US
USACorp Intelligence

Privacy Policy

Last updated: September 2026

1. Data We Collect

USACorp Intelligence aggregates and processes only legally available, publicly accessible corporate data from US government sources (Secretary of State registries, federal court records via PACER/CourtListener, OFAC sanctions lists) and commercial aggregators (OpenCorporates, SEC EDGAR, GLEIF). We do not collect or process personal data of private individuals beyond what is publicly disclosed in corporate registries and court dockets.

For registered users, we collect: full name, email address, a hashed password (Argon2id — we never store or can recover your plaintext password), your subscription plan, and a record of which companies you've unlocked (to enforce your plan's monthly limit) and searched. We log IP addresses briefly for rate-limiting and abuse prevention, not for tracking.

If you generate an API key, we store only a one-way hash of it — the key itself is shown once at creation and cannot be retrieved afterward, including by us.

2. Marketing Communications

We only send product updates or announcement emails if you've opted in — this is unchecked by default at signup and never assumed from other consents (such as accepting these Terms). You can turn it on or off at any time from Account → Billing, and every marketing email includes an unsubscribe link. Turning this off does not affect transactional messages needed to operate your account (e.g. password resets), though we do not currently send any such emails either — sign-in is entirely token-based today.

3. Cookies & Local Storage

We don't use tracking or advertising cookies. Your sign-in session is a token kept in your browser's local storage, scoped to this site only, and is removed when you sign out.

4. Who We Share Data With

We do not sell personal data, and we do not share your account information with the data sources listed above (they never see who is searching). Corporate data displayed on the platform comes from those public sources — it is not information about you.

5. CCPA / GDPR Rights

Wherever the CCPA, GDPR, or a similar law applies to you, you may request a copy of your account data or its deletion at any time by contacting us. Deleting your account removes your profile, saved searches, watchlist, and API keys; anonymized usage counts may be retained for abuse prevention.

6. Data Security

Passwords are hashed with Argon2id and never logged. Access tokens expire after 15 minutes; refresh tokens after 30 days. Login and registration are rate-limited against automated abuse, and accounts lock temporarily after repeated failed sign-in attempts. Connections to usacip.com are encrypted in transit (TLS via a Let's Encrypt certificate, auto-renewing); the bare-IP address this platform was previously reachable at (ahead of the domain being connected) is not encrypted and should not be used going forward.

Account and subscription data (including billing status and company name, where provided) is only reachable through an internal admin tool gated behind a separate secret credential, not by any user-facing login. Every change made through that tool — activating or disabling a subscription, or deleting an account — is written to an internal audit log recording what changed, for which account, and when.

7. Contact

For privacy inquiries, data access, or deletion requests: privacy@usacorp.io