Legal

Privacy policy

This is what FoundFirst does with personal information on this site and in the service behind it. It is written to describe what the site actually does — including the parts that are deliberately plain, like keeping no analytics and running no advertising pixels.

  • Version v1 — draft
  • Last updated 1 October 2026
  • Applies to the US site and the US report service

01Who we are

FoundFirst is the controller of the personal information described here: the business that decides what is collected and why. We sell one thing: a written Local Visibility Report on your firm for $749, plus a free one-hour implementation call.

Controller

FoundFirst
Registered address
Argonweg 73, 1362 AD Almere, Nederland
Company registration (KvK)
81834500
VAT identification (btw-id)
NL003609731B25

Registered with the Dutch Chamber of Commerce (KvK). The KvK number and btw-id are disclosed here as Dutch law requires.

We are a small, new operation — no revenue has been earned yet, so there is no customer archive and no mailing list beyond what the forms on this site have collected. Nothing in this policy describes data we do not have.

02What we collect

There are three moments at which we can receive anything about you.

The free mini-check (business name, city, e-mail)
You type your firm's name, the city you draw clients from, and an e-mail address, and you tick a consent box to have the result e-mailed to you. The record we keep holds the firm name, the city, your e-mail address, the exact consent sentence you ticked, the version of that sentence, and the time you submitted it. It also holds the date and location of the search we ran, the exact query, the finding we showed you and the honest summary next to it — so that you can check later what we told you. Your IP address and browser user-agent are stored alongside it in hashed or shortened form, to stop the free check being abused.
A separate attempt log
To keep the mini-check within its rate limits and to measure honestly how many people ask for a check at all, we also record each attempt — the firm name, the city a shortened form of the e-mail address, an IP hash, the user-agent, the outcome and how long it took. This is a measurement log, not a mailing list: the address in it cannot be read back and no e-mail is ever sent from it.
An order (business details and payment status)
After you pay, you send us your firm's details so we can run the report: firm name, practice area, city and state, an e-mail address, an optional phone number and an optional Google Business Profile link. Your card is handled by Stripe; we receive a payment reference and whether the payment succeeded — never your card number, and we store no payment credentials of yours.

We collect nothing else. There is no account to create, no login, no cookie banner because there is nothing to consent to, and no hidden field gathering anything you did not type.

03Why we use it

To deliver what you bought
Your firm details are what the report is made of, and your e-mail is how it reaches you. Basis: the contract between us — we can only do the work with those details.
To e-mail you the mini-check result and follow up about it
Basis: the consent you gave by ticking the box on the form. It is not bundled with anything, it is unticked by default, and you can withdraw it at any time — see “Your rights” below. Every message we send carries a way out.
To keep the service usable and honest
Rate-limiting the free check, spotting abuse, and measuring how many checks were run and what came of them. Basis: our legitimate interest in a small, working service that does not get drained by one visitor. These are the hashed logs described above.
To correct and re-run the work if something was wrong
If a report contained an error we fix it, which means keeping enough of the original record to see what went wrong. Basis: the contract and our legitimate interest in standing behind our own output.

If you are in the EEA or the UK, that is a summary written in the terms of the GDPR: consent (Article 6(1)(a)) for the e-mail contact, and contract or legitimate interests (Article 6(1)(b) and (f)) for everything else. The rights in the “Your rights” section apply to you in full.

04What we never do

  • We do not sell personal information, and we do not share it with data brokers, list merchants or advertisers. There is no sale or “sharing” as those terms are used by US state privacy laws.
  • We run no analytics scripts and no advertising pixels — no tag manager, no cross-context behavioural advertising, no profile of you across other sites.
  • We do not fabricate anything about you or your firm, and we do not send you manufactured urgency. The one limit we state anywhere is the real founding price for the first five clients per market, described in full in the terms of service.
  • We do not ask for access to your website, your Google account, your analytics or your card details.

05Who we share it with

We use a short list of services to run this business. Each one sees only what it needs, and we name the categories plainly instead of hiding behind “partners”:

  • Stripe — payments. Your card data goes to Stripe directly; we receive a payment reference and status.
  • Our e-mail provider — sending you the mini-check result, the report and the booking link.
  • Our hosting and database provider — the site and the records described in this policy live there.
  • Our search-data provider and our AI provider — running the checks. What leaves us for them is the business name and the city as a search query, and the public information behind that query. Your e-mail address is not sent to them.
  • Our scheduling service — booking your free one-hour call.

None of these providers is allowed to use your information for their own marketing. Several of them process data outside your country, including in the United States; they do so under their own standard contractual terms. We do not claim a signed processing agreement with every one of them yet, because we do not have one — that item is on our own list before this policy is treated as final.

06How long we keep it

Consent records (the mini-check and the opt-ins)
Kept while they are relevant — they are the proof of what you agreed to and the record of what we told you. They are append-only: nothing is edited or deleted in place, and if you unsubscribe or ask us to stop, we add a new dated entry recording that instead of quietly removing the first one, because a deletion would also delete the proof that you asked us to stop.
Mini-check results
Kept so the same firm is not paid for twice inside 30 days and so you can see the finding you were shown. Your address in the attempt log is stored in a form that cannot be read back.
Order and invoice records
Kept as long as tax and accounting rules require them to be kept — for our own administration that is seven years. This is an obligation, not a preference.
Attempt and page-view logs
Given a 12-month cap. We will be straight with you: the deletion runs behind that cap are not automated yet. If that changes, the change shows up here first.
Your e-mail address for follow-up
Kept until you withdraw consent or unsubscribe, and then not used for anything but recording that fact.

07Cookies and tracking

This site sets no cookies at all — not for analytics, not for advertising, not for a session. It stores nothing in your browser's local storage either, which is why there is no consent banner: there is nothing to ask you about.

Two things worth naming so that “no cookies” is not read as a trick:

  • When you click through to pay, you are on Stripe's page, under Stripe's own privacy and cookie policy. The same applies to our scheduling provider when you book the call.
  • The daily work of running a check produces server-side logs on our own host — that is what the hashed IP entries above describe. No log is used for advertising or profiling.

08Your rights

You can ask us, at any time and free of charge, to:

  • tell you what we hold about you, and give you a copy;
  • correct anything that is wrong;
  • delete what we are not obliged to keep (we will tell you plainly where an accounting or consent-proof obligation means we must keep a record, rather than pretending a deletion happened);
  • stop using your details, or restrict how we use them;
  • withdraw your consent to e-mail at any time, without it affecting anything we did before you withdrew;
  • send your data to you or to someone you name, in a readable format;
  • not be subject to a decision made purely by a machine on the e-mail we send you — nothing here is decided that way.

If you are a California resident: you have the rights to know, to delete, to correct, and to opt out of the sale or sharing of personal information. We do not sell or share personal information, and we do not discriminate against anyone who exercises these rights — the price of the report is the same whoever you are.

If you are in the EEA or the UK: these are your GDPR rights, including the right to complain to a supervisory authority. Our established regulator is the Dutch Autoriteit Persoonsgegevens; you may also complain to your own local authority.

One route to exercise any of this: e-mail foundfirst-2d92f6bd@ctomail.io. Say what you want and enough to identify the record — the firm name and the e-mail you used is normally all we need. We answer as soon as we can and within 45 days at the very latest.

09How we protect it

Access to the records is restricted to the systems that need them; the database requires credentials that are not stored in the site's own code; and IP addresses in our logs are stored hashed rather than in the clear. No system is perfect, and we will not claim otherwise. If a breach ever affected your information, we would tell you and the relevant authority, and say what happened.

10Children

This is a business service sold to firms, and the site is not directed at children. We do not knowingly collect anything about anyone under 16, and if you believe we have, tell us and we will delete it.

11Changes

If this policy changes, this page changes, with a new date at the top. We will not quietly widen what we collect and keep the same date on it. Material changes that affect people we may still e-mail are also mentioned in that e-mail.

12Contact

Any question about this policy, or a request about your information: foundfirst-2d92f6bd@ctomail.io. By post, use the registered address at the top of this page. There is no phone line and no support portal; e-mail reaches a person.

Draft status · v1 — draft

This document is a draft, written to match exactly how this site and the service behave today. It is v1 — draft, dated 1 October 2026, and it is still to be reviewed by a qualified lawyer before we treat it as final. If anything here contradicts what the site or an invoice tells you, tell us and we will correct this page — the page changes, the promise does not.