Privacy Policy

How we handle personal information, and the rights you have.

Effective Date: June 13, 2026 | Last Updated: June 13, 2026

Who this policy covers

Hypertouch operates a lead intelligence platform and related services. This policy explains how we handle personal information for two groups:

  • A. Customers and website visitors who create an account, contact us, or browse our site.
  • B. Business professionals whose contact and employment information we compile into our database and make available to our customers for business-to-business outreach and research.

1. Information We Collect

A. From customers and visitors

  • Account information: name, business email, company, and login credentials (passwords are stored using one-way hashing).
  • Billing information: plan, transaction history, and billing details. Card payments are processed by our payment processor; we do not store full card numbers.
  • Content you provide: data, lists, suppression files, brand materials, and other Customer Data you upload or generate.
  • Usage and device data: log data, IP address, browser and device information, and actions taken in the Services.
  • Communications: messages you send us, including support and contact-form submissions.

B. Business contact data in our database

For our lead intelligence database, we compile information about business professionals, which may include:

  • Name and professional identifiers, including business email, business phone or mobile number, and a LinkedIn or other professional profile URL.
  • Employment information, such as job title, seniority, function, and current employer.
  • Company information associated with the contact, such as industry (NAICS/SIC), size, revenue range, location, technologies used, hiring activity, funding, and growth signals.

This database currently focuses on United States and Canadian business contacts.

2. Where the Information Comes From

  • Directly from you when you register, contact us, or use the Services.
  • Automatically through cookies and similar technologies when you use our site (Section 7).
  • From publicly available and commercial sources for the business contact data in our database, such as business directories, professional networks, public filings and registries, and other commercial sources. This data is compiled through a single, provenance-tracked pipeline and deduplicated; it is not pooled from data co-ops or blended from unattributed third-party lists, and the origin of each record is retained.

The business contact data in our database is professional information sourced from publicly available and commercial sources. It has not been opted into by the individuals it concerns, and we make it available only for business-to-business sales, marketing, and research, subject to the rights described in Section 10 and Section 13.

3. How We Use Information

  • Provide, operate, secure, and improve the Services, including the Platform, API, and Managed Email Service.
  • Make business contact data available to customers for business-to-business sales, marketing, and research.
  • Process payments, manage accounts, and provide support.
  • Detect, prevent, and address fraud, abuse, security incidents, and violations of our Terms.
  • Communicate with you about your account, transactions, and service updates.
  • Comply with legal obligations and enforce our agreements.

4. How We Disclose Information

  • To service providers and subprocessors who perform functions on our behalf, such as hosting, payment processing, email delivery infrastructure, and AI/model processing, under obligations to protect the information.
  • To customers of our platform, who can access and export business contact data from our database as part of the Services. This is the core function of the product.
  • To Operators and their authorized end clients under white-label or partner arrangements.
  • For legal reasons, such as to comply with law, respond to lawful requests, or protect rights, safety, and property.
  • In a business transfer, such as a merger, acquisition, financing, or sale of assets.

We do not sell or rent the account, billing, or Customer Data you provide to us for others' marketing. Disclosure of the business contact data in our database is addressed in Section 5.

5. "Sales" and "Sharing" of Personal Information

Certain U.S. state privacy laws, including the California Consumer Privacy Act as amended (CCPA/CPRA), define "sale" and "sharing" broadly. Because we make business contact data available to our customers, that activity may be considered a "sale" or "sharing" of personal information under those laws.

We do not knowingly sell or share the personal information of individuals under 16. You have the right to opt out of the sale or sharing of your personal information, and to direct us not to include your information in our database (Section 10 and Section 13).

6. AI & Automated Processing

We use automated systems, including AI models, to enrich data and to research and draft outreach as part of the Services. We do not sell your Customer Data, and we do not make it available to other customers. Where we use models to provide the Services, we apply reasonable measures intended to keep your Customer Data confidential and limited to providing the Services to you.

7. Cookies & Similar Technologies

We use cookies that are necessary for the Services to function, such as session management and security. We do not currently use third-party advertising or cross-site tracking cookies. If we add analytics or similar technologies, we will update this policy. You can control cookies through your browser settings, though disabling essential cookies may affect functionality.

8. Data Retention

  • Account information: retained while your account is active and as needed thereafter for legitimate business and legal purposes.
  • Customer Data: retained to provide the Services and deleted or returned within a reasonable period after termination, subject to backups and legal requirements.
  • Business contact data: retained and updated on a rolling basis, and removed in response to valid deletion or suppression requests.
  • Financial records: retained as required by law (typically several years).

9. Data Security

Encryption

Data is encrypted in transit, and at rest where appropriate, using industry-standard protocols.

Access Control

Access is limited on a need-to-know basis with authentication requirements.

Account Isolation

Customer accounts and their uploaded data are logically separated.

Ongoing Review

Security practices are reviewed and updated over time.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Your Privacy Rights

A. Rights available to everyone

Access & portability

Request a copy of the personal information we hold about you.

Correction

Ask us to correct inaccurate information.

Deletion & opt-out

Ask us to delete your information or to stop including it in our database or outreach.

B. California (CCPA/CPRA)

California residents have the right to know the categories and specific pieces of personal information we collect, disclose, sell, or share; to request deletion and correction; to opt out of the sale or sharing of personal information; to limit the use of sensitive personal information; and to be free from discrimination for exercising these rights.

The categories of personal information we may collect include identifiers, commercial information, internet or other network activity, professional or employment-related information, and inferences. The categories that may be "sold" or "shared" are identifiers and professional or employment-related information (the business contact data in our database).

To opt out, see Section 13 or contact us using the details below. We honor recognized opt-out preference signals, such as the Global Privacy Control (GPC), where required. You may use an authorized agent to submit requests.

C. Other U.S. states

Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana, among others) have rights to access, correct, delete, and obtain a copy of their personal information, and to opt out of targeted advertising, the sale of personal information, and certain profiling. You may appeal a decision on your request by contacting us; if we deny your appeal, you may contact your state attorney general.

D. Canada (PIPEDA)

If you are in Canada, you may request access to and correction of your personal information and may withdraw consent, subject to legal and contractual limits. You may also contact the Office of the Privacy Commissioner of Canada. Marketing to Canadian recipients is also subject to Canada's Anti-Spam Legislation (CASL).

E. EEA / UK

Our Services are intended for United States and Canadian business data. We do not direct our Services to the European Economic Area or the United Kingdom, we do not knowingly include EEA or UK personal data in our database, and we ask our data sources to exclude it; if we identify such data without a lawful basis to process it, we remove it. If applicable data protection laws such as the GDPR or UK GDPR nonetheless apply to you, you may have additional rights, including the right to object to or restrict processing and to lodge a complaint with a supervisory authority. Contact us to exercise these rights.

11. How to Exercise Your Rights

You can submit a privacy request using the contact details at the bottom of this policy. We will verify your request as required by law before responding, and we will not discriminate against you for exercising your rights. We aim to respond within the timeframes required by applicable law. An authorized agent may submit a request on your behalf with proof of authorization.

12. Data Broker Disclosure

Because we compile and make available business contact data sourced in part from third parties, we may be considered a "data broker" under laws in certain states (such as California, Texas, Oregon, and Vermont). Where required, we register as a data broker and honor deletion mechanisms those laws provide. [Registration details, if applicable.]

13. How Business Contacts Can Opt Out or Be Removed

If your information appears in our database and you would like to access, correct, delete, or suppress it, or opt out of its sale or sharing, contact us using the details below. On a valid request, we will remove or suppress your information from our database and propagate suppression so that it is not made available going forward. If you received outreach sent through our Services, you may also use the unsubscribe mechanism in that message.

14. Children's Privacy

The Services are for business use and are not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe we have such information, contact us and we will delete it.

15. International Users & Data Location

We operate the Services from the United States. If you access the Services from outside the United States, you understand your information may be processed in the United States, where data-protection laws may differ from those in your jurisdiction.

16. Changes to This Policy

We may update this policy as our Services and legal obligations evolve. We will post the updated policy with a new "Last Updated" date and, for material changes, provide additional notice. Your continued use after the effective date constitutes acceptance.

Privacy Requests & Questions

Contact us for any privacy concern, data request, or removal request.

Email: support@hypertouch.ai

[COMPANY MAILING ADDRESS]

Get Started