Privacy Policy
How Cleanlist Inc. collects, uses, discloses and protects personal information across the website, the application, the browser extension, the API, and the integrations, and what you can ask us to do with yours.
Last Modified: September 6, 2026
- Who We Are and What This Covers
- Definitions
- Information We Collect, by Relationship
- Business Contact Data
- Browser Extension Data
- HubSpot and Other CRM Integrations
- How We Use Information, and Our Legal Bases
- How We Disclose Information
- Data Sources and Subprocessors
- International Transfers
- Retention and Deletion
- Individual Rights and Choices
- Suppression
- Sale, Sharing and Targeted Advertising
- Cookies and Analytics
- Security
- Artificial Intelligence Features
- Children
- Policy Changes
- Contact and Complaints
Who We Are and What This Covers
This Privacy Policy explains how Cleanlist Inc. (“Cleanlist”, “we”, “us”), a corporation incorporated under the Canada Business Corporations Act, corporation number 1507534-3, with its business address at 240 Richmond St W, Toronto, Ontario M5V 2C5, Canada, collects, uses, discloses and protects personal information.
This policy covers all of the following, and there is no surface of Cleanlist that falls outside it:
- cleanlist.ai and any other website we operate
- the Cleanlist application
- the Cleanlist browser extension
- the Cleanlist API and MCP functionality
- integrations with HubSpot and other third party services you connect
- business contact data we process about individuals in their professional capacity
- customer support, sales and marketing communications
Not a customer? If your business contact details appear in Cleanlist because one of our customers looked you up, the sections on Business Contact Data, Individual Rights and Suppression are the ones that apply to you. You do not need a Cleanlist account to exercise any of those rights.
Definitions
These terms carry the same meaning here and in our Terms of Service.
- Account Data. Information about customers and authorised users, including identity, authentication, organisation, billing, support and account administration information.
- Customer Data. Information a customer or authorised user submits to, imports into, or directs Cleanlist to process through the services.
- HubSpot Customer Data. Customer Data accessed from or written to a HubSpot account through a customer authorised integration.
- Business Contact Data. Professional information about an individual acting in a business capacity: name, job title, employer, business email address, business telephone number, company information and professional profile URL.
- Extension Data. The webpage URL, the user action, the lookup identifier, the result and diagnostic data processed through the browser extension.
- Integration Data. OAuth authorisation details, account identifiers, scopes, field mappings, sync configuration, event logs and Customer Data processed through an integration.
- Usage Data. Device, browser, IP address, authentication, feature use, event and diagnostic information collected when a person uses the services.
Information We Collect, by Relationship
What we hold about you depends on your relationship with Cleanlist. We set it out that way deliberately, so that website analytics, a customer’s CRM records and provider sourced business contact data are not blended together into a single undifferentiated list.
If you visit our website
Identifiers, device and browser information, cookie data, marketing preferences, and anything you type into a form or send us. Sources are you, your browser, and the analytics providers named in Cookies and Analytics. We use it to operate the site, answer you, measure use, keep the service secure, and market to you where that is permitted.
If you are a customer or an authorised user
Account, organisation, billing, authentication, support and usage data. Sources are you, your organisation, our payment provider and our own systems. We use it to provide the service under our contract with you, administer the account, bill you, support you and keep the service secure.
If you are a record inside a customer’s workspace
Customer Data and the enrichment inputs and outputs associated with it. Sources are the customer, any CRM they have connected, and our contracted data providers. We process it to perform the workflow the customer asked for, on the customer’s instructions.
If you are a business contact
Professional identity, employment, company, work email address, work telephone number and professional profile URL. Sources are our contracted business data providers and identifiers supplied by our customers. See Business Contact Data, which is the section written for you.
If you use the browser extension
Business Contact Data
This section applies if you are not a Cleanlist customer or website visitor, but your business contact details appear in Cleanlist because one of our customers looked you up. It takes precedence over the rest of this policy for that data.
Where it comes from
We do not collect this information from you directly. We do not operate a web crawler, and we do not build our own contact database by copying web pages. Cleanlist obtains Business Contact Data from contracted business-to-business data providers.
We require those providers to represent that they hold the rights and lawful bases needed to supply the data, that they give any legally required notice, that they support individual rights, and that they honour applicable suppression requirements. That does not end our own responsibility. Cleanlist independently evaluates its purposes and its own legal bases for processing the data, and operates its own rights and suppression process, described below.
Our contracted providers, and the subprocessors that help us run the service, are published and maintained at cleanlist.ai/data-sources. You can also request the current list at any time by writing to support@cleanlist.ai.
What we hold
- Name and job title
- Employer name, company domain and company firmographics
- Business email address and business telephone number
- Professional profile URL
We hold this data about you in a professional capacity only. We do not knowingly collect or store special category data, government identifiers, financial account details, or health information about these individuals.
What it is not
The presence of your work email address in Cleanlist does not mean you agreed to hear from anyone. It is not evidence of consent to marketing, telephone or automated communications. Our customers are contractually required to determine their own lawful basis before contacting you, and to honour your objections, unsubscribe requests and do-not-call registrations. We do not use Business Contact Data, and we require that our customers do not use it, for consumer credit, insurance, housing, employment, tenancy or other decisions about your eligibility for something.
Browser Extension Data
When a customer asks for a lookup through the Cleanlist browser extension, Cleanlist may receive the URL of the webpage the customer selected, as an identifier, together with the action the customer took and diagnostic data about the request.
Cleanlist uses that identifier to request Business Contact Data from its contracted data providers, in the same way it would for a URL typed into the application or supplied in a CSV. The result is assembled from what those providers hold. A lookup is always initiated by the customer: the extension does not perform lookups on its own.
The Chrome permissions the extension requests, and the reason for each one, are disclosed in the Chrome Web Store listing. That listing, this policy and the extension manifest are maintained so that they agree with one another.
HubSpot and Other CRM Integrations
When you connect HubSpot or another third party service, you authorise Cleanlist through OAuth to access the account, objects, fields and actions shown to you during the connection process. We request only the permissions required for the features you have selected.
We use Integration Data and Customer Data only to provide, secure, maintain and support the integration you asked for, to comply with law, and to enforce our agreement with you. We do not sell HubSpot Customer Data and we do not use it for Cleanlist’s own marketing.
Business Contact Data returned through an enrichment workflow does not establish that an individual consented to receive marketing communications. Cleanlist does not treat enrichment as marketing consent, and does not change a HubSpot contact’s subscription status, lawful basis or communication consent status because a record was enriched. Deciding whether and how you may contact an individual remains yours.
You can revoke our access at any time by disconnecting the integration, in Cleanlist or in HubSpot. After disconnection we stop new access, and we delete or deidentify Integration Data and HubSpot Customer Data on the basis set out in Retention and Deletion, except where we must keep something to comply with law or to resolve a billing or security matter.
How We Use Information, and Our Legal Bases
We match each purpose to a category of information and to a basis, rather than claiming every purpose for every kind of data.
- To provide the service you asked for. Account Data, Customer Data, Extension Data and Integration Data, on the basis of our contract with you and your instructions.
- For B2B contact discovery and enrichment. Business Contact Data and customer supplied identifiers. In the European Economic Area and the United Kingdom we rely on our legitimate interests under Article 6(1)(f), being the legitimate interest of businesses in reaching other businesses through professional contact details, balanced against the interests and rights of the individual and safeguarded by the notice, objection, deletion and suppression rights in this policy. Where local law requires consent, we rely on consent obtained by the source provider.
- For security and fraud prevention. Account, usage, payment, authentication and event data, on the basis of our legitimate interests, our contract, and our legal obligations.
- For billing and accounting. Account and transaction data, on the basis of our contract and our legal obligations.
- For product analytics and improvement. Usage Data, and aggregated or deidentified data, on the basis of our legitimate interests, or consent where required. Customer Data and Business Contact Data are separately restricted, see Artificial Intelligence Features.
- To market to customers and prospects. Account, enquiry and marketing preference data, on the basis of consent or legitimate interests where permitted, with a right to opt out at any time.
- To operate rights and suppression. Request, verification, source and the minimum suppression identifiers, on the basis of our legal obligations and our legitimate interest in making sure a record you asked us to remove does not come back.
An opt out is a safeguard we provide. It is not, and we do not present it as, evidence that you consented in the first place.
How We Disclose Information
We disclose information to the following categories of recipient, in each case under contract and only for the purpose named:
- Business data providers, to resolve a lookup requested by a customer
- Cloud hosting and infrastructure providers, to run the service
- Analytics providers, to measure how the service is used
- Payment providers, to take payment and prevent payment fraud
- Communication and support providers, to answer you
- AI service providers, only as described in Artificial Intelligence Features
- CRM and sales tools you have connected, on your instruction
- Professional advisers, acquirers and authorities, where the law requires it or a corporate transaction makes it necessary
We use account, payment and authentication data to prevent fraud against accounts and payments. We do not supply Business Contact Data for credit risk assessment, and we do not permit it to be used for decisions about an individual’s eligibility for credit, insurance, housing, employment or education.
Data Sources and Subprocessors
Our contracted data providers and our subprocessors are published at cleanlist.ai/data-sources, with the purpose of each. We reconcile that page against the providers and vendors actually in production every quarter, and whenever one is added or removed. If you are a customer with a data processing agreement in place, we give the notice of subprocessor changes that agreement requires.
International Transfers
Cleanlist is based in Canada and uses service providers in Canada, the United States and the European Economic Area. Where we transfer personal information out of the European Economic Area or the United Kingdom, we rely on an applicable transfer mechanism, which for most transfers means the European Commission’s Standard Contractual Clauses together with the United Kingdom Addendum, or the adequacy decision covering transfers to Canada where it applies.
We do not treat your use of the website as consent to an international transfer. You can request a copy of the safeguards that apply to a specific transfer by writing to support@cleanlist.ai.
Retention and Deletion
We keep each category of information for as long as the purpose that justifies holding it still applies, and then we delete or deidentify it. The trigger for each category is set out below. Where a fixed period applies under tax, accounting or limitation law, that period governs.
- HubSpot Customer Data and other Integration Data. Deleted or deidentified after you disconnect the integration, terminate your account, or instruct us to delete it, subject only to the legal, security and backup exceptions below.
- OAuth tokens. Revoked and deleted on disconnection or on authorisation failure.
- Integration configuration and field maps. Deleted after disconnection or termination, once any open support or billing matter is closed.
- Sync and audit logs. Kept in minimised form for the period we need them for security, troubleshooting and dispute resolution, then aged out on a schedule.
- Business Contact Data. Deleted or refreshed when a provider withdraws it, when you ask us to delete it, when you object, or when it is too old to be useful.
- Suppression identifiers. Kept for as long as necessary to honour your objection, and no longer. See Suppression.
- Account and billing data. Kept for the term of the account and afterwards for the period required by tax, accounting, fraud and limitation rules.
- Support communications. Kept after a matter is closed for the period we need to handle a related question or dispute.
- Backups. Expire automatically on our backup cycle. Access to backups is restricted to restoration and security work, and a record deleted from production is not reintroduced from a backup.
- AI prompts and outputs. Kept for the feature history period disclosed for that feature, and excluded from the training uses described in Artificial Intelligence Features.
Individual Rights and Choices
Depending on where you live, you have some or all of the following rights, and we honour all of them regardless of whether you are a customer: to access the information we hold about you, to correct it, to delete it, to object to our processing, to ask about the source a record came from, to opt out of any sale or sharing, and to appeal a decision we make on your request.
Write to support@cleanlist.ai. We will acknowledge your request, verify your identity using the least information that will do the job, and respond within the deadline the law of your jurisdiction sets. Where the law allows an extension and we need one, we will tell you before the original deadline expires and explain why. You may use an authorised agent where your local law provides for one.
These are four separate actions and we do not confuse them: deleting your Cleanlist account, deleting a record a customer controls inside their own workspace, deleting Business Contact Data we hold about someone who is not a customer, and retaining a suppression identifier so that a deleted record is not recreated. You do not have to delete an account to have your business contact details removed, and you never needed one in the first place.
One limit we want to be straightforward about. When a customer exports data into their own systems, that copy is under their control, not ours. We will tell them of your request where we are required to, and our agreement with them requires them to honour it, but we cannot delete a record from a system we do not operate.
Suppression
When we delete Business Contact Data or honour an objection, we keep only the minimum identifier needed to stop the record being reintroduced. That suppression record is used for that one purpose and for nothing else. It is never used to contact you, to build a profile, or to enrich anything.
We also record the request so that a later refresh from a provider does not recreate the record you asked us to remove, and we direct the relevant providers to honour your request where our contract with them or the law requires it. Suppression is applied across production, our caches, provider refreshes and future imports.
Sale, Sharing and Targeted Advertising
Some United States state privacy laws define “sale” and “sharing” broadly enough to capture making business contact information available to a customer, whether or not money changes hands for that record. Rather than assert a conclusion, we give you the right directly: you may opt out of any sale or sharing of your personal information, and of targeted advertising, by writing to support@cleanlist.ai. We honour Global Privacy Control signals where they apply.
We do not sell HubSpot Customer Data or other Customer Data a customer submits to us, in any sense of the word.
Cookies and Analytics
We use cookies and similar technologies that are strictly necessary to operate the site and keep it secure, and separately, analytics tools that help us understand how the site is used. Where consent is required in your jurisdiction, non-essential tools do not load until you give it, and you can change your choice at any time.
Most browsers let you refuse or delete cookies through their own settings. Refusing non-essential cookies does not stop you using the site.
Security
We use administrative, technical and physical measures appropriate to the risk, including encryption in transit, access controls and least-privilege access to production systems, authentication controls, logging, and vendor security review. No system is perfectly secure, and we do not claim otherwise. If you believe you have found a vulnerability, or you think your account has been compromised, write to support@cleanlist.ai.
Artificial Intelligence Features
Cleanlist does not use HubSpot Customer Data or Business Contact Data to train general purpose or third party artificial intelligence models.
Where an AI service provider processes information in order to deliver a feature a customer has asked for, it may process that information only for that purpose, under contractual confidentiality, security, retention and use restrictions that prohibit it from training its own models on the information.
We may use aggregated or deidentified service metrics to maintain and improve the services, where the information cannot reasonably be used to identify a person or a customer.
Children
The services are business tools, intended for use by organisations and the people who work for them. They are not directed at children, and we do not knowingly collect personal information from anyone under 16. Business Contact Data is professional information about people acting in a business capacity. If you believe we hold information about a child, write to support@cleanlist.ai and we will delete it.
Policy Changes
We update this policy when our practices change. The Last Modified date at the top is the date the current version was published, and we do not backdate it. Where a change materially affects your rights, we will give notice through the service or by email before it takes effect.
Contact and Complaints
Cleanlist Inc., 240 Richmond St W, Toronto, Ontario M5V 2C5, Canada.
- Privacy requests, security reports and everything else: support@cleanlist.ai
If you are not satisfied with our response you may appeal by replying to our decision and asking for a review. You also have the right to complain to your data protection authority: in Canada the Office of the Privacy Commissioner, in the United Kingdom the Information Commissioner’s Office, and in the European Economic Area your national supervisory authority.
Ask us anything in here.
Write to the privacy address and we will acknowledge your request and answer within the deadline your jurisdiction sets. You do not need a Cleanlist account.
If your business contact details appear in Cleanlist and you are not a customer, the sections on business contact data, your rights and suppression are the ones written for you.