Privacy notice

This privacy notice took effect on 7 October 2026. It describes what this website collects, why, who receives it and how to ask us to change or delete it.

Who we are

Generativa LLC operates this website under the name Sell Business Data. Our registered address is 16192 Coastal Highway, Lewes, Delaware 19958, United States. For the personal information described below, Generativa LLC decides why and how it is used. You can reach us about it at privacy@sellbusinessdata.com.

Who the site is for

The site is for owners, officers and advisers who are looking at what a services firm's operating records could be worth to AI buyers. The first sales we take on are for firms in the United States. Personal data from the European Union, the United Kingdom or Vietnam is outside the first scope of any sale. If you write to us from one of those places, we use what you send only to answer you, and we tell you where things stand.

The agreements for an actual data sale, including how records from your systems are handled, are separate documents. You sign them before any work on your records starts.

What we collect, surface by surface

Visiting the site. Our hosting provider receives the technical details every web server receives: your IP address, the page requested (including any answers carried in its address), the time and your browser type. If you open the estimate from the buyer-fit check, your answers to that check travel in the page address, so they appear in our host's request logs. We use Vercel Web Analytics to count page views. Vercel's documentation describes this service as working without cookies. The site's forms also put started, finished, submitted and booked events in the browser's event queue. The finished event records the industry, staff count, years of records, number of systems, reference count and result status. It includes no company name, contact name, email address or price range.

The records form. You describe the company by its legal name, country, ownership structure, status, location and employee counts, and whether those counts are measured, estimated or unknown. You also give its industry, systems, years of records, working language, signing authority, parent ownership, administrator access, client or sensitive-record share, existing offers or exclusivity, previous exports and whether records show how work ended. The inventory asks for categories, record types, systems, dates, counts and units, export availability, rights status and exclusivity. For categories excluded from a first deal, it records only whether the category is present, not its contents. Do not enter a person's name or an actual record. When you submit, your browser sends the company and inventory details and screening answers to our server. It stores them with the score, result and time, then returns the next step. This request includes the company name; contact names and email addresses come later. The tool does not calculate a seller-specific price range. Your browser also keeps the form answers and inventory result in session storage for the visit, including the ownership and sensitive-record answers that are not part of the initial server screening request.

Contact form and call booking. If you go on, we ask for your name and work email, and for some forms your company, website, role, phone number, country, what you are considering and a message. Contact details entered after the screening result are attached to that stored record. Other contact forms and call booking can also send the saved form answers and inventory result. There is no seller-specific price range. They send the page you landed on, the page that referred you and the campaign tags in your link, such as utm_source or gclid. Your browser holds these in session storage until you close the tab. A contact submission is also written to our server log. A call booking stores your name, email, phone number, website, role, time zone and chosen time slot.

Sign-in. If you are invited to a seller or buyer account, or you book a call, we create the account and email a private sign-in link to your email address. The site records the link request, the sign-in, your IP address and your browser type. While you are signed in, your browser holds one session cookie that the site needs to recognise you. It is not used for advertising or tracking.

The newsletter. The newsletter is a separate signup with its own unticked box. We store your email address, the language and page you signed up from, the topic you chose if any, the consent wording shown to you, the time, and a private token that lets you unsubscribe. We add an address only when you tick the box and submit the form. Sending the estimate or contact form does not subscribe you.

Spam and abuse protection. Some endpoints count requests per IP address in short time windows to limit repeated requests. An expired window stops affecting the limit, but its stored counter is removed only during a later cleanup. Forms carry a hidden field that people never fill in.

Cookies and advertising

The site sets no advertising cookies and no analytics cookies. The only cookie is the sign-in session cookie described above. The site does not currently load any Google advertising or analytics tag. If we start Google Ads or Google Analytics, we will update this notice before the tag goes live, and we will ask visitors in the European Union and the United Kingdom for consent before any such cookie is set.

Why we use it

  • To answer your request, discuss your inventory, arrange a call and set up your seller account if you go ahead.
  • To decide who we call first, using the stored estimate answers and score.
  • To run, secure and improve the site, and to count how people use it.
  • To send the newsletter, only to people who ticked its box.

We do not sell or rent your contact details. We do not share your contact details or your estimate answers with a buyer.

Where the General Data Protection Regulation or the UK GDPR applies to something you send us, we rely on the following. We take steps you ask for before a contract when we reply to your estimate, contact or booking request. We rely on our legitimate interest in running the site, keeping it secure and answering business enquiries from companies. We rely on your consent for the newsletter, and you can withdraw it at any time with the unsubscribe link. You can object to processing that rests on our legitimate interest, and you can complain to your data protection authority.

Who receives it

  • Hosting and analytics: Vercel hosts the site and provides Web Analytics.
  • Database: a hosted database provider stores the estimate, contact, booking, account and newsletter records.
  • Email: an email delivery service, Cloudflare, sends our messages and acts only on our instructions. It receives the recipient address, the subject and the message, which includes the sign-in link.
  • Our people: the people at Generativa LLC and its contractors who handle your request.
  • Authorities: a court, regulator or other public body, when the law requires it.

If we sell or reorganise the business, the records described here may transfer to the new owner under this notice.

How long we keep it

We have not set or implemented automatic deletion periods for estimate, contact, booking, account, audit or newsletter records. These records do not disappear when a request is closed, a sign-in link expires or you unsubscribe. We review requests for a copy, correction or deletion through the privacy contact below; the site has no self-service account-deletion function.

Unsubscribing marks your newsletter subscription as inactive. It does not erase your email address, consent record or unsubscribe token. Audit records include actions, the actor's email address and, where recorded, an IP address. Sign-in messages and links are also stored in our outbox and written to server logs. No automatic deletion schedule is implemented for those copies.

Access expiry is different from deletion:

  • Request counters stop applying after their short window, up to one hour. Expired counter rows are removed during some later requests, not by a scheduled deletion job.
  • A sign-in link works once and expires after 15 minutes. Expiry does not delete the stored link or outbox record.
  • A sign-in session lasts 7 days for sellers and buyers and 12 hours for our administrators. Expiry ends access; signing out deletes the current session record. There is no scheduled purge of all expired session records.
  • Temporary upload chunks are encrypted and removed when an upload is assembled. Chunks older than one day are removed when another chunk is received; an abandoned upload can remain longer if no later upload triggers that cleanup.
  • Our hosting provider sets its own server-log retention under its published policy.

We will update this notice when a retention policy has been approved and its deletion process is implemented and verified.

Your rights and how to use them

Write to privacy@sellbusinessdata.com to ask for a copy of what we hold about you, to correct it, or to delete it. For the newsletter, use the unsubscribe link in any issue. We may ask you to confirm that you control the email address before we act. We reply within one month. We apply these rights to everyone who writes to us, wherever you live.

California residents have the rights to know what personal information we hold, to correct it, to delete it, and to be free from discrimination for asking. We do not sell personal information and we do not share it for cross-context behavioural advertising.

What not to send

Please do not send passwords, client files, tax returns, health records, candidate CVs or any other restricted record through the site's forms. Records for a sale come later, under a signed agreement.

How uploads work, and what we refuse

We are not accepting real seller records yet. A signed seller agreement is required before records can be submitted through the app. The intended upload is a reviewed, cleaned package, not an original export.

  • The tested browser path. You run the removal tool and review flagged items on your own computer. The normal browser uploader checks the cleaned package before sending it. In the recorded browser test, selecting a raw CSV generated no upload request. Original exports and the detailed review queue are intended to remain on your computer.
  • Direct requests and JavaScript limits. A direct API request or a form used with JavaScript disabled can send bytes to the server before it refuses them. For larger uploads, the server can temporarily store encrypted chunks before it assembles and checks the package. These controls are not a guarantee that raw bytes can never reach or be temporarily staged on our server.
  • Acceptance checks. Before adding a file to the accepted seller-file store, the server checks the package's manifest, file hashes, completed review record, deal-key signature and specified personal-data patterns. An invalid or unfinished package is refused. Refusal audit entries include the file name, size, fingerprint and reason; they are not a retained copy of the rejected file.
  • Who can open what. Our staff can open accepted cleaned packages and their reports. Admin downloads of legacy raw seller files are blocked, and accepted packages are checked again before an admin download.
  • What these checks cannot prove. The seller holds the signing key. A valid signature binds the package to that key; it does not prove that our tool made the package, that review was diligent, that all personal data was removed or that the seller has the rights to sell it. Local review and a comparison with the original remain required.

Security

Session identifiers are random and our database stores only a one-way hash of each. The session cookie is HttpOnly and is marked secure on encrypted connections. The records, follow-up contact, booking, newsletter and sign-in endpoints check request-origin headers and apply request limits. The general contact endpoint does not currently apply the same origin check or rate limit; its hidden spam field is not a substitute for those controls. Uploaded packages are encrypted at rest with a separate key for each file. No system is perfectly secure, and we cannot promise that a transmission or a stored record will never be exposed.

Children

The site is for business owners and advisers and is not directed at children. We do not knowingly collect information from children.

Changes

We will update this notice when the site changes how it handles information, and we will show the new date at the end of this page.

Last updated 8 October 2026.