Last updated: August 23, 2026
This Privacy Policy explains how VertData, Inc. ("VertData", "we", "us", "our") collects, uses, discloses, retains, and protects data in connection with the VertData platform, data products, and API services (collectively, the "Services").
By using the Services, you agree to the practices described in this policy. If you don't agree, don't use the Services. Capitalized terms not defined here have the meanings given in our Terms of Service and Data Processing Agreement.
VertData collects publicly available business, property, and professional records from government filings, county assessor databases, state bar records, licensing boards, court dockets, and other public sources.
Lists, notes, tags, saved searches, and any data you upload into your VertData workspace. This data is treated as Customer Data under the DPA — you own it; we process it on your instructions.
We do not sell individual contact data to third parties for marketing purposes unrelated to VertData's services.
We retain data only as long as necessary for the purpose it was collected, plus any period required by law. Standard retention windows:
| Data category | Retention period |
|---|---|
| Active account data (email, workspace, saved lists) | Duration of subscription |
| Data after account closure or termination | Up to 30 days reactivation window, then permanently deleted from primary systems within 60 days |
| Encrypted backups | Rolling 90-day cycle |
| Billing and tax records | 7 years (US tax/accounting requirement) |
| Security and application logs | 90 days to 12 months |
| Analytics (aggregated, de-identified) | Up to 26 months (Google Analytics default) |
| Support correspondence | 3 years from last contact |
| Publicly-available record data | Retained while the source record remains public; refreshed regularly; removed on verified data-subject request per §7 |
After the applicable retention period, data is permanently deleted or fully anonymized. Data subject to legal hold or ongoing dispute is retained until the hold is released.
We use vetted sub-processors to operate the Services. Each is bound by written data-protection obligations no less protective than this policy and our DPA.
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase | Managed Postgres, authentication | US (us-west-2) |
| Stripe | Payment processing, subscription billing | US / global |
| Resend | Transactional email delivery | US |
| Anthropic | AI-scored insights on non-personal record data | US |
| Cloudflare | DNS, edge protection, DDoS mitigation | Global |
| Google Analytics | Aggregated, anonymized site analytics | US |
| Hostinger | Underlying VPS infrastructure | US |
The current list is also maintained on our Security page. We give at least 30 days' notice of material additions or replacements via the revision log below.
You have the right to: access, rectify, erase, restrict processing, object to processing, data portability, and to lodge a complaint with a supervisory authority. To exercise these rights, email privacy@vertdata.com. We respond within 30 days.
You have the right to know, delete, correct, and opt out of the sale/sharing of personal information. VertData does not sell personal information as defined by CCPA. Requests: privacy@vertdata.com.
Individuals whose information appears in VertData's publicly-sourced dataset may request removal by emailing privacy@vertdata.com with sufficient information to identify the record. We verify identity where practicable and process valid requests within 30 days.
See our Cookie Policy for full detail. In summary: we use strictly-necessary cookies for authentication and session management, and aggregated analytics cookies (Google Analytics) with IP anonymization enabled.
Our servers are located in the United States. Where we transfer Personal Data from the EEA, UK, or Switzerland to the US, we rely on the appropriate transfer mechanism (Standard Contractual Clauses, UK IDTA, or equivalent) as detailed in the DPA.
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Access is restricted, logged, and monitored. See our Security page for detail on our controls and incident-response practices.
The Services are for business use and are not directed to children under 16. We do not knowingly collect data from children. If you believe a child has provided data to us, contact privacy@vertdata.com and we will delete it.
We may update this policy from time to time. Material changes are notified via email to account holders and posted here with a revised "Last updated" date. Continued use after the effective date constitutes acceptance.
Privacy inquiries: privacy@vertdata.com
Security matters: security@vertdata.com
General: support@vertdata.com
VertData, Inc.