Privacy Policy

Privacy Policy

Last Updated: [insert date]

This Privacy Policy describes how Findabetterboss, Inc., a Delaware corporation (in formation) (“Findabetterboss”, “we”, “us”, “our”) collects, uses, and discloses information when you use our websites, applications, and related services (the “Services”).

Privacy contact: privacy@findabetterboss.com
Security contact: security@findabetterboss.com
Administrative mailing address: Postbox 700845, 22008 Hamburg (administrative correspondence only)


1) Notice at Collection (California)

The table below summarizes the categories of personal information we collect (California Civil Code §1798.140), purposes, whether we “sell” or “share” (as defined by CPRA) and retention defaults.

Category (CPRA) Examples Purpose Sold? Shared for CCBA? Retention
Identifiers (A) Name, email; optional org/role Accounts, support, security No No Account life + up to 36 months inactivity
Commercial (D) Subscription tier, invoices Billing, support, compliance No No 7 years (legal/tax)
Internet/Network (F) IP, device, referrer, pages Security, fraud, performance No Only if marketing tags enabled with consent (see §11) Logs up to 12 months
Geolocation (approx.) Inferred from IP (city/region) Security, abuse mitigation No No Logs up to 12 months
Inferences Non-sensitive usage clusters Product analytics, improvements No No GA4 up to 14 months
Sensitive PI Not sought; we do not use SPI to infer characteristics N/A No No N/A

Do Not Sell or Share: Use our Do Not Sell or Share My Personal Information page or send a valid GPC signal (see §11).
Limit Sensitive PI: See Limit the Use of My Sensitive Personal Information (we do not use SPI beyond permitted purposes).


2) Scope & Approach

The Services are operated as a U.S.-first service. We do not restrict access from other jurisdictions. Where privacy laws of another jurisdiction (e.g., EU/EEA, UK, Switzerland) apply to our processing, we comply with applicable obligations. Mandatory local laws are not waived by this Policy.

3) Controller

For the purposes described in this Policy, Findabetterboss is the “controller”. For enterprise features where we process on behalf of an organization, we act as “processor/service provider” under a Data Processing Addendum (see Terms, Appendix C).

4) Information We Collect

  • Account & Identifiers — email, password hash, optional name/role.
  • Contact & Subscription — newsletter preferences, tags (e.g., investor, beta).
  • Usage & Technical — IP, device, user agent, referrer, session IDs, page interactions, cookies or similar technologies.
  • Experience Reports — standardized 72-item responses that generate numeric dimension scores and a composite Leader Score; no free text.
  • Payment Data — if/when payments start, via a PCI-compliant processor; we do not store full card data.

5) Sources

Direct from you (registration, forms), automatically via your device (logs, cookies), and from service providers (e.g., auth, payments, anti-bot, analytics) as needed to operate the Services.

6) Purposes of Processing

  • Provide, maintain, and improve the Services and accounts.
  • Security, fraud prevention, integrity monitoring.
  • Transactional communications; marketing with consent.
  • Analytics and performance measurement.
  • Publishing the platform’s scores and analytics derived from Experience Reports (see §9).
  • Contract performance (Art. 6(1)(b) GDPR): account, core services.
  • Legitimate interests (Art. 6(1)(f)): security, fraud prevention, product analytics using strictly-necessary or de-identified data.
  • Consent (Art. 6(1)(a)): optional analytics/marketing cookies and emails. Consent can be withdrawn at any time in Preferences or via unsubscribe links.

8) Service Providers & Disclosures

  • Supabase (authentication, storage; US region)
  • SiteGround (hosting)
  • WordPress (CMS); selected plugins
  • hCaptcha (bot protection)
  • Mailchimp (email automation/newsletter)
  • Google Tag Manager (tag orchestration)
  • Google Analytics 4 (analytics, with consent)
  • Payment processor (if/when billing starts)

Current subprocessors are listed at /legal/subprocessors. We require confidentiality, security, and data protection commitments from providers.

9) Cookies & Similar Technologies

We use cookies and similar technologies to operate the Services, authenticate users, secure sessions, and — with your consent — measure performance.

  • Essential — strictly necessary (session, security); cannot be disabled if you use the site.
  • Google Analytics 4 (via Google Tag Manager) — used only with your consent; configured with limited retention (see §12).
  • Google Tag Manager — used to manage and orchestrate tags. GTM itself does not collect personal data; it only triggers tags you have consented to.
  • Future tags — additional analytics or marketing technologies may be implemented via Google Tag Manager. These will only be activated if you provide consent in Preferences.

10) Experience Reports — Separation & Publication

  • Experience Reports are closed-form (72 items, numeric only; no free text).
  • Each individual report is published as an anonymized numeric record. From the first report onward, the platform computes six dimension scores and a composite Leader Score; with two (2) or more reports, mean values may be displayed.
  • We technically and organizationally separate account data from report data to minimize linkability.
  • Aggregated exports and advanced slicing are allowed only when thresholds are met (e.g., k ≥ 7, diversity/dominance safeguards); otherwise, export/views are suppressed.

Disclaimer: Scores reflect subjective experiences of individual users and are not statements of fact or guarantees of representativeness. Scores evolve as more reports are submitted.

11) Global Privacy Control (GPC) & Do Not Sell/Share

We honor valid GPC signals as an opt-out of sale/share where required by law. You can also use:

We do not knowingly sell or share personal information of consumers under 16 years of age.

12) Retention

  • Accounts — life of account + up to 36 months after last activity (unless deleted earlier upon request).
  • Experience Reports — retained indefinitely as anonymized/non-personal data to preserve historical integrity.
  • Security & access logs — up to 12 months (longer only if required for incident response).
  • Analytics (GA4) — 14 months (configurable).
  • Backups — rolling up to 90 days.
  • Billing — 7 years (legal/tax).

13) Security & International Transfers

  • Security — we apply commercially reasonable technical and organizational measures (TLS in transit, encryption at rest where applicable, least privilege, MFA for admin, monitoring). No method is 100% secure.
  • Transfers — data may be processed in the United States. For EU/EEA/UK/CH transfers, we use appropriate safeguards such as Standard Contractual Clauses (SCCs) with the UK Addendum/Swiss addendum where applicable.
  • DPA — for enterprise processing, our Data Processing Addendum applies; see Terms, Appendix C.

14) Children

The Services are intended only for individuals aged 18+. We do not knowingly collect personal information from children under 13. If you believe a child provided data, contact us to delete it.

15) Your Privacy Rights

Depending on your location, you may have rights to access, correct, delete, restrict/opt out of certain processing, data portability, and to opt out of sale/share or limit the use of sensitive personal information.

  • How to submit — email privacy@findabetterboss.com or use our web tools: Do Not Sell/Share and Preferences.
  • Verification — we will verify your identity and request details before acting.
  • Authorized agents (California) — may submit requests with proof of authorization.
  • Response times — California: within 45 days (extendable); EU/UK: within 1 month (extendable).
  • Non-discrimination — we will not discriminate against you for exercising your rights.

16) U.S. State Notices

California (CCPA/CPRA) — see §§1, 11, 15. You have rights to access, delete, correct, opt out of sale/share, and limit sensitive PI. We provide two or more methods to submit requests and honor GPC signals.
Nevada — we do not sell personal information for monetary consideration; contact us to exercise Nevada rights.
Other U.S. states — where applicable, we honor comparable rights (e.g., access, deletion, opt-out).

17) Changes

We may update this Policy. Material changes will be posted here with a new “Last Updated” date. Continued use of the Services after the effective date indicates acceptance.

18) Contact

Questions or requests: privacy@findabetterboss.com. For security matters: security@findabetterboss.com.

EU/UK Representative (GDPR Art. 27): Findabetterboss will appoint a representative in the EU and UK for GDPR/UK-GDPR purposes. Until appointed, please direct requests to the contacts above.