ClientFinch

Legal

Privacy Policy

We collect only what we need to run your account and the website, we do not sell personal data, and you can export or delete your data at any time.

Last updated

ClientFinch (“we”, “us”) is operated by Arwenus LLC, a limited liability company registered in the State of Wyoming, United States (EIN 61-2117863), whose registered office is at 1309 Coffeen Ave STE 1200, Sheridan, WY 82801, United States. We are the controller of the personal data described in this policy.

If you have any questions about this policy or your data, contact us at info@clientfinch.co.uk or through the contact form on this website.

  • Account data: your email address, optional name, a securely hashed password (we never store your password in plain text), how you sign in, and whether your email address has been verified. If you use Google sign-in, we also receive your name and profile picture from Google.
  • Session and security data: a sign-in session cookie, one-time verification and password reset tokens (stored only in hashed form), and records of failed sign-in attempts linked to your IP address and email address to protect against password guessing.
  • Saved leads and notes: the companies you save (company name and number) and any notes you write about them.
  • Contact form messages: your name, email address, optional company name, the topic and your message, together with a one-way hash of your IP address used to prevent abuse.
  • Preferences stored in your browser: your cookie choices, and, if you used ClientFinch before creating an account, any companies you saved in that browser until you import them.
  • Technical data: our hosting provider processes standard server logs (such as IP address, browser type and the pages requested) to run and secure the service.

We do not sell personal data, we do not use it for advertising, and we do not send marketing emails without your consent.

  • To create and run your account, keep you signed in and keep your saved leads in sync across devices — necessary to perform our contract with you.
  • To send essential service emails such as email verification and password reset links — necessary to perform our contract with you.
  • To keep the service secure, prevent abuse and enforce our terms — our legitimate interests.
  • To reply to messages you send us — our legitimate interests in responding to enquiries.
  • To meet legal obligations, such as responding to lawful requests from authorities.

ClientFinch displays public information from the Companies House register through the official Companies House Public Data API, under the Open Government Licence v3.0. This is company-level information such as company names, numbers, status, incorporation dates, registered office addresses and SIC codes. For some small companies, the registered office may be a home address, which can be personal data.

We process this public information to provide search results, on the basis of our legitimate interests and yours in researching businesses. We do not combine it with personal contact details. If you use information from ClientFinch to contact a business or person, you are responsible for doing so lawfully under UK GDPR and the Privacy and Electronic Communications Regulations (PECR). If information about you on the register is wrong, you will need to correct it with Companies House.

We use a small number of service providers (processors) who act on our instructions and are bound by data protection terms:

  • Cloud hosting and application infrastructure providers that run and secure the service.
  • Managed database hosting (MongoDB) for account data, saved leads and contact messages.
  • Transactional email delivery (Resend, provided through our platform’s managed email integration) for verification, password reset and contact form emails.
  • Authentication provider for Google sign-in, where you choose to use it.
  • Companies House: when you search, your search terms are sent to the Companies House API to retrieve results. No account information is sent.

Some of our providers may process data outside the UK. Where they do, we rely on adequacy regulations or appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.

  • Account data, saved leads and notes: until you delete your account. Deleting your account removes this data from our live database immediately, and from routine backups within 30 days.
  • Sign-in sessions: up to 7 days, or until you sign out.
  • Email verification links: 24 hours. Password reset links: 1 hour. Both can only be used once.
  • Failed sign-in records: automatically deleted after 24 hours.
  • Contact form messages: automatically deleted after 180 days, unless we need them longer to deal with an ongoing matter.

Under UK GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased — you can delete your account at any time from Account settings;
  • restrict or object to certain processing;
  • data portability — you can export your saved leads to CSV at any time;
  • withdraw consent where we rely on it, for example for optional cookies.

Please contact us first at info@clientfinch.co.uk so we can try to help. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK data protection regulator, at ico.org.uk or on 0303 123 1113.

We use HTTPS throughout, store passwords using a strong one-way hashing algorithm, keep session and one-time tokens in hashed form, limit repeated sign-in attempts and make sure each account can only access its own saved leads. No system is perfectly secure, so please use a strong, unique password.

ClientFinch is a business tool and is not intended for anyone under 18.

We will update this page if our practices change and, where the changes are significant, tell account holders by email.