Your information
Privacy Policy
This Privacy Policy explains how Boonly Organization (“Boonly,” “we,” “us,” or “our”) collects, uses, stores, protects, and shares information when you use the Boonly website, platform, and related services.
Effective September 15, 2026
Version 2026-09-15-activity-logging-retention
1. Information you provide
Depending on how you use Boonly, you may provide:
- Your name, email address, password-based account information, or information used to authenticate your account.
- Your business name, website, location, industry labels, NAICS codes, years in business, employee count, and revenue or revenue range.
- Whether your business has a physical, brick-and-mortar, or home-based location.
- Business certifications and ownership or business characteristics that you voluntarily choose to share.
- Your funding interests, goals, saved finds, and notification preferences.
- Other profile information or communications that you voluntarily provide.
Business-profile questions are optional. You may skip onboarding questions and add or update applicable information later. Boonly does not infer optional ownership characteristics that you do not provide.
2. Google Sign-In
Boonly offers optional “Continue with Google” authentication using Google OAuth through Supabase Auth. If you choose it, Boonly may receive basic account information you authorize Google to provide, such as your name, email address, profile information or avatar where supplied, and the Google account identifier needed for authentication.
We use this information to authenticate you, create or connect your Boonly account using Supabase-supported identity behavior, maintain your account and session, and provide the service. Boonly does not use Google Sign-In to access Gmail, Google Drive, contacts, calendars, or other Google account content.
Boonly’s use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including its Limited Use requirements where applicable.
3. Information collected automatically
When you use Boonly, our application and operational providers may automatically process technical information such as your IP address, browser and device type, pages and features used, timestamps, session information, diagnostics, request logs, and security events.
Boonly currently uses Google Analytics to understand visits and use of the website and platform. Google Analytics may use cookies or similar technologies and process information such as page views, browser or device information, approximate location derived from IP address, and interaction timestamps. See our Cookie Policy for more information.
Activity, usage and security records
When you use Boonly we keep records of what happens in your account. These records may include:
- your IP address, as observed by our servers when you sign in or take an action;
- browser and device information sent by your browser (such as the user-agent string);
- session identifiers associated with your signed-in session;
- account and authentication activity, such as account creation, email verification, sign-in and sign-out;
- product usage records, such as markets you select or create, research you request, research runs that complete for you, and results you view, save, dismiss or follow;
- research and source access records, such as when you use a free source unlock and when you open a protected source; and
- subscription and payment lifecycle records received from our payment processor.
We use these records to:
- provide and operate the service;
- keep accounts and the service secure;
- detect and prevent fraud and abuse;
- troubleshoot problems;
- provide customer support;
- enforce our agreements; and
- handle payments, chargebacks and payment disputes, including demonstrating to our payment processor that the service was delivered.
We do not collect precise or GPS location. Where a general region or country is shown, it is derived from your IP address and is approximate only. We do not use session-replay, screen recording, keystroke logging, clipboard capture, or mouse or cursor tracking, and we do not record the contents of your passwords, authentication tokens or payment card numbers.
Authorized Boonly staff can view these records through our internal administration tools for the purposes listed above. Records are kept in an append-only log: they cannot be edited or rewritten after the fact.
4. How we use information
We use information to:
- Create, operate, authenticate, and secure customer accounts.
- Maintain business profiles and personalize funding find discovery.
- Generate and explain personalized matches, including eligibility and uncertainty indicators.
- Provide saved finds, in-app alerts, immediate email alerts, and daily or weekly digests.
- Process and administer subscriptions and billing.
- Send account, security, service, billing, and other transactional communications.
- Monitor, improve, troubleshoot, and measure the service.
- Prevent fraud, misuse, security incidents, and violations of our terms.
- Comply with legal obligations and protect legal rights.
5. Funding profiles and matching
Boonly processes information in your business profile to evaluate the relevance of published funding finds and generate personalized matches, reasons, scores, labels, and alerts. Missing profile information may create uncertainty rather than a negative determination.
These results are informational tools. They do not guarantee eligibility, application success, approval, funding, or an award. You should review the current requirements and materials supplied by the original funding provider.
6. Payments
Boonly uses Stripe to process subscription checkout, recurring payments, invoices, cancellations, and customer billing management. Payment-card details are submitted to and handled by Stripe; Boonly does not store full payment-card numbers. Boonly receives and maintains limited subscription and transaction information needed to manage access, such as Stripe customer and subscription identifiers, plan, billing interval, status, and billing-period dates.
7. Service providers and sharing
We may share or allow processing of information when reasonably necessary to operate Boonly, comply with law, or protect rights. Current provider categories include:
- Supabase for authentication and database infrastructure.
- Google for optional Google authentication and Google Analytics.
- Stripe for payment and subscription processing.
- SendGrid for transactional and find-alert email delivery.
- Hosting, application infrastructure, scheduling, monitoring, and related technical providers needed to operate the service.
These providers process information for their operational role and under their own applicable terms and privacy practices. We may also disclose information if required by law, to investigate abuse or security threats, in connection with a business reorganization or transfer, or with your direction or consent. We do not represent that operational providers never process customer information.
8. Email, text messages, and notifications
We may send account, authentication, security, subscription, and other service communications. If your membership includes find notifications, Boonly may send new-match, Hidden Gem, closing-soon, reopened-find, or meaningful-update alerts immediately or in daily or weekly digests, according to your preferences.
You can manage available optional alert categories and email frequency from your Alerts settings. Transactional or security messages necessary to operate your account may not be subject to those optional alert settings.
Mobile information and SMS
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing with subcontractors for support services, such as customer service, is permitted. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
9. Cookies and similar technologies
Boonly and its providers use browser storage, cookies, and similar technologies for authentication and session continuity, security, application operation, and analytics. Stripe may use its own technologies when you enter its checkout or billing portal. Boonly does not currently offer an in-product cookie-consent manager. Learn more, including browser controls and the effect of disabling essential storage, in our Cookie Policy.
10. Data retention
We generally retain account, profile, saved-find, match, alert, preference, and subscription information while your account is active. After an account or subscription ends, we may retain information for a reasonable period when needed for security, fraud prevention, legal compliance, billing and tax records, dispute resolution, enforcing agreements, backups, or ordinary operational continuity. Retention periods vary by record and purpose.
Boonly generally retains security, product-usage, session, and dispute-evidence records for up to 24 months after an account closes or the relevant service relationship ends, unless a longer period is reasonably necessary for an active payment dispute, fraud investigation, legal hold, enforcement of our agreements, or other legal obligation. When no longer needed, records are deleted or appropriately anonymized where practical.
Some records are kept under their own rules: invoices, payment records and other financial or tax records are retained for the period required by applicable accounting, tax and payment-network requirements, and records subject to a legal hold are retained until the hold is lifted.
11. Data security
We use reasonable administrative, technical, and organizational safeguards designed to protect information, including authenticated access and access controls for customer information. No transmission, storage system, or security measure is completely secure, so we cannot guarantee absolute security.
12. Your choices and privacy rights
You can update applicable business-profile information and notification preferences in Boonly. You may contact privacy@boonly.org to ask about access, correction, deletion, or another privacy request. We may need to verify your identity before acting on a request, and some records may be retained where permitted or required by law.
Privacy rights differ by jurisdiction. Depending on where you live, you may have additional rights or the right to appeal a response. You can also manage browser technologies as described in the Cookie Policy.
13. Children’s privacy
Boonly is a business service intended for people who have the legal capacity to enter into an agreement and use the service on behalf of themselves or a business. It is not directed to children. If you believe a child has provided personal information to Boonly, contact us so we can review and take appropriate action.
14. Changes to this policy
We may update this Privacy Policy as Boonly or legal requirements change. We will post the updated policy here and revise the effective date when appropriate. If a change is material, we may provide additional notice through the service or by email.
15. Contact us
Questions or privacy requests may be sent to:
Boonly Organization301 S. McDowell St.
Charlotte, NC 28204
privacy@boonly.org