Prospektr
Legal

Privacy Policy

Last updated: April 26, 2026

1. Introduction

This Privacy Policy explains how Prospektr™ ("we," "us") collects, uses, stores, and shares information when you use our service at prospektr.co(the "Service"). It applies to information about our customers and to information about the third-party businesses our customers research through the Service.

We aim to keep this policy plain-language. If anything is unclear, email privacy@prospektr.co.

2. What we collect

From you (the customer)

  • Account info: email address, name (optional), and profile metadata.
  • Workspace settings: business type, target customer types, geographic scope, and quality preferences you configure.
  • Billing info: handled by Stripe — we receive only the customer ID, subscription status, and last-four card digits. We never see or store full card numbers.
  • Usage telemetry: sign-in timestamps, error logs, and aggregate metrics needed to operate the Service.

About third-party businesses

Prospektr discovers and classifies publicly listed businesses using Google Places and our customers' defined criteria. The data we store about each prospect is information that is publicly available from their website or Google Places listing — name, address, phone, website URL, surfaced email addresses, and our classifier's reasoning. We do not collect personal data about individual employees beyond what they themselves publish.

3. How we use it

  • To provide the Service (run searches, classify prospects, send digests).
  • To bill you for your subscription.
  • To communicate about your account (sign-in links, billing notices, security alerts).
  • To improve the Service and our classifier accuracy via aggregated, anonymized usage patterns.
  • To comply with legal obligations.

We do not sell your data, train AI models on your Customer Data, or use your data for advertising.

4. Sharing & sub-processors

We use a small set of third-party services to operate Prospektr. These sub-processors receive only the data necessary to perform their function:

Sub-processorPurposeData sharedLocation
VercelApplication hostingAll Service traffic (transit only; no persistence)USA
NeonPostgres databaseCustomer Data + workspace settingsUSA
StripeSubscription billingEmail, name, card details (Stripe-hosted)USA
ResendTransactional emailEmail address + email content (sign-in links, digests)USA
Anthropic (Claude)Prospect classificationProspect website text + business nameUSA
Google Places APIBusiness discoverySearch query terms (no customer-identifying data)USA

We may also disclose information when legally required (subpoena, court order, law enforcement). We will give you notice when permitted by law.

5. Cookies & similar technologies

We use a small number of cookies, all strictly necessary for operation:

  • authjs.session-token — keeps you signed in. HTTP-only, secure, expires after 30 days.
  • prospektr-cookie-consent— records your cookie banner choice so we don't show it again.

We do not use advertising cookies, third-party trackers, or cross-site analytics that profile individual visitors. Aggregate analytics (page-view counts, no PII) may be added in the future and will be disclosed here.

6. Data retention

  • Account & workspace data: retained while your subscription is active.
  • After cancellation: retained for 30 days in case you reactivate, then permanently deleted from production databases.
  • Backups: rolling 35-day window. Data in backups is overwritten on schedule.
  • Billing records: retained 7 years per US tax regulations.

7. Security

We use industry-standard security practices including TLS encryption in transit, encryption at rest (Neon-managed), HTTP-only cookies for sessions, and least-privilege access controls. See our Security overview for more detail.

8. Your rights

Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. To exercise these rights, email privacy@prospektr.co.

We respond to verified requests within 30 days. Most data is self-serve via your dashboard's account settings.

9. Children

Prospektr is a B2B service not directed to children. We do not knowingly collect data from anyone under 16.

10. Changes

Material changes to this policy will be communicated by email at least 14 days before they take effect.

11. Contact

Privacy questions: privacy@prospektr.co
Data subject requests: privacy@prospektr.co
Mailing address: Busy Screenprinting, Florida, USA.