FirstFlag Privacy Policy
Effective date: 20 August 2026
This policy explains how BuzzLead LLC, a Florida limited liability company operating FirstFlag ("FirstFlag," "we," "us"), collects and uses personal information. It covers two distinct groups, and we address them separately because our obligations to each differ:
- Users. People who create FirstFlag accounts and visit our site.
- Business contacts in our dataset. Professionals whose business contact information appears in signals we deliver to users. These individuals typically have no direct relationship with FirstFlag.
Part A. Information About Users
What we collect
- Account information: name, work email, company name, password hash (via our authentication provider) or Google account identifier if you sign in with Google.
- Configuration data: your website URL, positioning analysis, ICP criteria, champion lists, keywords, and delivery preferences.
- Billing information: handled by Stripe. We store your Stripe customer ID, plan, and billing status; we never see or store full card numbers.
- Usage data: signals viewed, approved, exported; feature usage; log data including IP address, browser type, and timestamps; referral activity.
- Communications: emails you send us and digest delivery/engagement metadata.
How we use it
To provide and operate the service (matching signals to your criteria, generating drafts, delivering digests); to process payments and prevent fraud and referral abuse; to secure the service; to communicate with you about your account; to improve the product using aggregated usage patterns; and to comply with law. We do not sell user personal information and we do not use your configuration data or champion lists to serve other customers.
Legal bases (where GDPR applies)
Performance of contract (providing the service you signed up for), legitimate interests (security, fraud prevention, product improvement), consent (where required, e.g., certain communications), and legal obligation.
Part B. Information About Business Contacts in Our Dataset
This is the part of our service that involves people who have not interacted with us directly, so we want to be precise about it.
What we process
Business contact and professional information: name, job title, employer, business email address (with the date it was verified), business phone number where available, LinkedIn profile URL, and the business signal that made the account relevant (for example, that the person's employer raised funding or that the person changed jobs).
We process business-card-level professional information only. We do not collect or deliver sensitive categories of data, home addresses, or information about individuals in a personal (non-professional) capacity.
Where it comes from
- Licensed third-party business data and enrichment providers;
- Public records, including securities filings and government notices;
- Publicly available professional information, such as company websites, press releases, job postings, and public professional profiles.
Why we process it and on what basis
We process this information on the basis of legitimate interests (Art. 6(1)(f) GDPR, where GDPR applies): enabling relevant, targeted business-to-business communication between our users and companies exhibiting buying signals. We limit processing to professional context, deliver data only to authenticated paying or registered users under license restrictions that prohibit resale, and honor objection and deletion requests as described below. We have assessed that this processing, limited to professional data used for B2B outreach, does not override the interests or fundamental rights of the individuals concerned.
Where GDPR Article 14 applies, this policy serves as our public notice to individuals whose data we process without a direct relationship. Because individually notifying every business contact would be disproportionate to the B2B nature and scale of the processing, we make this notice permanently available here and honor the rights below without requiring an account.
Your rights if you are in our dataset
If you believe your information appears in FirstFlag, you may, at no cost:
- Request access to the information we hold about you;
- Request correction of inaccurate information;
- Object to processing or request deletion. We will remove your record from our delivery systems within 30 days and add your identifiers to a suppression list so the record is not re-created from future source refreshes.
Contact privacy@firstflag.io with enough information to identify your record (name and business email is usually sufficient). We may take reasonable steps to verify your identity. Note that FirstFlag users export data to their own systems; removal from FirstFlag does not remove data a user already exported, and each user is independently responsible for their own outreach compliance.
Subprocessors and Service Providers
We share personal information only with providers that help us run the service, under contracts limiting their use of it: Supabase (database, authentication), Stripe (payments), Vercel and Railway (hosting), Resend (transactional email), Anthropic (AI processing of positioning analysis and draft generation), analytics providers, and our licensed signal and enrichment data providers. [Maintain the live list at /subprocessors and update this sentence to link to it.] We may disclose information if required by law or in connection with a merger, acquisition, or sale of assets, in which case this policy continues to apply to previously collected data.
International Transfers
We are a U.S. company and process data in the United States. Where we transfer personal data from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as Standard Contractual Clauses with our subprocessors.
Retention
User account data is retained while your account is active and deleted or anonymized within 90 days of account deletion, except billing records we must keep for tax and accounting purposes. Signal staging data is retained on a rolling basis consistent with our data providers' terms. Suppression-list entries are retained indefinitely so deletions stick.
Security
We use industry-standard measures including encryption in transit, row-level access controls isolating each customer's data, restricted service credentials, and least-privilege access for our team. No system is perfectly secure; we will notify affected users of any breach as required by law.
California Residents (CCPA/CPRA)
We do not sell or share personal information as defined by the CCPA, and we do not use sensitive personal information beyond what is necessary to provide the service. California residents may exercise rights of access, deletion, and correction via privacy@firstflag.io, and will not be discriminated against for doing so. Categories collected are described above; sources and purposes are described above.
Cookies
We use essential cookies for authentication and session management, and privacy-respecting analytics to understand aggregate site usage. [If any advertising pixels are added later. E.g., LinkedIn Insight or Meta. This section and the CCPA section must be updated first, as those can constitute "sharing" under CPRA.]
Children
FirstFlag is a business tool and is not directed to anyone under 18. We do not knowingly collect information about minors.
Changes
We will post updates here and, for material changes affecting users, notify you by email or in-product before they take effect.
Contact
BuzzLead LLC. St. Pete Beach, Florida Privacy requests: privacy@firstflag.io · General: support@firstflag.io