Skip to main content

Privacy Policy

Effective June 11, 2026 · Last updated June 11, 2026

What this means

We hold account data about customers and business-contact records in our database. Anyone — customer or not — can ask to see, correct, or delete data about them, no account needed.

Who this policy covers

This policy covers two different groups of people:

  • Customers — people with an Clapleads Atlas account. We hold the data you give us to run your account.
  • People in the database — business contacts whose professional details appear in our records. You do not need an account to act on your rights — see How to use your rights.

Data about account holders

If you have an account, we hold:

  • Account data — your name or username, email address, password (stored as a one-way hash), company name, and role.
  • Billing data — your plan, credit balance, and payment history. Card details go directly to Stripe; we never see or store full card numbers.
  • Usage data — your searches, exports, saved lists, and settings, so the product works and so credits are counted correctly.
  • Log data — technical records like IP address and request times, used for security and troubleshooting.

What the database contains

The database holds business information about companies and the people who work at them:

  • Company records — names, websites, addresses, industries, size, and similar firmographic details.
  • Business contact records — names, job titles, work email addresses, work phone numbers, and professional profile links of people in their work roles.

We are direct about this: business contact records are personal data about real people. That is why anyone can ask to see, correct, or delete their record at any time, and why opt-outs are enforced on every export.

Where database records come from

Records are built from public and openly-published business information, collected and verified through our data pipeline. Sources that do not allow resale, have unclear redistribution rights, or carry platform/provenance risk are blocked from paid exports. You can review the categories of sources we rely on, and the licenses that govern them, on our data sources page.

Why we process data

Where laws like the GDPR apply, our legal bases are:

  • Contract — running your account, billing you, and providing the service you signed up for.
  • Legitimate interest— maintaining a database of professional, business-context contact details for business-to-business sales and marketing. This data is limited to people's work lives, and everyone can object or opt out at any time.
  • Consent — optional cookies and anything else we ask you about explicitly.
  • Legal obligation — keeping records we must keep, like tax and audit records.

How we share data

We do not sell account-holder data. We share data only with:

  • Stripe, which processes payments;
  • Hosting and infrastructure providers that run our servers under contract;
  • Customers — database records (not your account data) are the product customers search. Paid exports are organization-only by default and exclude contact, person, and professional-profile fields unless a deployment has a separate counsel-approved basis for enabling them;
  • Authorities — if the law requires it.

For people in the database, "do not sell / do not share" requests (for example under the CCPA) are honored through the data request portal and enforced through the suppression list.

International transfers

The service is available worldwide, so data may be processed outside your own country. Where transfer rules like the GDPR's apply, we rely on recognized safeguards such as standard contractual clauses with our providers.

How long we keep data

  • Account data — kept while your account is active. Deactivated accounts and their data are removed after a reasonable wind-down period, except records we must keep for legal reasons.
  • Database records— kept while they remain current and lawful to hold. Deleted contacts go on a suppression list — a minimal "do not re-add" marker — so they stay removed even when new data arrives.
  • Audit logs — kept as an immutable record of compliance actions.

Your rights

Depending on where you live, you may have the right to access, correct, delete, or export data about you; to object to or restrict processing; and to withdraw consent:

  • EU / UK (GDPR) — all of the above, plus the right to complain to your data protection authority.
  • California (CCPA/CPRA) — the rights to know, delete, correct, and opt out of sale or sharing, without being discriminated against for using them.
  • Canada (PIPEDA) — the rights to access and correct your information and to withdraw consent.

We apply the same core rights — access, correction, deletion, objection, do-not-sell — to everyone, wherever you live.

How to use your rights

  • Submit a request through the data request portal — no account needed. We respond within the timeframe the law requires.
  • Businesses can also claim their company profile to manage how they appear.
  • Account holders can change account details in profile settings, and can ask for account deactivation through the support page.

Cookies

We use necessary cookies to keep the site working, and we ask before setting anything optional. The Cookie Policy lists each category and how to change your choices.

Children

Clapleads Atlas is a business tool for adults. We do not knowingly collect data about anyone under 18, and the database is limited to professional, work-context information. If you believe we hold data about a child, tell us through the data request portal and we will remove it.

Changes to this policy

If we change this policy in a meaningful way, we will update the "Last updated" date and, for significant changes, give notice in the app or by email before the change takes effect.

Related policies

Questions or requests

If anything on this page is unclear, or you want to act on your rights, you can reach us through the support page. To ask about data we hold on you or your business, use the data request portal — no account is needed.

Data protection contact

For data-protection matters — access, correction, deletion, objection, portability, or “do not sell” requests under GDPR/CCPA — the fastest route is the data request portal, which is logged and tracked to completion. Identity is verified before any personal data is disclosed.