This Privacy Policy explains how Niche Busters ("we", "us") collects, uses, and protects information when you use our Service. We are committed to transparency and to only collecting what we need to run the product.
1. Information We Collect
You provide directly
- Account data: email, name, password hash, profile preferences.
- Billing data: handled by Stripe; we receive subscription status, plan tier, and the last 4 digits of your card. We never store full card numbers.
- Inputs: niches, prompts, URLs, and other content you submit to generate reports.
- Business Intelligence Profile: your business name, business type, primary city or market, state or region, primary goal, website (or your statement that you do not have one), primary social profile (or your statement that you do not use social media), and business stage. We require this before running any personalized analysis, including free teaser analyses, so results can be produced, stored against your account, and reused without asking you for the same details again. Profiles and the results generated from them are restricted by row-level security to the account that owns them, and you may correct or delete them.
- Audience Independence Score™ and Self-Reported Score™: we store the answers you give to the 12-question Audience Independence assessment and the 6-question Self-Reported assessment, the business they relate to, the scores, classifications, dependency-risk level, Reality Gap™ figures, the method version used, and any retake you complete. Drafts are saved so you can resume, and completed results are kept as history rather than overwritten, so you can see movement over time. We do not connect to, log into or collect data from your social platforms, advertising accounts, email tools, website or customer lists for these assessments — everything comes from what you enter. Records are restricted by row-level security to the account that owns them, and you can ask us to delete them.
- Business Adoption Program: if you are added to the program we store your business name, the account it is linked to, and where you supplied them your contact name, contact email, business type and city, plus your current phase, status, phase dates, and score timelines from the two assessments above. Our administrators may record private internal notes about the working relationship; those notes are admin-only and are not shown to anyone else. If we add a business we are working with that has not signed up, we store only the business and contact details needed to run the program. Permission to take part is recorded separately from permission to display results: nothing about you, and no score or movement, is shown publicly, in a live demonstration, or in marketing without your separate written permission, which you may withdraw, and you may ask us to delete your program records at any time.
- Intake data: information you enter into intake wizards (Quick Reports, Niche Scans, Business Impact, Brand Truth, Trust & Cultural, Commerce, Product Survival Scan™, BUYERFIT™, and the Vendor / Organizer Event portal) — including business details, offers, pricing, margins, unit costs, inventory commitments, booth fees, event details, audience and segment assumptions, marketing information, and evidence you choose to upload.
- Product Survival Scan™: product, cost, margin, inventory, and comparable-listing details you submit are used to produce your report and are retained with the scan. Private business figures (cost, margin, inventory) are never shown in samples, demos, shared snapshots, or competitor comparisons.
- Cross-Cultural Revenue Gap Analyzer™ and Community Trust & Retention Analyzer™ (internal, admin-only): analyses are created and reviewed by our team from business-level information, publicly observable signals, and evidence sources with dates and reliability ratings. We do not collect protected-characteristic data about individual customers for these tools, and PDF exports — available only for admin-approved analyses — record the methodology version, report status, and export metadata.
- Community Intelligence & Reactivation Pilot: if you apply as a community administrator we collect your name, email, optional phone, and details about the community you run (name, platform, public or private status, general location, category, member and active-member counts, activity level, member types, and the concerns you describe). During a pilot we additionally store the periodic metrics you enter, any screenshots or typed summaries you upload, and — if you choose to import one — a de-identified member export. Member exports are de-identified before analysis: personal identifiers such as names, emails, phone numbers, and profile links are stripped, and only aggregate patterns are retained. We never ask for your platform password, never sign in to your group, and never scrape member data. Individual members are never scored, and community or member data is never sold, rented, or shared with third parties. Pilot records are retained for the retention period shown in your workspace (365 days by default) and are archived or deleted on request. We publish a pilot write-up on our public site only with your prior written permission, which we record against that write-up before it goes live; your community’s name is withheld unless you ask us to include it, and you may ask us to take a published write-up down at any time.
- Serious Business Score™ calibration pilot: if you apply we collect your contact details and the business information you enter on the application. If you are invited, we store your invitation record, your consent to take part, your answers to the 24 behaviour-based questions, the score and level produced, the scoring version used, your written feedback on whether the result matched your business, and any reassessment you complete. Our reviewers may record their own blinded classification of your business and internal calibration notes; those records are admin-only and are used solely to test whether the score is accurate. Access is restricted by row-level security so you can only see your own records. Permission to take part is recorded separately from permission to display results: nothing about you is shown publicly, in a live demonstration, or in marketing unless you give that separate written permission, and you can withdraw it or ask us to delete your pilot records at any time.
- Founding Growth Cohort: applications include your contact details, business information, goals, and the evidence you choose to submit. We use them to assess fit, run the program, and record measured progress. Published outcomes are used only with your permission, which you may withdraw.
- BUYERFIT™ CSV mapping: when you use Verify mode, your customer or order CSV is parsed in your browser only. We store the column mapping you choose, row counts, and data-quality metrics — we do not upload or store your raw customer rows, names, emails, or order records.
- Demo event data: name, email, business name, and optional Live Gap Snapshot application details you submit when registering for a demo event.
- Third-party information you supply: details you choose to enter about competitors, event organizers, venues, or prospects. You are responsible for ensuring you may lawfully submit it, and you must not submit sensitive personal data, health information, or confidential third-party records.
- Sample report opt-in: if you request the sample-report walkthrough, we store the email address, optional name, business name, niche, and interest you submit, together with your consent, and use it to send you that walkthrough and related follow-up. You can unsubscribe at any time.
- Competitor URLs you seed: when you (or our team) add a competitor web address, we fetch that page's publicly available content and record observable signals only (for example page title, mobile responsiveness, visible contact or booking links, structured data, and load time). We do not access private accounts or logged-in areas.
- Local Visibility Launcher™: business or event profile details (name, category, service area, city/ZIP, audience description, offer, budget range, dates, links, and any logo or image you upload), the outlets you select, campaign copy you edit, and results you self-report. Published campaign pages you choose to publish are public by design — do not include information you are not willing to publish.
- Newsletter & blog sign-ups: the email address, optional name, and consent you submit, used to send updates you can unsubscribe from at any time.
- Testimonials: the name, business, role, rating, and story you submit for review before publication. Published testimonials appear publicly with the details you approved.
- Strategic Advisor conversations: the questions you ask, the reports the assistant is allowed to read on your behalf, the plans and action steps you save, and per-request usage and cost metering. Conversations are scoped to your account and are not used to answer other users’ questions.
- Communications: support emails and feedback.
Collected automatically
- Usage data: pages viewed, features used, quota consumption, timestamps.
- Device & log data: IP, browser, OS, referrer, error logs.
- Campaign analytics (Local Visibility Launcher™): when someone views a published
/lv/campaign page or follows a tracking link, we record an aggregate, privacy-safe event (timestamp, coarse referrer source, and the outlet or link involved). We do not build visitor profiles, use cross-site advertising trackers, or store full IP addresses against these events. - Cookies: see our Cookie Policy.
From third parties
- Authentication providers (e.g., Google OAuth) — basic profile + email.
- Public platform APIs (YouTube, Reddit, etc.) — public content surfaced inside reports. We do not collect private user data from these platforms.
2. How We Use Information
- Provide, operate, and secure the Service.
- Generate reports, calendars, and AI outputs you request.
- Process payments and manage subscriptions.
- Send transactional emails (receipts, account, plan changes, security alerts, intake confirmations, report-ready notifications, demo event RSVPs, and follow-up reminders).
- Send product updates (you can opt out at any time).
- Detect abuse, prevent fraud, and enforce our Terms.
- Improve the Service using aggregated, de-identified analytics.
3. Legal Bases (EEA / UK)
Where GDPR applies, we process personal data under: (a) contract — to deliver the Service you subscribed to; (b) legitimate interest — to secure and improve the product; (c) consent — for marketing emails and non-essential cookies; (d) legal obligation — for tax and compliance.
4. Sharing
We share data only with the following categories of processors:
- Infrastructure & database: our backend provider (hosting, auth, storage).
- Payments: Stripe.
- AI providers: Lovable AI Gateway and underlying model vendors used to generate reports.
- Email delivery: our transactional email provider.
- Analytics & error monitoring: privacy-respecting analytics services.
NicheMeld collaboration sharing: when you enable discovery, the profile details you choose to publish (business name, category, service area, capabilities and collaboration preferences) become visible to other NicheMeld participants. When you move a NICHE BUSTERS report into NicheMeld, the specific fields shown on the consent review screen are copied only after you confirm. Invitations, blueprints and messages you send are visible to the participants you send them to. Blocks and mute preferences are honored, and you can turn discovery off at any time.
We do not sell or rent personal data. We may disclose data if legally required (subpoena, court order) or to protect rights, safety, and security.
5. AI Processing
Inputs you submit may be sent to AI model providers to generate Output. Our providers are bound by enterprise agreements and do not train their public models on your inputs. Do not submit information you would not want processed by an AI system.
We do not sell your submitted information and we do not use it to train outside AI models unless you expressly authorize that in writing.
5a. Controlled Pilot: Alerts, Sponsored Places & Aggregate Market Reporting
Some accounts take part in a small controlled pilot. If yours does, the following applies.
- Market movement alerts. In-app alerts are part of the service. Email alerts require your consent. Text and push alerts are available only on eligible paid or sponsored plans, and recurring text messages require separate, explicit consent that you can withdraw at any time. Consent to operational alerts is never treated as consent to marketing messages. We honor unsubscribe and suppression requests, and we apply quiet hours and frequency limits you set.
- Alert feedback. When you mark an alert as acted on, deferred, dismissed, or irrelevant, we use that only to prioritize your own future alerts. It is not sold, shared, or used to train outside AI models.
- Sponsored places. A sponsor or partner may fund a fixed number of snapshots or action sprints. Sponsors receive aggregate reporting only. They do not see or influence your diagnosis, cannot suppress a negative finding, cannot contact you through us, and receive no identifiable information about your business unless you give explicit, separate permission.
- Aggregate market reporting. Houston, Dallas, Austin and San Antonio market reporting describes groups of businesses, never an individual one. A group is withheld unless enough separate businesses are in it, and it is withheld again if a single business supplies too much of its data. Customer-submitted, public-source, and inferred data are counted separately. Reports require administrator review and approval, and no report is published publicly during the controlled pilot.
6. Data Retention
- Account data: retained while your account is active and up to 90 days after deletion.
- Reports & Outputs: retained while your subscription is active; you may delete them at any time.
- One-time purchased reports (Quick Reports, Vendor Event, Commerce reports) and their intake submissions: retained for 24 months so you can re-download them, unless you request deletion sooner.
- Demo event registrations: retained for 24 months after the event date for follow-up and analytics, unless you request deletion sooner.
- Local Visibility Launcher™ campaigns, outlet selections, tracking links, and aggregate page-view analytics: retained while your entitlement is active and for 24 months afterwards, unless you delete the campaign or request deletion sooner.
- Strategic Advisor conversations, saved plans, and usage/cost metering records: conversations and plans are retained until you delete them; metering records are kept for up to 24 months for billing accuracy and abuse prevention.
- Newsletter subscriptions: retained until you unsubscribe, plus a suppression record so we do not email you again.
- Billing records: retained as required by tax law (typically 7 years).
- Logs: typically 30–90 days.
7. Your Rights
Depending on your jurisdiction (GDPR, UK GDPR, CCPA/CPRA, etc.), you may have rights to:
- Access, correct, or delete your personal data.
- Port your data to another provider.
- Object to or restrict processing.
- Withdraw consent at any time.
- Lodge a complaint with your local data protection authority.
- (California residents) Opt out of "sharing" for cross-context advertising — we do not engage in such sharing.
To exercise rights, email info@getnichebusters.com.
8. Security
We use encryption in transit (TLS), encryption at rest, row-level security on per-user data, hashed credentials, and least-privilege access. No system is 100% secure; report vulnerabilities to info@getnichebusters.com.
9. International Transfers
Your data may be processed in countries other than your own. Where required, we rely on Standard Contractual Clauses or equivalent safeguards.
10. Children
The Service is not directed to children under 16. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
11. Changes
We may update this Policy. Material changes will be announced via email or in-app. The "Last updated" date above reflects the most recent revision.
12. Contact
Data controller: NICHE BUSTERS, 3245 Main St. Ste.235 #304, Frisco, TX 75034. Contact: info@getnichebusters.com.
