Privacy Policy
1. Overview and Commitment
FindForce.io ("we," "us," "our") is committed to protecting your privacy and maintaining the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our email verification service, browser extension, and website.
Our Data Commitment:
- We DO NOT sell your data to third parties
- We use data solely to provide and improve our service
- We implement industry-leading security measures
- We are fully responsible for the safety of your data
2. Information We Collect
Account Information
- Name and email address (for account creation)
- Company name and job title (optional)
- Billing information (processed securely through Stripe)
- Password (encrypted and never stored in plain text)
Usage Data
- Email addresses you verify through our service
- Verification results and confidence scores
- Browser extension usage patterns
- Website navigation and feature usage
- Technical information (IP address, browser type, device information)
Service Integration Data
- HubSpot CRM Integration: Contact data you choose to sync with your HubSpot account
- Chrome extension activity logs (for performance optimization)
- API usage statistics and rate limiting data
Automatically Collected Information
- Log files including timestamps, requests, and responses
- Cookies and similar tracking technologies
- Error reports and crash diagnostics
- Performance metrics and analytics data
3. How We Use Your Information
Core Service Provision
- Email Verification: Process and verify email addresses you submit
- Account Management: Maintain your account and subscription
- Customer Support: Respond to inquiries and provide technical assistance
- Billing and Payments: Process subscription fees and manage accounts
Service Improvement
- Product Development: Analyze usage patterns to enhance features
- Quality Assurance: Improve verification accuracy and performance
- Security Enhancement: Detect and prevent fraudulent activity
- Bug Fixes: Identify and resolve technical issues
Communication
- Service Updates: Notify you of important changes or new features
- Marketing Communications: Send relevant product updates (with consent)
- Security Alerts: Inform you of security-related issues
- Legal Notices: Communicate changes to terms or policies
Legal and Compliance
- Regulatory Compliance: Meet legal obligations and regulatory requirements
- Dispute Resolution: Investigate and resolve disputes or violations
- Safety and Security: Protect our users and prevent misuse
4. Data Sharing and Disclosure
We DO NOT Sell Your Data
We never sell, rent, or lease your personal information to third parties for marketing or commercial purposes.
Service Partners (Limited Sharing)
- HubSpot CRM: When you choose to integrate with HubSpot, we share only the contact data you authorize
- Stripe: Payment processing (they receive only billing information necessary for transactions)
- Email Verification Providers: Third-party APIs for enhanced verification (email addresses only, no account data)
- Cloud Infrastructure: AWS/Google Cloud for secure data storage and processing
Legal Requirements
We may disclose information when required by law:
- Court orders, subpoenas, or legal process
- Government investigations or regulatory compliance
- Protection of our rights, property, or safety
- Prevention of fraud or illegal activity
5. Data Retention and Deletion
Retention Periods
- Account Data: Retained while your account is active
- Verification Results: Stored for 30 days for performance optimization
- Usage Logs: Retained for 90 days for security and analytics
- Billing Records: Retained for 7 years for accounting and legal compliance
Data Deletion
- Account Deletion: All personal data deleted within 30 days of account closure
- Right to Erasure: EU users may request immediate data deletion
- Automated Purging: Verification data automatically deleted per retention schedule
- Secure Deletion: Data permanently removed using industry-standard methods
6. Data Security Measures
Technical Safeguards
- Encryption: All data encrypted in transit (TLS 1.3) and at rest (AES-256)
- Access Controls: Role-based access with multi-factor authentication
- Network Security: Firewalls, intrusion detection, and VPN requirements
- Regular Audits: Quarterly security assessments and penetration testing
Organizational Safeguards
- Employee Training: Regular privacy and security training for all staff
- Data Access Policies: Strict need-to-know basis for data access
- Incident Response: 24/7 monitoring and rapid response procedures
- Vendor Management: Security assessments for all third-party providers
7. Your Privacy Rights
GDPR Rights (EU Residents)
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data
- Right to Portability: Receive your data in a structured format
- Right to Restrict Processing: Limit how we process your data
- Right to Object: Opt-out of certain data processing activities
CCPA Rights (California Residents)
- Right to Know: Information about data collection and use
- Right to Delete: Request deletion of personal information
- Right to Opt-Out: Opt-out of sale of personal information (we don't sell data)
- Right to Non-Discrimination: Equal service regardless of privacy choices
General Rights (All Users)
- Email Preferences: Unsubscribe from marketing communications
- Account Controls: Update or delete account information
- Data Export: Download your verification history
- Support Access: Contact customer support for privacy concerns
8. Cookies and Tracking Technologies
Essential Cookies
- Authentication: Keep you logged in during sessions
- Security: Protect against cross-site request forgery
- Preferences: Remember your settings and preferences
Analytics Cookies
- Usage Analytics: Understand how you use our service (anonymized)
- Performance Monitoring: Identify and fix technical issues
- Feature Usage: Optimize product features based on usage patterns
9. International Data Transfers
Data Processing Locations
- Primary: European Union (GDPR-compliant infrastructure)
- Future Expansion: United States (potential deployment based on power user demand)
- Verification APIs: EU-based network with global reach for optimal performance
Transfer Safeguards
- EU-First Approach: Primary data processing within EU jurisdiction
- Standard Contractual Clauses: EU-approved transfer mechanisms for any future international transfers
- Adequacy Decisions: Transfers only to countries with adequate protection
- Security Measures: Enhanced protections for any international transfers
10. Children's Privacy
Age Restriction: Our service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware of data collection from a child, we will delete it immediately.
11. Privacy Policy Updates
Change Notification
- Material Changes: 30-day advance notice via email
- Minor Updates: Website notification and updated effective date
- Version History: Previous versions available upon request
Continued use of our service after changes constitutes acceptance of the updated Privacy Policy.
12. Contact Information
Privacy Inquiries
- Email: privacy@findforce.io
- Response Time: 48 hours for general inquiries, 72 hours for complex requests
- Data Subject Requests: privacy@findforce.io with "Data Request" in subject line
Data Protection Officer
- Email: dpo@findforce.io
- Address: Harju maakond, Tallinn, Kesklinna linnaosa, Kiriku tn 6, 10130, Estonia
Last Review Date: Jun 22, 2025
Next Review Date: Jun 22, 2026
This Privacy Policy demonstrates our unwavering commitment to protecting your privacy while providing exceptional email verification services. We regularly review and update our practices to ensure the highest standards of data protection and user privacy.