Privacy Policy

Last updated: 2024-01-15

1. Introduction

AcquiScan ("we," "our," or "us") operates a B2B deal intelligence platform that provides AI-powered analysis of acquisition opportunities. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

By using AcquiScan, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Name, email address, password (hashed), and workspace details
  • Lead Information: If you submit a lead form, we collect name, email, buyer type, deal size, and business criteria
  • Workspace Data: Connector configurations, scoring preferences, and deal notes
  • Communication: Messages sent through our platform or support channels

2.2 Automatically Collected Information

  • Usage Data: Pages visited, features used, time spent, and interaction patterns
  • Device Information: IP address, browser type, device type, operating system
  • Log Data: Request timestamps, error logs, and performance metrics
  • Cookies and Tracking: See Section 6 for details on our use of cookies and analytics

2.3 Third-Party Sources

We collect deal information from publicly available sources including marketplaces, RSS feeds, and web scraping (where permitted). This data is aggregated and analyzed but originates from third-party sources over which we have no control.

3. How We Use Your Information

  • Provide, maintain, and improve our service
  • Process transactions and manage your account
  • Send administrative information, updates, and security alerts
  • Respond to your inquiries and provide customer support
  • Send marketing communications (with your consent, where required)
  • Monitor and analyze usage patterns to improve our service
  • Detect, prevent, and address technical issues and security threats
  • Comply with legal obligations and enforce our terms

4. Data Sharing and Disclosure

4.1 Service Providers

We may share your information with third-party service providers who perform services on our behalf:

  • Cloud Infrastructure: Hosting and data storage providers
  • Email Services: Resend for transactional and marketing emails
  • Analytics: Plausible Analytics for privacy-friendly website analytics (see Section 6)
  • AI Services: OpenAI for deal analysis and memo generation
  • Payment Processing: Payment processors (when billing features are enabled)

These providers are contractually obligated to protect your information and use it only for the purposes we specify.

4.2 Legal Requirements

We may disclose your information if required by law, court order, or government regulation, or if we believe disclosure is necessary to:

  • Comply with legal obligations
  • Protect our rights, property, or safety
  • Protect the rights, property, or safety of our users or others
  • Prevent or investigate fraud or security issues

4.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of any such change in ownership.

5. Data Security

We implement industry-standard security measures to protect your information:

  • Encryption of data in transit (TLS/SSL)
  • Encryption of sensitive data at rest (AES-256-GCM for API keys)
  • Secure password hashing (bcrypt)
  • Regular security audits and vulnerability assessments
  • Access controls and authentication
  • Rate limiting and abuse prevention

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

6. Cookies and Analytics

6.1 Cookies

We use cookies and similar tracking technologies to:

  • Maintain your session and authentication state
  • Remember your preferences and settings
  • Analyze website usage and performance

You can control cookies through your browser settings. However, disabling cookies may limit your ability to use certain features of our service.

6.2 Analytics

We use Plausible Analytics, a privacy-friendly analytics service that:

  • Does not use cookies
  • Does not collect personal data or track users across websites
  • Complies with GDPR, CCPA, and PECR
  • Provides aggregated, anonymized statistics

Plausible Analytics does not create profiles of individual users and does not share data with third parties. For more information, visit Plausible's data policy.

7. Your Rights and Choices

7.1 Access and Correction

You can access and update your account information at any time through your account settings.

7.2 Data Deletion

You can request deletion of your account and associated data by contacting us at privacy@acquiscan.com. We will process your request within 30 days, subject to legal retention requirements.

7.3 Marketing Communications

You can opt out of marketing emails by clicking the unsubscribe link in any marketing email or by updating your preferences in your account settings.

7.4 GDPR Rights (EU Users)

If you are located in the European Economic Area (EEA), you have additional rights under GDPR:

  • Right to access your personal data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Right to withdraw consent

To exercise these rights, contact us at privacy@acquiscan.com.

7.5 CCPA Rights (California Users)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information is collected
  • Right to delete personal information
  • Right to opt out of sale of personal information (we do not sell personal information)
  • Right to non-discrimination for exercising your rights

8. Data Retention

We retain your information for as long as necessary to:

  • Provide our services to you
  • Comply with legal obligations
  • Resolve disputes and enforce agreements
  • Maintain security and prevent fraud

When you delete your account, we will delete or anonymize your personal information within 30 days, except where retention is required by law.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country.

We ensure appropriate safeguards are in place for international transfers, including standard contractual clauses approved by the European Commission where applicable.

10. Children's Privacy

Our service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the new Privacy Policy on this page
  • Updating the "Last updated" date
  • Sending an email notification (for significant changes)

Your continued use of our service after changes become effective constitutes acceptance of the updated Privacy Policy.

12. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us: