Privacy Policy
Last updated: August 10, 2026
This Privacy Policy explains how Exenro (“we”, “us”, or “our”) collects, uses, and shares information about you when you use our website at exenro.com and the services available through it (the “Service”). It applies to visitors, registered users, and anyone who contacts us. The operator of Exenro is the controller of the personal data described here and can be reached at hello@exenro.com. Using the Service is voluntary; if you do not agree with this policy, please do not use it.
Information We Collect
Information you provide
- Account data: your name and email address, the organisation or team you create or join, your role, and any invitations you send or accept.
- Indications of interest: if you register a buy or sell indication for a company, we collect your name, whether you act as an individual or for an organisation, the organisation name, your email address and phone number, your preferred contact channel and messenger handle, the indicative size you select, and any note you write.
- Messages: the content of enquiries, demo requests, support messages, and any other correspondence you send us, along with the contact details you use.
Information collected automatically
When you use the Service we automatically collect technical and usage data, including your IP address, approximate location derived from it, device and browser type, operating system, referring page, the pages and features you view, actions you take, timestamps, and diagnostic and error data. We use cookies and similar technologies for this, described in our Cookie Policy.
We use Microsoft Clarity for product analytics. Clarity records how the Service is used, including clicks, scrolling, mouse movement, and a reconstruction of the pages you viewed, and it may set its own identifiers. This is used to understand how people navigate the Service and to find usability problems, and it is processed by Microsoft under its own privacy terms. Clarity masks form input by default, but please avoid typing sensitive information into free-text fields.
Payment information
We do not store your full payment card details. Payments are processed by our third-party payment providers (Stripe, Dodo Payments, PayPal), which operate under their own privacy policies. They pass back to us limited billing data such as your subscription status, plan, transaction identifiers, amounts, country, and the last digits and brand of the card.
Information from other sources
We collect information about companies from public sources, news, third-party data providers, and voluntary disclosures. That material can include personal data about founders, executives, and other individuals connected with those companies, such as their name, role, and publicly reported statements. See Information about companies and individuals below.
How We Use Your Information and Our Legal Bases
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Performance of a contract: to create and operate your account, provide the Service, process transactions, and send service messages such as sign-in codes, receipts, and notices.
- Legitimate interests: to secure the Service and prevent fraud and abuse, to understand and improve how the Service is used, to maintain and publish our company database, to handle indications of interest, and to establish, exercise, or defend legal claims. We balance these interests against your rights.
- Consent: for non-essential cookies and analytics where consent is required, and for marketing emails where required. You may withdraw consent at any time.
- Legal obligation: to meet accounting, tax, sanctions, and other legal requirements.
Sharing of Information
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We may share information with:
- Service providers who process data on our behalf under contract: cloud hosting and database providers, caching and queueing providers, email delivery (Resend), product analytics (Microsoft Clarity), and payment processing (Stripe, Dodo Payments, PayPal). A current list is available on request.
- Counterparties and brokers when you submit an indication of interest. We may pass the details of that indication, including your contact details, to third parties so they can decide whether to contact you. Those third parties act as independent controllers under their own privacy policies, and we are not responsible for what they do with the data. If you do not want this, do not submit an indication.
- Legal authorities and advisers when required by law, or where we consider disclosure necessary to enforce our Terms, investigate suspected fraud or abuse, or protect the rights, safety, or property of any person.
- Acquirers in connection with a merger, acquisition, financing, reorganisation, or sale of assets, including during negotiations.
International Transfers
We operate internationally and our providers are located in various countries, including the United States. Your personal data may therefore be transferred to, stored in, and processed in countries whose data protection laws differ from those of your country. Where required, such transfers rely on an adequacy decision or on standard contractual clauses with appropriate safeguards. By using the Service you understand that your data will be processed in this way.
Cookies
We use cookies to keep you signed in, to remember your preferences, and to understand how you use the Service. You can control cookies through your browser settings. See our Cookie Policy for details.
Data Retention
We keep personal data for as long as your account is active and for as long as needed for the purposes described in this policy. After an account is closed we delete or anonymise account data within a reasonable period, except where we must keep it longer to comply with legal, tax, or accounting obligations, to resolve disputes, or to enforce our agreements. Billing records are kept for the statutory retention period. Aggregated or anonymised data that can no longer identify you may be kept indefinitely.
Your Rights
Depending on where you live, you may have the right to access, correct, or delete your personal data, to object to or restrict processing, to receive your data in a portable format, and to withdraw consent. If you are in the EEA or the UK you also have the right to lodge a complaint with your local supervisory authority. If you are a California resident, you have the right to know, delete, and correct your personal information, and to be free from discrimination for exercising those rights; as noted above, we do not sell or share personal information as those terms are defined by the CCPA.
To exercise any of these rights, contact us at hello@exenro.com. We may ask for information to verify your identity, and we will respond within the time limits set by applicable law. We may decline a request where the law allows, for example where it is manifestly unfounded or excessive or where the data is needed to establish or defend legal claims.
Information about Companies and Individuals
The Service publishes profiles of private companies built from public and third-party sources. Where those profiles contain personal data about individuals connected with a company, we process it on the basis of our legitimate interest in providing market information about the private markets and in the public availability of that information. Much of this content is compiled and summarised by automated systems and may be incomplete or inaccurate.
If you are named on the Service and wish to object to the processing or request correction or removal, write to hello@exenro.com with the specific page and the change you are asking for. We will review the request and correct or remove content where we consider it appropriate or where the law requires it. Acting on such a request is not an admission of any liability.
Automated Decision-Making
We use automated processing to produce estimates and content about companies. We do not make decisions about you that produce legal effects concerning you or similarly significantly affect you based solely on automated processing.
Security
We take reasonable technical and organisational measures to protect personal data, including encryption in transit and access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security or that unauthorised access, loss, or disclosure will never occur. You are responsible for keeping your credentials and devices secure. To the extent permitted by law, we accept no liability for any security incident that occurs despite reasonable measures.
Third-Party Links and Services
The Service links to and embeds content from third parties whose privacy practices we do not control. This policy does not cover them, and we are not responsible for their handling of your data. Review their policies before providing information to them.
Children’s Privacy
The Service is not directed to anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes by email or a notice on the Service and update the date at the top of this page. Continued use after changes take effect constitutes acceptance.
Contact Us
Exenro
hello@exenro.com
