Privacy Policy
Effective: 14 June 2026
Who we are
GTMBase ("we", "us") is operated by Taimoor Tariq as a sole proprietor. Contact details are in the Imprint. Email: taimoor@gtmbase.io.
What this policy covers
This policy describes what personal data we process when you visit gtmbase.io and use the GTMBase account-mapping web app, and your rights under the EU General Data Protection Regulation (GDPR).
Data we collect about you (the user)
When you sign up and use the app we collect and store:
- Your email address (used for login via magic link or Google OAuth)
- Your company's domain and a buyer profile you create (value proposition, ICP, buying committee โ anything you type into the profile editor)
- The accounts you map, the results we produce, and feedback you submit (๐/๐ on recommendations)
- Anonymous usage logs (timestamp + map ID + cost estimate) for rate limiting and abuse prevention
Legal basis: performance of the contract you enter into when signing up (GDPR Art. 6(1)(b)).
Data we collect about third parties (people we map)
To produce an account map we fetch publicly-available LinkedIn profile data โ name, public job title, current company, public profile URL, public profile photo URL, public employment history and headline โ for employees of the company you ask us to map. We do this via:
- Blitz (third-party LinkedIn data provider) โ under a data-processing agreement. They source data from public LinkedIn pages.
- Direct read of the public LinkedIn page โ only the HTML
<title>tag, used to verify that a recommended contact is still at the company we're mapping.
We cache this data in our own database so we don't re-query the same person twice. Cached data is shared across all users of GTMBase (one Blitz call for "Stripe employees" serves anyone mapping Stripe), but your buyer profile, your maps, and your feedback are private to your account.
Legal basis: legitimate interest in providing a B2B sales-intelligence service (GDPR Art. 6(1)(f)). The data we process about third parties is limited to public business contact information, which they have themselves published on a professional networking platform. We do not enrich personal email addresses or phone numbers in the free tier.
Data subjects' rights
Anyone whose data appears in our system โ whether you, or a third party we've mapped โ has the right under GDPR to:
- Access the data we hold about them (Art. 15)
- Correct or update inaccurate data (Art. 16)
- Request deletion ("right to be forgotten", Art. 17)
- Object to processing (Art. 21)
- Request a copy in machine-readable form (Art. 20)
- Lodge a complaint with a supervisory authority (Art. 77) โ in Germany, the BfDI
To exercise any of these rights, email taimoor@gtmbase.io. We respond within 30 days as required by law.
Sub-processors
We rely on the following services to operate. They process data on our behalf under contract:
- Supabase (database + auth) โ EU region. Hosts your account, buyer profile, maps, and feedback.
- Vercel (hosting + serverless) โ processes requests and runs the engine.
- Resend (transactional email) โ sends magic-link login emails.
- Blitz (LinkedIn data) โ public profile enrichment.
- DeepSeek (LLM provider) โ generates the buyer profile during onboarding and ranks contacts during a map run. We send the candidate pool (public LinkedIn data) and your buyer profile to DeepSeek; we do not send your email or any login data.
Cookies and tracking
We use only the cookies required to keep you logged in (Supabase auth session). We do not use third-party analytics or advertising cookies. No consent banner is needed because we use only strictly necessary cookies (ePrivacy Directive ยง 5(3)).
Data retention
We keep your account data as long as your account is active. If you delete your account, we erase your profile, maps, feedback, and login records within 7 days. Cached third-party LinkedIn data is refreshed on a rolling 14-day window and is removed when no longer needed for the service.
Where data is processed
Supabase + Vercel: EU region. Resend: EU. DeepSeek: data is sent to DeepSeek's API endpoints (operated outside the EU). The data we send to DeepSeek is limited to: your buyer profile + public LinkedIn data for the account you're mapping. No login identifiers, no internal user IDs.
Changes to this policy
We'll post any changes here and update the "Effective" date at the top. For material changes that affect your data, we'll also email you.
Contact
Questions about this policy or your data: taimoor@gtmbase.io.