Privacy Policy
Effective date: 5 April 2026
Last revised: 5 April 2026 — professional/business contact focus; stronger acceptable-use and sensitive-data clarity.
Introduction and organizational information
Ploid processes information only as described in this policy and only where permitted by applicable law, including the GDPR (where it applies) and California privacy law (CCPA/CPRA); both are summarized under Your privacy rights (GDPR and California). Data is collected and used through ploid.com, our applications, and related communications for defined purposes—we do not use it for unrelated or undisclosed purposes. We focus on professional and business contact data (for example work-related names, employers, roles, and business-relevant email or phone)—not on operating a consumer people-search or personal directory. Our people-intelligence product is intended for lawful B2B and professional use only; search and enrichment may return contact points (including email) from public sources, third-party providers, and Ploid's own systems—see Professional use and contact data. California-specific detail also appears under California (CCPA/CPRA) in that section.
- Providing and securing the platform, including account management, authentication, billing, and support.
- Delivering search, enrichment, and people-intelligence functionality you request under your agreement with us.
- Detecting, investigating, and preventing fraud, abuse, and violations of our terms and policies.
- Complying with legal obligations and defending our legal rights where permitted.
We apply technical and organizational measures designed to protect personal information against unauthorized access, loss, misuse, disclosure, alteration, or destruction. Access is limited to personnel and subprocessors with a legitimate need, subject to confidentiality obligations and ongoing review.
We do not maintain a designated Data Protection Officer (DPO). For privacy questions or requests, contact Kamran@ploid.co. We respond in line with applicable law and may verify identity before disclosing or changing information.
Subprocessors that process personal information on our behalf must meet contractual data-protection and security requirements. We do not authorize them to use your personal information for their own marketing or for purposes unrelated to services they provide to Ploid.
Scope and application
This policy applies to personal information processed in connection with ploid.com, our services, and related interactions with visitors, trial users, registered users, and customers. It describes what we collect, why we process it, how we protect it, who we share it with, and the rights you may have. If you do not accept these practices, you must not use our services.
Data sources (why this information exists)
People and company information in Ploid is assembled for lawful professional use (for example recruiting and go-to-market workflows). It may include public web and professional-network signals, licensed or partner feeds, enrichment vendors, and data we index or derive in our own systems. Contact fields (such as email or phone) may be inferred or supplied by third parties and are not guaranteed complete or current. For detail on contact data, enrichment, and warranties, see Professional use and contact data and Where contact data comes from (third parties and Ploid). Core search and contact-resolution features require a signed-in account—see Security and operations.
Professional use and contact data
We focus on professional and business contact data. That means information tied to work, employers, roles, and business outreach—similar to how B2B data providers describe their datasets—not on collecting data for private, non-business, or purely personal purposes. Ploid is built for professional, business, and lawful recruiting and go-to-market use—not for stalking, harassment, or unpermitted consumer surveillance.
Built for business use—not consumer personal use. Search, sourcing, and enrichment return information about people from a mix of third-party data partners (including subprocessors listed in this policy), other vendors we integrate with, and Ploid's own data assets and processing (for example indexing, merging, scoring, or storing information derived from public or licensed inputs). That can include names, employers, roles, and contact points such as work email addresses or phone numbers when those fields are returned by a provider or inferred from available data. Third-party sources vary in quality; a contact point is not guaranteed to be strictly "work-only," and you must assess whether your use complies with applicable law (including marketing and employment rules) and your internal policies.
Where contact data comes from (third parties and Ploid)
Third-party vendors. Email addresses and phone numbers surfaced through search and enrichment—including fields labeled or treated as work or personal—may be supplied by independent data and enrichment vendors we engage. Examples appear in the subprocessors table under Data sharing (for example FullEnrich). Those vendors operate their own databases, models, and classification logic. Ploid does not control how they source, label, score, refresh, or store that information.
Ploid's own data and processing. The product also returns information drawn from Ploid's own systems—such as data we index, store, merge, rank, or derive in the course of operating search, sourcing, and related features. That is not limited to repackaging a single vendor's feed; it can include our pipelines, databases, and product logic built on top of public, licensed, and partner inputs.
No warranty on contact data. To the maximum extent permitted by applicable law, Ploid does not warrant or guarantee that any contact data—whether it originates from a third-party vendor or from our own systems—is accurate, complete, up to date, lawful for your intended use, or free from error (including whether an email is truly "work" or "personal," or current). That data is provided to help you operate your workflow; you are responsible for validating information and for compliance when you rely on it, as further described under Your responsibility for use of data. Third-party practices are governed by their own terms and privacy notices (see Data sharing).
Account and service email. The email address you use to register or sign in is processed as part of your account relationship with Ploid (authentication, security notices, billing, support). That processing is separate from contact data shown in search results, but the same policy and subprocessors (for example analytics or payments) may apply where described in this policy.
Website and technical data. Operating ploid.com and our applications involves technical information (such as IP address, cookies, device and browser signals) and security and operations data as described under Data storage and protection and Security and operations.
Your responsibility for use of data
You are responsible for how you use this data—and you must use it for lawful business purposes only. Ploid may enable access to information about individuals (including professional or public information and data obtained from third-party sources). You—not Ploid—are solely responsible for your decisions and actions based on that information, including compliance with anti-spam, telemarketing, employment, and privacy laws. That includes reliance on contact data from third-party vendors and from Ploid's own systems, as described under Where contact data comes from (third parties and Ploid).
Business use only. You must use the service and any data obtained through it for legitimate business purposes consistent with this policy and your agreement with us (for example recruiting, sales, and professional outreach where permitted). You must not use the service or data for personal, non-business purposes that would violate reasonable privacy expectations or applicable law (such as tracking individuals for personal reasons, romance scams, or non-work harassment).
No spam, harassment, or abuse. You must not use the service or data to send spam, deceptive or bulk unsolicited messages without a lawful basis, or to harass, threaten, stalk, or dox anyone. You must not use the service or data for unlawful discrimination, unauthorized surveillance, or any purpose prohibited by law or by your agreement with us. Enforcement, suspension, and termination for violations are described in our Terms of Service.
You must otherwise use the service and any data obtained through it only in compliance with applicable laws and regulations, including those governing privacy, employment, credit and background screening (where applicable), anti-discrimination, direct marketing, and consumer protection. You are responsible for obtaining and documenting any notices, consents, rights, or authorizations required for your specific use cases, and for honoring individuals' rights to the extent you act as a controller or business in your own context. Nothing in this policy or the service constitutes legal, HR, or compliance advice; you should consult qualified counsel for your obligations.
Data collection and processing
The following list details categories of information we may process. We focus on professional and business contact data for B2B workflows; people-intelligence features are described under Professional use and contact data. Search and enrichment may surface email addresses and similar contact fields from subprocessors and other third parties, and from Ploid's own data and processing—always subject to your obligations in Your responsibility for use of data.
- Professional name, title, and employer or organization (as tied to a business or public professional profile)
- Professional and business contact data—primarily work-oriented email addresses, phone numbers, and similar contact points for B2B recruiting, sales, and go-to-market use (from search and enrichment via subprocessors and partners, and/or Ploid's own systems). We do not position Ploid as a consumer directory; mixed or misclassified contact types can still appear—you must use data only for lawful business purposes and in line with this policy
- Professional or public biography, role, and education where available in business contexts
- Account email address you provide for login, security, billing, or support (your service account contact only)
- Browser information and language
- IP address
- Browsing history (on our sites and apps, where applicable)
- IP-based approximate location
- Browser fingerprint
- Operating system and version
- Search queries, prompts, and similar content you submit to AI-assisted or natural-language features (processed to provide the service)
- Purchase history and billing records tied to your business account
- Payment method and history
We limit collection and processing to what is necessary for the purposes stated in this policy, your agreement with us, and applicable law. We do not collect categories of data for speculative or undisclosed future uses.
We may use personal information for the following purposes (and compatible purposes required to deliver the service):
- Operating, delivering, and securing the Ploid platform for business and professional users (including search, enrichment, and people-intelligence features intended for lawful B2B use—not for consumer personal use unrelated to a legitimate business purpose).
- Running AI-assisted and natural-language features where we send queries or prompts to model providers on our instructions.
- Authenticating accounts, preventing fraud and abuse, and enforcing our terms and acceptable use.
- Complying with legal obligations and responding to lawful requests.
- Measuring and improving product performance, reliability, and security (using aggregated or de-identified data where feasible).
- Communicating with you about the service, billing, and material changes, where permitted.
Processing beyond these purposes requires a lawful basis under applicable law (for example contract, consent where required, legitimate interests balanced against your rights, or legal obligation). Where we rely on consent, you may withdraw it as described in this policy and in-product controls, without affecting prior processing that was lawful.
Sensitive personal data—we do not collect it as a product category
We do not collect sensitive personal data (for example health, racial or ethnic origin, religious beliefs, union membership, sexual orientation, genetic or biometric data used to identify you, or government identifiers) as a core, intentional category for the Ploid product. We do not design the service to display or sell such information as a primary output. Third-party or public sources could theoretically include incidental mentions in unstructured text; you must not use the service to seek, scrape, or rely on sensitive data for unlawful purposes. If you believe we are processing sensitive information about you in error, contact Kamran@ploid.co or use Data rights & requests.
Personal data not obtained directly from you (including GDPR Article 14)
Some personal data we process may come from sources other than the individual it relates to—for example, information made available in professional or public contexts, or data submitted by our customers when they use our services under their own legal bases and agreements. Where the GDPR applies, Article 14 requires us to provide certain information to those individuals, subject to exceptions in applicable law.
What we publish. This Privacy Policy describes categories of personal data we may process, purposes of processing, how we protect data, who we may share with, how long we keep data (where described), and your rights. For a dedicated place to exercise rights or ask questions without an account, see our Data rights & requests page (including how to delete your account by emailing Kamran@ploid.co).
Disproportionate effort and alternatives. Where the GDPR or other law permits, we may rely on transparency measures such as this Policy and our public data-rights channel instead of contacting each person individually when doing so would involve disproportionate effort, provided your statutory rights remain available. Whether an exception applies depends on the facts and the law; nothing here limits your right to contact us or a supervisory authority.
Impact assessments. We conduct data protection impact assessments and internal reviews when required for high-risk processing under applicable law, and we adjust our practices as our products and regulatory expectations evolve.
To exercise rights or ask for information about processing of data relating to you, contact Kamran@ploid.co or use the request options on our Data rights & requests page.
Data storage and protection
Data storage
Personal information is stored on secure cloud infrastructure. Depending on how our services are deployed, primary processing regions are often United States–based, but specific subsystems (for example databases, object storage, or analytics workloads) may use regions or providers configured for performance and redundancy. For transfers across borders, we work to ensure that such transfers comply with applicable laws and maintain appropriate safeguards where required.
Data hosting partners: We partner with reputable providers for application hosting, databases, object storage (including S3-compatible storage such as Cloudflare R2 where configured), and related services—selected for security and data-protection expectations.
Data protection measures
- Encryption: We use industry-standard encryption for data in transit and, where appropriate, at rest.
- Access control: Access to personal information is denied by default; grants are limited in time and scope to personnel and roles with a documented need. We review access periodically and revoke when no longer required.
- Logging and monitoring: We log and monitor systems for unauthorized access attempts and security events, and we investigate anomalies in line with our incident procedures.
- Vendor security: We require subprocessors to implement appropriate technical and organizational measures and to process data only on documented instructions.
Security and operations
In addition to organizational measures described above, our API and web applications use technical controls intended to reduce abuse and protect accounts, including (where applicable): serving traffic over HTTPS (TLS), applying security-related HTTP headers, restricting cross-origin access to approved front-end origins, rate limiting sensitive endpoints, and authenticating sessions for logged-in use. We retain limited server and application logs to operate the service, troubleshoot issues, and investigate misuse—typically including elements such as timestamps, request identifiers, IP address, and user agent. We may apply rate limits, usage caps, and export or API restrictions to reduce abuse and protect the service. This section describes our practices at a high level; it is not an exhaustive security specification or a guarantee that any particular threat will never occur.
Data sharing and disclosure
We do not sell your personal information for monetary consideration. We share personal information only with third-party service providers that perform services on our behalf under written terms, or when required by law, to protect rights and safety, or in connection with a business transaction subject to confidentiality and continuity safeguards. Providers may access personal information only on a need-to-know basis, must keep it confidential, and must not use it for any purpose other than providing services to Ploid as instructed.
Third-party service providers
| Service | Provider | Purpose(s) | Collected personal data types | Privacy policy |
|---|---|---|---|---|
| PostHog | PostHog Inc. |
|
| Link |
| Stripe | Stripe, Inc. |
|
| Link |
| Google (Sign in with Google) | Google LLC |
|
| Link |
| Resend | Resend, Inc. |
|
| Link |
| FullEnrich | FullEnrich (or its affiliates) |
|
| Link |
| Amazon Web Services | Amazon Web Services EMEA SARL |
|
| Link |
| Cloudflare | Cloudflare Inc. |
|
| Link |
This table lists key third-party services that process personal information on our behalf where applicable. We may add or change providers as the service evolves. People and contact data in the product can also come from Ploid's own systems (for example data we index, store, or derive)—not only from the vendors above. Depending on deployment and features, we may also use additional APIs and infrastructurenot named in every row (for example search and retrieval providers, AI/LLM inference gateways, analytics/query databases, and other hosting services)—always under agreements that govern processing on our instructions. Review each provider's policy for details.
Where GDPR or similar laws apply, we use Data Processing Agreements (DPAs) or equivalent terms with processors, specifying subject matter, duration, nature and purpose of processing, categories of data, controller/processor obligations, and assistance with data subject requests and security expectations.
We will notify you of material changes to subprocessors or sharing practices where your contract or law requires. For questions about sharing and disclosure, contact Kamran@ploid.co.
Your privacy rights (GDPR and California)
This section first summarizes rights under the General Data Protection Regulation (GDPR) for individuals in the European Economic Area, Switzerland, and the UK (where applicable). Immediately after, we summarize how we align with California law (CCPA/CPRA). Additional U.S. state detail appears in United States privacy laws. Contact us to exercise any right that applies to you.
GDPR (EU, EEA, Switzerland, and UK)
We respect your rights regarding personal information under the GDPR. Below is an overview; contact us to exercise these rights.
- Right of access (Art. 15 GDPR): Request access to the personal information we hold and information about how we process it.
- Right to rectification (Art. 16 GDPR): Request correction or completion of inaccurate or incomplete data.
- Right to erasure (Art. 17 GDPR): Request deletion when data is no longer necessary for the purposes collected, among other grounds.
- Right to restriction (Art. 18 GDPR): Request restriction of processing under certain conditions.
- Right to data portability (Art. 20 GDPR): Receive your data in a structured, commonly used, machine-readable format and transmit it to another controller where applicable.
- Right to object (Art. 21 GDPR): Object to processing under certain conditions, including direct marketing.
- Right to withdraw consent (Art. 7(3) GDPR): Withdraw consent at any time where processing is based on consent, without affecting prior lawful processing.
- Right to lodge a complaint (Art. 77 GDPR): Lodge a complaint with a supervisory authority if you believe our processing violates applicable law.
California (CCPA/CPRA)
We align our practices with the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including applicable notice, disclosure, and consumer-rights requirements for California residents. California residents should also review the United States privacy laws section below for rights such as access, deletion, correction, and opt-out where those terms apply. Nothing in this policy limits rights granted under California or other state law.
To exercise GDPR or California rights (or other rights we honor), contact Kamran@ploid.co. We will respond in accordance with applicable law and may need to verify your identity. You can also start a request from our Data rights & requests page (email-based).
Cookies and tracking technologies
We use cookies and similar technologies on ploid.com to operate our platforms, improve experience, and understand usage.
Cookies are small files on your device that help remember preferences and collect usage information. Beacons and pixels help us understand how you interact with our site.
How we use these technologies
- Essential cookies: Necessary for functionality such as authentication and security. Where required by law, essential cookies may not need consent.
- Performance and analytics cookies: Help us understand how visitors use the site and improve performance.
- Functional cookies: Enable enhanced functionality and personalization.
- Advertising and targeting cookies: We do not operate third-party ad networks on the core product today; if we introduce advertising or remarketing technologies that use such cookies, we will update this policy and obtain consent where required.
Where required by law, we obtain consent before setting non-essential cookies or similar technologies, and we provide a way to withdraw consent or change preferences. Essential cookies needed for security and core functionality may be used without consent where permitted.
Product analytics (PostHog)
We use PostHog on our sites and apps for product analytics: event capture, funnels, and optional session replay to understand how features are used and to fix bugs. Our deployment may route events through our domain (for example /ingest) to PostHog's U.S. cloud. Depending on configuration, PostHog may receive page views, UI interaction events (autocapture), and when you sign in, identifiers such as your account email for associating events with your workspace. Session replay may capture on-screen content; password fields are masked, but other inputs are not masked by default, so avoid entering secrets outside of password fields. We configure additional privacy controls in PostHog where supported. You may be able to opt out of analytics via your browser or device settings, or through controls PostHog offers, in addition to choices we surface in the product where applicable.
International data transfers
We may transfer personal information outside your country of residence, including to the United States and other jurisdictions. Where the GDPR or UK GDPR applies, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or other mechanisms recognized by applicable law, supplemented by technical and organizational measures. You may request more information about transfers by contacting Kamran@ploid.co.
United States privacy laws
To appeal a decision regarding a privacy request, contact us within 60 days of our response via the methods below. Include your original request, the date of our response, and why you believe the decision was incorrect.
Email: Kamran@ploid.co
For residents of the United States, including California, the following may apply:
- A. Individual rights: State laws may provide additional rights regarding personal information.
- B. Right to know: You may request disclosure of categories and specific pieces of personal information collected, used, shared, or sold, and the purposes and categories of third parties.
- C. Right to delete: You may request deletion of personal information we have collected, subject to exceptions.
- D. Right to correct: You may request correction of inaccurate information.
- E. Right to limit: You may request limited use of certain sensitive personal information where applicable.
- F. Right to opt-out: You may have the right to opt out of the sale or sharing of personal information where applicable law defines those terms.
- G. Non-discrimination: You have the right not to receive discriminatory treatment for exercising privacy rights.
- H. Submitting requests: Email Kamran@ploid.co. We may verify your request against information in our records.
- J. Sensitive or biometric data: We only process sensitive personal data with appropriate legal basis and disclosure, where applicable. You may withdraw consent where processing is consent-based, as described in your notices.
Data breach notification
We maintain security measures intended to prevent breaches. If we become aware of a breach that is likely to result in a risk to individuals' rights and freedoms, we assess the incident without undue delay, document it where required, and comply with notification obligations to regulators and affected individuals under applicable law.
- Detection: We use monitoring and security practices to detect and respond to incidents.
- Assessment: We assess the nature, scope, and impact of a breach, including categories of data affected.
- Authorities: Where required by law, we notify regulators within the timeframes specified by applicable law (not all laws use the same deadline).
- Individuals: Where required, we notify affected individuals with clear information about the breach and protective steps.
Questions about a possible breach: contact Kamran@ploid.co.
Policy updates
We may update this privacy policy to reflect legal, technical, or business changes. Material changes will be communicated as required by applicable law (for example, email, in-product notice, or prominent on-site notice before or at the time of the change). Continued use of the service after notice may constitute acceptance where permitted by law. The effective date at the top of this page will be updated; review this policy regularly.
Contact us
Questions about this policy: Kamran@ploid.co.