Last updated: October 2, 2026
This document describes what data Finddax ("we", "the service") collects, why it is needed, and how we store and protect it. By using the service, you agree to this policy.
The Finddax service is operated by sole proprietor (FOP) Мелай Даяна Дмитрівна (Melai Daiana Dmytrivna), Ukraine. We act as the data controller for your account data. Public data about the businesses you find (Google Maps) comes from a public source and is not personal data of the account owner.
The technical cookie is session: a signed authentication token (httpOnly, not accessible to JavaScript), valid for 30 days or until you log out. For analytics we use Microsoft Clarity: it sets its own cookies (_clck, _clsk) and records how visitors use the site (clicks, scrolling, page views) so we can see what is inconvenient or broken. Text typed into fields is masked by Clarity and not sent. There are no advertising cookies.
Plan payments are processed by Monobank Acquiring on the bank’s own secure page — your card number, CVV and other card details never reach our servers and are not visible to us. We only store the fact of the order: amount, plan, payment status and the bank’s invoice ID — enough for reconciliation and support, without access to the payment details themselves.
We share the minimum necessary data with the following services to make the features work:
We do not sell your data to third parties and do not use it for advertising.
Regardless of your country of residence, you have the right to:
Requests to delete or export data — to finddax.support@gmail.com; we respond within 30 days.
We do not sell or "share" personal data as defined by the CCPA/CPRA, do not show behavior-based targeted advertising, and do not knowingly collect data from persons under 16.
The application runs on a server in the EU (Denmark). The database is the managed MongoDB Atlas cloud service. Google, DeepSeek, Abect and Brevo process data on their own infrastructure under their own privacy policies.
Connections are HTTPS only. Passwords are an irreversible hash (`scrypt`), unreadable even to us. The session token is an httpOnly cookie, out of reach of client-side JavaScript. Card details never reach our servers (section 5). No method of storing data on the internet is completely secure, but we take reasonable technical measures to protect it.
The service is not intended for persons under 16.
We notify you of material changes by email at least 14 days before they take effect. The current version is always available on this page.
Email: finddax.support@gmail.com · Phone: +380 98 027 58 19