Privacy Policy
This Privacy Policy explains how 1Lookup Inc. (“1Lookup,” “we,” “us,” or “our”) collects, uses, shares, and protects personal information. It covers our websites, our APIs and dashboards, and the data validation services we provide (together, the “Service”). It is part of, and should be read with, our Terms of Service.
1. Scope of This Policy
This policy applies to personal information we handle as a business, including information about visitors to our websites, people who contact us or sign up for marketing, our customers and their authorized users, and individuals whose information appears in data our customers submit or receive through the Service.
This policy does not apply to our customers’ own privacy practices. If a business used the Service to check information about you, that business decides why and how it processes your data, and its own privacy policy governs. See Section 16.
2. Two Kinds of Data, Two Different Roles
We handle two distinct categories of information, and our responsibilities differ for each. This distinction matters for understanding your rights.
2.1 Our Own Business Data (we are the controller)
This is information about you as a website visitor, prospect, customer, or authorized user: your account details, billing information, support messages, and how you use our site and product. We decide how this is used, and we are the controller for it. Most of this policy describes this category.
2.2 Customer Lookup Data (we are the processor)
When a customer submits a phone number, email address, IP address, or name to be validated, we process that data on the customer’s instructions in order to return a result. For that processing, the customer is the controller or business, and we act as a processor or service provider. We do not decide the purpose of those lookups, and we do not use lookup inputs to build marketing profiles or to market to the individuals involved.
Where required, a data processing addendum between us and the customer governs this processing and takes precedence over this policy for that data.
3. Information We Collect
3.1 Information You Give Us
| Category | Examples |
|---|---|
| Account information | Name, business name, work email, password, phone number, job role |
| Billing information | Billing name and address, tax details, and the last four digits and expiry of your card. Full card numbers go directly to our payment processor and are not stored on our systems. |
| Communications | Support tickets, emails, sales enquiries, meeting bookings, survey and review responses |
| Marketing preferences | Newsletter subscriptions, topic interests, consent and opt-out records |
3.2 Information We Collect Automatically
| Category | Examples |
|---|---|
| Device and connection data | IP address, browser type and version, operating system, device type, screen size, language, and general location inferred from IP |
| Usage data | Pages viewed, referring page, links clicked, search terms used on our site, session duration, and timestamps |
| Product and API telemetry | API endpoints called, request volumes and rates, response times, error rates, and API key identifiers |
| Cookies and similar technologies | Cookies, pixels, local storage, and device or browser identifiers, as described in Section 9 |
3.3 Information From Third Parties
We receive information from our payment processor about transaction status, from advertising and analytics platforms about how visitors reach our site, from fraud prevention providers about payment and signup risk signals, and from business data providers about company details used to qualify accounts. Some of the tools described in Section 9 attempt to identify the company associated with a visitor’s IP address.
3.4 Lookup Inputs and Outputs
Customers submit phone numbers, email addresses, IP addresses, and names, and we return results such as validity, line type, carrier, deliverability signals, geolocation, and risk indicators. This data is handled as described in Section 2.2.
3.5 What We Ask You Not to Send Us
Our Terms of Service prohibit submitting government identification numbers, financial account numbers, health information, biometric data, precise geolocation, credentials, or other sensitive categories of personal data to the Service. We do not want this data, the Service is not designed for it, and you should not send it.
4. Where Lookup Data Comes From
The information we return about a phone number, email address, or IP address is compiled from third-party and public sources. These include telecommunications and carrier records, numbering and portability databases, regulatory and public filings including U.S. Federal Communications Commission data, network and IP registry records, and commercial data providers who represent to us that they collect data lawfully.
We do not compile this information from private communications, and we do not purchase data we know to have been obtained unlawfully. Because these sources change constantly and are outside our control, results may be incomplete or out of date, as our Terms of Service explains.
5. How We Use Information
- To provide the Service: creating and administering your account, authenticating you, processing lookups, and returning results
- To bill you: processing payments, metering usage, preventing payment fraud, and collecting amounts owed
- To support you: answering questions, investigating issues, and communicating about your account, security, and service changes
- To secure the Service: detecting and preventing fraud, abuse, unauthorized access, and violations of our Terms, including identifying duplicate or abusive free trial signups
- To improve the Service: analyzing usage and performance, debugging, measuring data quality, and developing new features
- To market to businesses: sending newsletters and product information you asked for, measuring our advertising, and reaching potential customers. You can opt out at any time
- To comply with law: meeting legal and tax obligations, responding to lawful requests, and establishing or defending legal claims
5.1 Aggregated and De-identified Information
We create aggregated and de-identified statistics from use of the Service, such as overall data quality rates and usage trends, and we may use and publish them for any lawful business purpose. This information does not identify you or any individual, and we do not attempt to re-identify it.
5.2 Automated Decision-Making
We do not make decisions about you that produce legal or similarly significant effects based solely on automated processing, other than automated fraud and abuse controls that may block a signup, decline a trial, or suspend an account. You can contest such a decision by contacting us at the address in Section 20.
6. Legal Bases for Processing
If the EU or UK General Data Protection Regulation applies to our processing, we rely on the following legal bases.
| Purpose | Legal basis |
|---|---|
| Providing the Service and performing our contract with you | Performance of a contract, Article 6(1)(b) |
| Billing, collections, and record keeping | Contract performance and compliance with a legal obligation, Article 6(1)(b) and (c) |
| Security, fraud prevention, and abuse detection | Legitimate interests in protecting the Service and our business, Article 6(1)(f) |
| Service improvement and analytics | Legitimate interests in operating and improving our product, Article 6(1)(f) |
| Advertising cookies and marketing pixels | Consent, Article 6(1)(a), where consent is required |
| Marketing emails to business contacts | Consent or legitimate interests, depending on the jurisdiction and how you were added |
| Responding to legal requests and defending claims | Legal obligation and legitimate interests, Article 6(1)(c) and (f) |
Where we process lookup data as a processor for a customer, that customer is responsible for establishing the legal basis for the processing it instructs.
8. Selling and Sharing for Advertising
We do not sell your personal information for money. We do not sell, rent, or trade your account information, your billing details, your support messages, or the lookup data you submit.
We do share limited online identifiers with advertising platforms. Our websites run advertising and measurement pixels from Google, Meta (Facebook), and Reddit, listed in Section 9. These tools receive online identifiers such as cookie IDs, device identifiers, and IP address, together with pages you viewed and actions you took on our site. Under the California Consumer Privacy Act as amended by the California Privacy Rights Act, and under several other U.S. state privacy laws, this activity is treated as “sharing” for cross-context behavioral advertising and can fall within the statutory definition of a “sale,” even though no money changes hands.
We say this plainly because it is accurate. A previous version of this policy stated that we never share personal information with third parties for any purpose. That was not correct with respect to these advertising tools, and this section replaces it.
8.1 How to Opt Out
You can opt out of this sharing in any of these ways, and you do not need an account to do so:
- Email privacy@1lookup.io with the subject line “Do Not Sell or Share My Personal Information.” We will process your request and confirm when it is done
- Enable a recognized opt-out preference signal in your browser, such as Global Privacy Control, which we honor as a valid opt-out request where required by law
- Block or delete cookies in your browser settings, and use your browser’s tracking protection features
- Use the advertising controls offered by the platforms themselves, including Google Ads Settings and the ad preference settings in your Meta and Reddit accounts
We do not knowingly sell or share the personal information of anyone under 16 years of age.
8.2 Sensitive Personal Information
We do not use or disclose sensitive personal information, as that term is defined under California law, for purposes that would require us to offer a right to limit its use.
10. How Long We Keep Information
| Information | Retention |
|---|---|
| Account and profile information | For as long as your account is open, and then up to 24 months after closure |
| Billing and transaction records | Up to 7 years after the transaction, to meet tax, accounting, and audit obligations |
| Support and communication records | Up to 36 months after the last contact |
| API and access logs | Typically up to 90 days in identifiable form, then deleted or aggregated |
| Lookup inputs and results | Retained only as long as needed to return and reconcile the result and to meter billing, then deleted or de-identified. Retention for a specific customer may be set by that customer or by a data processing addendum |
| Fraud, abuse, and trial abuse signals | Up to 24 months, so that repeat abuse and duplicate trials can be identified |
| Marketing and consent records | Until you opt out, plus a suppression record kept indefinitely so we can honor your opt-out |
| Aggregated and de-identified data | Indefinitely, since it no longer identifies anyone |
We may keep information longer where we need it to comply with a legal obligation, resolve a dispute, enforce our agreements, or defend a legal claim. When retention is no longer needed, we delete or de-identify the information.
11. Security
We maintain technical and organizational measures designed to protect personal information, including encryption of data in transit and at rest, access controls and multi-factor authentication for internal systems, network protection, logging and monitoring, and internal policies limiting access to those who need it. Our security page describes our controls in more detail.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any regulator as required by applicable law. Report a suspected vulnerability or incident to security@1lookup.io.
12. Your Privacy Rights
Depending on where you live, you may have some or all of the following rights. We honor these requests as required by applicable law, and we extend the core rights to everyone regardless of location where we reasonably can.
- Know and access. Ask what personal information we hold about you and get a copy
- Correct. Ask us to fix inaccurate or incomplete information
- Delete. Ask us to delete your personal information, subject to legal exceptions
- Portability. Get a copy in a structured, machine-readable format, or have it sent to another provider where technically feasible
- Opt out of sale or sharing. Stop the advertising sharing described in Section 8
- Opt out of marketing. Unsubscribe from marketing email at any time using the link in any message, or by contacting us
- Object or restrict. Object to processing based on legitimate interests, or ask us to restrict processing in certain circumstances
- Withdraw consent. Where we rely on consent, withdraw it at any time, without affecting processing already carried out
- Non-discrimination. Exercise these rights without being denied service, charged a different price, or given lower quality
12.1 How to Exercise Your Rights
Email privacy@1lookup.io or use our contact form. Tell us what right you want to exercise and enough detail for us to find your information. Account holders can also access and update much of their information directly in the dashboard.
We will acknowledge your request and respond within 45 days for U.S. state privacy requests, and within one month for requests under EU or UK law. We may extend that period where the law allows, and we will tell you if we do. We may need to verify your identity before acting, and we will only ask for information necessary to do so. We do not charge a fee unless your request is excessive or repetitive, in which case we will tell you first.
12.2 Authorized Agents
You may use an authorized agent to submit a request. We will ask for proof that you gave the agent permission, and we may ask you to verify your own identity directly.
12.3 If We Decline
If we deny your request, we will explain why. You may appeal by replying to our decision with the word “Appeal” and any additional information. We will respond to an appeal within 45 days. If you remain unsatisfied, you may complain to your state attorney general or, in Europe and the UK, to your supervisory authority.
13. California Privacy Rights
This section applies to California residents and supplements the rest of this policy. It is provided under the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the “CCPA”). Terms used here have the meanings given in the CCPA.
13.1 Categories We Collect, Why, and Who Receives Them
| Category of personal information | Collected | Disclosed for a business purpose | Shared for advertising |
|---|---|---|---|
| Identifiers, such as name, email, IP address, and account or cookie IDs | Yes | Yes | Yes |
| Customer records, such as billing name, address, and partial card details | Yes | Yes | No |
| Commercial information, such as plan purchased and transaction history | Yes | Yes | No |
| Internet and network activity, such as pages viewed and API usage | Yes | Yes | Yes |
| Geolocation, meaning approximate location inferred from IP address | Yes | Yes | Yes |
| Professional or employment information, such as company and job role | Yes | Yes | No |
| Inferences, such as visitor scoring for sales qualification | Yes | Yes | No |
| Sensitive personal information | Not intentionally collected | No | No |
| Biometric information, or education records | No | No | No |
The sources of this information are described in Section 3, our business and commercial purposes for collecting it are described in Section 5, and the categories of recipients are described in Section 7 and Section 9.
13.2 Your California Rights
You have the right to know, access, correct, and delete your personal information, the right to data portability, the right to opt out of the sale or sharing of your personal information, the right to limit the use of sensitive personal information, and the right not to be discriminated or retaliated against for exercising these rights. Exercise them as described in Section 12.1, and opt out of sharing as described in Section 8.1.
13.3 Do Not Sell or Share My Personal Information
As explained in Section 8, we share online identifiers with advertising platforms, which the CCPA treats as sharing for cross-context behavioral advertising. To opt out, email privacy@1lookup.io with the subject “Do Not Sell or Share My Personal Information,” or enable a Global Privacy Control signal in your browser, which we treat as a valid opt-out.
13.4 Retention and Financial Incentives
We keep personal information for the periods described in Section 10. We do not offer financial incentives or price differences in exchange for the retention or sale of personal information.
13.5 Shine the Light
California Civil Code Section 1798.83 permits California residents to request information about disclosure of personal information to third parties for direct marketing. Send such requests to privacy@1lookup.io.
14. Other U.S. State Privacy Rights
Residents of states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and a growing number of others, have rights to confirm and access their personal data, correct it, delete it, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and certain profiling. Exercise these rights as described in Section 12.1, and opt out of targeted advertising as described in Section 8.1.
Where your state law provides a right to appeal a denied request, you may appeal as described in Section 12.3. We recognize universal opt-out mechanisms, including Global Privacy Control, in states that require it. We do not use personal data for profiling that produces legally significant effects, other than the fraud and abuse controls described in Section 5.2. We do not knowingly process the sensitive data of a known child, and we do not sell the personal data of consumers we know to be under 16.
Nevada residents may submit a verified request not to have covered information sold to privacy@1lookup.io.
15. EU, UK, and Swiss Privacy Rights
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the rights of access, rectification, erasure, restriction, portability, and objection, the right to withdraw consent, and the right not to be subject to solely automated decisions with legal or similarly significant effects. Our legal bases are set out in Section 6. Exercise your rights as described in Section 12.1.
Where we rely on legitimate interests, you may object, and we will stop unless we have compelling grounds to continue. Where we rely on consent for advertising cookies, you may withdraw it at any time as described in Section 8.1.
You have the right to complain to your supervisory authority. In the UK, that is the Information Commissioner’s Office. In the EEA, it is the authority in your country of residence or workplace. We would appreciate the chance to address your concern first.
16. If Your Data Was Looked Up by a Customer
If a business used the Service to validate information about you, that business determined why, and it is the controller of that processing. We processed the request on its instructions. Your first point of contact for access or deletion of that data is that business, and its privacy policy governs what it did with the result.
You can still contact us at privacy@1lookup.io. We will do the following:
- Tell you what we can about whether your phone number, email address, or other identifier appears in the data we use to answer lookups, and where we sourced it
- Add your identifier to our suppression list on request, so we stop returning enriched information about it, subject to any legal obligation to retain records
- Forward your request to the relevant customer where we are able to identify them and are permitted to do so
- Correct information we hold about you where you show us it is wrong
We are not a consumer reporting agency, our data is not a consumer report, and our Terms of Service prohibit customers from using the Service to decide your eligibility for credit, employment, housing, insurance, or benefits. If a business told you that a 1Lookup result was used for such a decision, that use violated our Terms. Please tell us at privacy@1lookup.io.
17. Children's Privacy
The Service is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16, and we do not knowingly sell or share the personal information of anyone under 16. If you believe a child has given us personal information, contact privacy@1lookup.io and we will delete it promptly.
18. International Data Transfers
We are based in the United States, and we and our service providers process personal information in the United States and in other countries. Privacy laws in those countries may differ from those where you live, and some may not provide the same level of protection.
Where we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, together with additional measures where needed. To request a copy of the safeguards that apply to a particular transfer, email privacy@1lookup.io.
19. Changes to This Policy
We may update this policy. When we do, we will change the effective date at the bottom of this page. If a change materially affects how we handle personal information, we will provide additional notice, such as an email or an in-product notice, before it takes effect where required. Continuing to use the Service after a change takes effect means you accept the updated policy.
20. Contact Us
For privacy questions, requests, or complaints, contact privacy@1lookup.io. For general enquiries, contact contact@1lookup.io or use our contact form. For security reports, contact security@1lookup.io.
1Lookup Inc.