Privacy Policy
Last updated 12 July 2026
This policy explains what data FisherLeads, LLC(“FisherLeads,” “we,” “us”) collects, why, and what rights you have. We keep it plain and readable. It covers both the people who use FisherLeads (account holders) and the businesses that appear in our feed. FisherLeads, LLC is the data controller, and you can reach us any time at support@fisherleads.com.
1. The business data we publish
FisherLeads’ core product is a feed of newly launched and existing businesses, built only from publicly available business information, the kind a company publishes about itself on its own website or that is otherwise publicly discoverable. For each business this can include the domain name and the website or ecommerce platform it runs on, the product or service category and the country it operates from, the technologies and apps detected on the public site, the business or store name shown on the site, and the contact details a business lists publicly on its own site, such as a business email address and links to public social profiles.
How we collect it.We gather this from public web pages, public certificate transparency logs, public domain records (RDAP and WHOIS), and public data endpoints that sites expose, for example a store’s public product listing. We do not collect data from behind logins or paywalls, and we do not buy or use privately scraped personal databases. Our crawler identifies itself as FisherBot and honors robots.txt, so if a site disallows crawling, we skip it.
Personal data within business data.Most of what we hold is about businesses, not individuals. Some public business contact details can, however, relate to an identifiable person, for example a sole trader’s email, a personal name used as a store or founder name, or a personal social handle. Where our data identifies an individual, we process it under the legitimate interestsbasis (GDPR Article 6(1)(f)): operating a business intelligence and lead generation directory of companies. We have weighed that interest against individuals’ rights, kept the data to a business context, and provide an easy objection and removal path (Section 6). We do not build profiles of individuals’ private lives and do not knowingly collect special category data.
2. Account data
If you create a FisherLeads account, we store:
- your email address, to identify your account and send you messages about it;
- a securely hashed password, hashed with a salted PBKDF2 (HMAC SHA256) and never stored in readable form;
- your plan and subscription status, and the identifiers our payment processor issues for your subscription;
- your country, derived from your IP address by our network provider (Cloudflare) the first time you sign in;
- basic account timestamps (when you signed up and your last activity) and your email preference.
We use this only to operate your account and provide the service. We do not sell your account data.
3. Payments
If you subscribe to a paid plan, you can pay by card or by cryptocurrency.
- Card payments are processed by Stripe. Stripe handles your card details directly, so we never see or store your full card number, only your subscription status and the identifiers Stripe returns to us.
- Cryptocurrency payments are handled directly on the public blockchain, and we never take custody of your funds. We quote a unique amount to a wallet address and detect your payment on the blockchain. We never store wallet credentials or private keys.
4. Finn, the AI outreach assistant
FisherLeads includes Finn, an optional AI assistant (on our Business and Enterprise plans) that helps you build an audience from the feed and draft outreach.
- Connecting your own mailbox. To send email through Finn you connect your own mailbox. With an app password (SMTP) we store your sending address and that password in encrypted form. With Gmail or Outlook we use OAuth and store only an encrypted token that can send but not read, because we ask for permission only to send on your behalf, never to read your inbox. You can disconnect a mailbox at any time, which deletes the stored credentials. Connecting Gmail or Outlook is also governed by Google’s or Microsoft’s terms.
- Drafting messages. To generate text, the instructions you give Finn and the relevant public business details are sent to our AI provider, Anthropic, solely to produce the draft you asked for. Anthropic does not train its models on data submitted through its API.
- Instagram and Facebook. Finn only prepares drafts that you send yourself by hand. FisherLeads never logs into, posts from, or automates your social accounts.
You are responsible for the outreach you choose to send and for complying with applicable spam and data protection laws (for example GDPR) in your own sending.
5. Information collected automatically
When you use our website, our infrastructure automatically logs basic technical information, your IP address, browser type, referring pages, and access times, for security, abuse prevention, debugging, and keeping the service running. Our network and security provider, Cloudflare, sits in front of our site and processes this traffic to protect and deliver it.
Cookies and sign in. We keep you signed in using a token stored in your browser’s local storage, not a tracking cookie. We do not use third party advertising or analytics trackers, and we run no advertising pixels on our own site. Cloudflare may set strictly necessary cookies for security and bot protection.
6. Your rights and removal requests
Business or listing removal. If you operate a business listed in FisherLeads and want it removed, email support@fisherleads.com with your domain. We remove it promptly and can suppress it from future collection.
Individual rights. Depending on where you live, you may have rights over personal data we hold about you:
- EU and UK (GDPR): access, correct, delete, restrict, or object to our processing (including our legitimate interests processing), data portability where applicable, and the right to complain to your local data protection authority.
- California (CCPA and CPRA): the right to know, access, delete, and correct personal information, and to opt out of any “sale” or “sharing” of it, without discrimination for exercising those rights.
- Residents of other regions (for example Canada under PIPEDA) have comparable rights.
To exercise any of these, contact support@fisherleads.com. We verify and respond within the timeframes the law requires, and there is no charge for a reasonable request.
7. Service providers
We share limited data with a small set of trusted providers, only as needed to run the service, each under its own privacy terms:
- Stripe, for card subscription payments.
- Resend, for account and transactional emails such as verification codes and receipts.
- Anthropic, for generating Finn’s message drafts.
- Cloudflare, for DNS, CDN, and the security layer in front of our site.
- DigitalOcean, for hosting our servers and databases.
When you connect a Google or Microsoft mailbox to Finn, you also authorize us to send through Google or Microsoft on your behalf. We do not share your personal data for any purpose other than operating FisherLeads, except where required to comply with law, respond to lawful requests, or protect our legal rights.
8. Where your data is stored, and international transfers
FisherLeads’ servers and databases are hosted with DigitalOcean in the United States. Our network layer (Cloudflare) and several providers above are also based in the United States. If you access FisherLeads from outside the United States (including the EU and UK), your data will be transferred to and processed in the United States. Where required, these transfers are covered by appropriate safeguards such as the Standard Contractual Clauses in our providers’ data processing agreements.
9. Security
We protect data with encryption in transit (HTTPS and TLS across the site), passwords that are hashed and salted, and encryption at rest for any connected mailbox credentials. No system is perfectly secure, but we work to protect your information and limit access to it.
10. Data retention
- Business records are kept while the business remains active and are archived (not immediately deleted) when a site goes offline, so the feed stays consistent. We remove records on a valid request.
- Account data is kept while your account is open and deleted or anonymized after you close it, subject to records we must keep for legal, tax, or fraud prevention reasons.
- Automatic logs are retained only for a limited period for security and debugging.
11. Children
FisherLeads is a business tool not intended for anyone under 18, and we do not knowingly collect personal data from children.
12. Changes to this policy
We may update this policy from time to time to reflect changes in our practices or for legal reasons. The “last updated” date above reflects the current version, and significant changes will be communicated where appropriate.
13. Contact
Questions, requests, or complaints? Email support@fisherleads.com.