Legal

    Privacy Policy

    Last updated: August 20, 2026

    Our privacy-first stance

    Stack Finder is a data architecture and AI consultancy. We are deliberately built so that your data stays with you. We do not run a SaaS product that ingests your CRM, billing, or warehouse data into our systems. We do not resell tools, we do not broker your data, and we do not need to copy your records to do our work.

    Client data ownership & guest access

    When we partner with a client, every third-party tool in the stack—CRM, data warehouse, outbound platform, AI vendor—is purchased and owned directly by the client on their own accounts. Stack Finder operates inside those tools as a guest user with permissions granted by the client. Access is scoped to the engagement, can be revoked at any time, and is removed at the end of the engagement.

    We do not export, copy, or persist client production data into Stack Finder–owned systems except for the minimum artifacts required to deliver work (architecture diagrams, redacted examples, written recommendations), which are stored in the client's shared workspace whenever possible.

    NDAs & confidentiality

    All client engagements are covered by mutual confidentiality from day one. Some clients require us to sign their own NDA before any discovery work begins—we are happy to do so. Other clients prefer to operate under our standard mutual confidentiality terms (included in our engagement letter). Either path is fine; reach out before kickoff if you need to issue a specific NDA.

    Information we collect on stackfinder.com

    When you use this website, we collect:

    • Account data: email address (and Google profile basics if you sign in with Google) used for authentication and saving your stacks.
    • Saved stacks & assessments: the tool selections, AI Readiness Assessment answers, and stack notes you choose to save.
    • Support messages: anything you submit via our support, chat widget, or contact forms.
    • Payment metadata: for paid services, Stripe processes the transaction. We receive confirmation, customer email, and order metadata. We never see or store your card number.
    • Usage analytics: aggregate page views, session interactions, and device/browser metadata as described below.

    Cookies & analytics

    We show a cookie consent banner to visitors from the EU/UK and require opt-in before loading non-essential analytics. Visitors outside the EU/UK have analytics enabled by default and can opt out at any time by declining the banner. We use the following categories:

    • Essential: authentication session, cookie consent state, security.
    • Analytics: Google Analytics for aggregate traffic and conversion measurement.
    • B2B identification: RB2B identifies the company behind inbound business traffic so we can understand which organizations are researching us. This is company-level, not individual profiling, and we do not sell or broker it. In the EU/UK it only loads after you accept the banner.

    We no longer run session replay (Mouseflow) or Leadfeeder on this site; those scripts have been removed.

    AI processing

    Several features on this site are powered by AI. Our chat widget, the AI Readiness Assessment, the Revenue Agent scan, and our stack detection and recommendation tools route your prompts and inputs through the Lovable AI Gateway to Google Gemini models.

    • Inputs are processed to generate your response and are not used to train the underlying models.
    • We may retain prompts and outputs associated with your account or session so we can show you past results, debug problems, and improve our own product.
    • URLs you submit for analysis are fetched by our servers so the scan can read the page.

    Please do not paste secrets, credentials, or regulated personal data (such as health, financial account, or government identification data) into any AI feature on this site.

    Third-party processors (subprocessors)

    We rely on a small set of vetted vendors to operate this site. This list is current as of the "Last updated" date above; material additions will be reflected here.

    VendorPurposeData touchedRegion
    Lovable Cloud (managed Supabase)PostgreSQL database, authentication, file storage, serverless functionsAccount data, saved stacks, assessment submissionsUS
    StripePayments and billingBilling metadata, customer email (no card numbers)US
    ResendTransactional email deliveryRecipient email address, message contentUS
    GoogleSign-in with Google, Analytics 4, Gemini models via Lovable AI GatewayAuth identity, usage analytics, AI promptsUS
    RB2BCompany-level B2B visitor identificationIP and company-level signalsUS
    Cal.comDiscovery and Deep Dive schedulingName, email, booking detailsUS/EU

    Your rights

    You can request access, correction, export, or deletion of personal data we hold about you (including GDPR/UK GDPR and CCPA rights where applicable). Email us via our support page and we'll respond within 30 days.

    Data retention

    Account data is retained until you request deletion. Saved stacks and assessment results are retained while your account is active. Analytics retention follows each provider's defaults (typically 14–26 months). Payment records are retained as required by tax and accounting law.

    International transfers

    Stack Finder operates from the United States, and our processors are primarily US-based. By using the site you understand that your information may be processed in the US under appropriate safeguards (Standard Contractual Clauses where required).

    Children

    Stack Finder is a B2B service and is not directed at anyone under 16. We do not knowingly collect data from children.

    Changes & contact

    We'll update this page when our practices change and revise the "Last updated" date above. Questions? Reach us via support.