, all strictly necessary for operation:
authjs.session-token— keeps you signed in. HTTP-only, secure, expires after 30 days.prospektr-cookie-consent— records your cookie banner choice so we don't show it again.
We do not use advertising cookies, third-party trackers, or cross-site analytics that profile individual visitors. Aggregate analytics (page-view counts, no PII) may be added in the future and will be disclosed here.
6. Data retention
- Account & workspace data: retained while your subscription is active.
- After cancellation: retained for 30 days in case you reactivate, then permanently deleted from production databases.
- Backups: rolling 35-day window. Data in backups is overwritten on schedule.
- Billing records: retained 7 years per US tax regulations.
7. Security
We use industry-standard security practices including TLS encryption in transit, encryption at rest (Neon-managed), HTTP-only cookies for sessions, and least-privilege access controls. See our Security overview for more detail.
8. Your rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. To exercise these rights, email privacy@prospektr.co.
We respond to verified requests within 30 days. Most data is self-serve via your dashboard's account settings.
9. Children
Prospektr is a B2B service not directed to children. We do not knowingly collect data from anyone under 16.
10. Changes
Material changes to this policy will be communicated by email at least 14 days before they take effect.
11. Contact
Privacy questions: privacy@prospektr.co
Data subject requests: privacy@prospektr.co
Mailing address: Busy Screenprinting, Florida, USA.