Privacy Policy

Draft. This page has been written by us and has not yet been reviewed by a lawyer. We have tried to describe what the code actually does rather than what a policy usually says. Where we are unsure, we have written that down instead of guessing.

Last updated: 8 August 2026. This version corrects the one dated 12 July 2026, which said lead records describe businesses and not private individuals. That was not true, and the section on lead data explains why.

Momentum Minds LLC, a New Mexico (USA) limited liability company doing business as Findkeep.io, operates Findkeep at leads.momentumminds.net. Contact for anything on this page: privacy@momentumminds.net.

We have two different roles, and they are not the same

Most privacy policies can get away with one. This product cannot, because it holds two kinds of personal data for two different reasons.

The line between the two is not perfectly clean, and we would rather say so. You decide who to search for and what to do with the result; we decide which fields the search asks Google for, and how long a row lives by default. We treat you as the controller of your pipeline and ourselves as your processor, and confirming that split is one of the questions we have put to counsel.

Account data: what we hold as controller

We do not profile you, we do not advertise to you, we do not sell anything to anyone, and there is no analytics product anywhere in this application.

Lead data: what we hold as your processor

When you run a search, we ask the Google Places API for businesses matching your query and save each result to your account: the trading name, the phone number, the street address, the town, the business type, a link to the Google Maps listing, Google's own place identifier, and whether the business appears to have a website, only a social page, or nothing. To that we add whatever you record yourself — the pipeline stage, your notes, call outcomes, follow-up dates. Imported CSV rows work the same way. Findkeep does not enrich this data from any other source.

Some of these are people

The previous version of this page said lead records "describe businesses, not private individuals". That was wrong, and it was wrong in an obvious way: a great many Danish businesses are sole traders — a one-person firm trading under a name like NyFarve v/Jensen. A sole trader is a natural person. The trading name identifies them, the business number is often their own mobile, and the business address is sometimes their home. So yes: lead records in Findkeep can be, and frequently are, personal data about identifiable people who never heard of us.

The lawful basis, and the balancing test behind it

Where a lead is a natural person, the basis relied on is legitimate interests, Art. 6(1)(f) — our customer's interest in offering their services to businesses that may want them, and ours in providing the tool. That basis only works if it survives a balancing test, so here is ours, in the three parts it is normally done in.

The safeguards we rely on are: this page and the data request page as public notice; an absolute right to object to direct marketing, which we honour without weighing anything against it; a contractual duty on every customer to act on a removal request we forward to them; and a hard limit on what we collect. A fuller written assessment is being prepared for review — this section is a summary of it, not a substitute.

Article 14: what we owe a business we have never met

Article 14 of the GDPR says that when personal data is obtained from somewhere other than the person themselves, they must be told: who holds it, what it is, why, where it came from, how long it is kept, and what they can do about it. That is what this page is. All of it applies to lead records, and the source is always the same one: the Google Places API.

We cannot send that notice to each business individually. In most cases we hold no email address for them at all — only a telephone number — and the records sit in our customers' workspaces rather than ours. Art. 14(5)(b) allows the information to be made publicly available instead where individual notice would involve disproportionate effort, and this page plus the data request page are how we do that. Whether that is sufficient in our particular case is one of the questions we have put to counsel, and we will change this if the answer is no.

If you have found this page because someone called you about your business, the data request page is written for you. In short: you can ask what is held, ask for it to be corrected, ask for it to be erased, and object. An objection to direct marketing under Art. 21(2) is absolute — there is nothing for us to weigh, and we act on it.

Cookies and what is stored in your browser

Findkeep sets one cookie. It is called findkeep_session, it holds a signed session token and nothing else, and it carries HttpOnly, Secure and SameSite=Lax. If you tick "Remember me" it lasts up to 30 days; if you do not, it disappears when you close the browser. Signing out deletes it.

That cookie is strictly necessary to provide a service you asked for — without it there is no way to stay signed in. Under the ePrivacy rules (in Denmark, cookiebekendtgørelsen) strictly necessary cookies do not require consent, which is why Findkeep shows no cookie consent banner. There are no analytics cookies, no advertising cookies and no third-party cookies, because there is no analytics or advertising code in the product at all. We do count a few things about accounts on our own server — see “Product measurements” in the retention list below — but nothing in your browser reports to us or to anyone else, and no third party is involved.

Three preferences are kept in your browser's localStorage rather than in a cookie: your light/dark theme choice, your board filter, and which pipeline columns you have collapsed. They never leave your browser and are never sent to us. Clearing site data removes them.

If we later switch on the Cloudflare Turnstile anti-bot check, two pages will load a script from Cloudflare: the signup form and the form on the data request page. Both are pages you can reach without signing in, and it appears on none of the pages a customer uses day to day. It is not switched on today, and this page will say so when it is.

Who else touches the data

Google (the Places API), Stripe (payments) and our hosting provider are the three third parties involved today; an email provider is configured but not yet switched on. Each one, what it receives, where it processes and on what legal footing is set out on the sub-processor page, which also explains how we announce changes to that list.

International transfers

Momentum Minds LLC is a US company and Findkeep runs on a server in the United States. So if you are in the EU or the EEA, your account data and your leads are transferred to the United States as soon as you use the product, and Google and Stripe process in the United States too.

For transfers to us, the Data Processing Agreement incorporates the European Commission's Standard Contractual Clauses. For transfers onward to Google and Stripe, we rely on the transfer mechanism in each provider's own data processing terms; the sub-processor page names which. We have not appointed an Art. 27 representative in the EU yet. We are working on it, and until it is done, write to us directly at the address above.

How long we keep things, and the backups

Most of what Findkeep holds is kept until you delete it, because it is the thing you are paying us to keep. Six kinds of record expire on a timer instead, and these six are the whole list. Five of them are cleared by a housekeeping job inside the application that runs every six hours and deletes nothing else; the sixth is the nightly backup rotation.

Two things are deliberately not on a timer, and it is more honest to name them than to leave the list looking complete:

There is also the correspondence about data requests itself. If you write to us, or use the form on the data request page, what you send — your reply address, the business name and phone number you give us, and your message — is kept in the mailbox that receives it and written to the server's log so that a request is not lost if an email fails to send. We have not yet set a retention period for the server log; that is a setting on the host rather than in this application, and it is on the list of things to fix before this page stops calling itself a draft.

What deleting your account actually removes

This depends on whether you are the owner of the account or a member of somebody else's, because the two do quite different things:

A lapsed subscription never causes deletion.

The backups are the honest exception. We take one compressed snapshot of the whole database every night and keep the last 14 of them. A record you deleted therefore continues to exist in backup copies for up to 14 more nights before the last copy holding it is rotated out and destroyed. Those backups are only ever used to recover from a disaster; nobody reads them to answer a question about a customer, and if we ever have to restore from one we re-apply any deletion made since it was taken. Saying "deleted immediately" without this paragraph was not accurate, which is why the paragraph is here.

Five other things outlive account deletion, and you should know about all of them:

Security

Passwords are hashed with Argon2. Any Google API key you add is encrypted at rest. Everything is served over HTTPS; the session cookie is HttpOnly, Secure and SameSite=Lax; the app sends a Content-Security-Policy and verifies a CSRF header on every state-changing request. The database file itself sits on the server's disk and is not separately encrypted — see the security annex of the DPA for the full list of measures, including what we do not do.

Your rights

If you are a Findkeep customer, you may ask us for access to your personal data, correction, erasure, restriction and portability, and you may object to processing based on legitimate interests. Write to privacy@momentumminds.net and we will answer within one month.

Portability does not need a request. Two exports are built into the product and neither one involves asking us:

Both stay available when a subscription has lapsed and when an account is on hold, which is deliberate: every message this product sends about a payment problem ends by saying your data is safe and always exportable, and a customer who cannot get their records out is a customer being held by them.

If you are in someone's pipeline rather than a customer, your rights are the same and the route is different — see the data request page.

You can complain to a supervisory authority. In Denmark that is Datatilsynet (datatilsynet.dk); if you are elsewhere in the EU or EEA, it is the authority for your own country.

Changes to this policy

We will update this page when the product changes, and the date at the top says when it last happened. If a change materially affects customers, we will email account owners before it takes effect.

← Back to Findkeep