Privacy policy.
This is a v1 privacy policy that will be replaced with attorney-reviewed copy before sustained marketing campaigns. The substance - what we collect and why - is accurate.
What we collect
- Anonymous analytics via Vercel Analytics and Google Analytics 4 (page views, referrers, country, device class). No personally identifying information.
- Email + name when you submit a prep-center claim form, listing-suggestion email, or contact form.
- DNS-TXT verification tokens when you go through our DNS-based listing claim flow. These tokens are random strings stored against your claim and discarded after verification completes.
- Cookies for session continuity if you sign in to manage a claimed listing (Supabase Auth + magic-link email).
What we don't collect
- Behavioral tracking for advertising. We don't run ads.
- Cross-site cookies, device fingerprints, or third-party trackers beyond GA4.
- Card numbers. Operator subscriptions and one-off purchases run through Stripe Checkout and Stripe Elements, so card details go straight to Stripe and never touch our servers or our database. We store only Stripe's identifiers and the resulting subscription state.
- Phone numbers (unless you voluntarily provide one in a claim or contact form).
Third parties we share with
- Vercel - hosts the site; sees request metadata.
- Supabase - database + auth; stores claim records.
- Resend - delivers transactional emails (magic-link sign-in, claim verifications).
- Google Analytics 4 - aggregated traffic analytics.
- Stripe - processes operator payments and subscriptions. Stripe receives the billing details you enter on its own checkout surface.
- Anthropic - the contents of a match request are sent to Anthropic's API to classify the request and to rank which verified centers fit it. That includes the name, email, and company you typed into the form. Nothing an AI model writes is ever sent to you: every buyer-facing message is assembled from structured form fields.
- Google (Gmail API) - our hello@ mailbox sends and stores correspondence with buyers and operators.
- MillionVerifier - receives an email address on its own to check the mailbox exists before we write to it, so a reply does not bounce.
- Slack - new match requests and operator events, including the submitter's email address, post to private internal channels so a human sees them quickly.
We do not sell, rent, or trade your data. We share only what's necessary to operate these specific services.
Our public API and AI assistants
We publish a read-only Model Context Protocol endpoint at /api/mcp/, plus JSON dataset endpoints. These let an AI assistant search our verified directory and cite it. They serve only information that is already public on this site.
- They require no sign-in and collect no personal data. There is deliberately no tool that accepts your name, email, or phone number. If you want a hand-matched shortlist, you fill in the form on this site, where this policy governs.
- They return no operator contact addresses, only links back to the profile page.
- Results are ordered by fit and verification recency. Paid placement is not applied on this surface, and no click from an assistant is billed to an operator.
- As with any web request, our host receives standard request metadata such as IP address and user agent. We use it to rate-limit abuse, not to profile you.
The data is published under CC BY 4.0. You are free to reuse it with attribution to fbaprepfinder.com.
How long we keep things
- Approved claims and live operator accounts: kept indefinitely so operators can continue to manage their listing. You can request removal at any time via the operator dashboard or by emailing us.
- Rejected or duplicate applications, and rejected or revoked claims: contact fields (email, phone, name) are anonymized 24 months after the rejection. The row itself stays so we can answer "did you ever consider X?" honestly, but the personal data is removed.
- Match requests (the "get matched" form): contact fields are anonymized once the match is closed or after 24 months, whichever comes first.
- Operator audit log: kept for the life of the listing as a record of who changed what. Removal of the listing also removes the audit rows.
We anonymize older records periodically as we scale. Write to hello@fbaprepfinder.com any time to request earlier deletion of your own data.
Contact
Questions or requests (deletion, access, correction): hello@fbaprepfinder.com. We respond within 7 days.