Privacy Policy
Last updated
We store what we need to run your account and report your results, and nothing else. Published landing pages set no cookies and record no IP addresses — a visitor is counted using a random identifier stored in their own browser, which we only ever keep as an irreversible hash. We do not sell your data or run advertising on it.
1. Who is responsible
Validate Demand, 312 White Cap Ln, Newport Coast CA 92657, USA is the data controller for your account. Contact us at our contact form.
For the people who sign up through your landing pages, you are the controller and we are your processor. You decide what to ask them for and what to do with it; we store it for you and act on your instructions. That distinction matters if someone asks you to delete their record — see section 7.
2. What we collect about you
- Account — your name and email address, held by our authentication provider so you can sign in.
- Your work — the ideas you describe, the offers and landing pages generated from them, the domains you connect, and your publishing settings.
- Billing — your plan, subscription status, billing period, and the price you pay. Card details are handled entirely by Paddle and never reach us.
- Usage — a record of each successful landing-page generation, so we can count it against your monthly allowance.
- Support — the messages you send us and the address you sent them from.
3. What your published pages collect
This is deliberately as little as it can be while still measuring anything:
- Form submissions — whatever your chosen signal asks for: email address, and optionally name, company, a short note, and which pricing plan the visitor selected.
- Three funnel events — a page view, a click on the main call to action, and a click on a pricing plan. Nothing else is tracked.
- A hashed visitor identifier — the page generates a random identifier and keeps it in the visitor’s own browser storage so repeat visits are not double-counted. It is hashed with SHA-256 before it reaches our database. We store only the hash, and it cannot be reversed to identify anyone.
Published pages set no cookies, load no advertising or analytics scripts, and we do not log or store visitor IP addresses. Nothing a visitor does on your page is used to build a profile or shared with anyone but you.
4. Cookies on this site
validatedemand.com and the console are not your landing pages. The promise above — no cookies, no analytics, no IP logging — is about the pages you publish. This site itself uses two kinds of cookie:
- Sign-in cookies, set by Clerk. Strictly necessary: without them you cannot stay signed in to the console.
- Google Analytics, to count visits and see which pages people read before signing up. It tells us how many people came and roughly where from. We do not use it for advertising, and it is never loaded on a landing page you publish.
Your browser’s own controls will block either of these. Blocking the analytics cookie has no effect on the product; blocking the sign-in cookie will stop you signing in.
5. Why we process it, and on what basis
- To provide the service (performance of our contract with you) — running your account, generating pages, publishing them, and reporting your evidence.
- To take payment (contract, and legal obligation for tax records) — via Paddle.
- To keep the service working and secure (legitimate interests) — enforcing plan limits, preventing abuse, and diagnosing faults.
- To answer you (legitimate interests) — support correspondence.
We do not use your data, or your visitors’ data, to train AI models, and we do not sell it to anyone.
6. AI providers
When you generate an offer or a landing page, the text you entered and the offer it produced are sent to a third-party AI provider to produce the result. Do not paste anything confidential, personal, or belonging to someone else into the idea or instructions boxes.
Your landing page visitors’ details are never sent to an AI provider — page generation happens before any visitor exists.
7. Who else processes data
We use these providers to run the service. Each sees only what its job requires, and each is bound to protect it.
- Clerk — Authentication — your name, email and login sessions.
- Render — Hosting and the PostgreSQL database where your data is stored (US).
- Cloudflare — Serving published landing pages, and TLS for custom domains.
- OpenAI — Generating an offer from the idea text you enter.
- Anthropic — Generating landing pages from your offer.
- Paddle — Payments, as merchant of record. They handle card details; we never see them.
- Resend — Delivering support emails you send us.
- Google Analytics — Counting visits to validatedemand.com itself. Never loaded on a published landing page.
Our infrastructure is hosted in the United States, so your data is stored and processed there. Where data is transferred out of the UK or EEA, it is done under the safeguards those laws require.
8. Your rights, and your visitors’
Depending on where you live you may have the right to access, correct, export, or delete your personal data, to object to or restrict processing, and to complain to your data protection regulator. Email our contact form and we will respond within 30 days.
If someone who signed up through your landing page asks you to delete their record, you can do it yourself — each signup can be deleted from the Users tab of the validation it belongs to. If a request reaches us instead, we will pass it to you rather than act on it, as you are the controller for those records.
9. How long we keep things
- Your account and work — for as long as your account exists.
- Deleted validations — removed immediately, along with their offer, signups and events.
- A closed account — pages are taken down and data deleted within 30 days.
- Billing records — kept as long as tax law requires, typically six years, and held mainly by Paddle as merchant of record.
10. Security
Connections use TLS, database access is restricted, and we do not store card details. Passwords are handled by our authentication provider, not by us. No service can promise perfect security, but if a breach affects your data we will tell you and the relevant regulator as the law requires.
11. Children
The service is not intended for anyone under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, tell us and we will delete it.
12. Changes
If we change this policy the date at the top changes with it, and we will tell account holders about material changes by email. See also our Terms of Service and Refund Policy.