Legal · Privacy

Privacy Policy.

This policy explains how Riley Ventures LLC ("data.cool", "we") collects, uses and shares personal information on data.cool and rl.data.cool, and how we handle personal information that may appear inside business datasets offered on the exchange. We do not sell or share our users' personal information for advertising.

Effective October 7, 2026 · Last updated October 7, 2026

1. Who we are and what this covers

Riley Ventures LLC, a Florida limited liability company at 1615 S Congress Ave, Ste 103, Delray Beach, FL 33445, is the controller (or "business") for personal information about our site visitors and the people who use the Platform for buyers (labs), owners (sellers) and brokers. This is covered in sections 2 and 4 to 13.

Datasets that owners list may contain personal information about the owner's employees, customers and correspondents. For that information the owner is the controller and we act on the owner's instructions as its processor or service provider. Section 3 explains how this works.

2. Information we collect about users

  1. Site visitors. Our hosting provider records standard request logs: IP address, user agent, page requested, referrer and time. We do not use analytics, advertising or cross-site tracking tools. If you arrive through a broker's referral link, we store that broker's referral code in a first-party cookie (see the Cookie Policy).
  2. Labs (buyers). Name, work email, organization, role, stated use case, NDA acceptance (typed name, time and IP address), business verification (KYB) results, requests, bids, deposits, license records, API key records and spending caps, and sample download events.
  3. Owners (sellers). Name, work email on the company domain, business name, domain and details, systems and volumes, reserve price, mandate and confirmation records (time and IP address), disputes, and payout details collected by Stripe. If you verify your identity, Stripe Identity verifies your ID document; we receive the verification status, a name-match result and the verified name, and we do not request your date of birth or ID number. If you run Data Proof, you connect Google Workspace or Microsoft 365 read-only and we receive counts, date ranges and the account domain only: never message bodies, subjects, senders, contact names or file titles. The access token is revoked or discarded once the measurement finishes.
  4. Brokers. Name, email, company, listings and the owner contacts you submit, agreed commissions, referral relationships, terms acceptance (version, time and IP address), notification preferences, bond and Broker Pro billing status, and payout status. Stripe Connect collects your identity, tax and bank details directly; we receive the account status, not your full bank or tax numbers.
  5. Verification sources. To vet a listing we look up public information about the business and its domain: registration data (RDAP/WHOIS), DNS records, Internet Archive history, domain popularity and technology lookups. Where enabled, we also check business registries and enrichment services (such as Middesk, OpenCorporates, UK Companies House and People Data Labs), sanctions lists (OpenSanctions), and court records (CourtListener). These checks may include the owner's name.
  6. Communications. Emails and messages you send us, and delivery events for emails we send.

3. Personal information inside datasets

The exchange licenses business records, not lists of people. Before any sample or delivery leaves our systems, the Clean Room removes direct identifiers (such as emails, phone numbers and addresses), replaces names with consistent pseudonyms, screens for privileged and special-category content, and produces a measured residual-risk report. Deal sheets show bucketed figures so that no published combination singles out a business.

  1. Our role. We process personal information in a Dataset only on the owner's documented instructions, to vet, de-identify, sample and deliver it, as the owner's processor (GDPR and UK GDPR) or service provider (CCPA and similar laws). The Data Processing Addendum governs this processing.
  2. The owner's role. The owner is responsible for having a lawful basis to collect the data and to license it, for any notices or consents its employees and customers are owed, and for honoring their rights requests. If you believe your information is in a Dataset, contact the business that holds it; you may also contact us at privacy@data.cool and we will pass your request to the owner and help them respond.
  3. De-identification. We take reasonable measures to ensure licensed data cannot reasonably be linked to an individual, we commit to keeping it in de-identified form and not attempting to re-identify it, and we contractually prohibit buyers from re-identifying it. Pseudonymized data can still be personal data under the GDPR and similar laws, which is why the owner's responsibilities and the DPA continue to apply.
  4. Blind Deals. In a Blind Deal, data.cool licenses the de-identified Dataset in its own name as the owner's agent and licensor of record, solely under the owner's Mandate. This keeps the owner's identity from the buyer; it does not shift the owner's responsibilities above to us.

4. How we use information

  • Run the Platform: accounts, listings, deal sheets, requests, bids, deal rooms and deliveries.
  • Verify mandates, identities, businesses and buyers, and screen for fraud, sanctions and abuse.
  • Process payments, deposits, holdbacks, invoices, subscriptions, commissions and payouts.
  • Send transactional emails and, where you opt in, digests and alerts you can unsubscribe from.
  • Keep records of acceptance, verification and access, and enforce our terms.
  • Publish aggregate, de-identified demand statistics and improve the Platform.
  • Comply with law and respond to lawful requests.

5. Legal bases (EEA, UK and Switzerland)

  • Contract: to provide the Platform and complete deals you take part in.
  • Legitimate interests: to verify listings and counterparties, prevent fraud and circumvention, secure the Platform and improve it. We balance these against your rights; you can object (section 10).
  • Legal obligation: tax, accounting, sanctions and responses to lawful requests.
  • Consent: optional emails and Data Proof connections. You can withdraw consent at any time.

6. How we share information

  • Service providers listed on the Subprocessors page, under contracts that limit their use of the data.
  • Deal counterparties, only as the deal requires. Buyers see anonymized deal sheets. An owner's identity is disclosed to a buyer only if the owner elects disclosure to the buyer's counsel at diligence; in a Blind Deal it is not disclosed. Brokers see their own listings and approved commissions. Owners see their broker's identity.
  • Legal and safety: to comply with law, enforce our terms, or protect rights and safety.
  • Business transfers: in a merger, financing or sale of assets, subject to this policy.

We do not sell personal information about our users, and we do not "share" it for cross-context behavioral advertising, as those terms are defined in the CCPA. We do not use it for targeted advertising or profiling with legal or similarly significant effects.

7. Retention

  • Owner and business identity (domain, owner name, contacts, notes, reserve and vetting detail) on listings that are rejected, withdrawn or expire, and on rejected requests, is purged 90 days after they end. Unconfirmed broker listings expire 60 days after submission. We keep the listing ID, status and dates.
  • Clean Room originals and sample packs are purged on a fixed schedule, currently 30 days after upload.
  • Account data is kept while your account is open and for a reasonable period after it closes.
  • Records of acceptance, payments, invoices and payouts are kept as long as tax, accounting and limitation-period rules require, generally up to seven years.
  • Access logs are kept as long as needed for security and audit.

8. Security

We use safeguards designed for sensitive business data, including:

  • AES-256-GCM encryption at rest for identity fields (owner, business, contact and verification details), with keyed blind indexes so records can be matched without decrypting them;
  • encryption in transit (TLS);
  • database row-level security and least-privilege access for staff and services;
  • named staff accounts, with every reveal of identity recorded in an access log;
  • identity kept out of emails and application logs, and rate limits on public endpoints;
  • signed, sealed Data Proof reports and watermarked, short-lived sample downloads.

No system is perfectly secure, and we cannot guarantee that data will never be accessed without authorization. If a breach affects your personal information, we will notify you and regulators as the law requires.

9. International transfers

We are based in the United States and our providers process data mainly in the United States. When we transfer personal data from the EEA, UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum and Swiss amendments as needed) or another lawful mechanism, as described in the Data Processing Addendum.

10. Your rights

Depending on where you live, you may have the right to know or access the personal information we hold about you, correct it, delete it, receive a portable copy, object to or restrict certain processing, withdraw consent, and opt out of sale, sharing, targeted advertising or significant profiling. We do not engage in those last activities, so there is nothing to opt out of, but you may still ask.

  1. US states. Residents of California (CCPA/CPRA) and other states with privacy laws, such as Colorado, Connecticut, Virginia, Texas, Oregon and Florida, may exercise these rights. Some laws apply only to businesses above revenue or volume thresholds (for example, the Florida Digital Bill of Rights applies mainly to very large companies); we honor the requests below regardless. We will not discriminate against you for exercising your rights. In the past 12 months we collected the categories in section 2 for the purposes in section 4 and disclosed them to the recipients in section 6; we did not sell or share them.
  2. EEA, UK and Switzerland. You have the rights above under the GDPR, UK GDPR and Swiss law, and may complain to your local data protection authority.
  3. How to ask. Email privacy@data.cool from the address on your account. We verify requests by confirming control of that email, and may ask for more if needed. An authorized agent may ask for you with your signed permission. We respond within the time the law requires (45 days under most US state laws, one month under the GDPR). If we decline, you may appeal by replying to our decision; we will answer the appeal within the legal deadline and tell you how to contact your attorney general if you disagree.

11. Do Not Track and Global Privacy Control

We do not track you across other sites, so a Do Not Track signal changes nothing on our sites. We treat a Global Privacy Control signal as a valid request to opt out of sale and sharing for that browser; since we do neither, no further action is needed, and we will keep honoring it if that ever changes.

12. Google and Microsoft data (Data Proof)

data.cool's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data Proof uses read-only, metadata-level scopes; we use the results only to publish coarse volume and history bands on the owner's listing, never to train models, serve ads or for any other purpose, and we do not transfer them except as needed to provide Data Proof or comply with law. The same limits apply to Microsoft Graph data.

13. Children

The Platform is for businesses and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you think we have, contact privacy@data.cool and we will delete it.

14. Changes

We will post updates here with a new date, and notify account holders of material changes by email or on the Platform before they take effect.

Riley Ventures LLC, a Florida limited liability company, 1615 S Congress Ave, Ste 103, Delray Beach, FL 33445. Questions: privacy@data.cool. All legal documents: /legal.