FINDDAX
PricingAboutContacts

Privacy Policy

Last updated: October 2, 2026

This document describes what data Finddax ("we", "the service") collects, why it is needed, and how we store and protect it. By using the service, you agree to this policy.

1. Who we are and what we are responsible for

The Finddax service is operated by sole proprietor (FOP) Мелай Даяна Дмитрівна (Melai Daiana Dmytrivna), Ukraine. We act as the data controller for your account data. Public data about the businesses you find (Google Maps) comes from a public source and is not personal data of the account owner.

2. Account data

  • Sign-in with Google — name, email and profile photo received during OAuth authentication.
  • Sign-in with email and password — email, name (optional) and password. The password is never stored in plain text — only an irreversible hash (`scrypt`) that we physically cannot read or recover.
  • Email verification and password reset — a one-time 6-digit code, valid for 15 minutes, sent to your email and deleted after use or expiry.
  • Credit balance, selected plan and last sign-in date.

3. Data related to using the service

  • Search queries — the keywords, cities and filters you enter, as well as saved searches.
  • Data about businesses found — public information from Google Maps (name, address, phone, rating, reviews) for the businesses you open.
  • Generated content — AI business analysis, pitch texts and data of sites created on your behalf through the public abect.com API.

4. Technical data and session

The technical cookie is session: a signed authentication token (httpOnly, not accessible to JavaScript), valid for 30 days or until you log out. For analytics we use Microsoft Clarity: it sets its own cookies (_clck, _clsk) and records how visitors use the site (clicks, scrolling, page views) so we can see what is inconvenient or broken. Text typed into fields is masked by Clarity and not sent. There are no advertising cookies.

5. Payment data

Plan payments are processed by Monobank Acquiring on the bank’s own secure page — your card number, CVV and other card details never reach our servers and are not visible to us. We only store the fact of the order: amount, plan, payment status and the bank’s invoice ID — enough for reconciliation and support, without access to the payment details themselves.

6. Third parties

We share the minimum necessary data with the following services to make the features work:

  • Google — OAuth authentication and business search via Google Maps.
  • Abect API — creating and publishing a site for a business you found.
  • DeepSeek AI — business analysis and pitch text generation.
  • Brevo — sending emails with sign-up verification and password reset codes.
  • Monobank — processing plan payments (see section 5).
  • MongoDB Atlas — a managed database storing accounts, searches and results.
  • Microsoft Clarity — website usage analytics (see section 4).

We do not sell your data to third parties and do not use it for advertising.

7. Data retention

  • Account — while active; fully deleted at your request (`/app/account`) or by writing to the email below.
  • Session — 30 days from sign-in or until you explicitly log out.
  • Verification / password reset code — 15 minutes, then automatically invalid.
  • Searches, leads, generated sites — as long as the account exists; deleted together with it.

8. Your rights

Regardless of your country of residence, you have the right to:

  • find out what data we store about you;
  • correct inaccurate data;
  • receive a copy of your data in a machine-readable format;
  • delete your account and related data;
  • object to the processing of your data.

Requests to delete or export data — to finddax.support@gmail.com; we respond within 30 days.

9. California residents (CCPA/CPRA)

We do not sell or "share" personal data as defined by the CCPA/CPRA, do not show behavior-based targeted advertising, and do not knowingly collect data from persons under 16.

10. Data location

The application runs on a server in the EU (Denmark). The database is the managed MongoDB Atlas cloud service. Google, DeepSeek, Abect and Brevo process data on their own infrastructure under their own privacy policies.

11. Security

Connections are HTTPS only. Passwords are an irreversible hash (`scrypt`), unreadable even to us. The session token is an httpOnly cookie, out of reach of client-side JavaScript. Card details never reach our servers (section 5). No method of storing data on the internet is completely secure, but we take reasonable technical measures to protect it.

12. Children

The service is not intended for persons under 16.

13. Changes to this policy

We notify you of material changes by email at least 14 days before they take effect. The current version is always available on this page.

14. Contacts

Email: finddax.support@gmail.com · Phone: +380 98 027 58 19

FINDDAX

We find local businesses without a website and hand you a ready-made pitch in minutes.

ProductPricingAboutContactsWhat’s new
LegalPrivacy PolicyTerms of Use
Contacts+380 98 027 58 19finddax.support@gmail.comФОП Мелай Даяна Дмитрівна
© 2026 Finddax. All rights reserved.