Legal

Privacy Policy

Effective July 20, 2026 · PearFare LLC · legal@trypearfare.com

01Who we are and scope

PearFare LLC ("PearFare", "we", "us") is a Wisconsin, USA limited liability company. We run a batch data-extraction service. Clients upload pages they have already collected, or direct us to collect publicly accessible pages for them (Managed Collection), and we convert those pages into schema-validated JSON on GPU servers we own, at a single private facility in Wisconsin. We use no public-cloud compute.

This policy covers three properties and one service:

We handle information in three distinct contexts, and this policy keeps them separate throughout:

Questions about anything in this policy go to legal@trypearfare.com.

02The short version

Plain language summary. We run no analytics or trackers. The only cookie we set ourselves is the sign-in cookie the client portal needs to keep you signed in. Cloudflare, which hosts our sites, may set strictly necessary security cookies that do not track you across sites. We do not sell personal information, and we show no ads. The pages you upload for processing, or direct us to collect for you, are used only to do your job and to tune your own dedicated extractor. They are purged 14 days after delivery, or immediately if you choose the zero-retention option. Our sites also load fonts from Google Fonts, so your browser sends your IP address and user agent to Google when a page loads. The rest of this policy explains these points in more detail.

03Information we collect

The table below lists everything, grouped by the three contexts from Section 1. If a category is not listed here, we do not collect it.

CategorySourcePurposeRetention
A. Website visitors (trypearfare.com, app.trypearfare.com). We run no analytics or trackers. The client portal sets one strictly necessary sign-in cookie, and Cloudflare may set strictly necessary security cookies, both listed below.
Cloudflare edge logs: traffic metadata such as IP address, user agent, requested URLs, and timestamps Generated automatically when you visit. Held by Cloudflare, which hosts our sites and routes our traffic Serving the sites, network security, abuse prevention Cloudflare's standard edge-log retention. We run no analytics on this data
Strictly necessary security cookies that Cloudflare may set on our sites, such as bot-management cookies Set by Cloudflare's security systems when needed on properties it protects. We do not control when they appear Distinguishing people from bots and mitigating attacks. Not used to track you across sites Short-lived, set and expired by Cloudflare under its own policy
Portal session cookie (pf_session), set on app.trypearfare.com only Set by us when you create an account or sign in to the client portal Keeping you signed in. Strictly necessary for the portal to work; not used for tracking Expires 30 days after your last visit; removed at sign-out
Google Fonts requests: your IP address and user agent, disclosed to Google Your browser requests font files from fonts.googleapis.com and fonts.gstatic.com when a page loads Font delivery Governed by Google's privacy policy. We never receive this data
B. Clients and account holders, plus anyone who emails us
Account details: work email, password (stored only as a hash), company name You, when you open an account Authentication, account management, service communication Life of the account; deleted after closure, except records we must keep for tax and accounting (Section 8)
Billing details: billing email, business address (optional), invoices You, plus invoices we generate Billing and invoicing Life of the account, plus records we must keep for tax and accounting
Payment card details Collected directly by Stripe when payments go live Payment processing Held by Stripe. We never store card numbers
Usage records: batch counts, page counts, timestamps Generated when you use the service Billing, capacity planning, support Life of the account, plus tax and accounting records
Access logs: API and portal access events Generated when you call the API or sign in Security and troubleshooting About 90 days
Correspondence: emails you send us, including support questions and privacy rights requests You, when you email us Answering you, providing support, handling and documenting rights requests Kept as long as needed to handle the matter and to keep a record that we did, then deleted
C. Client Data (processed as a service provider; see Section 4)
Pages you upload and the JSON we extract from them. These may contain personal information about third parties, such as names, job titles, and phone numbers in a directory Uploaded by you through the batch API, or collected by us from publicly accessible sources you specify (Managed Collection) Running the extraction you ordered and tuning your own dedicated extractor; no other purpose Purged 14 days after delivery, or immediately on delivery confirmation with the zero-retention option

04Client Data: our role as processor

Plain language. When you upload pages, or direct us to collect pages for you, you stay in charge of the personal information inside them. You are the controller. We are your processor, or in US state-law terms, your service provider. We touch that data only to do the job you ordered, on your documented instructions. We do not decide what to do with it, we do not use it for ourselves, and we delete it on schedule.

Pages that clients upload, or direct us to collect, often contain personal information about people who are not our clients: names, titles, phone numbers, and similar details found in directories and public listings. For that information:

Managed Collection

Some clients direct us to collect publicly accessible pages for them instead of uploading pages themselves. Under Managed Collection the only thing that changes is who fetches the pages; every commitment in this policy applies the same way:

05How we use information

We use information for these purposes and no others:

06How we share information

We share information only with the service providers below, each for a single narrow job, and in the limited circumstances described after the table: legal process and business transfers. We do not sell or rent information to anyone, and we do not share personal information for cross-context behavioral advertising, as the California Consumer Privacy Act defines selling and sharing.

ProviderWhat they do for usWhat they receive
Cloudflare Hosting, CDN, email routing, and encrypted staging storage for portal uploads and results Traffic metadata for our sites and API, standard edge logs, email routed to our address, and staged copies of batch files uploaded through the portal and their result files, encrypted at rest and removed within 14 days
Stripe Payment processing, when payments go live Billing contact details and payment card information, which Stripe collects directly. We never see or store card numbers
Google Fonts Font delivery on our websites Your IP address and user agent when your browser loads font files
GitHub Source code hosting Our source code only; no account data and no Client Data

GPU marketplace tenants and Client Data

We rent spare GPU capacity to third-party marketplace tenants. Tenants run only on hosts that are not processing Client Data, and they can never access Client Data. Client Data lives on encrypted volumes available only to the hosts doing client work; tenant hosts have no path to those volumes. Tenants are not a recipient of any information covered by this policy. See our Security page for how this isolation works.

Legal process

We disclose information in response to legal process only when we are required to. When a demand covers a client's data, we notify that client before disclosing, unless the law prohibits notice. We push back on requests that are overbroad and disclose only what the process compels.

Business transfers

If PearFare is involved in a merger, acquisition, financing, reorganization, or sale of some or all of its assets, information we hold may be transferred to the successor as part of that transaction, including during due diligence under confidentiality obligations. Any successor takes the information subject to this policy as it applied when the information was collected. Client Data remains subject to the retention limits in Section 8 and to our contracts with clients, including any data-processing addendum, and a transfer does not enlarge how Client Data may be used. If a transaction leads to material changes to this policy, we will provide notice as described in Section 14.

07What we never do

The statements in this section are binding commitments.

08Retention and deletion

You can request deletion of your account data at any time by emailing legal@trypearfare.com. Deletion of Client Data flows through the retention system above, and clients can instruct earlier deletion of any batch. Purging is final: once Client Data is purged, we cannot restore or retrieve it.

09Security

Processing happens on GPU servers we own, at a single private facility in Wisconsin, and runs continuously. We use no public-cloud compute. Client Data sits on encrypted volumes available only to the hosts doing client work; GPU marketplace tenants run only on separate hosts that never process Client Data and have no access to those volumes. The API requires key authentication, connections to our sites and API use HTTPS, and passwords are stored only as hashes.

No security measure is perfect. We describe our controls in detail, including the isolation model for rented GPU time, on our Security page.

10Your rights and choices

If you are in the United States, we honor these rights for the account, billing, visitor, and correspondence information we control, regardless of which state you live in. Some state privacy laws apply only to businesses above certain size thresholds; we do not condition these rights on whether a given law technically applies to us. For personal information inside pages a client submitted or directed us to collect, the client controls that data. Section 4 explains our role, and on request we will pass your inquiry to the relevant client and confirm to you that we have done so.

How to exercise them

Email legal@trypearfare.com. We verify requests with reasonable steps: usually by asking you to write from the email address on your account, or by asking for enough information to match you to our records. We never ask for more than we need to verify you, and we use the information you provide for verification only for that purpose. An authorized agent may submit a request for you if the agent provides your written permission; we may still verify your identity with you directly.

We confirm receipt of a request within 10 business days and respond within 30 days of receiving it. If a request is unusually complex, we may take up to 30 additional days, and we will tell you within the first 30 days why we need the extension. We will not discriminate against you for exercising any right. If we decline a request, we will tell you why, and you can ask us to reconsider.

Because our retention windows are short, the data a request concerns may already be gone. If it has been deleted under Section 8, we will tell you so. Purged data cannot be recovered, so a deletion request for it is already satisfied, and an access or portability request for it will return nothing.

If your request concerns personal information inside Client Data, the client that supplied it or directed its collection is the controller. We will refer you to that client where we can and notify them, as described in Section 4.

Global Privacy Control and Do Not Track

Global Privacy Control is a browser signal that tells businesses not to sell or share your data. Because we do not sell or share data or track visitors, the signal does not change how we handle a visit. Visits with GPC enabled are treated the same as all other visits and are not tracked. We treat Do Not Track signals the same way.

11Data breach notification

Wisconsin's breach notification statute, Wis. Stat. § 134.98, requires an entity to make reasonable efforts to notify each affected person within a reasonable time, not to exceed 45 days after the entity learns that personal information has been acquired by someone unauthorized to have it. Notice may be delayed at the request of law enforcement, and if a single incident affects 1,000 or more people, the statute also requires notice to the nationwide consumer reporting agencies. We will comply with this statute, and with other breach notification laws that apply to the incident.

We also commit to more than the statute requires. If we confirm a security incident affecting your Client Data or your account information, we will notify you without unreasonable delay and no later than 72 hours after confirmation. We will tell you what happened, what data was involved, and what we are doing about it. The statute excuses individual notice where the acquisition creates no material risk of identity theft or fraud. Even in that case, we will still tell affected clients.

12Children

PearFare is a business-to-business service. Our sites and service are not directed to children, and you must be at least 18 to open an account. We do not knowingly collect personal information from anyone under 18. If you believe we have, email legal@trypearfare.com and we will delete it.

13International use

All processing happens in the United States, at our single Wisconsin facility and with the US service providers listed in Section 6. We have no establishment in the EU or UK. If you access the service from outside the United States, your information will be transferred to and processed in the United States.

Any client that needs a data-processing addendum, including EU or UK clients, can request one by email at legal@trypearfare.com.

14Changes to this policy

When we change this policy, we will post the new version at this page and update the effective date at the top. If a change is material, we will email account holders before it takes effect. We will never change this policy to permit selling personal information or to weaken the Client Data commitments in Section 4 retroactively.

15Contact

PearFare LLC, Wisconsin, USA.

Email legal@trypearfare.com for privacy questions, rights requests, data-processing addendum requests, or anything else in this policy. For support and everything operational, email pilot@trypearfare.com. Our Terms of Service and Security page cover the rest.