Privacy Policy
Last updated 2 September 2026
This policy explains how Vestal Hub (“we”) handles personal data in FindLeadEmails. It covers two distinct kinds of data, which is the part that matters most: data about you, our customer, and data about the people you look up.
1. Who is responsible
Vestal Hub is the controller of your account data. For the contact data you submit for lookup, you are the controller and we are the processor: you decide whose addresses to find and why, and we process on your instructions.
Contact: privacy@vestalhub.com.
2. Data about you
| What | Why | Lawful basis |
|---|---|---|
| Email address, password hash, workspace name | To create and secure your account | Contract |
| Credit balance and transaction ledger | To meter usage and bill accurately | Contract |
| Billing details held by Stripe | To take payment | Contract / legal obligation |
| Usage events and API key activity | To operate, debug and prevent abuse | Legitimate interests |
| Hashed IP address on the public demo | To rate-limit anonymous use | Legitimate interests |
We never store raw IP addresses for the public demo tool — only a salted hash, which cannot be reversed into an address.
3. Data about the people you look up
To perform a lookup we process the name and company domain you supply, and the professional email addresses we derive and verify. This is business contact data.
We retain derived addresses and learned company email conventions so repeat lookups are free and faster. Learned conventions are patterns (for example first.last), not personal data in themselves.
Your obligations. You must have a lawful basis for processing the contact data you submit and for contacting those people. Under GDPR that usually means legitimate interests for B2B outreach, along with a clear notice at first contact and an easy way to opt out.
4. Data subject rights
If you are in the UK, EU or a comparable regime you have rights to access, correct, delete, restrict and port your data, and to object to processing. Email privacy@vestalhub.com and we will respond within one month.
If you were looked up rather than being a customer, you may still ask us to erase or stop processing your address. Write to the same address and we will action it and suppress it from future results. You may also complain to your national supervisory authority.
Suppression is enforced in the product, not only as a policy. A suppressed address is removed from every cache and is never derived, verified, returned or stored again — and because our address predictions are generated rather than looked up, we suppress the person as well as the address, so a different spelling of the same mailbox cannot be produced instead. We keep only an irreversible SHA-256 hash of a suppressed address, so honouring the request does not require us to retain the address itself.
5. Sub-processors
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication | EU (Paris) |
| Vercel | Application hosting | EU (Paris) for compute |
| MillionVerifier | Mailbox verification | EU |
| Stripe | Payments | EU / US under SCCs |
Where data reaches a country without an adequacy decision, it is covered by Standard Contractual Clauses. We will give notice before adding a sub-processor that materially changes this.
6. Retention
- Account and billing records: for the life of the account, then as tax law requires.
- Lookup results and verification outcomes: while your account is active, so repeats stay free, and in any case no longer than 12 months, after which they are deleted automatically.
- Company email conventions (for example first.last) are kept indefinitely. These describe an organisation, not a person, and contain no personal data.
- Public demo rate-limit hashes: 30 days.
- On account closure: deleted or anonymised within 90 days, except records we must keep.
7. Security
- Data is encrypted in transit and at rest.
- API keys are stored only as SHA-256 hashes and shown once at creation.
- Database access is protected by row-level security and scoped service credentials.
- We do not receive or store payment card details.
8. Cookies
We set only what is required to keep you signed in and to remember your session. We do not use advertising or cross-site tracking cookies, which is why you are not asked to consent to any.
9. Changes
We will notify you of material changes by email or in the application before they take effect.