Skip to content

not.a.broker · Legal

Privacy Policy

Effective September 24, 2026 · Last updated September 24, 2026

Your business search involves information that matters. This policy explains what we collect, why we use it, who may receive it, and the choices available to you.

1. Who we are and what this policy covers

not.a.broker (“we,” “us,” and “our”) provides a membership platform for business acquisition research, seller information, and related workspace tools. This policy covers information handled through notabroker.io, your account, business submissions, and communications with our team. It applies to visitors, members, business owners, and people whose business contact information appears in our research or listings.

Other websites, independent buyers and sellers, and third-party services have their own privacy practices. Our Terms of Use explain the rules for using the platform; this policy explains our information practices.

2. Information we collect

Account and contact information: your name, email address, buyer or company name, account identifiers, authentication details, profile preferences, and information you provide when asking for help. If social sign-in is available and you choose it, the identity provider supplies information such as your account identifier, name, and email address under the permissions you approve.

Workspace and business information: research records, saved companies or leads, searches, notes, source links, acquisition interests, business submissions, and updates. Submissions and listings may include owner or representative names, business contact details, location, industry, financial ranges, employee ranges, seller context, and information about a potential sale. We also obtain business information from public sources, business representatives, research, and communications with owners.

Billing and communication information: subscription status, billing identifiers, invoices, payment history, support messages, email preferences, and delivery or complaint records. Stripe processes payment details through its payment interface. Our application does not receive or store full card numbers or card security codes.

Technical and activity information: IP addresses or identifiers derived from them, browser and device information, request and security logs, session information, and interactions needed to operate features. For eligible membership follow-ups, we record signup, checkout, and payment-form interaction timestamps, not the contents of payment fields.

3. How we use information

We use information to create and secure accounts, deliver the features included in your membership, organize research and seller submissions, process subscriptions, respond to support requests, maintain records, investigate abuse, and improve the service. We also use it to communicate about account access, confirmations, security, billing, and service changes.

Promotional membership emails are separate from operational messages. Where you opt in, we may send offers and relevant follow-ups. You can change your email preferences or use an unsubscribe link. Opting out of promotions does not stop necessary account, security, support, or billing messages.

Where a legal basis is required, we process information as necessary to provide requested services, meet legal obligations, pursue legitimate interests such as security and business administration, or act on your consent where required. You may withdraw consent for future consent-based processing without affecting processing already lawfully completed.

4. When information is shared

Within the platform: business information and seller contact details may be made available to members whose access permits them to view that information, including paying members. Information submitted for listing can become part of a listing after review. Community contributions are visible to their intended audience. Workspace records and private notes are subject to the platform’s account and organization access controls; authorized staff may access information to operate the service or resolve issues. Do not submit information you lack permission to share.

Service providers: we use providers for hosting, authentication, databases, payment processing, and email delivery. These include Vercel, Supabase, Stripe, and Resend. They receive information needed for their roles. Providers such as payment processors and identity providers may also process information under their own policies and legal obligations.

Other disclosures: we may disclose information when you request an introduction or otherwise direct us to share it; to professional advisers; when reasonably necessary to comply with law, protect rights, prevent fraud, or address a security issue; and in connection with a merger, financing, reorganization, or transfer of the business, subject to applicable protections.

Access to seller and business information is part of our paid service. We do not describe that information as never shared or sold. Where applicable privacy law treats a disclosure as a sale or sharing of personal information, you may contact us to exercise the rights available to you, including a request to opt out.

5. Cookies, browser storage, and third parties

We use cookies and similar technologies for authentication, session security, and service preferences. Browser storage can remember choices such as dismissed installation or live-event notices. Blocking cookies may prevent sign-in or other essential features from working.

Embedded media, such as YouTube videos, payment interfaces, and external links may let third parties receive technical information and use their own cookies or storage. Their policies apply to their services. Review your browser and provider settings for available controls. Where consent is legally required for optional technologies, those technologies must be handled in accordance with that requirement.

6. Retention and security

We retain information for as long as reasonably needed to provide the service, maintain account and transaction records, resolve disputes, prevent misuse, and satisfy legal obligations. Retention depends on the type of information and why it was collected. Closing an account or canceling a subscription does not automatically erase every record; billing, security, legal, and backup records may need to be retained longer.

We use technical and organizational safeguards, including authenticated access and restrictions on organization and member data. No website, storage system, or transmission method can be guaranteed completely secure. Keep your credentials private and notify us if you suspect unauthorized access.

7. Your choices and privacy requests

You can update available profile and email preferences in your account. To request access, correction, deletion, a copy of your information, or restriction of its use, email support@notabroker.io. Business owners and contacts can also ask us to review inaccurate or inappropriate information in a listing. Include enough detail to identify the relevant account or record; do not send passwords or full payment details.

Depending on your location and the law that applies, you may have rights to portability, objection, withdrawal of consent, an opt-out of certain disclosures or targeted advertising, and appeal of a request decision. We may verify identity or an authorized agent’s authority before responding. Some information may be withheld or retained where permitted or required by law, including to protect other people’s information. We respond within applicable legal time limits and do not unlawfully discriminate against you for exercising your rights.

If you disagree with our response, reply requesting a review. You may also have the right to contact the privacy regulator or supervisory authority where you live. Information already independently collected by another member or external website may need to be addressed with that party directly.

8. International use and age requirements

Our service and providers may process information in the United States and other countries where they operate. Those countries may have different privacy laws. Where required, international transfers must be subject to appropriate legal safeguards.

The service is intended for adults aged 18 or older. We do not knowingly seek personal information from children. If you believe a child has provided information to us, contact support so we can investigate and take appropriate action.

9. Updates and contact

We may update this policy as the service or our practices change. The date at the top identifies the current version. We will provide additional notice of material changes where required and obtain consent where applicable law requires it. For privacy questions or requests, contact not.a.broker at support@notabroker.io.

Questions or requests? Email support@notabroker.io.