StellaBasestellabaseTermsPrivacyAcceptable useDMCADPASecurityAccessibilitySubprocessors

Data Processing Addendum

Effective October 7, 2026 · Version 2026-10-07.2

This Addendum is part of the Terms of Service between StellaBase (“we”) and each business that uses StellaBase (“you”). It covers personal information about your customers and leads (“Customer Data”) that we process to run your site and tools. It applies automatically; there’s nothing to sign.

1. Roles

You decide why and how Customer Data is used and are its controller (a “business” under the CCPA). We process it only on your behalf as your processor (a “service provider” or “processor” under U.S. state privacy laws), following your instructions given through the product and these Terms.

2. What we won’t do

  • Sell or share Customer Data, or use it for cross-context behavioral advertising.
  • Use it for our own purposes, or combine it with data from other businesses, except as the law allows a service provider to (for example security, fraud prevention and fixing problems).
  • Keep it after you delete it or close your account, beyond the periods in our Privacy Policy.

3. Your responsibilities

You give your customers the notices and get the consents the law requires (for example for marketing email and texts), have a lawful reason to collect what your forms ask for, and don’t ask for sensitive information you don’t need, such as Social Security or full card numbers.

4. Security

We use reasonable technical and organizational measures for the risk, including encryption in transit, encryption of sign-in and connection tokens at rest, separation of each business’s data in the application, least-privilege access, rate limits on public forms, and logging of staff access to accounts. Our staff only open a business’s dashboard to support it, read-only unless the owner grants edit access, and every visit shows in that business’s activity log.

5. Subprocessors

You authorize the subprocessors below. We bind each to data-protection terms at least as protective as these, and remain responsible for them. We’ll update this list before adding a new one.

  • Vercel: hosting, file and photo storage, and domain registration
  • Neon: database
  • Stripe: card and bank payments for businesses and their customers, and our own subscriptions
  • Postmark: email delivery: sign-in links, receipts, alerts, and businesses' customer and marketing emails
  • Google: sign in with Google, sending from a business's connected Gmail, and Gemini for optional AI writing
  • Microsoft: sending from a business's connected Outlook account
  • Anthropic: Claude, for optional AI features
  • Meta: importing leads from a business's own Facebook lead ads, when connected
  • RentCast: home value estimates on real estate sites
  • MLS Grid: listing data for real estate agents who connect their MLS
  • Apple, Google and Mozilla push services: phone and browser alerts a business owner turns on
  • OpenStreetMap: map tiles and address lookups on sites that show a map
  • YouTube and Vimeo: videos a business chooses to embed on its site

6. Security incidents

If we confirm a breach of security that leads to unauthorized access to your Customer Data, we’ll notify you without undue delay, and within 72 hours of confirming it where possible, with what we know, what we’re doing, and the information you need to meet your own obligations to notify customers or regulators.

7. Requests from your customers

The product lets you find, export, correct and delete a contact. If a customer contacts us directly, we’ll pass the request to you and help you respond.

8. Deletion

You can delete your account anytime in Settings. We delete Customer Data within 90 days after that, except where the law requires us to keep it; backups roll off on their normal schedule.

StellaBase

Questions or requests: use our contact form (or Help → Contact support in your dashboard). For a business’s own products or services, contact that business.