Privacy Policy
Last updated 6 September 2026
Placeholders still in this document
Company name, address, and jurisdiction are unset in src/lib/legal.ts. Fill them in before taking payment, and have a lawyer read both pages. These are a sound starting draft, not legal advice, and they have not been reviewed by anyone qualified.
Who we are
ClientPerch is operated by [Your registered company name], of [Registered business address]. For anything in this policy, write to [support@yourdomain.com].
What we collect about you
- -Account details. Your email address, and your name if you give one. Authentication is handled by Supabase; we never see or store a password.
- -Billing details. Handled entirely by Stripe. We store only your Stripe customer and subscription identifiers, your plan, and your usage counts, but never your card number.
- -What you scan. The website addresses you submit, any prospect name or note you attach, and the resulting reports.
- -Branding you upload. Logo and favicon files, stored in Supabase Storage and served publicly so they can appear in reports you share.
Data about third parties, and your responsibility for it
This service is built to gather information about businesses that are not our customers: the websites you scan, and the businesses Lead Finder returns. That data is personal information under most privacy law when it identifies a person, and how you use it is your responsibility, not ours.
- -We read publicly accessible pages only. We do not attempt to log in, bypass access controls, or reach anything behind a paywall or password.
- -Contact details are extracted from what a business has chosen to publish on its own website. We do not guess email addresses from name patterns, and we do not buy or enrich from third-party data brokers.
- -Lead Finder results come from the Google Places API and are subject to Google's own terms.
- -You are the controller of prospect data you collect here. If you use it for outreach, complying with the marketing and data protection rules of your and their jurisdiction (including consent, opt-out, and identification requirements) is on you. A business asking you to stop must be honoured by you; we cannot do it for you.
If you install the lead-capture widget
The widget collects the website address, email, and optionally the name and phone number of people who use it on your site. Those people are your contacts, and you are the controller of that data. We process it on your behalf to run the scan, store the result, and email it to them. You are responsible for telling visitors to your site what you do with what they submit.
Who we share data with
We use these processors, and nobody else receives your data:
- -Supabase: database, authentication, and file storage.
- -Vercel: application hosting.
- -Stripe: payments and billing.
- -Anthropic: writes report recommendations. It receives the observed findings for a scanned site, not your account or billing details. It is not used to train models on your data.
- -Google: PageSpeed Insights and the Places API.
- -Resend: sends report and lead notification emails.
We do not sell your data, and we do not share it for advertising.
How long we keep it
Reports and prospects are kept while your account is open, so you can return to them. Delete your account and we remove your account record, reports, prospects, and uploaded branding within 30 days. Billing records are kept as long as tax law requires. Ask us to delete anything sooner and we will.
Your rights
You can ask for a copy of your data, correct it, delete it, or object to how we use it. Email [support@yourdomain.com] and we will respond within 30 days. If you are unhappy with the response you can complain to [the Information Regulator of South Africa].
Security
Traffic is encrypted in transit. API keys are stored as hashes, never in plain text, and are shown once at creation. Database access is restricted to the application. No system is perfect, and we will tell you promptly if a breach affects your data.
Changes
If we change this policy in a way that materially affects you, we will email you before it takes effect. The date at the top always reflects the current version.