This Privacy Policy (“Policy”) describes how Inspex (“Inspex,” “we,” “us,” or “our”) collects, uses, discloses, and otherwise processes personal information in connection with the Inspex platform available at inspex.io and related websites, applications, APIs, and services (collectively, the “Services”). The Services include digital asset valuation, analytics, marketplace listings, and related tools for websites, SaaS products, domain names, mobile applications, and e-commerce businesses.
By accessing or using the Services, you acknowledge that you have read and understood this Policy. If you do not agree, you must not use the Services.
1. Scope and data controller
This Policy applies to personal information we process as a controller when you visit our marketing properties, create an account, connect third-party accounts, upload documents, purchase subscriptions, or otherwise interact with the Services. The entity responsible for processing your personal information is Inspex. For questions about this Policy or our privacy practices, contact us at hello@inspex.io.
2. Information we collect
2.1 Information you provide directly
We may collect information that you voluntarily provide, including:
- Account and profile data, such as name, email address, company name, job title, password or authentication credentials, and communication preferences.
- Asset and listing information you submit for valuation, verification, or marketplace participation, including URLs, descriptions, financial metrics, traffic or revenue summaries, and other business details you choose to share.
- Payment and billing information processed by our payment processor (Stripe). We generally do not store full payment card numbers on our systems; Stripe's use of such data is governed by Stripe's privacy policy and terms.
- Support and correspondence, including messages you send to us by email or through in-product channels.
2.2 Information collected automatically
When you use the Services, we and our service providers may automatically collect certain information, such as IP address, device type, browser type, operating system, referring URLs, pages viewed, approximate location derived from IP address, and dates and times of access. We may also collect event and usage data associated with your account and interactions with the Services.
2.3 Information from third parties and OAuth connections
If you authorize us to connect third-party services (for example, GitHub, GitLab, or similar developer or analytics platforms) via OAuth or comparable mechanisms, we may receive account identifiers, repository or project metadata, commit activity, contributor information, and other data made available by those providers subject to your permissions and their terms. The scope of data we receive depends on the permissions you grant and the third party's API. We encourage you to review each provider's privacy notice before connecting an account.
2.4 Session replay and behavioral analytics (Microsoft Clarity)
When our platform operators enable session recording and you have accepted analytics cookies where we request consent (or equivalent preferences), we may load Microsoft Clarity on our public marketing website (for example inspex.io) and the signed-in product experience (for example app.inspex.io). Clarity provides aggregated usage insights, heatmaps, and optional session replays to help us improve the Services. Processing may include interaction data and information visible on screen during a recorded session (which could include content you type or display while browsing our marketing site or using the product). Microsoft processes this data as described in Microsoft's Privacy Statement and the Microsoft Clarity terms. If you decline analytics cookies or session recording is disabled for the platform, we do not load Clarity for that context.
3. Cookies and similar technologies
We use cookies, local storage, pixels, and similar technologies to operate the Services, remember preferences, authenticate sessions, analyze performance and usage, and, where permitted, support marketing. You may control cookies through your browser settings; disabling certain cookies may limit functionality of the Services. Where required by law, we will obtain your consent before using non-essential cookies or similar technologies. Our Cookie Policy describes categories, typical storage keys, and how to use the in-product consent experience on our marketing properties.
Authentication uses first-party session storage managed by Supabase for signed-in users. Optional analytics or marketing technologies are loaded only when you allow those categories in the cookie banner or preferences UI, where applicable. When you opt in to analytics and our operators enable session recording, we may load Microsoft Clarity as described in Section 2.4.
4. How we use information
We use personal information for purposes that include:
- Providing, operating, maintaining, and improving the Services;
- Creating and displaying valuations, reports, and marketplace listings in accordance with your instructions;
- Authenticating users, securing accounts, detecting fraud and abuse, and enforcing our terms and policies;
- Processing transactions, managing subscriptions, and communicating about billing;
- Communicating with you about updates, security alerts, and support requests;
- Complying with legal obligations and responding to lawful requests from public authorities;
- Conducting analytics, research, and product development, including training and improving models where permitted by law and consistent with our agreements with you.
We process personal information where we have a lawful basis under applicable law, such as performance of a contract, legitimate interests (balanced against your rights), consent where required, or legal obligation.
5. Artificial intelligence and automated analysis
Certain features of the Services use artificial intelligence and machine learning, including services provided by OpenAI and potentially other vendors, to analyze data you provide or that we obtain from connected sources. Outputs may include valuations, summaries, risk indicators, or recommendations. Automated processing may involve combining your inputs with model-generated content. You should not rely solely on automated outputs for legal, tax, investment, or transactional decisions without independent professional advice. We implement contractual and technical measures with our AI subprocessors designed to limit unauthorized use and retention of your data, subject to each vendor's terms and our configuration of those services.
6. Document uploads and verification materials
You may upload documents (for example, revenue reports, bank statements, contracts, or identity verification materials) to support valuations, listings, or compliance checks. Such files may contain special categories of personal information if you include them. We treat verification documents as confidential business records. Documents are stored using encryption in transit and at rest where supported by our infrastructure. Unless a longer period is required by law, dispute resolution, or your explicit agreement for a specific transaction, verification documents are subject to an automatic deletion or archival policy after a defined retention window aligned with the purpose of collection. Retention periods may vary by document type and regulatory requirements; we will document material changes to retention in product notices or updates to this Policy where appropriate.
7. Hosting, databases, and infrastructure
We use Supabase and related cloud infrastructure (including PostgreSQL-backed storage) to host application data, authentication metadata, and operational logs. Data may be processed in data centers located in the United States or other regions where our subprocessors operate. We enter into data processing agreements with vendors where required and implement access controls and monitoring designed to protect personal information.
8. How we share information
We may disclose personal information:
- To service providers and subprocessors that perform functions on our behalf, such as hosting, analytics, session replay and behavioral analytics when enabled (Microsoft Clarity), email delivery, customer support tooling, payment processing (Stripe), AI inference (OpenAI), and identity or fraud prevention, subject to contractual confidentiality and security obligations;
- To other users of the Services and visitors to the marketplace when you publish a listing or share a report, as you direct;
- In connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate confidentiality and continuity safeguards;
- To comply with law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Inspex, our users, or others;
- With your consent or at your direction, including when you connect third-party integrations.
We do not sell personal information as defined under the California Consumer Privacy Act (CCPA), as amended, or similar state laws, except as expressly stated if our practices change and we provide required notice and choice.
9. International transfers
If you access the Services from outside the United States, your information may be transferred to, stored in, and processed in the United States or other countries where we or our vendors maintain facilities. Where required, we implement appropriate safeguards such as Standard Contractual Clauses approved by the European Commission or other lawful transfer mechanisms.
10. Retention
We retain personal information for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law. Criteria used to determine retention include the nature of the data, the risk of harm from unauthorized use, legal and regulatory requirements, and whether retention is advisable in light of litigation or investigations.
11. Security
We implement administrative, technical, and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. These measures may include encryption, access controls, logging, and vendor security reviews. No method of transmission over the Internet or electronic storage is completely secure; we cannot guarantee absolute security.
12. Your rights and choices
Depending on your jurisdiction, you may have rights to access, correct, delete, or port your personal information; to restrict or object to certain processing; to withdraw consent where processing is consent-based; and to lodge a complaint with a supervisory authority. Residents of the European Economic Area, United Kingdom, and Switzerland may exercise GDPR-related rights as provided by applicable law. California residents may exercise CCPA/CPRA rights, including the right to know, delete, and correct personal information, and to opt out of sale or sharing of personal information where those concepts apply. To submit a request, email hello@inspex.io. We will verify your request consistent with applicable law and may need additional information to confirm your identity.
13. Children
The Services are not directed to individuals under 16 years of age, and we do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us and we will take appropriate steps to delete it.
14. Changes to this Policy
We may update this Policy from time to time. We will post the revised Policy on this page and update the “Last updated” date. If changes are material, we will provide additional notice as required by law, such as by email or an in-product notification. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy, to the extent permitted by law.
15. Contact
For privacy-related inquiries, contact Inspex at hello@inspex.io.