Last updated: August 23, 2026

Privacy Policy

This Privacy Policy explains how VertData, Inc. ("VertData", "we", "us", "our") collects, uses, discloses, retains, and protects data in connection with the VertData platform, data products, and API services (collectively, the "Services").

1. Overview

By using the Services, you agree to the practices described in this policy. If you don't agree, don't use the Services. Capitalized terms not defined here have the meanings given in our Terms of Service and Data Processing Agreement.

2. Data we collect

Publicly-available records

VertData collects publicly available business, property, and professional records from government filings, county assessor databases, state bar records, licensing boards, court dockets, and other public sources.

Account and usage data

Customer-uploaded data

Lists, notes, tags, saved searches, and any data you upload into your VertData workspace. This data is treated as Customer Data under the DPA — you own it; we process it on your instructions.

3. How we use data

We do not sell individual contact data to third parties for marketing purposes unrelated to VertData's services.

4. Legal bases for processing (GDPR / UK GDPR)

5. Data retention

We retain data only as long as necessary for the purpose it was collected, plus any period required by law. Standard retention windows:

Data categoryRetention period
Active account data (email, workspace, saved lists)Duration of subscription
Data after account closure or terminationUp to 30 days reactivation window, then permanently deleted from primary systems within 60 days
Encrypted backupsRolling 90-day cycle
Billing and tax records7 years (US tax/accounting requirement)
Security and application logs90 days to 12 months
Analytics (aggregated, de-identified)Up to 26 months (Google Analytics default)
Support correspondence3 years from last contact
Publicly-available record dataRetained while the source record remains public; refreshed regularly; removed on verified data-subject request per §7

After the applicable retention period, data is permanently deleted or fully anonymized. Data subject to legal hold or ongoing dispute is retained until the hold is released.

6. Sub-processors

We use vetted sub-processors to operate the Services. Each is bound by written data-protection obligations no less protective than this policy and our DPA.

Sub-processorPurposeRegion
SupabaseManaged Postgres, authenticationUS (us-west-2)
StripePayment processing, subscription billingUS / global
ResendTransactional email deliveryUS
AnthropicAI-scored insights on non-personal record dataUS
CloudflareDNS, edge protection, DDoS mitigationGlobal
Google AnalyticsAggregated, anonymized site analyticsUS
HostingerUnderlying VPS infrastructureUS

The current list is also maintained on our Security page. We give at least 30 days' notice of material additions or replacements via the revision log below.

7. Your rights

GDPR / UK GDPR (EEA, UK, Switzerland residents)

You have the right to: access, rectify, erase, restrict processing, object to processing, data portability, and to lodge a complaint with a supervisory authority. To exercise these rights, email privacy@vertdata.com. We respond within 30 days.

CCPA / CPRA (California residents)

You have the right to know, delete, correct, and opt out of the sale/sharing of personal information. VertData does not sell personal information as defined by CCPA. Requests: privacy@vertdata.com.

Removal from public-record dataset

Individuals whose information appears in VertData's publicly-sourced dataset may request removal by emailing privacy@vertdata.com with sufficient information to identify the record. We verify identity where practicable and process valid requests within 30 days.

8. Cookies and tracking

See our Cookie Policy for full detail. In summary: we use strictly-necessary cookies for authentication and session management, and aggregated analytics cookies (Google Analytics) with IP anonymization enabled.

9. International transfers

Our servers are located in the United States. Where we transfer Personal Data from the EEA, UK, or Switzerland to the US, we rely on the appropriate transfer mechanism (Standard Contractual Clauses, UK IDTA, or equivalent) as detailed in the DPA.

10. Security

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Access is restricted, logged, and monitored. See our Security page for detail on our controls and incident-response practices.

11. Children

The Services are for business use and are not directed to children under 16. We do not knowingly collect data from children. If you believe a child has provided data to us, contact privacy@vertdata.com and we will delete it.

12. Changes to this policy

We may update this policy from time to time. Material changes are notified via email to account holders and posted here with a revised "Last updated" date. Continued use after the effective date constitutes acceptance.

Revision log

13. Contact

Privacy inquiries: privacy@vertdata.com
Security matters: security@vertdata.com
General: support@vertdata.com
VertData, Inc.