Legal
Privacy Policy
Effective August 30, 2026
Template — review before launch
1. Who we are
Big Data / Little Guy (“BDLG”, “we”, “us”) operates the Data Partnership Deal Flow platform available at bdlg-flow.vercel.app (the “Service”). This policy explains what information we collect from customers who use the Service, how we use it, who we share it with, and the choices you have.
2. Our core data rule
The Service stores metadata about your business data. It does not store your business data itself. We never collect email bodies, chat messages, documents, CRM customer records, database contents, uploaded files, or any raw enterprise content through the Service. When you connect a business system through our integrations partner Nango, we retrieve high-level admin totals such as user count, mailbox count, and storage used, not the content those systems hold.
3. Information we collect
3.1 Account information
When you create an account we collect:
- your name and email address (authenticated via Supabase Auth);
- a password hash (Supabase Auth manages this; we never see your plain password);
- the organization you create or are invited to, and your role within it.
3.2 Company qualification information
During the qualification wizard we collect information you provide about your company: legal and doing-business-as name, industry, headquarters country, employee count bucket, years in business, primary and technical contact details, and your answers to the qualification questions (system platforms in use, retention bucket answers, sensitivity flags, and free-form notes you enter).
3.3 Metadata from connected business systems
If you elect to connect a business system (for example, Google Workspace or Microsoft 365), our integrations partner Nango performs OAuth on your behalf and holds the access tokens. We call the provider through Nango’s Proxy API and receive only the aggregate admin metrics listed in the connect flow (for example, user count, storage totals, mailbox count, site count, shared drive count). We do not receive or store the content of your emails, files, or customer records via these connections.
3.4 Audit records
We record significant events performed within the Service (account created, organization created, qualification updated, connection created, refresh completed, profile submitted for review, and so on). Audit records include the actor’s user identifier, the affected resource identifier, and small structured metadata about the event. Audit records do not contain OAuth tokens, secrets, passwords, or raw enterprise content.
3.5 Operational information
Standard web server logs (IP address, user agent, requested path, timestamp) are captured by our hosting providers (Vercel and Supabase) for security, abuse prevention, and troubleshooting. These logs are retained per the providers’ own retention policies.
4. What we do not collect
The following are out of scope for the Service:
- email bodies, chat messages, or meeting transcripts;
- documents, spreadsheets, presentations, or their contents;
- CRM customer records or personal identifiers about your customers;
- row contents of your internal databases;
- OAuth access tokens or refresh tokens (held by Nango, never by us);
- passwords, API keys, or authentication secrets you might paste into a notes field (we caution you against pasting them, and our audit sanitizer strips well-known credential keys defensively).
5. How we use your information
We use the information described above to:
- provide the Service, including generating your Data Partnership Manifest;
- authenticate you and enforce role-based access within your organization;
- enable authorized BDLG reviewers to evaluate your Data Partnership Profile;
- communicate with you about your profile, information requests, and, if applicable, offer decisions;
- secure the Service (rate limiting, anti-abuse, audit trails);
- improve the Service (aggregate, non-identifying analytics only).
6. How we share your information
6.1 Within your organization
Members of your organization can see the organization’s company profile, data profile, and manifest according to their role (Owner, Admin, Data Manager, Viewer). Row-Level Security in our database prevents cross-organization access.
6.2 BDLG staff
Authorized BDLG staff (with the BDLG_ADMIN, BDLG_REVIEWER, or BDLG_SALES internal role) can view submitted Data Partnership Manifests to support review, information requests, and licensing coordination. Staff access is audited.
6.3 Prospective data licensees
We do not share your Data Partnership Manifest with any potential data licensee without your explicit action (submitting your profile for a quote). Even then we share the standardized Manifest, not raw source material.
6.4 Service providers
Our subprocessors:
- Supabase — hosted PostgreSQL, authentication, and Row-Level Security. Data resides in Supabase’s cloud regions.
- Vercel — application hosting, edge routing, static asset delivery, request logs.
- Nango — OAuth authorization broker for connected business systems. Nango holds the OAuth tokens and executes provider API calls through its Proxy API on our behalf. We never see the tokens.
- Providers you elect to connect (Google, Microsoft, and others as added) are contacted through Nango when you initiate a connect. Each provider has its own privacy policy that applies to your relationship with them.
6.5 Legal requirements
We may disclose information when required by applicable law, regulation, legal process, or governmental request, or when necessary to protect the rights, property, or safety of BDLG, our customers, or the public.
6.6 Business transfers
If BDLG is involved in a merger, acquisition, or sale of all or a portion of its assets, information may be transferred as part of that transaction. Customers will be notified via email and/or a prominent notice on the Service of any change in ownership or use of information.
7. Data retention
We retain account and qualification information for as long as your account exists. Audit records are retained on an append-only basis and may be kept for up to seven years for compliance and security purposes. If you delete your account or your organization, we will delete or anonymize your personal information within 90 days, subject to any legal or regulatory retention obligations.
8. Your privacy rights
Depending on your jurisdiction, you may have rights to access, correct, delete, or export your personal information; to object to or restrict certain processing; and to withdraw consent where processing is based on consent. To exercise any of these rights, contact us at the address in section 14. We will respond within the period required by applicable law.
9. Security
We use technical and organizational safeguards designed to protect your information, including TLS in transit, encryption at rest at our hosting providers, Row-Level Security policies on every tenant table, immutable append-only audit records, and least-privilege scopes for third-party integrations. No system is perfectly secure; please report any suspected vulnerabilities to the address in section 14.
10. International data transfers
Our service providers may process information in the United States or other countries where they operate infrastructure. Where required, we rely on approved transfer mechanisms (Standard Contractual Clauses or equivalent) to protect information transferred across borders.
11. Children
The Service is intended for business users aged 16 or older. We do not knowingly collect information from children under 16. If you believe a child has provided information to us, please contact us and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be highlighted at the top of the page and communicated by email or in-app notice. Continued use of the Service after the effective date of a change constitutes your acceptance of the updated policy.
13. Cookies and similar technologies
We use a small number of first-party cookies strictly necessary to operate the Service (authentication session, active organization preference). We do not use third-party advertising cookies. Standard hosting-provider cookies may be set for routing and security by Vercel.
14. Contact us
Questions about this policy, or requests to exercise your privacy rights, can be sent to privacy@bigdatalittleguy.com. Replace this address with your organization’s privacy contact before launching to customers.