Dolphwin Privacy Policy
Beta · Last updated October 3, 2026
SparkIntell Inc., doing business as Dolphwin (“we”), provides a business research service about companies. This Policy explains what personal information we handle, why, who helps us handle it, how long we keep it, and the choices and rights available to you.
Contact: privacy@dolphwin.com · SparkIntell Inc., Texas (postal address on request)
Part A — Customers, users and website visitors
1. Information we collect
- Sign-up and account information: organization name, website, your name, work email address, the purpose you certify for using Dolphwin and any detail you add, the exact certification text you agreed to with its version and time, and the IP address you signed up from (used to limit sign-ups per address and to keep a record of the agreement). We note whether you confirmed your email address, your plan, and whether a person at Dolphwin verified your business.
- Keys and sign-in: your API key and the per-browser keys created when you sign in with an emailed sign-in link. We keep only a one-way hash of each key (and the last four characters, so you can recognise it), and a one-way hash of each sign-in link, with the email address it was sent to and when it was used.
- What you look up: the company names and states you search, the companies you open, the answers we give (“Receipts”, which include your query), lists you upload for batch checks and their results, companies on your watchlist and the changes we report on them, feedback you send (confirmations, corrections, notes), requests for a hand check of a company (with the email address the answer goes to), and ownership-statement requests you send to a company (with the company email address you give us and your note). We count lookups per account and per day to apply allowances.
- Visitors without an account (clickwrap): before the first answer, you agree to our Terms. We record a random visitor id that your browser keeps, which version of the Terms you agreed to, when, the text you agreed to, and a one-way hashed fingerprint of your IP address and browser user-agent (not the address or user-agent itself).
- Technical information: to apply speed limits and stop abuse, the server holds your IP address in memory for about a minute. Our hosting provider’s logs record requests (including IP address, time and the page requested) and errors.
- Payment information: handled by our payment processor, Stripe. Stripe collects your card and billing details on its own checkout page; we never see or store your card number. We keep the Stripe customer and subscription identifiers, your plan and renewal date, and records of payments received.
- Communications: support requests and correspondence sent to our addresses.
2. What we store in your browser
We do not use advertising or analytics cookies or trackers. The site
uses your browser’s local storage (localStorage) for:
- your Dolphwin key, so you stay signed in on that browser
(
dolphwin_key); - a random visitor id for the clickwrap record above
(
dolphwin_vid) and whether you agreed to the current Terms (dolphwin_terms); and - the page to return to after signing up (
dolphwin_return).
You can clear these at any time in your browser settings; you will then be signed out and asked to agree to the Terms again.
3. How we use it
- To provide, secure and support the Service. This includes producing reproducible Receipts and keeping the audit ledger that ties each Receipt to its sources.
- To send the emails the Service relies on: confirming your email address, sign-in links, nightly watchlist digests, notices that a company signed a statement you asked for, answers to hand checks, and service notices.
- To review sign-ups and protect the Service: a person at Dolphwin can see an account’s searches when checking a business or investigating abuse, and we may suspend accounts that break our Acceptable Use Policy.
- To improve the Service. Feedback is used, without identifying you to others, to improve entity matching and parent detection for all users.
- To bill, communicate about the Service, enforce our Terms and Acceptable Use Policy, and meet legal obligations.
We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not disclose what a customer has researched to any other customer.
4. Who we share it with
We share information only with:
- service providers acting on our behalf, under contract:
- Fly.io (hosting: our server, its disk and its logs, in the United States);
- Resend (sending email: the recipient address, subject and text of each email we send);
- Stripe (payments and billing);
- Cloudflare, if enabled (network protection in front of the site, and forwarding of mail sent to our addresses); and
- a cloud storage provider for off-site copies of our backups, when configured;
- professional advisers;
- authorities, where the law requires it; and
- a successor in a merger or acquisition, subject to this Policy.
When you look up a company, our server asks the public sources listed in section 7 about that company. The company name you typed is sent to those sources; nothing that identifies you is.
5. Retention
- Receipts (each answer, including the query that produced it) and the saved source copies behind them: kept indefinitely, because customers rely on them as audit evidence and may re-open them years later, unless you ask us to delete your query history (subject to legal holds and our need to keep proof of statements already shared with others).
- Account data, lookup counts, watchlists, batch results and hand-check requests: for the life of the account, and up to 24 months after it closes, then deleted or de-identified.
- Sign-in links expire after a short time and cannot be reused; their records are kept with the account.
- Clickwrap records (visitor id, Terms version, time, hashed fingerprints): kept as proof of agreement for as long as claims could arise.
- Feedback: indefinitely, in de-identified form. Your link to it is removed when your account is deleted.
- Payment records: as long as tax and accounting law requires (Stripe keeps its own records under its own policy).
- Backups: a copy of our database is made every night. We keep the last 14 nightly copies on our server and, when off-site backup is configured, further copies with a cloud storage provider. A deletion reaches the backups as they age out; we do not restore deleted data except to recover from a failure.
- Server logs at our hosting provider are kept for the provider’s standard log period.
6. Security
We use encryption in transit (HTTPS), store keys and sign-in links only as one-way hashes, restrict administrative access, keep secrets out of our code, and keep backups. No system is perfectly secure; if a breach affects your personal information we will notify you as the law requires.
Part B — Individuals named in public records and in ownership statements
7. What Dolphwin retrieves
Dolphwin retrieves records from official public sources about legal entities:
- SEC EDGAR filings; the GLEIF LEI database; SAM.gov entity registrations; USAspending.gov award records; and the OFAC sanctions lists published by the U.S. Department of the Treasury (companies only: we do not load entries for individuals);
- the Texas Comptroller of Public Accounts (open data, and its franchise-tax officer and director records through the Comptroller’s API); Florida Division of Corporations bulk data files; Virginia State Corporation Commission files, via the Virginia Open Data Portal; the Connecticut Secretary of the State; and open-data portals of New York, Pennsylvania, Colorado, Oregon, the District of Columbia and Delaware; and
- business-license and trade-name open data published by cities (for example New York, Los Angeles, San Francisco and Seattle).
These records sometimes name individuals, for example directors and officers in filings, officers and managers in state records, registered agents, and signatories. We store an exact copy of each retrieved record (an “echo”) so that every Receipt can be checked against its source. Before storing, we remove officers’ addresses from the Texas officer records. From the Florida files we keep officer names and titles and a one-way hash of company addresses (used only to count companies sharing an address), not the addresses themselves. From the Virginia files we keep officer names and titles only, never their addresses.
8. Ownership statements
When a customer asks a company for an ownership statement, we email the address the customer gave us with a link (and record when it was opened). If the company signs, we keep the statement: the signer’s name, title and email address, the IP address it was signed from (kept as evidence of the signature and never shown to customers), the names, roles and ownership bands (for example 25–50%) of owners, any parent company, and one person who controls the company. We do not ask for dates of birth, ID numbers or home addresses. The signer chooses who can see the statement and can change that or withdraw it at any time with the private link we email them. Anyone who asks can stop all future statement-request emails to their address.
9. What we do and do not do with individuals’ names
- We do not offer search by person, person profiles, or lists of individuals.
- We do not publish home addresses or personal contact details. Where a state record lists what appears to be a residential address, we do not display it.
- A person’s name appears in the Service only inside the public record, or the company’s own signed statement, that supports a finding about a company. Watchlist digests can report that a company’s listed officers or owners changed.
- We do not combine public-record data with non-public data about individuals.
10. Your choices and requests
If you are named in a record that Dolphwin displays, you can:
- ask us to correct how we present it (for example if we attributed a record to the wrong entity);
- ask us to suppress your name, or any personal detail, from display; and
- make any request available under the Daniel’s Law or address-confidentiality provisions described in our Corrections, Disputes & Takedown Policy.
We cannot change the underlying government record. You can correct it with the agency that holds it.
Part C — Your privacy rights
11. U.S. state privacy rights
Depending on where you live, you may have the right to:
- know or access the personal information we hold about you;
- correct it;
- delete it;
- obtain a portable copy; and
- opt out of sale, sharing or targeted advertising. We do not sell personal information, share it for cross-context advertising, or use it for targeted advertising.
You also have the right not to be discriminated against for exercising these rights.
To make a request, email privacy@dolphwin.com. We will verify your request in a way that fits its nature, and respond within the time required by law, generally 45 days. Authorized agents may submit requests with proof of authorization. If we deny your request, you may appeal by replying to our decision.
Data broker laws. Dolphwin’s product is about companies, and we do not sell individuals’ personal information. If a state’s data broker law applies to us, we will register and honor deletion requests made through that state’s process, including California’s Delete Request and Opt-out Platform (DROP).
12. Children
The Service is for businesses and is not directed to children under 16. We do not knowingly collect children’s personal information.
13. International users
The Service is operated from the United States, and your information is stored there. We currently serve customers in the United States.
14. Changes
We will post updates here and, for material changes, notify account holders by email.