Privacy Policy
Effective: March 23, 2026 · Last updated: March 23, 2026
Aisling Consulting Firms LLC (“Company”, “we”, “us”, “our”) operates the Intent Signaler platform (the “Service”), a B2B SaaS platform that helps local service businesses find and reach potential customers using public data signals. This Privacy Policy describes how we collect, use, disclose, and protect information when you use our Service.
By using the Service, you agree to the collection and use of information as described in this policy.
1. Information We Collect from Subscribers (Tenants)
When you create an account and use the Service, we collect:
- Account information: name, email address, business name, business address, phone number, and login credentials (managed via Amazon Cognito)
- Business profile: service categories, service areas (zip codes), client addresses you enter, and territory/zone selections
- Billing information: payment method and billing details processed by Stripe. We never store credit card numbers on our servers.
- Contact methods: email, phone, website URL, and booking URL you provide for inclusion in outreach communications
- Sending domain: domain you verify for branded email delivery, including DNS verification records
- Usage data: login activity, feature usage, dashboard interactions, and signal engagement (opens, clicks, approvals)
- Communications: support requests, feedback, and correspondence with our team
2. Information We Process on Your Behalf
To deliver leads and business intelligence, we collect and process publicly available information from third-party data sources. This data is processed on your behalf and is scoped to your purchased service areas (zones).
- Public records: building permits, business license filings, and property records from government open data portals (Socrata, county assessor databases)
- Business directory data: business names, addresses, phone numbers, ratings, and business types from Google Places API
- Contact enrichment: business contact information (names, email addresses, job titles, phone numbers) from People Data Labs (PDL), Apollo.io, and Hunter.io
- Domain intelligence: WHOIS registration data, DNS records, and website contact page information gathered through passive OSINT techniques
- Web search results: business website discovery via Serper.dev (Google Search API) and GNews (news articles)
- Weather and environmental data: NOAA weather alerts, FEMA disaster declarations (used to identify service demand signals)
All third-party data processing is passive — we do not conduct active network scanning, penetration testing, or any form of intrusive data collection against prospect targets.
3. How We Use Your Information
- To deliver ranked business leads and intelligence to your dashboard
- To personalize signal discovery based on your business categories and service areas
- To generate AI-powered outreach email drafts via our Writer agent
- To send daily lead digest emails and SMS notifications to your registered contact methods
- To build company profiles (dossiers) on potential prospects in your zones
- To identify competitors in your service areas and categories
- To build targeted advertising audiences (hashed email lists) for Facebook Custom Audiences and Google Customer Match, on your behalf and with your consent
- To process your subscription payments and manage your account
- To provide customer support and respond to inquiries
- To improve the Service, including signal quality, scoring accuracy, and platform reliability
4. Email and SMS Communications
Transactional communications (required for service delivery):
- Daily lead digest emails containing qualified leads with suggested outreach
- SMS/WhatsApp notifications for time-sensitive signals (requires your phone number)
- Account-related emails (password resets, billing notifications, security alerts)
Outreach communications (on your behalf):
- AI-generated outreach emails sent to business prospects in your zones
- Emails are sent from your verified sending domain or from our platform domain with your business name
- All outreach includes a one-click unsubscribe link (CAN-SPAM compliant)
- Recipients can opt out at any time; opt-outs are permanent and cross-tenant
Opt-out: You may disable SMS/WhatsApp notifications in your dashboard Settings at any time. You may unsubscribe from marketing emails. Transactional notifications required for service delivery cannot be disabled while your account is active.
Mobile Information Sharing Policy
We do not share mobile phone numbers or SMS/WhatsApp consent data with any third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are never shared with any third parties. Phone numbers provided for SMS/WhatsApp notifications are used exclusively for delivering the transactional messages you have opted into and are shared only with Twilio (our SMS/WhatsApp delivery provider) solely for the purpose of message delivery.
5. Third-Party Service Providers
We use the following third-party services to operate the platform:
Infrastructure & Hosting
- Amazon Web Services (AWS): Cloud infrastructure including ECS (compute), RDS (database), S3 (storage), SQS (messaging), Cognito (authentication), and SES (email backup). Data stored in US-East-1 region.
- Cloudflare: CDN, DNS, and web application firewall (WAF) services.
Communications
- SendGrid (Twilio): Primary email delivery service for digest emails and outreach.
- Amazon SES: Backup email delivery service.
- Twilio: SMS and WhatsApp message delivery for signal notifications.
Data Enrichment
- Google Places API: Business information, addresses, phone numbers, and ratings.
- People Data Labs (PDL): Person and business contact enrichment from public records.
- Apollo.io: Company enrichment (industry, size, revenue) and decision-maker contact discovery.
- Hunter.io: Email address discovery and deliverability verification.
- Serper.dev: Google search results for business website discovery.
- Shodan: Passive technical footprint analysis (domain/IP intelligence).
Payments
- Stripe: Payment processing and subscription management. Stripe’s privacy policy governs payment data handling.
CRM Integrations (Optional)
- HubSpot, Pipedrive, Salesforce: Optional CRM integrations that sync leads to your CRM. Enabled only with your explicit OAuth authorization. You may revoke access at any time from your dashboard.
6. Data Sharing and Disclosure
- We never sell your personal information.
- We never share your prospect data, leads, or dossiers with other tenants. Each tenant’s data is isolated in a separate database schema.
- We never contact your prospects without your authorization. In non-production environments, all outbound is redirected to the account owner.
- We may share information with third-party service providers listed above, solely for the purpose of operating the Service.
- We may disclose information if required by law, regulation, or legal process.
- We may share aggregated, anonymized data (e.g., platform usage statistics) that cannot identify individual tenants or their prospects.
7. Data Retention and Deletion
- Account data: Retained while your account is active. Deleted within 90 days of account closure upon request.
- Signal data: Archived after 30 days, permanently deleted after 90 days.
- Company profiles (dossiers): Retained for 12 months, then purged.
- Outreach history: Retained for 12 months for compliance and deliverability tracking.
- Contact block registry: Opt-out records are retained permanently to ensure we never re-contact opted-out recipients.
- Payment records: Retained per legal and tax requirements (up to 7 years).
- Audit logs: Retained for 24 months for security and compliance purposes.
You may request deletion of your account and associated data by contacting us at [email protected]. We will process deletion requests within 30 days.
8. Data Security
- All data is encrypted in transit using TLS 1.2 or higher
- All data is encrypted at rest using AES-256 (AWS RDS, S3)
- OAuth tokens for CRM integrations are encrypted with a dedicated encryption key before database storage
- Authentication managed via Amazon Cognito with Google OIDC federation support
- Email authentication: DKIM, SPF, and DMARC configured and verified
- Web application firewall (Cloudflare WAF + AWS WAF) protects all endpoints
- Per-tenant data isolation via separate PostgreSQL schemas
- Regular security audits and dependency vulnerability scanning
9. Cookies and Tracking
- Essential cookies only: Session management and authentication (NextAuth.js session cookie)
- No third-party tracking cookies
- No advertising cookies or pixels
- Email open tracking via SendGrid (can be disabled upon request)
10. Your Rights
All Users
- Access, correct, or delete your account data at any time via the dashboard or by contacting us
- Export your data (signals, contacts, outreach history) from the dashboard
- Opt out of SMS/WhatsApp notifications in Settings
- Revoke CRM integration access at any time
- Request complete account deletion
California Residents (CCPA)
- Right to know what personal information we collect and how it is used
- Right to request deletion of your personal information
- Right to opt out of the sale of personal information — we do not sell personal information
- Right to non-discrimination for exercising your privacy rights
- To exercise these rights, contact us at [email protected]
European Economic Area Residents (GDPR)
- Right to access, rectify, erase, or restrict processing of your personal data
- Right to data portability
- Right to object to processing
- Right to withdraw consent at any time
- Right to lodge a complaint with a supervisory authority
- Legal basis for processing: contract performance (service delivery), legitimate interest (platform improvement), and consent (marketing communications)
- Data transfers outside the EEA are protected by AWS data processing agreements and Standard Contractual Clauses
11. Children’s Privacy
The Service is designed for business use only and is not directed at individuals under the age of 18. We do not knowingly collect personal information from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on the Service prior to the change becoming effective. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
13. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact us at:
Aisling Consulting Firms LLC
Attn: Privacy
14362 SE 152nd Pl
Weirsdale, FL 32195
Email: [email protected]