Version 1.1 · Last updated July 9, 2026
Privacy Policy
This policy explains what data we collect, why we collect it, and your rights regarding that data — for both Customers of ReachNow and individuals whose contact details appear in our system.
0. Who This Policy Covers
This policy applies to two distinct groups of people:
- Customers — individuals or companies who create an account and use the ReachNow service.
- Data Subjects — individuals whose business contact details (name, job title, professional email, LinkedIn profile) we collect, verify, and make available to Customers. Data Subjects may never have used our service directly.
For the business contact data we provide to Customers, ReachNow acts as a data controller.
1. Who We Are
ReachNow (“ReachNow”, “we”, “us”) operates the ReachNow service and the website at reachnow.io. We are the data controller for the personal data described in this policy.
Registered address: [your registered business address]
Contact: support@reachnow.io
2. What Data We Collect
From Customers:
- Email address and hashed password
- Billing information processed via Stripe — we do not store card numbers or full payment details
- Usage data (searches performed, credits consumed, export history)
- Account connection details, if you choose to connect a third-party account such as LinkedIn — used only to provide the features you request
About Data Subjects:
- First name and last name
- Job title and seniority level
- Employer company name and domain
- Professional email address(es)
- LinkedIn profile URL and profile ID
- Company industry and staff count
3. Where the Data Comes From
- Directly from Customers (signup forms, CSV uploads, and any account you choose to connect)
- From LinkedIn profiles and other publicly available professional sources
- From third-party enrichment and verification providers (see §5)
4. Why We Process It and Our Lawful Basis
- Customer account management and billing → necessary for the performance of a contract with you.
- Providing and verifying business contact data → our legitimate interest in enabling B2B sales and recruitment outreach. We have balanced this against Data Subjects' rights and determined that professional contact data, used strictly for business-to-business purposes, falls within the reasonable expectations attached to publicly visible professional profiles.
- Marketing communications to Customers → based on your consent (the opt-in at signup). You may withdraw consent at any time.
We process business and professional contact data only. We do not collect or process consumer data, sensitive personal data, or special-category data as defined under applicable data protection law.
5. How We Share Data — Third-Party Service Providers & Sub-processors
We share data in the following ways:
- With Customers — delivering verified contact data is the core purpose of the service.
- Payment processor (Stripe) — to process your purchases. Stripe's privacy policy governs their handling of billing data.
- Third-party email verification and deliverability providers — email addresses may be shared with external email-validation sub-processors solely to check whether an address is valid and deliverable. The data shared is limited to the email address being verified and, where technically necessary, its associated domain.
- Cloud hosting & database providers — infrastructure, storage, and backups for the service.
Except for Customers, the recipients above act as processors (sub-processors) on our behalf: they process personal data only under our documented instructions, are bound by data-processing agreements with confidentiality and security obligations, and receive only the data necessary to perform their specific function. They may not use the data for their own purposes.
We do not sell personal data to advertisers or use it for ad targeting.
6. Your Rights
Both Customers and Data Subjects have the following rights under applicable law:
- Access — request a copy of the data we hold about you.
- Correction — ask us to correct inaccurate data.
- Deletion / Erasure — request removal of your data from our system.
- Objection — object to processing based on legitimate interest.
- Restriction — ask us to restrict how we use your data while a dispute is resolved.
Data Subjects: to request deletion of your contact data, use our self-service page: reachnow.io/opt-out. Individuals who opt out are added to a permanent suppression list and will not reappear in future enrichment results.
We will respond to all rights requests within 30 days. To exercise any right, contact us at support@reachnow.io. You also have the right to lodge a complaint with your local data protection authority.
7. Data Retention
- Customer data: retained while your account is active and for 24 months after account closure, unless you request earlier deletion (billing records are kept longer where tax or accounting law requires).
- Contact data (Data Subjects): retained until an opt-out request is received or until the data is no longer accurate, up to a maximum of 5 years from collection.
- Suppression list entries: kept indefinitely to honour opt-out commitments. Removing a suppression entry would risk re-collecting the same data.
8. Security
We use encryption in transit (TLS), hashed passwords (we never store plaintext credentials), and role-based access controls. Our sub-processors are contractually required to maintain appropriate security standards. No internet transmission is 100% secure; we take reasonable precautions but cannot guarantee absolute security.
9. International Transfers
Some of our providers are located outside your country, including in the European Union and the United States, so your data may be transferred internationally. Where required, we put appropriate safeguards in place — such as the EU Standard Contractual Clauses or an equivalent mechanism — to protect your data. A copy can be requested at support@reachnow.io.
10. Cookies
We use only essential authentication and session cookies, plus Stripe's payment-security cookies at checkout. We do not use analytics or advertising cookies. Full details are in our separate Cookie Policy.
11. Children
The service is intended for business users and is not directed at anyone under the age of 16. We do not knowingly collect data from minors.
12. Changes to This Policy
We may update this policy from time to time. Material changes will be notified to Customers by email or via an in-app notice before taking effect. The current version and last-updated date are shown at the top of this page. Continued use of the service after a change constitutes acceptance of the revised policy.
Questions? Contact support@reachnow.io.