Legal

Privacy Policy

Last updated: 22 July 2026

What we collect, why we collect it, and what happens to the data you pull out of our tools. Written to be read, not to be survived.

Who we are

The Company Co ("we", "us") operates thecompanyco.ai and the tools available to signed-in users at /dashboard. For the personal data described below, we are the data controller. You can reach us at hello@thecompanyco.ai.

What we collect

From the website: your name, email and message when you book a call or contact us. From an account: your email address, your credit balance and transaction history, the inputs you submit to a tool, and metadata about each run (which tool, when, how many results, what it cost).

From payments: we never see or store your card details. Stripe processes payments and returns only a customer reference and a payment identifier, which we store to credit your wallet and to prevent a payment being credited twice.

Automatically: standard server logs and privacy-friendly product analytics (page views and aggregate usage). We do not use advertising cookies.

Why we use it

To deliver what you asked for: reply to enquiries, run the tools you start, deliver and export your results, keep your credit ledger accurate, and provide support. To keep the service working: fraud prevention, abuse limits, debugging, and legal or accounting obligations. Our legal bases are performance of a contract, our legitimate interest in operating a secure service, and consent where you have given it.

Who we share it with

Only the processors we need to run the service: Supabase (database and authentication), Vercel (hosting), Stripe (payments), Resend (transactional email), and the data source behind whichever tool you run — currently Apify. Each processes data on our instructions under a data processing agreement. We do not sell, rent or trade your personal data.

Data you collect using our tools

Our tools return information about businesses — which can include names, phone numbers, email addresses and other details of real people. For that data you are the controller and we are your processor. You decide what to search for, what to keep, and what to do with it.

That means you are responsible for having a lawful basis for collecting and using it, for honouring objections and deletion requests from the people in your lists, and for complying with GDPR, the ePrivacy rules on electronic marketing, and any local marketing law that applies where you operate.

Our own dataset

We also retain the business records our tools collect in a dataset of our own, separate from your account. We use it to serve repeat searches without querying the source again — which is why an identical search inside the same month returns instantly — and to build and improve our own tools and services. For that dataset we are the controller.

It holds business contact information of the kind that is published publicly: company names, addresses, phone numbers, websites and generic business email addresses. It is never sold, published, or made available to other customers as a data product, and it is not linked to your account or shared with the people you search for.

If you are a business whose details appear in our dataset and you want them removed, write to hello@thecompanyco.ai and we will delete them.

How long we keep it

Tool results stay visible in your account for 90 days after a run — export what you need within that window. After 90 days the results are no longer shown to you, while the underlying business records are retained in the dataset described above. Run metadata (tool, date, result count, credits) and your credit ledger are kept for as long as your account exists, and afterwards only where accounting law requires it. Enquiry emails are kept for up to 24 months.

Deleting your account removes your profile, wallet, runs and your stored results. Business records already folded into our own dataset are not tied to your account and are governed by the section above. Ask us at hello@thecompanyco.ai and we will confirm once it is done.

Your rights

You can request access to your data, correction, deletion, a portable copy, or restriction of processing, and you can object to processing based on legitimate interest. Write to us and we will respond within 30 days. If you are in the EU/EEA and think we have got it wrong, you can complain to your national data protection authority.

Security and transfers

Data is encrypted in transit and at rest, access is restricted to those who need it, and service credentials are held outside the codebase. Our processors are based in the EU or transfer data under the European Commission's standard contractual clauses.

Children

The service is for businesses. It is not directed at children and we do not knowingly collect data from anyone under 16.

Changes

If we change this policy we will update the date above, and we will email account holders before any material change takes effect.

← Back to the site