legal

Privacy Policy

Built on records that are already public. Exactly what we process, what we deliberately do not, and how to reach a person about either.

Last updated September 22, 2026

What we process

Two kinds of data, and only two:

  • Public business records. Legal entity names, filed business addresses, filing dates and types, collateral descriptions as filed, and named secured parties — read from official state and federal filing systems. Every signal in the product links to the public filing it was read from.
  • Customer account data. The name, work email, workspace settings and billing status of the people who sign up to use the product — the minimum needed to run their account. Concretely that means: account information (name and work email), workspace configuration (your credit box and preferences), product usage events (which leads you viewed, claimed, or dismissed — used to run allocation and improve the product), and records of the transactional emails we send you.

What we do not process

  • No consumer credit data — no credit scores, no credit reports, ever.
  • No individual-eligibility profiles: we do not build, buy, or sell profiles of people, and nothing we provide may be used for FCRA-regulated decisions.
  • No individual filings: public records that name a person rather than a registered business are dropped at ingest and never reach a feed.

Payment data

Payments are processed by Stripe. Your card details go directly to Stripe and never touch our servers — we store only what Stripe reports back: your subscription status and billing history.

Contact enrichment is business-contact only

Public filings never carry a phone number or an email, so our enrichment layer hunts for business contact details: the company's own website first, then business-data providers. We do not use consumer data brokers and we never touch consumer credit files to find a contact.

So the business contact data in the product comes from two places only: public-record filings and licensed business-data providers — and it describes businesses, not consumers.

Suppression and opt-out

If your business appears in our customers' feeds and you want out, use the contact page or email the founder at yaniv@ybhltd.com and we will suppress your business across every customer feed. Do-not-contact requests are honored the same way. One honest caveat: the underlying filing is a government record — we can remove it from Borrower Radar, but we cannot remove it from the public index it lives in.

How long we keep things

Filing signals stay in the system for as long as they are useful lending context — UCC lapse and renewal timelines run in years, so filing history is the product. Account data is kept while your account is active and deleted on request when you close it. The suppression list is kept indefinitely, because deleting it would undo the opt-out.

To delete your account and its data, ask through the contact page — a person handles it, not an automated queue.

Where things run

The application is hosted on Vercel and the database on Supabase. All traffic between your browser and the product is encrypted in transit (TLS/SSL).

Cookies

Today the application sets essential session cookies only — the ones needed to keep you signed in — and that is what they are for. We do not sell personal information. If we ever add analytics or advertising pixels to these pages, this policy will be updated first to say so.

Contact

Privacy questions, suppression requests, deletion requests — all of it goes to a person, not a form: yaniv@ybhltd.com.