Privacy policy
This policy explains what personal data MimicRadar collects, why, how long we keep it and what you can ask us to do with it. It covers both our public website and the account area.
Last updated 16 September 2026
Who is responsible for your data
The controller of the data described here is Lerudi Consulting S.L., Calle Pozos de Sierrezuela 32, 29651 Las Lagunas, Malaga, Spain, the company operating MimicRadar — see our company details page. Privacy questions and rights requests go to privacy@mimicradar.com.
What we collect and why
| Data | Why we hold it | Legal ground (GDPR) |
|---|---|---|
| Email address and name you register with | To create your account, confirm your email address, sign you in and send scan alerts | Performance of our contract with you |
| Company details and locations you enter (business name, website, phone, addresses) | These are the search terms the daily monitoring runs on, and the basis for deciding whether a listing is yours | Performance of our contract |
| Findings and listing records (URLs, listing names, addresses, phone numbers, websites found in public sources) | To show you what was found and keep a dated record you can rely on later | Performance of our contract; our legitimate interest in providing a monitoring service |
| Billing data (subscription status, period, payment status, Stripe identifiers) | To take payment, show your billing history and handle cancellations | Performance of our contract; legal obligation for tax records |
| Support tickets and messages | To answer your questions and keep a record of what was agreed | Performance of our contract |
| Technical and security logs (IP address, timestamps, activity in your account) | To keep accounts secure, investigate abuse and diagnose faults | Our legitimate interest in a secure and working service |
We do not buy personal data, we do not run advertising or tracking cookies, and we do not sell or share personal data for targeted advertising.
Card details
Card numbers never reach us. Payments are handled by Stripe, which collects and stores card data as its own controller. We receive only the subscription status and the last billing details needed to show your invoices.
Data about third parties in findings
A finding may contain a business name, address, phone number or website that belongs to someone else, taken from a public source. We process it only to show you the match and its source. If you are named in a MimicRadar finding, write to privacy@mimicradar.com and we will tell you what we hold and act on your rights.
How long we keep it
Account, company and finding data is kept while your account is open. After you close it we delete or anonymise the account and monitoring data within 90 days, keeping billing records for as long as tax law requires (usually 6–10 years) and security logs for up to 12 months.
Who processes data for us
We use a small number of providers to run the service — hosting, database and email delivery, payment processing, and the search and extraction services behind the daily checks. Each is bound by a data processing agreement and named on our subprocessors page.
International transfers
Some of these providers are based in the United States, so your data may be transferred outside the EEA and the UK. Those transfers rely on the European Commission's Standard Contractual Clauses, or on the provider's certification under the EU–US Data Privacy Framework, together with technical measures such as encryption in transit and at rest.
Your rights
If the GDPR applies to you, you can ask for access to your data, correction, deletion, restriction, portability, and you can object to processing based on our legitimate interests. You may also complain to your national data protection authority. Details and how to exercise each right are on our GDPR page.
If you are in California, Colorado, Connecticut, Texas, Virginia or another US state with a privacy law, you have comparable rights to know, correct, delete and to opt out of sale, sharing and profiling. We do not sell or share personal data and we do not profile you for automated decisions, so there is nothing to opt out of — but you may still ask us to confirm, correct or delete what we hold, without being treated differently for asking.
Security
Data is encrypted in transit and at rest, access rules restrict every record to the account that owns it, and administrative access is limited to the people who need it. Sign-in requires a confirmed email address.
Children
MimicRadar is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children.
Changes and contact
We will update this policy when the service changes and will email account holders about material changes. Questions: privacy@mimicradar.com. Cookies are covered separately in our cookie notice.