Data & compliance
How ReachNow handles personal data
A plain description of what we process, where it comes from, how long we keep it, and how anyone can be removed. No compliance badges — just the mechanics, so you can reach your own conclusion.
Why this page does not say “GDPR compliant”
Because it would not mean anything. Whether processing a particular person's contact details is lawful depends on who they are, where they are, where you are, what you send them and on what basis — variables that sit with you, the customer, not with the tool.
A vendor claiming blanket compliance is either describing its own internal practices in misleading shorthand, or implying a guarantee about your use of the data that it has no ability to give. Neither helps you.
So instead, this page describes exactly what happens to data in our systems. If you are assessing ReachNow for use in a regulated context, take this description to your own advisers — that is what it is for.
What ReachNow does, in one paragraph
ReachNow is a B2B contact data enrichment service. A customer supplies information about specific people they want to contact — most often a professional profile URL, entered individually, imported in a CSV, or saved with a browser extension. For each one, ReachNow uses the information provided to match and enrich the prospect record, identifies the employer's mail domain, constructs the business email addresses that domain is likely to use for that person's name, and tests those candidates against the employer's mail server. Verified business contact records are returned to the customer who asked for them.
The data processed is business contact data in a professional context: a person's name, their role, their employer and their work email address. ReachNow does not process, and cannot return:
- Personal (non-business) email addresses
- Phone numbers
- Home or postal addresses
- A pre-built contact database to search or browse
- Native write-back into a CRM
Enrichment happens only for prospects a customer has specifically supplied. ReachNow does not crawl for people nobody asked about, does not build a database of contacts for others to search, and does not sell contact data to anyone.
Processing
What is processed, and why
| Category | Examples | Where it comes from | Why |
|---|---|---|---|
| Prospect business contact data | Name, job title, employer, company domain, business email address | Professional profiles that a ReachNow customer supplies, plus verification against the employer's mail server | To return an enriched contact record to the customer who requested it |
| Customer account data | Email address, password credential, account settings | Provided by the customer at sign-up | To operate the account, authenticate the user and provide support |
| Usage and billing data | Credit balance, enrichment history, purchase records | Generated by using the service; payment records held by Stripe | To meter credits, show history and process payments |
| Suppression records | Email address of a person who asked to be removed | Submitted through the public data removal form | Retained specifically so the address is never returned again — deleting the suppression record would defeat the removal |
Removing your data
If your details have appeared in someone's outreach and you want them out of our systems, you can do that yourself. You do not need an account, you do not need to explain why, and you do not need to have any relationship with ReachNow.
Submit your email address on the removal page. It is erased from our records and added to a suppression list, which means it will not be returned by any future enrichment — including for customers who supply that person's profile again later.
The suppression record itself is retained deliberately. It holds the address for the sole purpose of continuing to block it; deleting it would allow the data to reappear, which is the opposite of what was asked for.
Practices
How data is handled
Access and correction
Anyone can ask what data we hold about them and ask for it to be corrected or deleted. Requests go to the address at the foot of this page and are answered within the period set out in the Privacy Policy.
Contacts are not shared between accounts
Contact records belong to the account that enriched them. We cache verification work at the level of company mail domains to avoid repeating it, which does not expose one customer's contacts to another.
Credentials
ReachNow never receives or stores your password for any third-party platform. The browser extension only sends ReachNow the prospect information you choose to save.
We do not sell data
Contact data is not sold, licensed or made available to third parties. It is returned to the customer who requested it, and to nobody else.
Retention
Data is kept while your account is active and for the period described in the Privacy Policy afterwards. Suppression records are the deliberate exception and are kept indefinitely.
Your obligations as a customer
Contacting people carries duties that vary by country — around lawful basis, opt-outs and unsolicited messages. The Terms of Service require lawful use, and that responsibility sits with you.
Who else is involved
ReachNow relies on a small number of service providers to operate. They are listed here by role. Customers who need the named list for a data processing agreement can request it.
For a data processing agreement or the named sub-processor list, write to support@reachnow.io.
Documents
The full legal texts
Policy version 1.1 · Last updated July 9, 2026
Privacy and data questions: support@reachnow.io