Last updated 27 August 2026
This service processes personal data about two different groups of people: our customers, and the people our customers look up. The second group did not sign up with us, so this policy is explicit about what happens to their data and how it can be removed.
Digital Footprint is operated by CSA APPS, the data controller for the purposes described below. For questions about this policy, or to make a request about your data, write to sales@digifootprint.dev.
For our customers’ own data: your account, your billing, your usage. We are the controller, and we decide what to collect and why, and this policy explains it.
For the data in a lookup: the email address, phone number, or username that a customer submits, and everything we find about it. The customer is the controller and we are their processor. They choose who to look up and why; we act on their instruction. That means we cannot decide on our own to look someone up, and it also means a customer’s lawful basis is theirs to have, not ours to supply.
When a customer submits an identifier, we check public platform surfaces and third-party sources and record what came back. That can include:
All of it comes from publicly accessible surfaces or from the categories of third-party source described in section 7. We do not buy personal data, we do not sell it, and we do not use it to build a profile of our own or to train models. A result we cannot confirm is reported as unconfirmed rather than guessed.
We will be straightforward about this, because it is the part most policies are vague on.
We are working toward automatic expiry of lookup records. Until it exists, deletion is on request and we do it by hand, see section 9.
We use a small number of specialist providers, each receiving only what it needs for its own function and none of them permitted to use it for their own purposes. They fall into these categories:
Some checks are performed by our own systems, which query a platform directly and share nothing with any party other than that platform.
Some of these operate outside your country, so data may be transferred internationally. Where that involves the UK or EEA, transfers rely on the UK Addendum or the EU Standard Contractual Clauses.
One cookie: an httpOnly, same-site session token set when you sign in, which the browser cannot read from JavaScript. It exists so you stay signed in. There is no analytics, advertising, or third-party tracking cookie anywhere on this site, and nothing to opt out of. Paddle sets its own cookies inside the checkout overlay when you open it, governed by their policy.
Depending on where you live you may have the right to access the personal data we hold about you, correct it, have it deleted, object to or restrict its processing, receive a portable copy, and complain to your data protection authority.
If you believe you have been looked up and want your data removed, write to sales@digifootprint.dev with the identifier concerned. We will delete every stored result for it. Two honest limits: where we hold the data as a processor we may need to pass the request to the customer who is its controller, and deleting a record does not stop the same identifier being checked again later. The underlying information is on the platforms, not with us. We respond within 30 days and do not charge for this.
Passwords, API keys, and password-reset tokens are stored only in hashed form using current industry-standard algorithms, and are unrecoverable once issued. Session tokens are held in cookies that browser JavaScript cannot read. All connections use TLS. Access to production data is limited to those who need it.
No system is perfectly secure. If a breach affects your personal data and the law requires notification, we will notify you and the relevant authority within the required time.
The service is for business use and is not directed at anyone under 18. We do not knowingly create accounts for children. Customers must not use the service to investigate minors.
If we change this policy materially we will email account holders and update the date above. See also our terms of service, which govern what customers may use the service for.