Privacy Policy

Effective date: To be set at publication · Last updated: July 15, 2026

Effective date: To be set at publication
Last updated: July 15, 2026

Greenfinch AI, Inc. ("Greenfinch," "we," "us") operates a property-intelligence platform for commercial real estate ("CRE") prospecting at greenfinch.ai and app.greenfinch.ai (the "Service").

This Privacy Policy is written for two audiences:

1. Customers, users, and website visitors — people who use the Service or visit our sites.
2. Professionals in our property and contact database — property owners, managers, and business decision-makers whose business information may appear in the Service even if they have never interacted with Greenfinch.

1. Summary of how Greenfinch handles information

  • We build business-context records that connect commercial properties with the organizations and professionals responsible for them. We use public government records, licensed business-data providers, public business websites, and AI-assisted research.
  • We do not intentionally collect or deliver sensitive personal information about professionals, such as health information, financial-account information, government identifiers, biometric or genetic information, precise device geolocation, or information about sensitive personal characteristics.
  • We do not sell our customers' or website visitors' personal information, and we do not use their personal information for cross-context behavioral advertising.
  • California launch restriction. We do not make Contact Data available to customers when our records identify the professional as working or residing in California. Records that have not passed our jurisdiction screening are withheld from customer delivery until they can be classified. Public property records may remain available because they are handled separately from Contact Data.
  • Outside restricted jurisdictions, providing business Contact Data to paying customers is part of the Service. That disclosure may be treated as a "sale" under some privacy laws even though the data is licensed for limited business use. Any professional may opt out of future delivery.
  • We accept verified access, correction, deletion, and delivery-opt-out requests regardless of whether a particular state law requires us to do so. A deletion removes personal fields, suppresses reintroduction, and triggers applicable provider and customer follow-up.

2. Information we collect from customers and users

  • Account information — name, email address, organization details, role, and authentication records, collected and managed through our authentication provider (Clerk).
  • Billing information — subscription and transaction metadata such as plan, status, invoices, and credit activity. Stripe handles payment-card information; Greenfinch does not store full card numbers.
  • Onboarding, survey, and waitlist information — role, use case, service area, and other information you choose to provide.
  • Customer Data — pipeline stages, deal values, notes, activity records, saved views, and records you upload. Customer Data is scoped to your organization and is not added to the shared Greenfinch property and contact database.
  • Communications — support requests, feedback, and correspondence with us.

3. Information collected automatically

We designed product analytics to minimize personal information:

  • Product usage telemetry — when enabled, we record feature-use and performance events against normalized page templates, a coarse device class, and server-assigned user and organization identifiers. We do not intentionally store search text or user-entered workspace content in telemetry. Raw telemetry is generally deleted within about 45 days; aggregated statistics may be kept longer.
  • Server, security, and audit logs — request records and records of administrative or data-affecting actions used for security, debugging, fraud prevention, and compliance.
  • Error reporting — technical error context, which may include a user identifier and limited request context. We configure error reporting to avoid default collection of unnecessary personal information.
  • Cookies and similar technologies — authentication and security cookies, local storage for interface preferences, and limited first-party functionality or measurement where enabled. We do not use third-party advertising cookies or cross-site behavioral advertising trackers on the Service. See our Cookie Policy.

4. How we use customer and visitor information

We use customer and visitor information to provide, secure, support, and improve the Service; authenticate users; administer organizations; process subscriptions, credits, and payments; enforce plan, seat, territory, and usage limits; communicate about accounts, billing, security, and product changes; respond to support requests; measure performance; and prevent fraud or abuse.

We do not contribute Customer Data to the shared database, and we do not use Customer Data to train a general-purpose AI model made available to other customers.

5. How we disclose customer and visitor information

We do not sell customer or visitor personal information. We disclose it only as needed to:

  • Service providers that operate portions of the Service, including Stripe, Clerk, U.S.-based cloud and database providers, transactional-email providers, error monitoring, secrets management, and AI model providers used for research features. They may process information only for the services they provide to us and subject to the agreements and controls applicable to their role.
  • Your organization so administrators and teammates can access organization-level settings, usage, billing, and shared workspace content according to their permissions.
  • Legal and safety recipients when required by law or legal process, or when reasonably necessary to protect Greenfinch, our users, or the public.
  • Transaction counterparties in a merger, acquisition, financing, reorganization, or sale of assets, subject to this Policy and appropriate confidentiality protections.

6. The Greenfinch property and contact database

This section applies to professionals whose information appears in Greenfinch data, including people who have never used the Service.

6.1 What we collect and why

Greenfinch helps CRE teams identify the organizations and professionals responsible for commercial properties. We compile:

  • Property records — parcel and assessor information, ownership names as recorded in public records, valuations, building characteristics, legal descriptions, property addresses and coordinates, and researched property attributes such as beneficial owner organization, management company, and asset category.
  • Organization records — firm name, website, industry, size, locations, and related public business information for property owners, operators, and management firms.
  • Business contact records — professional name, job title, employer, business email address, business phone number, professional profile URL, and business background.

6.2 Sources

  • Public county assessor, parcel, and other government records.
  • Licensed providers of professional-contact, organization, email-verification, and company information.
  • Public business websites, company team and contact pages, professional profiles, search results, and other information lawfully made available to the public.
  • Greenfinch's own AI-assisted and deterministic research, verification, correction, and quality-control processes.

6.3 Information and uses we exclude

  • Sensitive information. We do not intentionally collect or deliver health, biometric, genetic, financial-account, government-identifier, race or ethnicity, religion, sexual-orientation, or similar sensitive information about database professionals.
  • Location. Property addresses and parcel coordinates describe real estate. We do not collect precise location derived from a professional's device.
  • Phone delivery. We deliver a phone number only when our controls classify it as an eligible business number under our source, label, public-business-page, and jurisdiction rules. Personal or home numbers are withheld.
  • Minors. The database is intended for professionals acting in a business capacity. We do not knowingly include anyone under 18.
  • Business context. Contact records are intended to describe professional roles and business relationships, not an individual's activities in a personal or household context.
  • Legally significant decisions. We prohibit use of the Service for credit, employment, insurance, housing, tenancy, healthcare, government-benefit, or similar eligibility decisions.

6.4 How database information is used and disclosed

Property and eligible Contact Data may be made available through the Service to paying customers, subject to subscription, credit, geography, jurisdiction, and contractual controls. Customers may use it only for lawful business-to-business sales, marketing, and CRE prospecting. Our Terms prohibit resale, bulk republication, harassment, sensitive profiling, consumer-reporting uses, and unlawful outreach.

California. At launch, Contact Data is not customer-deliverable when our records identify the professional as working or residing in California. Unclassified records are held from delivery until screening is complete. We will not change that practice without implementing the controls required for the changed use and updating this Policy before the change takes effect.

EEA and UK. Greenfinch focuses on U.S. CRE and does not intentionally make Contact Data identified as relating to EEA or UK professionals available to customers. If we determine that European data-protection law applies to a record, we will withhold it unless and until we have documented an appropriate lawful basis, delivered required notice, and implemented any required transfer safeguard.

We also disclose database information to service providers as needed to operate, verify, secure, and maintain the Service, and when required by law.

7. AI processing

We use commercial AI services to research property ownership and management, categorize properties, find and verify business contacts, prune mismatches, and create research summaries. AI output can be incomplete, outdated, or wrong; customers must verify information before acting on it. We do not use AI to make legally significant decisions about individuals.

AI providers process prompts and output to provide their services to Greenfinch. We limit the information sent to what is reasonably needed for the research task and apply provider settings and contractual controls appropriate to the data and service.

8. Privacy choices and requests

8.1 How to submit a request

Any person whose information Greenfinch holds may request access, correction, deletion, or an opt-out from future Contact Data delivery through:

  • the Greenfinch privacy request form at https://greenfinch.ai/privacy/requests; or
  • email to privacy@greenfinch.ai.

The request form must be live before this Policy is published. You do not need to create a Greenfinch account. We may ask for information reasonably necessary to locate the record and verify identity or authority, but we will not require sensitive identity documents when a less intrusive method is sufficient. Authorized agents may submit requests with proof of authority.

We acknowledge requests, provide status notices, and complete or deny them within the period required by applicable law. If we deny a request in whole or in part, we explain the basis and provide an appeal method where required. We do not discriminate against anyone for exercising a privacy right.

8.2 What happens after a verified request

  • Access. We provide the personal information we can reasonably associate with the verified requester, its general sources, purposes, and recipient categories, subject to security, trade-secret, and third-party privacy limits.
  • Correction. We correct verified inaccuracies or suppress the record when correction cannot be completed safely.
  • Delivery opt-out. We promptly suppress the record from future customer delivery and prevent it from being reintroduced through ordinary enrichment.
  • Deletion. We first suppress the record from customer access, then scrub personal fields and their history through our erasure workflow. We retain a minimal non-identifying tombstone and request record to prevent reintroduction, demonstrate compliance, and protect system integrity.
  • Provider and customer follow-up. Where required and supported, we send a deletion or suppression instruction to the provider from which the information came. If a tracked record was previously delivered or exported, we direct the receiving customer to stop using and delete the affected Contact Data under its contractual obligations, unless a documented legal exception applies.

Public property records, non-personal organization information, billing and transaction records, security and audit records, and information required for legal claims or compliance may be retained when an applicable exception permits it. We do not retain an exception merely to continue the use that prompted the request.

8.3 Categories, sources, purposes, and recipients

Information categoryExamplesMain sourcesMain purposesRecipient categories
Identifiers and account informationName, email, user and organization IDsCustomer or user; ClerkAuthentication, account administration, support, securityOrganization administrators; service providers
Commercial informationPlan, subscription, invoices, credits, transactionsCustomer; Stripe; GreenfinchBilling, entitlements, fraud prevention, recordkeepingStripe; organization administrators; advisors as needed
Internet or application activityFeature events, page templates, device class, server and error logsBrowser, device, and ServiceOperation, security, debugging, aggregate analyticsHosting, monitoring, and security providers
Professional identifiers and employment informationName, employer, title, business email, eligible business phone, professional profileLicensed providers; public business sources; Greenfinch researchCRE business research, verification, customer delivery outside restricted jurisdictionsEligible customers; research and infrastructure providers
Property and organization informationParcel, address, coordinates, ownership record, firm identity and websiteGovernment records; licensed aggregators; public sourcesProperty intelligence, search, research, and verificationCustomers; infrastructure and research providers
Research findings and inferencesProbable owner or manager relationship, asset category, contact matchPublic and licensed sources; AI-assisted researchVerification, categorization, and CRE researchEligible customers; AI and research providers

8.4 Sale, sharing, and preference signals

  • We do not sell customer or visitor personal information and do not share it for cross-context behavioral advertising.
  • We do not make California Contact Data available to customers under the launch restriction in Section 6.4.
  • Outside restricted jurisdictions, making business Contact Data available to paying customers may be treated as a sale under an applicable law. A professional may opt out at any time through the request form or privacy@greenfinch.ai, whether or not the law requires Greenfinch to offer that choice.
  • Where legally required and technically applicable, we honor recognized browser-based opt-out preference signals. Because we do not use cross-context behavioral advertising, such a signal does not change advertising behavior on the Service.

9. Retention

  • Customer accounts and Customer Data — retained while the account is active. After verified account or organization deletion, access is disabled and personal workspace data is deleted after a short recovery window, currently about 30 days, subject to billing, tax, security, legal, and audit exceptions.
  • Professional Contact Data — retained while the record remains relevant to the Service's business purpose and within the applicable source-freshness period. Records are re-verified on provider- and field-specific schedules. Provider-cache contacts that were not delivered and are not otherwise linked to a live business record are automatically erased after 365 days without re-verification.
  • Suppressed or erased records — personal fields are withheld or scrubbed; minimal tombstones, request references, and delivery identifiers may be retained as needed to prevent reintroduction and administer downstream instructions.
  • Property and organization information — public property records and non-personal business identity information may be retained while the underlying source remains available and relevant.
  • Telemetry — raw product telemetry is generally retained for about 45 days; aggregate statistics may be retained longer.
  • Billing, security, and legal records — retained for the period reasonably necessary for tax, accounting, fraud prevention, security, dispute, and legal obligations.

10. Security

We use administrative, technical, and physical safeguards appropriate to the information and Service, including encryption in transit and at rest, organization-scoped logical access controls in a multi-tenant system, role-based internal access, audit logging, centralized secrets management, and monitored U.S. infrastructure. No system is perfectly secure. We notify affected persons and regulators of a qualifying breach as required by law. Report a suspected vulnerability to privacy@greenfinch.ai.

11. International processing

Greenfinch is a U.S. company and hosts the Service in the United States. A customer or user who accesses the Service from another country causes their account and Customer Data to be transferred to and processed in the United States. Where applicable law requires a transfer safeguard, we use an appropriate contractual or other recognized mechanism. Section 6.4 describes our separate delivery restriction for EEA and UK Contact Data.

12. Children

The Service is not directed to anyone under 18. We do not knowingly collect personal information from anyone under 18 or include minors in the professional contact database. Contact privacy@greenfinch.ai if you believe we hold a minor's information.

13. Changes to this Policy

We post updates with a new "Last updated" date. We provide advance email or in-product notice of a material change when required or when the change materially expands how we use or disclose personal information. We will not begin delivering a category of jurisdiction-restricted Contact Data until the associated notice and operational controls are in place.

14. Contact us

Privacy requests and questions: privacy@greenfinch.ai
Greenfinch AI, Inc.
Mailing address: To be inserted before publication

If applicable law gives you a right to complain to a regulator or supervisory authority, you may do so in the place where you live, work, or believe a violation occurred.

Related legal documents: