Privacy notice
This notice explains what we collect when you use the assessment and the Full Match Report, why we collect it, who processes it on our behalf, and how to exercise your rights.
Last updated 26 August 2026
What we collect
We collect only what is needed to build your match and run the product:
- Assessment answers. Your interests, skills and experience, resources, goals, work preferences, and hard constraints — used to build your profile and match it against the business opportunity library.
- Email address. Collected when you unlock your result or complete a purchase, so we can send your result link, durable purchase confirmation, any receipt or invoice, and account access.
- Pseudonymous analytics, product events, and performance signals. When analytics measurement is active — because you allowed it, or by default in the specifically reviewed opt-out regions shown in preferences below — we record page views, sessions, referring domains and bounded campaign parameters, browser and device context, approximate geographic context, page performance measurements, bounded link or button clicks on nonsensitive public pages, assessment starts and completions, result views, match selections, and similar in-product events. These are tied to an anonymous identifier rather than your name so we can understand whether the product is useful, how people find it, monitor the experience, and fix what is not. Declining stops optional behavioral analytics and does not change the product experience; in prior-permission regions nothing is recorded until you allow it.
- Advertising conversion measurement. After regional and browser-privacy checks, Google Ads may receive a bounded cookieless signal when a visitor starts or completes the assessment, selects an idea, unlocks by email, begins checkout, or purchases. If Advertising measurement is allowed, Google may also use first-party attribution cookies and ad-click context, and Meta may receive sanitized page views and the same bounded funnel milestones through its Pixel. Meta stays completely off when Advertising measurement is not allowed. These tools process consent state, bounded page context, browser and connection metadata such as IP address, and conversion details; purchase signals include the amount, currency, and an opaque internal transaction reference for deduplication. We do not send assessment answers, profile dimensions, opportunity or result identifiers, form values, email addresses, or Stripe identifiers.
- Short-lived abuse-prevention data. We use a one-way hash derived from your IP address to enforce shared request limits. The application database does not retain the raw IP address, and each rate-limit bucket expires within minutes.
- Payment and tax records. Stripe handles your card number, expiry, and CVC; we do not receive or store them. We retain transaction references, amounts, currency, payment, invoice, refund, and dispute status, and the billing or tax-location evidence Stripe returns, so we can provide access, administer purchases and refunds, reconcile the ledger, and meet accounting and tax obligations.
- Refund and abuse-prevention records. We use the purchasing email address, Stripe customer and transaction references, an HMAC-protected payment identity, and prior refund status to apply the voluntary guarantee's one-refund limit and investigate suspected fraud, repeated refund cycling, or coordinated abuse. We do not store the raw card fingerprint used to create that protected identity. These checks do not determine whether a mandatory statutory remedy applies.
- Paid-report usage evidence. For an active paid purchase, we keep aggregate first-use, most-recent-use, and count records for successful Full Match Report views and PDF downloads, linked to the purchase and result. We do not add an IP address, user agent, or page-by-page history to this record. We use it to confirm delivery, support customers, investigate suspected refund abuse, and understand whether paid access is working; it does not determine whether a mandatory statutory remedy applies.
- AI personalization inputs, for paid reports only. If you unlock the Full Match Report, relevant parts of your assessment answers and match results are sent to our AI provider to generate the personalized explanation of your report. This does not happen for the free result.
Why we collect it
Each category above is used only for the purpose described next to it: building and explaining your match, letting you return to your result, processing and reconciling payments, administering refunds and statutory remedies, preventing fraud and abuse, meeting legal obligations, and understanding — in aggregate — whether the assessment and matches are working. We do not sell your personal data, and we do not use your assessment answers to build a profile for advertising.
Who receives or processes data
We rely on a small number of service providers and measurement recipients. Each one receives only the data described for its function:
- Supabase — our database and authentication provider. Stores your assessment answers, account, and result records.
- Stripe — our payment processor. Handles checkout and card data directly; we never receive or store your full card details.
- OpenAI — generates the personalized narrative for paid Full Match Reports, using relevant assessment and match data as input.
- Vercel — hosts the website and application and handles the requests needed to serve it.
- Sentry — our reserved error-tracking provider. It is inactive unless we configure a project DSN; when enabled, it is used only to detect and diagnose application failures. It may receive an error type and message, the affected route, and opaque identifiers such as a result or purchase id — never your assessment answers, personalization content, email address, or any payment credential.
- PostHog — our EU-hosted product and web analytics provider, active only under your measurement choice. In regions requiring prior permission we ask before sending anything and nothing is sent unless you allow it; in specifically reviewed opt-out regions it may run by default with an immediate opt-out below. Declining changes nothing about how the product works for you. When active, the native browser SDK records page locations, page views and leaves, pseudonymous sessions, referring domains, bounded campaign parameters, browser and device context, approximate geographic context, Web Vitals, bounded link or button clicks on nonsensitive public pages, and explicit product events (for example assessment started, chapter completed, result viewed, or a match selected). URL and referrer properties retain their native context, while PostHog's personal-data masking remains enabled for known sensitive parameters; autocapture is excluded from assessment, result, authentication, account, admin, and QA surfaces. We do not send assessment answers, user-entered input values, report personalization content, your email address, your name, Stripe identifiers, access tokens, or payment credentials. Session recording and automatic input capture are disabled. Server-owned purchase, email, delivery, refund, and operational records remain in our first-party database and are not mirrored to PostHog. As with any service contacted directly by a browser, the connection includes transport metadata such as the IP address and browser User-Agent; PostHog uses the connection IP to derive approximate geographic fields and our EU project then discards the raw IP address. If you later withdraw permission, we stop sending immediately and clear what the provider stored in your browser.
- Google Ads — receives the bounded conversion milestones described above. After geography is resolved, we use Advanced Consent Mode with advertising storage and user-data consent denied until you allow them; in that denied state Google receives restricted cookieless measurement signals that can support aggregate conversion modelling, but it cannot use our first-party attribution cookie or server-side purchase attribution. Global Privacy Control is a hard block: the Google tag does not load. In specifically reviewed opt-out regions advertising measurement may be enabled by default, with an immediate opt-out below. For a consented ad-attributed checkout, we retain one bounded click identifier and a random revocation-token hash in a restricted first-party purchase-delivery queue so a confirmed purchase can later be uploaded even if the browser return is blocked. Withdrawing Advertising measurement switches browser signals back to denied storage and suppresses undelivered server attribution linked to that browser token; already delivered conversions require the separate refund/adjustment reconciliation described in our operational controls. Advertising personalization, remarketing, Google Analytics storage, enhanced conversions, and email matching are disabled. Where configured, the official Google Tag Gateway serves eligible tag traffic through our first-party domain without changing your consent choice. Google explains how it uses information from partner sites.
- Meta Ads — receives only explicit, bounded Pixel events when Advertising measurement is effectively allowed: sanitized page views, assessment start and completion, idea selection, email unlock, checkout start, and verified purchase. Meta has no cookieless fallback in our implementation, so its script is not requested in prior-permission regions until you allow it. Withdrawing invokes Meta's consent-revocation command, clears our queued events and accessible Meta attribution cookies, and blocks further application events. The client disables automatic event configuration and does not pass form values or advanced-matching fields. Account-side detailed page/product enrichment, automatic events, automatic advanced matching, and no-code auto tracking are off; traffic permissions accept this dataset's browser events only from
whatbusiness.aiand its subdomains. This release does not create audiences, personalize ads, publish ads, or change campaign budgets. Result URLs are normalized to/result/private; unsafe queries and fragments are removed, and an unsafe browser referrer suppresses the event. Purchase includes only value, currency, and an opaque internal transaction key. Meta explains how it processes information.
We choose processors that offer their own data-protection commitments, and we only share what each one needs to do its job.
How long we keep data
We keep assessment answers and result data for as long as your account or result link is active, so you can return to it. Payment, paid-report usage aggregates, refund, dispute, and related guarantee-verification records are kept only as long as needed for accounting, tax, delivery evidence, fraud prevention, dispute handling, and legal claims. Pseudonymous analytics events are retained only as long as useful for improving the product and are periodically reviewed for deletion. If you ask us to delete your data, we remove what we can while retaining the minimum needed to meet legal or accounting obligations or establish, exercise, or defend legal claims.
Measurement preferences
Optional analytics are currently not decided. You can change this choice at any time. Declining stops PostHog immediately and clears its local browser identity; it does not affect the assessment or your reports.
Advertising measurement is currently not allowed until you choose. It is separate from PostHog and never enables personalized advertising or remarketing. Unless Global Privacy Control blocks the tag, limited cookieless conversion signals may still be sent while optional advertising storage is declined or not yet decided.
Your rights
If you have an account, you can export or delete your stored profile and result data from Your reports. You can also email support@whatbusiness.ai from the address associated with your result or account to request access, correction, export, or deletion. Some transaction or legal records may need to be retained for the reasons described above.
We describe these as practices rather than a claim of compliance with any specific law (for example GDPR or CCPA) — where local law grants you additional or different rights, those rights apply and are not limited by this notice.
Product personalization vs. marketing
Using your assessment answers to personalize your business matches and your Full Match Report is part of delivering the product you asked for, not marketing. It is separate from any marketing communications (such as product updates or tips), which we will only send if you separately opt in, and which you can opt out of at any time.
Contact
Questions about this notice, or requests regarding your data, can be sent to support@whatbusiness.ai.
Data controller: LUCAS VICENTE, UNIPESSOAL LDA. Tax ID: PT519481747.