Privacy Policy
Effective: 14 June 2026
Who we are
GTMBase ("we", "us") is operated by Taimoor Tariq as a sole proprietor. Contact details are in the Imprint. Email: taimoor@gtmbase.io.
What this policy covers
This policy describes what personal data we process when you visit gtmbase.io and use the GTMBase account-mapping web app, and your rights under the EU General Data Protection Regulation (GDPR).
Data we collect about you (the user)
When you sign up and use the app we collect and store:
- Your email address (used for login via magic link or Google OAuth)
- Your company's domain and a buyer profile you create (value proposition, ICP, buying committee โ anything you type into the profile editor)
- The accounts you map, the results we produce, and feedback you submit (๐/๐ on recommendations)
- Anonymous usage logs (timestamp + map ID + cost estimate) for rate limiting and abuse prevention
Legal basis: performance of the contract you enter into when signing up (GDPR Art. 6(1)(b)).
Data we collect about third parties (people we map)
To produce an account map we fetch publicly-available LinkedIn profile data โ name, public job title, current company, public profile URL, public profile photo URL, public employment history and headline โ for employees of the company you ask us to map. We do this via:
- Blitz (third-party LinkedIn data provider) โ under a data-processing agreement. They source data from public LinkedIn pages.
- Direct read of the public LinkedIn page โ only the HTML
<title>tag, used to verify that a recommended contact is still at the company we're mapping.
We cache this data in our own database so we don't re-query the same person twice. Cached data is shared across all users of GTMBase (one Blitz call for "Stripe employees" serves anyone mapping Stripe), but your buyer profile, your maps, and your feedback are private to your account.
Legal basis: legitimate interest in providing a B2B sales-intelligence service (GDPR Art. 6(1)(f)). The data we process about third parties is limited to public business contact information, which they have themselves published on a professional networking platform. We do not enrich personal email addresses or phone numbers in the free tier.
Data subjects' rights
Anyone whose data appears in our system โ whether you, or a third party we've mapped โ has the right under GDPR to:
- Access the data we hold about them (Art. 15)
- Correct or update inaccurate data (Art. 16)
- Request deletion ("right to be forgotten", Art. 17)
- Object to processing (Art. 21)
- Request a copy in machine-readable form (Art. 20)
- Lodge a complaint with a supervisory authority (Art. 77) โ in Germany, the BfDI
To exercise any of these rights, email taimoor@gtmbase.io. We respond within 30 days as required by law.
Sub-processors
We rely on the following services to operate. They process data on our behalf under contract:
- Supabase (database + auth) โ EU region. Hosts your account, buyer profile, maps, and feedback.
- Vercel (hosting + serverless) โ processes requests and runs the engine.
- Resend (transactional email) โ sends magic-link login emails.
- Blitz (LinkedIn data) โ public profile enrichment.
- DeepSeek (LLM provider) โ generates the buyer profile during onboarding and ranks contacts during a map run. We send the candidate pool (public LinkedIn data) and your buyer profile to DeepSeek; we do not send your email or any login data.
- Apify (LinkedIn profile verification) โ we call their
harvestapi/linkedin-profile-scraperactor on the top 5 recommendations of each map to verify the person is still at the company. The actor receives the LinkedIn URL only. - PostHog (product analytics) โ EU region. Tracks anonymous pageviews and identified events (sign-in, map run, feedback submission) so we can see where our funnel breaks. We do not enable session recording. We attach your user ID after sign-in, plus your name and email if you provided them, so we can connect anonymous-visitor events with the same person after they log in.
Cookies and tracking
We use cookies and localStorage for two things:
- Strictly necessary: the Supabase auth session cookie that keeps you logged in. Without it the site cannot function.
- Product analytics: PostHog (EU region) stores an anonymous distinct ID in localStorage so we can measure how the product is used and where the funnel breaks. We do not run advertising or marketing cookies, do not enable session recording, and do not share data with ad networks.
Legal basis for analytics: legitimate interest in measuring the basic usage of a B2B sales tool we are personally responsible for. You can opt out at any time by emailing taimoor@gtmbase.io and we will exclude your user ID from analytics going forward.
Data retention
We keep your account data as long as your account is active. If you delete your account, we erase your profile, maps, feedback, and login records within 7 days. Cached third-party LinkedIn data is refreshed on a rolling 14-day window and is removed when no longer needed for the service.
Where data is processed
Supabase + Vercel: EU region. Resend: EU. DeepSeek: data is sent to DeepSeek's API endpoints (operated outside the EU). The data we send to DeepSeek is limited to: your buyer profile + public LinkedIn data for the account you're mapping. No login identifiers, no internal user IDs.
Changes to this policy
We'll post any changes here and update the "Effective" date at the top. For material changes that affect your data, we'll also email you.
Contact
Questions about this policy or your data: taimoor@gtmbase.io.