Legal
Privacy Policy
Last updated: March 12, 2026
At cornflower.ai ("Cornflower," "we," "us," or "our"), we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.
1. Information We Collect
Information you provide
- Scan requests: Business name and location you enter to run a visibility scan. No personal account is required for free scans.
- Account information: If you create an account for Monthly Monitoring, we collect your name, email address, and payment information.
- Communications: Any information you provide when contacting us via email or support channels.
Information collected automatically
- Usage data: Pages visited, features used, scan history, and interaction patterns.
- Device information: Browser type, operating system, device type, and screen resolution.
- Log data: IP address, access times, referring URLs, and pages viewed.
- Cookies: We use essential cookies for site functionality and optional analytics cookies to understand usage patterns. See Section 6 for details.
Information from third parties
Our visibility scans collect publicly available data about businesses from third-party platforms including Google Search, Google Maps, ChatGPT, Perplexity, Gemini, review sites, and social media. This data is about businesses, not individuals, and is already publicly accessible.
2. How We Use Your Information
We use collected information to:
- Generate and deliver visibility reports for the businesses you scan
- Provide, maintain, and improve our services
- Process payments and manage subscriptions
- Send service-related communications (scan results, score alerts, account updates)
- Analyze usage trends to improve the product experience
- Detect and prevent fraud, abuse, or technical issues
- Comply with legal obligations
We do not sell your personal information to third parties. We do not use your data for advertising purposes.
3. How We Share Your Information
We may share your information only in these limited circumstances:
- Service providers: Payment processors, hosting providers, and analytics services that help us operate our platform. These providers are contractually bound to use your data only to perform services on our behalf.
- Legal requirements: When required by law, subpoena, or government request, or to protect our rights, safety, or property.
- Business transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred. We will notify you of any such change.
4. Data Retention
We retain your personal information for as long as your account is active or as needed to provide our services. Scan reports are retained for the duration of your subscription. If you cancel your account, we will delete your personal data within 90 days, except where retention is required by law or for legitimate business purposes (such as resolving disputes).
Free scan data (business name and location only — no personal data) may be retained in anonymized, aggregated form for product improvement.
5. Data Security
We implement industry-standard security measures to protect your information, including encryption in transit (TLS/SSL), encrypted storage for sensitive data, access controls, and regular security reviews. However, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
6. Cookies & Tracking
We use the following types of cookies:
- Essential cookies: Required for basic site functionality (session management, security). These cannot be disabled.
- Analytics cookies: Help us understand how visitors interact with our site. You may opt out of analytics cookies through your browser settings or our cookie preferences.
We do not use advertising or tracking cookies. We do not participate in cross-site tracking or retargeting.
7. Your Rights
Depending on your location, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate or incomplete information
- Delete your personal information
- Export your data in a portable format
- Opt out of non-essential data processing
- Withdraw consent where processing is based on consent
To exercise any of these rights, contact us at privacy@cornflower.ai. We will respond within 30 days.
8. California Residents (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete it, and the right to opt out of the sale of personal information. We do not sell personal information.
9. European Residents (GDPR)
If you are located in the European Economic Area, we process your personal data under the following legal bases: performance of a contract (providing our services), legitimate interests (improving our platform), and consent (analytics cookies). You have the right to lodge a complaint with your local data protection authority.
10. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes via email. The "Last updated" date at the top of this page indicates when the policy was last revised.
12. Contact
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:
Email: privacy@cornflower.ai