Privacy Policy
Last updated: 2026-07-25
1. What we collect
Audit form
When you run a free audit we collect: business name, address, phone, optional hours of operation, optional service area, optional email (so we can send the report), and trade type. We also capture two hidden honeypot fields (website and email_alt) — these are blank for real users and used only to detect bots. Submissions flagged as bots are silently dropped without being added to our database.
Subscriber records
When you subscribe we keep the same business info plus: email, plan choice (monthly/annual), Stripe session and subscription IDs (so we can reconcile your payment), referral metadata (referred-by subscriber id, your own referral code, whether your reward has been claimed).
Account login
We use a magic-link login for our subscriber account dashboard at /account. Each login attempt issues a short-lived token (account_tokens) tied to your subscriber id and expiring after 15 minutes. Tokens are single-use and stored in our database until consumed or expired.
Analytics
Pages you visit are logged in our page_views table along with referrer URL, UTM parameters, SHA-256 hashed IP, browser user agent, session id, and a stable visitor_hash (a per-session per-browser fingerprint so we can count unique visitors without storing raw IPs). Funnel conversion events (events table) and session-level data (analytics_sessions) are stored the same way. If we run an A/B test we record one row per landing render in cta_exposures with the assigned variant.
We additionally load the Polsia Analytics pixel (POLSIA_ANALYTICS_SLUG) on every page. The pixel stores a randomized visitor id (polsia_vid) in your browser's localStorage and reports anonymous page views to Polsia — it's used to compute aggregated traffic patterns and never tied back to your account.
Addresses captured from the audit and signup flows are stored so we can deliver: the audit report, the post-payment onboarding sequence, the free-audit nurture sequence, the renewal reminder sequence, and the cold-outreach follow-up sequence. We log every send in onboarding_email_events, nurture_email_events, outreach_email_events, renewal_reminder_events, and email_sequence_sends; open/click/bounce signals are recorded in email_events so we can debug deliverability.
Bot defense
We log each bot-defense trigger in bot_defense_events: honeypot hits, rate-limit exceeded (more than 5 audit submissions from the same IP in an hour), and Google reCAPTCHA v3 (where a score below 0.3 is silently rejected). These records are used to maintain and tune the defense — they're not shared externally.
Cookies and local storage
connect.sid— express-session id (technical/functional, expires when you close the browser or after 30 minutes of inactivity).ll_referral— referrer subscriber id when you arrive via a referral link (functional, expires after the cookie session).ll_referral_mode— referral offer mode (functional, expires after the cookie session).ll_anon_id— anonymous id used to anchor the A/B test variant for unauthenticated visitors (functional, expires after 1 year).polsia_vid— randomized visitor id set by the Polsia Analytics pixel (analytics, persists inlocalStorageuntil cleared).
2. How we use it
We use the data above to: run the audit scan, email you the report and follow-up sequences, bill you through Stripe, detect and prevent abuse (bots, scraping, fraudulent submissions), debug deliverability, and improve the product.
We do not sell your data. We do not share it with third-party advertisers. We do not display ads on ListingLock or sell placement to anyone.
3. Third-party processors
The following services process data on our behalf:
- Stripe — payment processing for monthly and annual subscriptions. Card data is handled entirely by Stripe and never touches our servers; we only receive confirmation and subscription IDs.
- Polsia Analytics — anonymous page-view pixel loaded on every page (see Section 1 above).
- Polsia Email Proxy — transactional email delivery for audit reports, onboarding, nurture, renewal, referral, and outreach sequences. Email content is passed through Polsia's authenticated proxy.
- Google reCAPTCHA v3 — score-based bot detection on the audit form; verification tokens are validated server-side against the reCAPTCHA API and then discarded.
- Directory APIs — we call public lookups against Google Places, Yelp Fusion, Apple Maps Server API, Bing Local Business Search, Facebook Graph, BBB.org, Angi, HomeAdvisor, Houzz, Porch, Nextdoor, Yellow Pages, Manta, and Superpages to retrieve your public listing. Each request contains only the business name, address, and (sometimes) phone — no personal data.
4. Cookies & local storage
See the cookie list under Section 1 above. We don't use third-party advertising cookies. All cookies and local storage entries we set are first-party and tied to ListingLock or Polsia analytics — none are used for behavioral advertising.
5. Storage & retention
Application data is stored in a managed Postgres database (Neon). Retention:
- Subscribers: for as long as you remain a paying subscriber plus 90 days after cancellation, then anonymized.
- Free audit leads (non-subscribers): 90 days from submission, then anonymized.
- Account magic-link tokens: expire after 15 minutes and are deleted on use or on expiry check.
- Page views and analytics sessions: rolling 90 days.
- Stripe payment events: retained for accounting and audit purposes indefinitely.
- Email events: retained for 1 year for deliverability debugging, then aggregated.
6. Your rights
You can request:
- A copy of all personal data we hold about you.
- Deletion of your personal data (closes your account if you're a subscriber).
- Correction of incorrect business info.
- Opt-out of marketing email sequences without losing transactional emails about your subscription.
Email listinglock@polsia.app with your request. We'll action within 30 days, and sooner for straightforward deletions.
7. Security
We protect data with the following safeguards:
- IP addresses are hashed with SHA-256 before storage; raw IPs are not retained.
- Rate limiting on audit form submission (5 per IP per hour) and silent bot rejection.
- Honeypot fields to detect naive bots.
- Google reCAPTCHA v3 with a 0.3 score floor.
- Stripe handles all card data under PCI-DSS; we never see or store card numbers.
- Admin routes are password-protected.
- Database access requires credentials stored as environment secrets; no direct public exposure.
No method of transmission over the internet, however, is 100% secure. We cannot guarantee absolute security.
8. Children's privacy
ListingLock is a B2B service for adult business owners. It is not directed to children under 13 (or under 16 in jurisdictions with higher age thresholds). We do not knowingly collect personal data from children.
9. Changes to this policy
We may update this Privacy Policy. The "Last updated" date at the top reflects the most recent revision. For material changes — anything that affects what we collect or how we use it — we'll email active subscribers at least 14 days before the change takes effect.
10. Contact
Questions about this policy or our data practices? Email listinglock@polsia.app.