Legal
Privacy policy
This is what FoundFirst does with personal information on this site and in the service behind it. It is written to describe what the site actually does — including the parts that are deliberately plain, like keeping no analytics and running no advertising pixels.
- Version v1 — draft
- Last updated 1 October 2026
- Applies to the US site and the US report service
01Who we are
FoundFirst is the controller of the personal information described here: the business that decides what is collected and why. We sell one thing: a written Local Visibility Report on your firm for $749, plus a free one-hour implementation call.
Controller
- FoundFirst
- Registered address
- Argonweg 73, 1362 AD Almere, Nederland
- Company registration (KvK)
- 81834500
- VAT identification (btw-id)
- NL003609731B25
- Privacy contact
- foundfirst-2d92f6bd@ctomail.io
Registered with the Dutch Chamber of Commerce (KvK). The KvK number and btw-id are disclosed here as Dutch law requires.
We are a small, new operation — no revenue has been earned yet, so there is no customer archive and no mailing list beyond what the forms on this site have collected. Nothing in this policy describes data we do not have.
02What we collect
There are three moments at which we can receive anything about you.
- The free mini-check (business name, city, e-mail)
- You type your firm's name, the city you draw clients from, and an e-mail address, and you tick a consent box to have the result e-mailed to you. The record we keep holds the firm name, the city, your e-mail address, the exact consent sentence you ticked, the version of that sentence, and the time you submitted it. It also holds the date and location of the search we ran, the exact query, the finding we showed you and the honest summary next to it — so that you can check later what we told you. Your IP address and browser user-agent are stored alongside it in hashed or shortened form, to stop the free check being abused.
- A separate attempt log
- To keep the mini-check within its rate limits and to measure honestly how many people ask for a check at all, we also record each attempt — the firm name, the city a shortened form of the e-mail address, an IP hash, the user-agent, the outcome and how long it took. This is a measurement log, not a mailing list: the address in it cannot be read back and no e-mail is ever sent from it.
- An order (business details and payment status)
- After you pay, you send us your firm's details so we can run the report: firm name, practice area, city and state, an e-mail address, an optional phone number and an optional Google Business Profile link. Your card is handled by Stripe; we receive a payment reference and whether the payment succeeded — never your card number, and we store no payment credentials of yours.
We collect nothing else. There is no account to create, no login, no cookie banner because there is nothing to consent to, and no hidden field gathering anything you did not type.
03Why we use it
- To deliver what you bought
- Your firm details are what the report is made of, and your e-mail is how it reaches you. Basis: the contract between us — we can only do the work with those details.
- To e-mail you the mini-check result and follow up about it
- Basis: the consent you gave by ticking the box on the form. It is not bundled with anything, it is unticked by default, and you can withdraw it at any time — see “Your rights” below. Every message we send carries a way out.
- To keep the service usable and honest
- Rate-limiting the free check, spotting abuse, and measuring how many checks were run and what came of them. Basis: our legitimate interest in a small, working service that does not get drained by one visitor. These are the hashed logs described above.
- To correct and re-run the work if something was wrong
- If a report contained an error we fix it, which means keeping enough of the original record to see what went wrong. Basis: the contract and our legitimate interest in standing behind our own output.
If you are in the EEA or the UK, that is a summary written in the terms of the GDPR: consent (Article 6(1)(a)) for the e-mail contact, and contract or legitimate interests (Article 6(1)(b) and (f)) for everything else. The rights in the “Your rights” section apply to you in full.
04What we never do
- We do not sell personal information, and we do not share it with data brokers, list merchants or advertisers. There is no sale or “sharing” as those terms are used by US state privacy laws.
- We run no analytics scripts and no advertising pixels — no tag manager, no cross-context behavioural advertising, no profile of you across other sites.
- We do not fabricate anything about you or your firm, and we do not send you manufactured urgency. The one limit we state anywhere is the real founding price for the first five clients per market, described in full in the terms of service.
- We do not ask for access to your website, your Google account, your analytics or your card details.
06How long we keep it
- Consent records (the mini-check and the opt-ins)
- Kept while they are relevant — they are the proof of what you agreed to and the record of what we told you. They are append-only: nothing is edited or deleted in place, and if you unsubscribe or ask us to stop, we add a new dated entry recording that instead of quietly removing the first one, because a deletion would also delete the proof that you asked us to stop.
- Mini-check results
- Kept so the same firm is not paid for twice inside 30 days and so you can see the finding you were shown. Your address in the attempt log is stored in a form that cannot be read back.
- Order and invoice records
- Kept as long as tax and accounting rules require them to be kept — for our own administration that is seven years. This is an obligation, not a preference.
- Attempt and page-view logs
- Given a 12-month cap. We will be straight with you: the deletion runs behind that cap are not automated yet. If that changes, the change shows up here first.
- Your e-mail address for follow-up
- Kept until you withdraw consent or unsubscribe, and then not used for anything but recording that fact.
08Your rights
You can ask us, at any time and free of charge, to:
- tell you what we hold about you, and give you a copy;
- correct anything that is wrong;
- delete what we are not obliged to keep (we will tell you plainly where an accounting or consent-proof obligation means we must keep a record, rather than pretending a deletion happened);
- stop using your details, or restrict how we use them;
- withdraw your consent to e-mail at any time, without it affecting anything we did before you withdrew;
- send your data to you or to someone you name, in a readable format;
- not be subject to a decision made purely by a machine on the e-mail we send you — nothing here is decided that way.
If you are a California resident: you have the rights to know, to delete, to correct, and to opt out of the sale or sharing of personal information. We do not sell or share personal information, and we do not discriminate against anyone who exercises these rights — the price of the report is the same whoever you are.
If you are in the EEA or the UK: these are your GDPR rights, including the right to complain to a supervisory authority. Our established regulator is the Dutch Autoriteit Persoonsgegevens; you may also complain to your own local authority.
One route to exercise any of this: e-mail foundfirst-2d92f6bd@ctomail.io. Say what you want and enough to identify the record — the firm name and the e-mail you used is normally all we need. We answer as soon as we can and within 45 days at the very latest.
09How we protect it
Access to the records is restricted to the systems that need them; the database requires credentials that are not stored in the site's own code; and IP addresses in our logs are stored hashed rather than in the clear. No system is perfect, and we will not claim otherwise. If a breach ever affected your information, we would tell you and the relevant authority, and say what happened.
10Children
This is a business service sold to firms, and the site is not directed at children. We do not knowingly collect anything about anyone under 16, and if you believe we have, tell us and we will delete it.
11Changes
If this policy changes, this page changes, with a new date at the top. We will not quietly widen what we collect and keep the same date on it. Material changes that affect people we may still e-mail are also mentioned in that e-mail.
12Contact
Any question about this policy, or a request about your information: foundfirst-2d92f6bd@ctomail.io. By post, use the registered address at the top of this page. There is no phone line and no support portal; e-mail reaches a person.