Privacy policy

What Prospectly processes

Prospectly stores account details, organisation settings, subscription status, usage records, and business information that users request from public data providers. Website audit results and screenshots are stored so users can verify the findings attached to a lead.

How data is used

Data is used to provide business discovery, website auditing, scoring, outreach drafting, billing, abuse prevention, and customer support. Prospectly does not sell customer information and does not send outreach automatically.

AI processing

Only the sender profile, public business details, and verified issue summaries required to prepare a draft are sent to the configured AI provider. Raw website HTML is not included in outreach prompts.

Storage and retention

Customer-owned records are isolated by organisation. Audit snapshots may be cached for fourteen days to avoid unnecessary provider requests. Private screenshots are retained while their lead remains active and are removed with the lead or workspace. Expired public audit shares and operational rate-limit records are deleted on a schedule. Billing references and security records may be retained where required to prevent fraud or meet financial obligations.

Service providers and overseas processing

Prospectly relies on Supabase for account data and storage, Vercel for application hosting, Google for business discovery and measured audits, Browserless for controlled screenshots, a contracted language-model processor for evidence-grounded drafting, Stripe for billing, Resend for service email, PostHog for consented analytics, and Sentry for error monitoring. These providers may process data outside Australia under their contractual security and privacy terms.

Analytics and cookies

Essential cookies maintain authentication, security, privacy choices and attribution through sign-in. Product analytics and advertising pixels remain disabled until the visitor chooses the relevant category. Analytics never receives lead names, website addresses, notes or outreach drafts. Choices can be changed through the Privacy choices control on every page.

Your choices

  • Review and edit every outreach draft.
  • Mark businesses as do not contact.
  • Export approved records.
  • Delete workspace data.
  • Access or correct account information.
  • Withdraw optional analytics or advertising consent.

Security and data incidents

Prospectly uses tenant isolation, restricted server credentials, private storage, encrypted transport, rate limiting and provider access controls. Suspected security issues can be reported to security@prospectly.com.au. Eligible data breaches will be assessed and notified in accordance with applicable Australian requirements.

Contact

Privacy questions, access requests, corrections and complaints can be sent to privacy@prospectly.com.au. Include enough information to find your account, but never send a password or API key.