1. Who we are
SOSfinder operates an API for United States Secretary of State business entity records. This policy explains how we handle personal data when you visit our website, create an account, or use the API. For the personal data you provide to us as a customer, SOSfinder is the data controller.
We do not sell your data
2. What we collect
2.1 Account information
When you sign up we collect your email address and a securely hashed password, plus your name and company if you choose to provide them. If you have a Gravatar profile picture associated with your email, we display it — your email is hashed in your browser before it reaches Gravatar.
2.2 Payment information
Payments are processed by Paddle, our merchant of record. Card numbers and billing details are collected and stored by Paddle under PCI DSS standards and never reach our servers. We receive only what we need to run your account: your plan, subscription status, renewal date, and the country used for tax purposes.
2.3 API usage data
Every API request is logged so we can meter your plan, enforce rate limits, bill overage accurately, and debug failures. These logs include:
- The API key used, and the endpoint, timestamp, and response status
- The lookup parameters sent — typically a business name, entity number, and state
- IP address and user agent of the calling client
- Error traces when a request fails
Lookup parameters are business search terms, not personal data by design. If you send a personal name — for example when searching for a registered agent or officer — it is stored in these logs like any other query.
2.4 Website and product analytics
We record a coarse traffic source for the first page of a visit (search engine, referring site, or campaign tag) so we know which channels work. It is aggregate and not tied to your identity. We do not run advertising or cross-site tracking cookies.
2.5 Support conversations
Messages and any files you send through our support chat or by email are stored so we can answer you and keep a record of the issue. Conversations are read by our own team — not by a third-party support vendor.
3. Why we use it
We process the data above to run and improve the Service, on the legal bases noted in brackets:
- Provide the API, dashboard, and monitoring you signed up for [performance of a contract]
- Meter usage, bill your plan, and process renewals and refunds [contract, legal obligation]
- Send service notices, quota warnings, and security alerts [contract, legitimate interests]
- Answer support requests [contract, legitimate interests]
- Detect and prevent abuse, key sharing, fraud, and attacks [legitimate interests]
- Understand which features and traffic channels work, in aggregate [legitimate interests]
- Meet tax, accounting, and other legal obligations [legal obligation]
We send product and marketing email only if you opt in, and every such email has a one-click unsubscribe link.
4. Who processes data for us
We keep our vendor list deliberately short. Each of these providers processes data on our instructions only:
- Paddle — merchant of record: checkout, payments, invoicing, refunds, and sales tax
- Convex — application database, authentication, and backend functions
- Vercel — website and API hosting, edge delivery, and request logs
- Cloudflare — transactional email delivery and storage for support-chat attachments
- Gravatar — optional profile pictures, requested from your browser using a hash of your email
We may also disclose data where we are legally required to — in response to a valid court order or lawful government request — or where it is necessary to protect our rights, our users, or the security of the Service. If SOSfinder is ever acquired, data may transfer as part of that transaction, and we will notify you beforehand.
5. Where data is stored
Our infrastructure runs in the United States. If you are located outside the US, using the Service involves transferring your data there. Where required, those transfers rely on Standard Contractual Clauses or an equivalent safeguard in our agreements with the providers listed above.
6. How long we keep it
- Account records: for as long as your account is open
- API request logs: 90 days, then deleted or aggregated into usage counts
- Billing and invoice records: as long as tax and accounting law requires, typically seven years
- Support conversations: two years after the conversation closes
When you delete your account we remove your personal data within 30 days, except for records we are legally required to retain.
7. Security
All traffic runs over TLS. Passwords are hashed, never stored in plain text. API keys are stored as hashes and shown to you in full only once, at creation, and can be rotated or revoked at any time from your dashboard. Access to production data is limited to the people who need it to operate the Service. No system is perfectly secure, but if a breach affects your personal data we will notify you and the relevant authority without undue delay.
8. Your rights
Depending on where you live — including under the GDPR and the CCPA/CPRA — you have the right to:
- Access the personal data we hold about you
- Correct anything inaccurate
- Delete your data, subject to our legal retention obligations
- Receive your data in a portable format
- Object to or restrict processing based on legitimate interests
- Withdraw consent to marketing email at any time
- Complain to your local data protection authority
Email support@sosfinder.com to exercise any of these. We respond within 30 days and we never charge for it or treat you differently for asking.
9. Cookies
We use a small number of strictly necessary cookies and local storage entries: one to keep you signed in, and one to remember your light or dark theme. There are no advertising, profiling, or cross-site tracking cookies, which is why you are not greeted by a consent banner.
10. Public records in our API
The business entity records our API returns come from state government registries and are public by law. Some of them name individuals — a registered agent or an officer, for example. We publish that information as the state publishes it; we cannot amend or remove it, because we are not the source. Requests to correct a filing must go to the Secretary of State office that maintains it. If you believe a record is being surfaced unlawfully, contact us at support@sosfinder.com and we will review it.
11. Children
The Service is a business tool and is not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us data, contact support@sosfinder.com and we will delete it.
12. Changes to this policy
We will update this policy as the Service changes. Material changes are announced by email or in the dashboard, and the “Last updated” date above always reflects the current version.
13. Contact
For any privacy question or request, email support@sosfinder.com.