PRIVACY POLICY
How we work together.
RevenueBase Privacy Policy
Effective: July 27, 2026
About This Policy
RevenueBase, Inc. (“RevenueBase,” “we,” “us,” or “our”) is a B2B data infrastructure company based in Newton, Massachusetts, USA. This Privacy Policy explains how we collect, use, share, and protect personal information, and describes your rights with respect to that information.
This Policy covers two distinct groups of people, and your rights differ depending on which group you belong to:
Group 1 — Customers and Website Visitors. If you are a customer of RevenueBase, a prospective customer, or a visitor to our website, Section 1 of this Policy describes how we handle your information.
Group 2 — Business Professionals in Our Database. If your professional contact information — your name, job title, work email, phone number, or employer — is included in our database of business contacts, Section 2 of this Policy describes what we hold, why, and what rights you have. If you want to opt out of our database, please go directly to Section 5.5.
1. Customers and Website Visitors
1.1 Information We Collect
When you visit our website or use our products, we collect:
- Account and contact information. Your name, business email address, company name, job title, and account credentials, provided when you register or contact us.
- Billing information. Your billing address and payment method details, processed by our payment processor. We do not store full payment card numbers.
- Usage data. API call logs, query volumes, Credit usage, feature interactions, and technical data about how you use our Services. We use this to operate and improve the Services and to enforce our Terms of Service.
- Data you submit to the Services. The contents of your API calls, file uploads, and enabled integrations — for example, the email addresses you submit for verification or the company records you submit for enrichment (“Submitted Data”). Section 1.4 describes how we handle Submitted Data.
- Website analytics. Traffic data including pages visited, session duration, approximate location (country/region), device and browser type, and referral source, collected through Google Analytics and similar tools. This data is aggregated and not linked to your individual identity.
- Communications. Records of emails, support requests, or other messages you send to us.
1.2 How We Use This Information
We use account, billing, usage, and communications information to:
- Provide, operate, secure, and improve our Services;
- Process payments and send invoices and receipts;
- Respond to your inquiries and provide customer support;
- Send you product updates, security notices, and other account-related communications;
- Enforce our Terms of Service and other agreements; and
- Comply with applicable legal obligations.
We do not sell your account or usage information to third parties, and we do not use it for advertising.
1.3 Who We Share This Information With
We share customer and website visitor information with:
- Service providers who support our operations under contract, such as cloud infrastructure providers, payment processors, customer support tools, and analytics platforms. These providers may only use your data as necessary to provide services to us.
- Law enforcement or regulators if required by applicable law, court order, or to protect our legal rights.
- Acquirers in the event of a merger, acquisition, or sale of substantially all of our assets, provided the acquiring entity agrees to honor this Policy.
1.4 How We Handle Data You Submit to the Services
When you use our Services, you send us data — an email address to verify, a company name to resolve, a record to enrich. We use Submitted Data in two ways:
(a) To serve you. We process what you submit in order to return your results — verifying the email address, matching the company, enriching the record.
(b) To maintain and improve our database and services. Submitted Data is one of the signals we use to keep our database accurate, current, and comprehensive, as described in Section 2.2(c). This is an integral part of how the Services work: every customer's use of the Services contributes to the accuracy and coverage of the database that all customers rely on. Our Terms of Service grant us a license to retain and use Submitted Data for these purposes.
What we do not do with Submitted Data: we do not resell or redistribute what you submit as a standalone dataset attributable to you (for example, we will not take a list you submitted for cleaning and sell it as your list), and we do not disclose you as the source of any data. Business contact records derived from Submitted Data are incorporated into our database only after our verification process confirms them, and once incorporated they are maintained as part of our database like records from any other source.
If Submitted Data includes personal data, our Terms of Service require that you have provided any notices and secured any permissions required for this use under applicable law. Do not submit sensitive or special-category personal data (such as government identifiers, financial account numbers, or health data); our Terms of Service prohibit it.
2. Business Professionals in Our Database
2.1 What Our Database Contains
RevenueBase maintains a database of verified professional contact and company information. Our database currently contains records for approximately 390 million business professionals and 60 million companies worldwide. For individual professionals, a record may include:
- First and last name
- Job title, department, and seniority level
- Work email address and email verification status
- Direct phone number and mobile phone number
- Employer name and business address
- LinkedIn profile URL
- Professional verification timestamps (email last verified, profile last updated)
For companies, a record may include:
- Company name, website, and domain
- Industry classification (NAICS/SIC codes)
- Headcount range and revenue range
- Funding stage and funding history
- Headquarters address
- Technologies in use
- Hiring signals and company growth indicators
2.2 How We Build Our Database
We build and maintain our database through the following methods:
(a) Publicly available online sources. The majority of our contact and company data is collected from information that individuals and companies have made publicly available — including professional profiles on professional networking sites, company websites, business directories, government filings, court records, and other publicly accessible online sources. We conduct this collection using automated technology and through third parties we engage to collect raw publicly available data on our behalf.
(b) Purchased mobile phone data. Mobile phone numbers in our database are obtained from a licensed third-party data provider under a commercial data supply agreement. That provider independently collects and licenses this data and is responsible for its own privacy compliance.
(c) Data submitted by our customers. Our customers submit business contact and company data to our Services — for example, email addresses submitted for verification, or company records submitted for matching and enrichment. We retain this Submitted Data and use it as a signal to: confirm that professional contact information is current and active; identify contact and company records we have not seen before; and improve the accuracy, freshness, and coverage of our database. Before a record derived from customer submissions is added to our database, we verify it using our own internal verification technology and independent external signals; records that cannot be verified are not added. We also use Submitted Data, in aggregated and pseudonymized forms, to develop and improve our matching, verification, and machine-learning systems. We do not attribute any record to the customer that submitted it, and we do not sell any customer's submitted list as such. If your information reaches us this way, you have the same rights as anyone else in our database — including the rights to object, to request deletion, and to be added to our suppression list (Section 5) — and those rights apply directly against us, regardless of any agreement between us and the customer that submitted your information.
(d) Verification and enrichment. We verify and update records on a rolling basis — email addresses are reverified every 60 days and professional profiles every 90 days — to maintain data accuracy. Records that cannot be verified for more than 12 months are removed from our active database.
We do not purchase or license pre-built third-party contact databases as a primary source for our records.
2.3 Legal Basis for Processing (GDPR and UK GDPR)
For individuals in the European Union, European Economic Area, or United Kingdom, we process professional contact data on the following legal bases:
(a) Legitimate interests (Article 6(1)(f) GDPR). Our primary legal basis is legitimate interests — specifically, our interest and the interest of our business customers in facilitating business-to-business commerce. Business professionals have a reasonable expectation that professional contact information they have made publicly available in a professional context, or that circulates in ordinary business channels, may be used by others for professional purposes, including sales and marketing outreach. We have assessed that this interest is not overridden by the individual's rights and interests because: (i) we process only professional information, not sensitive personal data; (ii) the data concerns the individual's professional role, not their private life; (iii) individuals have a readily accessible opt-out mechanism (see Section 5.5); and (iv) we require customers to comply with applicable marketing laws, including laws governing consent and opt-out for direct marketing. This legal basis applies to our processing of professional contact data from all the sources described in Section 2.2, including data submitted by our customers.
(b) Legal obligation (Article 6(1)(c) GDPR). In some cases, we may process personal data to comply with legal obligations, such as responding to regulatory inquiries or court orders.
(c) Vital interests or public task. These bases do not apply to our standard processing activities.
Legitimate Interests Assessments: We have conducted Legitimate Interests Assessments (LIAs) for our processing activities, including our use of customer-submitted data described in Section 2.2(c). Summaries are available on request to privacy@revenuebase.ai.
2.4 How We Use and Share Professional Contact Data
We use professional contact and company data to:
- License it to business customers for B2B sales, marketing, recruiting, and related professional activities under our Terms of Service;
- Verify and update records to maintain accuracy, using our own verification technology, external signals, and the customer-submission signals described in Section 2.2(c);
- Develop and improve our Services, including training and improving our matching, verification, and machine-learning models using aggregated and pseudonymized data; and
- Respond to data subject rights requests (see Section 5).
We share professional contact data with:
- Our customers, under license agreements, for B2B professional purposes consistent with our Terms of Service;
- Verification and data partners, to validate records (e.g., confirming email deliverability or phone number validity);
- Infrastructure and service providers supporting our operations, under appropriate data processing agreements; and
- Law enforcement or regulators, when required by law.
We do not sell professional contact data for consumer marketing purposes or share it for advertising targeting.
3. International Data Transfers
RevenueBase is based in the United States. Our database includes personal data relating to business professionals in many countries, including the European Union, the United Kingdom, Canada, India, and Australia.
EU and UK transfers. When we transfer personal data from the EEA or UK to the United States, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914) or the UK Addendum to the EU SCCs, as applicable, as the lawful transfer mechanism. Business customers in the EEA or UK who require SCCs or a Data Processing Addendum may request them at privacy@revenuebase.ai.
Other international transfers. We comply with the applicable legal requirements for international data transfers in other jurisdictions, including India (DPDPA) and Australia (Privacy Act 1988).
4. Security
We implement appropriate technical and organizational security measures to protect personal data against unauthorized access, loss, alteration, disclosure, or misuse. These measures include:
- Encryption of data in transit (TLS) and at rest;
- Role-based access controls limiting access to authorized personnel;
- Regular security assessments and vulnerability testing; and
- Incident response procedures.
No system is completely secure. In the event of a security incident involving personal data, we will comply with applicable breach notification laws, including notifying affected individuals and regulators as required.
5. Your Rights
5.1 Rights Under GDPR (EU, EEA, and UK Residents)
If you are a business professional based in the EU, EEA, or UK, you have the following rights under the GDPR or UK GDPR:
- Right of access. Request a copy of the personal data we hold about you, including information about the categories of sources it came from.
- Right to rectification. Request that we correct inaccurate or incomplete data.
- Right to erasure. Request that we delete your personal data. We will honor this request unless we have a legitimate legal basis to retain it.
- Right to restriction. Request that we limit how we process your data while a dispute about its accuracy or our legal basis is resolved.
- Right to object. Object to processing based on our legitimate interests. Where you object and your interests or rights override ours in the specific circumstances, we will cease processing.
- Right to data portability. Request a machine-readable copy of your personal data.
- Right to withdraw consent. If any of our processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise these rights, contact us at privacy@revenuebase.ai. We will respond within 30 days (extendable by a further 60 days for complex requests, with notice to you). You have the right to lodge a complaint with your local data protection supervisory authority if you are not satisfied with our response.
EU and UK Representatives: We have appointed a representative in the European Union and a representative in the United Kingdom under Article 27 of the GDPR and UK GDPR. Their names and contact details are available at revenuebase.ai/representatives or on request to privacy@revenuebase.ai.
5.2 Rights Under CCPA and CPRA (California Residents)
If you are a California resident whose personal information is in our database, the California Consumer Privacy Act (as amended by the California Privacy Rights Act) gives you the following rights:
- Right to know. Request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, our purposes, and the categories of third parties we share it with.
- Right to access. Receive a copy of the specific personal information we hold about you.
- Right to correct. Request that we correct inaccurate personal information.
- Right to delete. Request that we delete your personal information, subject to certain exceptions.
- Right to opt out of sale or sharing. Request that we stop selling or sharing your personal information.
- Right to non-discrimination. We will not discriminate against you for exercising any of these rights.
Categories of personal information collected and sold or shared:
| Category | Collected | Sources | Sold or Shared |
|---|---|---|---|
| Identifiers (name, work email, phone number) | Yes | Public sources; licensed data provider (mobile numbers); customer submissions | Yes — licensed to B2B customers |
| Professional and employment information (job title, employer, department) | Yes | Public sources; customer submissions | Yes — licensed to B2B customers |
| Commercial information | No | — | No |
| Biometric information | No | — | No |
| Internet or electronic network activity (website visitors only) | Yes | Our website | No |
| Approximate geolocation (analytics only) | Yes | Our website | No |
| Sensitive personal information | No | — | No |
To submit a CCPA/CPRA request, contact privacy@revenuebase.ai with the subject line "California Privacy Request." We may need to verify your identity before fulfilling the request.
5.3 Rights Under Other U.S. State Laws
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), Oregon (OCPA), Montana, and other states with comprehensive privacy laws have rights that are similar to those described in Section 5.2, including rights to access, correct, delete, and opt out of the sale of personal data. To submit a request, contact privacy@revenuebase.ai with the subject line "State Privacy Request."
5.4 Rights Under Indian and Australian Privacy Law
India. Individuals in India have rights under the Digital Personal Data Protection Act, 2023 (DPDPA), including the right to obtain a summary of the personal data we process and to seek its correction or erasure. Contact privacy@revenuebase.ai to exercise these rights.
Australia. Individuals in Australia have rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, including the right to access personal information we hold about you and to seek its correction. Contact privacy@revenuebase.ai to submit a request. You also have the right to complain to the Office of the Australian Information Commissioner (OAIC) if you believe we have mishandled your personal information.
5.5 How to Opt Out of Our Database
To request removal of your professional contact information from our database:
- Send an email to privacy@revenuebase.ai with the subject line "Opt-Out Request."
- Include your full name, work email address, and current or most recent employer.
- We will process your request within 30 days and add you to our suppression list so your information is not re-added during future data collection cycles — including where your information is later submitted to us by a customer.
Please note: After we remove your data from our database, it may continue to appear in the systems of customers who licensed it before your request. We are not in a position to compel customers to delete their own CRM or marketing records, but we will ensure you are suppressed from any future data deliveries.
5.6 Data Broker Registrations
RevenueBase is registered as a data broker where required by applicable state law: California (Civil Code §1798.99.80 et seq., the Delete Act), Texas (Bus. & Com. Code ch. 510), Oregon (ORS 646A.593), and Vermont (9 V.S.A. §2446). California residents may submit deletion requests through the California Privacy Protection Agency's Delete Request and Opt-Out Platform (DROP); we check and process DROP requests at least every 45 days as required by law. We honor recognized opt-out preference signals (such as Global Privacy Control) as an opt-out of sale or sharing where required by applicable law.
6. Data Retention
Customer and website visitor data. We retain account and usage data for as long as your account is active and for up to three (3) years following account closure, or longer if required by applicable law or a legitimate business purpose such as resolving a dispute.
Database records. Records in our database are reverified on a rolling basis. Records that cannot be verified after 12 consecutive months are removed from our active database. Retention periods run from the record's collection or last independent verification against our published criteria — a failed or skipped verification does not extend retention. Records removed pursuant to an opt-out or deletion request are added to our suppression list and are not re-added during subsequent collection cycles or through customer submissions.
Submitted Data. Submitted Data used for the purposes in Section 1.4(b) is retained in accordance with this Policy. Where a record derived from Submitted Data does not pass verification, it is not incorporated into our database and the underlying submission is retained only as long as needed for service operation, quality assurance, and abuse prevention.
7. Cookies
We use cookies and similar tracking technologies on our website to:
- Operate and secure the site (strictly necessary cookies);
- Remember your preferences and login status; and
- Understand how visitors use our site through aggregated analytics.
We use Google Analytics for traffic analysis. Google Analytics may collect IP addresses, but we receive only aggregated, non-personally identifiable data. You can opt out of Google Analytics tracking using the Google Analytics Opt-Out Browser Add-On.
You can configure your browser to block or delete cookies, though this may affect certain site features.
We honor recognized opt-out preference signals, including Global Privacy Control (GPC), as a request to opt out of the sale or sharing of personal information where applicable law requires. We do not respond to older browser-level "do not track" signals that lack legal effect.
8. Children
Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected personal information from a child, we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy as our practices evolve or as applicable law changes. We will post any updated policy on our website with a new effective date. For material changes that affect your rights as a data subject or customer, we will provide additional notice by email or through the Services at least thirty (30) days before the change takes effect.
10. Contact Us
For privacy inquiries, data subject rights requests, or security concerns:
Email: privacy at revenuebase.ai
Subject lines: "Opt-Out Request," "California Privacy Request," "State Privacy Request," "GDPR Request," or "Privacy Inquiry" as applicable.
Mail: Privacy Officer, RevenueBase, Inc., 132 Adams St., Newton, MA 02460
Phone: +1 (617) 539-6584
We aim to respond to all privacy inquiries within thirty (30) days.