Privacy Policy
1. Who we are
Capbase (capbase.fyi) is operated by an individual proprietor based in Australia. This policy explains how we handle personal information, framed around the Australian Privacy Principles (APPs). Contact for anything privacy-related: support@capbase.fyi.
2. What we collect
- Account data — your name, email address, and password (stored only as a bcrypt hash; we never see the plain text).
- Contributions — data you submit to the database and its moderation history, linked to your account.
- Watchlist — companies you save to your profile.
- Reports— if you use “Report an issue”, what you write and, only if you choose to give it, a contact email, used solely to follow up on that report.
- Server logs — IP address, user agent, and request metadata, kept for security and debugging.
- Analytics data — aggregate usage statistics via Google Analytics (see sections 3–4).
3. Cookies
- capbase_token — an httpOnly authentication cookie set when you sign in. Essential for the Service to work; it is not used for tracking.
- capbase_consent — remembers whether you accepted or declined analytics cookies, for about six months. Essential; it holds only that choice.
- _ga, _ga_* — Google Analytics 4 cookies used to measure how the site is used (pages visited, approximate location, device type). Off by default:Google Analytics does not load, and these cookies are not set, unless you choose “Accept analytics” in the cookie banner. You can change your choice at any time with “Cookie preferences” in the site footer; declining removes the cookies.
4. Third-party processors
- Google Analytics 4 — usage analytics. Google processes usage data on our behalf; see Google's privacy policy and the GA opt-out browser add-on.
- Resend — sends our transactional email (such as the welcome email) and processes your email address to do so.
- Clearbit — company logos are fetched by your browserdirectly from Clearbit's logo service, which therefore sees your IP address. Requests are based on company domains, not on anything identifying you.
5. How we use personal information
We use it to operate the Service, moderate contributions, send transactional email, keep the Service secure, and understand aggregate usage. We do not sell personal information.
6. Company data vs personal data
Capbase profiles describe companies and people in their public, professional capacity — founders, executives, investors — using public sources such as regulatory filings and Wikidata. If a profile describes you and you want it corrected or removed, use the “Report an issue” link on that profile (no account needed) or email support@capbase.fyi, and we will review the request. A removed person profile is hidden from the Service. See our takedown & removal policy for what we remove and how quickly.
7. Storage and overseas disclosure
Our hosting providers and the processors above may store or process data outside Australia (including in the United States). Where that happens, we take reasonable steps to ensure it is handled consistently with the APPs.
8. Retention, access, correction, and deletion
We keep personal information only as long as needed for the purposes above. You can request access to, correction of, or deletion of your personal information by emailing support@capbase.fyi, or — for a profile that describes you — through its “Report an issue” link. We action these requests within 30 days (see the takedown & removal policy). Deleting your account removes your personal data; contributions already merged into the database may persist in de-identified form.
9. Complaints
If you believe we have mishandled your personal information, contact us first at support@capbase.fyi and we will respond within a reasonable time. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
10. Changes to this policy
We may update this policy from time to time. The current version is always published on this page with its “last updated” date.