Skip to content

Cookies on Loupe

Essential cookies keep Loupe working and are always on. With your agreement, Loupe also loads analytics to count visits and see which pages and tools are used. There is no advertising tracking. You can change your choice at any time from cookie settings. Read the cookie policy

Loupe home

Privacy policy

How Loupe collects, uses, shares and protects personal data, how long we keep it, and how you can exercise your rights under the GDPR, the UK GDPR and POPIA.
Draft for legal review

Last reviewed

Text in square brackets is a placeholder to complete before this policy is published.

Last updated [effective date].

This policy explains how Loupe collects, uses, shares and protects personal data when you visit our website, use the free tools and guides, create an account or request a dossier. It is written to meet the EU General Data Protection Regulation (GDPR), the UK GDPR and South Africa's Protection of Personal Information Act (POPIA). If you live somewhere else, such as the United States, Canada or Australia, you may have rights under local law, and we will respond to requests in line with that law.

Who we are

Loupe is operated by [legal entity name], a company registered in [country of registration] under number [registration number], with its registered office at [registered address]. We are the controller of your personal data under the GDPR and the UK GDPR, and the responsible party under POPIA.

  • Privacy contact: [privacy contact email]
  • Information Officer under POPIA: [information officer name and contact details]
  • Representative in the European Union, if required: [representative name and address]
  • Representative in the United Kingdom, if required: [representative name and address]

Personal data we collect

We collect only what we need to run Loupe and to provide the services you ask for.

Your account

  • Your name, email address and password. Passwords are stored in hashed form by our authentication provider, and we cannot see them.
  • If you sign in with Google or LinkedIn, the basic profile details that provider shares with us, such as your name and email address.
  • Your company, role and buyer type, if you give them during onboarding.
  • Your acquisition criteria: regions, sectors, business models, deal size band, whether you want businesses that can be run remotely and your preference for recurring revenue.
  • Things you save or set up: saved valuations, saved searches, your watchlist, checklist progress, alert and notification preferences, and whether you have turned on two-factor authentication.

Dossier requests

  • The listing you ask about, the scope you choose, your specific questions, the date you need the dossier by and how you intend to use it.
  • Your acceptance of our terms: the time, your IP address and the terms version, recorded when you submit a request and again when you accept a quote. When you accept a quote, we also record your browser details.
  • Quotes, your decision on each quote and any reason you give for declining.
  • A record of each time you view or download a dossier, with the time, your IP address, your browser details and the watermark text. Every dossier PDF carries a watermark with your name, email address and the time of download.

Billing and payments

  • The billing details you enter in your account: legal entity name, registration number, VAT or tax number, billing address, billing email and default purchase order reference.
  • Invoices, credit notes and payment records, including amount, date, method and reference.
  • If you pay by card through a payment provider we have switched on, you enter your card details on the provider's own page. We do not receive or store your full card number.

Messages

  • Messages you send and receive in a dossier request's message thread.
  • Messages you send through our contact form, with the name, email address and company you give, and your browser details.

Seller enquiries and the email course

  • If you use "Talk to us confidentially" in the valuation tool's seller mode, the name, email address, phone number, business name, country and message you choose to give us, and the valuation calculation you sent it from.
  • If you join the email course, your email address.
  • For both, a record of your consent: the time, the wording and its version, your IP address and your browser details. We keep the same record when you turn on product news in your account, and when you accept analytics cookies while signed in.

Anonymous valuation calculations

When anyone uses the valuation tool, we store the figures and answers entered and the result, so we can study them in aggregate and improve our benchmarks. A calculation made without an account is stored without a name, email address or IP address. It carries only a random identifier from an essential cookie called loupe_aid, which lasts 30 days. That identifier helps us limit misuse of our free tools and forms, and it lets you save a result to an account you create or sign in to from the same browser. If you send us a seller enquiry about a calculation, we link the enquiry to that calculation so we can see the figures you entered. We do not try to identify the people behind other calculations.

If you save a valuation to your account, that saved copy is linked to you like the rest of your account data.

How our pages and tools are used

We keep simple records of how our own guides and tools are used, such as guide views, tool starts and completions, and how many of those lead to a new account or a dossier request. If you are signed in, these records can be linked to your account. If you are not, they do not include your name, email address or IP address. They carry the identifier from the loupe_aid cookie only if you have agreed to analytics, so we can count how many people who use our guides and tools go on to create an account. Without that agreement, we do not link them to each other or to an account you create later.

Technical and security data

  • Your IP address, browser and device type, and the pages and features you request, which our hosting provider logs to deliver and secure the website.
  • Sign-in events, security alerts and an audit log of sensitive actions.
  • Records of emails we send you and whether they were delivered.
  • Rate limiting data used to stop abuse of sign-up, sign-in, the free tools and our forms. It is based on your IP address, account, email address or the random identifier in the loupe_aid cookie, which we store only in scrambled (hashed) form.

If you agree to analytics cookies, we collect information about how you use Loupe, such as pages viewed, features used, the site that referred you, device and browser type and approximate location. We do not load analytics until you agree. See our cookie policy.

People connected to the businesses we research

Listings and dossiers can include personal data about people who are not Loupe users, such as the owners, directors and officers of a business for sale, and brokers named in listings. We collect this from listing sources, listing alert emails that marketplaces send us, company registries, domain registration records, official sanctions lists, court and insolvency notices, review sites and other public sources. It can include names, roles, directorships and shareholdings, published contact details, public notices and the results of sanctions screening.

We include only what a buyer reasonably needs to assess the business, and we share it only with the client who requested the dossier. Some checks, such as sanctions screening or court notices, can bring up information about legal proceedings or alleged offences. We record that kind of result only where the law allows it and where it matters to the purchase. Analysts may use an AI provider, Anthropic, to help draft a dossier from this material, including the results of sanctions and registry checks. An analyst reviews every draft before it reaches a client. If you are one of these people, you have the rights described below.

Whether you have to give us personal data

You can read our guides and use the free tools without giving us any personal data. To create an account we need your email address, and to request a dossier we need a verified email address and your billing details, because we cannot issue an invoice without them. Everything else, such as your company, role and acquisition criteria, is optional, although criteria make fit scores and alerts more useful.

How we use personal data and our lawful bases

What we do Personal data involved Lawful basis
Provide your account, including sign-in, the full feed, fit scores, saved items, alerts and digests Account data, criteria and saved items Contract
Handle dossier requests, quotes, messages and delivery Request data, messages, access records Contract
Issue invoices and credit notes, record payments and keep accounting records Billing and payment data Contract, and legal obligation for the records tax and company law require
Record your acceptance of our terms and quotes Time, IP address, browser details and terms version Contract, and legitimate interests in being able to show what was agreed
Watermark dossiers and log views and downloads Name, email address, time of access, IP address and browser details Legitimate interests in protecting dossiers from redistribution
Research businesses for dossiers, including registry checks and sanctions screening Data about people connected to a business Legitimate interests of our clients and of Loupe in checking a business before a purchase
Send the email course and other marketing emails Email address and consent record Consent
Respond to seller enquiries Contact details, business details and consent record Consent
Reply to contact form messages Name, email address, company, message and browser details Legitimate interests in answering enquiries
Keep Loupe secure and prevent abuse IP address, device data, the identifier in the loupe_aid cookie, rate limiting data, security and audit logs Legitimate interests in protecting Loupe and its users
Count how our guides and tools are used, and study anonymous valuation calculations to improve our benchmarks Usage records, linked to your account if you are signed in, and valuation calculations with the random identifier described above Legitimate interests in improving Loupe
Count how many visitors who use our guides and tools go on to create an account Usage records carrying the identifier in the loupe_aid cookie Consent, given when you accept analytics cookies
Understand how Loupe is used Analytics data Consent
Meet legal obligations and deal with disputes Any relevant data Legal obligation, and legitimate interests in establishing or defending legal claims

Under POPIA, we rely on the matching justifications: consent, the conclusion or performance of a contract, compliance with a legal obligation and legitimate interests.

Where we rely on legitimate interests, we have weighed our interests against your rights. You can ask us for more detail and you can object, as explained below.

We also send service emails that are part of providing Loupe, such as email verification, quotes, invoices, delivery notices and security alerts. You can choose which alerts and digests you receive in your notification settings.

Automated processing

We use automated tools to classify listings, calculate fit scores and valuation results, and help analysts prepare a first draft of a dossier. None of these makes decisions about you that have legal or similarly significant effects. An analyst reviews and approves every dossier before it is delivered.

Who we share personal data with

We share personal data only where we need to:

  • with the service providers listed below, who process it on our instructions
  • with people who work for us, including analysts, who are bound by confidentiality and see only what they need for their work
  • with our professional advisers, such as accountants, lawyers and insurers
  • with authorities, courts or regulators where the law requires it
  • with a buyer of all or part of our business, under confidentiality, if that ever happens

We do not sell personal data and we do not share it with advertisers. We do not tell a seller or broker that you are interested in their business unless you ask us to.

Service providers (subprocessors)

These providers process personal data for us under written agreements. Google and LinkedIn are listed for completeness: when you choose to sign in with them, they act on their own account rather than for us.

Provider What it does for Loupe Personal data involved When it is used
Vercel Hosts and serves the website IP address, browser details and request logs Always
Supabase Database, sign-in and private file storage Account, request, billing, message and dossier data, and uploaded documents Always
Resend Sends email Name, email address, email content and delivery records Always
Anthropic AI models that help extract details from listings and draft parts of dossiers for analyst review Listing text, the client's questions, intended use and acquisition criteria, analyst notes and their authors' names, results of verification checks (including the names of people screened against sanctions lists and the outcome), and documents included in a dossier draft Always
Stripe Card payments Name, email address, invoice details and the card details you enter with Stripe Only if card payments through Stripe are switched on
Paystack Card payments Name, email address, invoice details and the card details you enter with Paystack Only if card payments through Paystack are switched on
Postmark Receives listing alert emails sent to our collection address Sender and recipient addresses, email headers and content, which can include brokers' names and contact details Only if we receive alert emails through Postmark
[mailbox provider] Hosts the mailbox we read listing alert emails from Sender and recipient addresses, email headers and content, which can include brokers' names and contact details Only if we read alert emails from a mailbox
Plausible Website analytics Visit data such as pages viewed, referrer, browser, device type and country, measured without cookies Only if we use Plausible and you agree to analytics
PostHog Product analytics Pages viewed, features used, a random identifier, device and browser details and approximate location Only if we use PostHog and you agree to analytics
Google Sign in with Google Name, email address and basic profile details Only if you choose to sign in with Google
LinkedIn Sign in with LinkedIn Name, email address and basic profile details Only if you choose to sign in with LinkedIn

Google and LinkedIn run their sign-in services under their own privacy policies. Anthropic does not use data sent through its commercial API to train its models by default.

We will update this list before we start using a new provider that processes personal data.

International transfers

We store our main database and files with Supabase in [hosting region]. Vercel serves the website from locations around the world. Resend stores email records in the United States, Anthropic is based in the United States, and other providers may process data outside your country. Plausible stores analytics data in the European Union. Where a provider lets us choose where data is stored, we choose [preferred region].

When personal data from the UK, the European Economic Area or South Africa goes to a country that does not have equivalent data protection law, we use safeguards the law recognises, such as:

  • standard contractual clauses approved by the European Commission
  • the UK international data transfer agreement or the UK addendum to the standard contractual clauses
  • the EU-US Data Privacy Framework and its UK extension, where the provider is certified
  • for data from South Africa, binding agreements that give protection comparable to POPIA, or another ground POPIA allows

You can ask us for more information about the safeguard used for a particular transfer.

How long we keep personal data

  • Account data, criteria and saved items: while your account is open. After you ask us to delete your account, we delete or anonymise this data within 30 days. If you have a dossier request that is still open, we complete the deletion within 30 days after it closes, for example when we deliver the dossier or the request is cancelled. The next section explains what deletion removes and what we keep.
  • Invoices, credit notes, payment records and the billing details they contain: for the statutory retention period that tax and company law requires, currently [statutory retention period], including after your account is deleted.
  • Dossier requests, quotes, acceptance records, messages and delivered dossiers: for [request retention period] after the request closes, including after your account is deleted, so we can answer questions and deal with any claim.
  • Dossier view and download records: [access log retention period], including after your account is deleted.
  • Our audit log of sensitive actions: we keep it as a security and accounting record, including after your account is deleted. Entries cannot be changed or deleted once written.
  • Sign-in events kept by our authentication provider: [sign-in log retention period].
  • Records of emails we send and whether they were delivered: 24 months.
  • Rate limiting records: 7 days.
  • Listing alert emails we receive from marketplaces, including the stored copy of each message: 12 months.
  • Contact form messages: 24 months after we last handled them.
  • Email course: until you unsubscribe. We then keep your email address on a suppression list so we do not email you again, and keep your consent record for [consent record retention period].
  • Seller enquiries: [seller enquiry retention period] after our last contact with you.
  • Analytics data: [analytics retention period].
  • Usage records of how our guides and tools are used: where a record carries the identifier from the loupe_aid cookie, we remove that identifier after 13 months. Records linked to your account are separated from it when your account is deleted.
  • Anonymous valuation calculations: we keep them for as long as they are useful for benchmarking. They contain no name, email address or IP address, only the random identifier from the loupe_aid cookie, which your browser deletes after 30 days.

Backups are overwritten on a rolling basis, so deleted data can remain in backups for up to [backup retention period] before it is removed.

When you delete your account

You can ask us to delete your account in the privacy section of your account. When we complete the deletion:

  • we delete your profile details, billing details, acquisition criteria, saved searches, watchlist, fit scores, checklist progress, notifications, email preferences and contact form messages, and we stop sending you email
  • we end your email course subscription and remove your name, email address, phone number, business name and message from any seller enquiry
  • valuations you saved are separated from your account and kept without your name, for benchmarking, and records of how you used our guides and tools are separated from your account
  • we keep the records of what you consented to and when, as evidence, without your email address, IP address or browser details
  • we remove your email address from our records of the emails we sent you, except invoice and credit note emails, which we keep as proof that they were sent
  • you can no longer sign in, or open dossiers you bought, so download anything you need before you ask

We keep your dossier requests, quotes, messages and delivered dossiers, the record of the terms you accepted (including the time, your IP address and browser details), records of dossier views and downloads, invoices, credit notes, payment records and our audit log of sensitive actions, for the periods set out above.

How we protect personal data

We use technical and organisational measures suited to the data we hold. These include encryption in transit, access limited by role, mandatory two-factor authentication for staff, private file storage with download links that expire quickly, database security rules that restrict who can read each record, rate limiting and audit logs of sensitive actions.

No system is completely secure. If a security breach affects your personal data, we will report it to the relevant regulator and tell you about it whenever the law that applies requires us to.

Your rights

Depending on where you live and the law that applies, you have the right to:

  • ask whether we hold personal data about you and get a copy of it
  • ask us to correct data that is inaccurate or incomplete
  • ask us to delete your data
  • ask us to restrict how we use your data
  • receive the data you gave us in a machine-readable format, or ask us to send it to another organisation
  • object to our use of your data where we rely on legitimate interests
  • object to direct marketing at any time
  • withdraw consent at any time, without affecting what we did before you withdrew it
  • not be subject to a decision based solely on automated processing that has legal or similarly significant effects
  • complain to a data protection regulator

Some rights have limits. For example, we cannot delete invoices that the law requires us to keep, and we may keep data we need to establish or defend a legal claim. If we cannot do what you ask, we will explain why.

How to exercise your rights

In the privacy section of your account, you can download a copy of your data and request deletion of your account. The download covers your account, requests, invoices and related records. For a complete copy, including internal notes and security logs, email [privacy contact email]. You can update your details in your profile and your acquisition criteria, and choose your emails in your notification settings. Every marketing email includes an unsubscribe link, and you can change your cookie choice at any time using the cookie settings link at the foot of every page.

For anything else, or if you do not have an account, email [privacy contact email]. We may ask you to confirm your identity before we act, for example by replying from the email address on your account.

Requests are free in most cases. We may charge a reasonable fee, or decline to act, only where a request is clearly unfounded or excessive, for example because it is repeated, and we will explain why.

Under the GDPR and the UK GDPR, we respond without undue delay and within one month of receiving your request. Under the UK GDPR, if we need to confirm your identity first, the month starts when we receive that confirmation. If a request is complex or you have made several, we may extend the time by up to two further months, and we will tell you within the first month, with our reasons. POPIA and other laws set their own time limits, and we will meet the limit that applies to your request.

Cookies

We use essential cookies to keep you signed in, keep Loupe secure, limit misuse of our free tools and forms, let you save a valuation you made before signing in and remember your cookie choice. We load analytics, and use the identifier in the loupe_aid cookie to count how many visitors go on to create an account, only after you agree. Our cookie policy lists the cookies we use and explains how to change your choice.

Marketing emails

We send marketing emails, including the "Buying a business in 10 emails" course, only to people who have agreed to receive them. The course uses double opt-in: you confirm your email address before the first email is sent. We record the time you agreed and the wording you agreed to. You can unsubscribe with one click from any marketing email.

Children

Loupe is for people researching the purchase of a business and is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.

Complaints

If you have a concern about how we handle personal data, please contact us first at [privacy contact email] so we can try to put it right. We will acknowledge your complaint within 30 days, look into it without undue delay, keep you informed and tell you the outcome.

You also have the right to complain to a regulator:

  • in South Africa, the Information Regulator
  • in the United Kingdom, the Information Commissioner's Office (ICO)
  • in the European Union or the European Economic Area, the data protection supervisory authority in the country where you live or work, or where you believe the problem occurred

If you live elsewhere, you can contact the data protection or privacy regulator in your country.

Changes to this policy

We may update this policy, for example when we add a service provider or change how Loupe works. The date at the top shows when it last changed. If a change is significant, we will tell you by email or in your account before it takes effect.