Legal

Privacy Policy

Last updated: 20 August 2026

This policy explains what information Portwatch collects, why, who we share it with, and the choices you have. It covers our website at portwatch.ai and the Portwatch application, which are offered in the United States only. If you connected a Google account, section 5 sets out exactly what we do and do not do with that access. If you are a business owner who has been contacted through Portwatch, or think you may appear in our research, section 6 is written for you — it lists what we hold, where we got it, and how to have it removed.

1. Who we are

Portwatch is an AI-assisted deal sourcing platform for people acquiring small and mid-sized businesses. It helps a buyer define an acquisition thesis, find companies matching it, research those companies and their owners, and contact them.

Portwatch (“we”, “us”) is operated by Nicholas Lazares. We are the data controller for all information described in this policy, including the information about business owners described in section 6. For privacy questions, contact nick@portwatch.ai.

2. Short version

  • Portwatch is offered in the United States only, and researches US businesses.
  • We collect what our users give us — account details and acquisition criteria — plus basic technical logs.
  • If you connect Gmail, we use it only to send messages you have approved. We cannot read your inbox; the access we request does not permit it.
  • We research businesses our users might buy. Because these are usually owner-operated, that research includes information about named individuals, and it can include personal contact details and an estimated age. Section 6 spells this out.
  • We never sell personal information, and we do not use your data or your Google data to train AI models.
  • You can disconnect Google access, request your data, or ask us to delete it at any time — including if you are not a customer.

3. Information we collect from users

3.1 Information you provide

  • Beta access requests. When you submit the form on our website: your name, work email, company or firm, buyer type, target deal size, search stage, and any acquisition thesis you describe.
  • Account information. Your name, email address, and either a password you set or the invitation or magic-link token used to sign you in, plus your organisation and team membership.
  • Your search content. The acquisition theses, criteria, filters, uploaded documents such as investment memos, uploaded lead lists, notes, and outreach drafts you create or upload.
  • Correspondence. Messages you send us for support or sales.

3.2 Information from connected accounts

You may connect a Google account so outreach sends from your own mailbox. This is optional, initiated by you, and used only for sending — it is not a sign-in method, and we do not use it to authenticate you. See section 5.

3.3 Information collected automatically

  • Server logs. IP address, user agent, pages or endpoints requested, referring page, and timestamps.
  • Product usage. Which features you use and when, so we can fix problems and prioritise work.
  • Cookies. We use only cookies that are strictly necessary — the authentication cookies that keep you signed in. We run no analytics, advertising, or third-party tracking on our website or in the application, and we set no non-essential cookies. There is nothing here to opt out of.

4. How we use information

PurposeInformation used
Provide and operate the service — build theses, generate and score leads, produce research profiles, send outreach you approveAccount information, your search content, connected-account access, company and owner information
Respond to beta requests and support enquiriesBeta form submissions, correspondence
Secure the service, prevent abuse and investigate incidentsServer logs, account information
Debug, monitor reliability and improve featuresProduct usage, server logs
Meet legal, tax and accounting obligationsAccount information
Send service and product announcementsName, email address

We use large language models and other automated systems to structure your criteria, summarise public information about target companies, and draft outreach for your review. As regards our own users, these systems are assistive and make no decisions about you. They do carry out automated profiling of the business owners we research — see section 6.4.

Outreach drafted by Portwatch is not sent until you approve it, either message by message or by approving samples and authorising the remainder of that campaign.

5. Google user data and Limited Use

Portwatch can send acquisition outreach from your own Gmail account, so that messages come from you and replies arrive in your inbox rather than through a third-party sender. This requires your explicit authorisation through Google’s consent screen, and you can revoke it at any time.

5.1 What we request

ScopeWhy we need it
gmail.send To send only the outreach messages you have approved, from your account. This is the narrowest Gmail scope that permits sending; it does not grant the ability to read, search, or modify your mailbox.
openid, userinfo.email To identify which mailbox is connected and display it in your settings.

We request no other Google scopes.

5.2 What we store

  • An encrypted OAuth access and refresh token for the connected account.
  • The email address and display name of the connected account.
  • A record of messages sent through Portwatch: recipient, subject, the body as drafted in Portwatch, timestamp, and whether our send request succeeded or failed. This is your campaign history.

We do not track whether a recipient opens your message, and we use no tracking pixels or open beacons. Any engagement status you record against a recipient is one you or your team set manually. If we ever add automated open or reply detection, we will update this policy and tell you before it takes effect.

5.3 What we do not do

  • We do not read, download, index, or store the contents of your mailbox, including received mail. The access we request makes this structurally impossible.
  • We do not access messages you did not create in Portwatch.
  • We do not sell or transfer Google user data to third parties, other than the service providers strictly necessary to operate the feature, or where required by law.
  • We do not use Google user data for advertising of any kind.
  • We do not use Google user data to develop, improve, or train generalised AI or machine learning models.
  • We do not allow humans to read your Google user data, except with your explicit consent for a specific issue such as support, where necessary for security purposes, to comply with applicable law, or where the data has been aggregated and anonymised.

5.4 Limited Use disclosure

Portwatch’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5.5 Revoking access

You can disconnect your Google account at any time in Portwatch under Settings, or directly at myaccount.google.com/permissions. When you disconnect, we delete the stored tokens immediately and stop all sending from that account. Your record of previously sent messages remains in your campaign history until you delete it or your account is closed.

6. Information about companies and their owners

If you are a business owner reading this: you may appear in Portwatch even though you have no relationship with us and never gave us your details. This section tells you what we hold, where we obtained it, how it is used, and how to have it corrected or removed. To make a request, email nick@portwatch.ai — you do not need to be a customer, and we will not ask you to create an account.

To help buyers find acquisition targets, Portwatch compiles profiles of businesses. Small businesses are usually owner-operated, so these profiles routinely contain information about identifiable individuals.

6.1 What we collect

Depending on what our sources return, a profile may include:

  • name, job title or role, and company affiliation;
  • business email address and business telephone numbers;
  • personal email address;
  • mobile and landline telephone numbers;
  • postal addresses, which may be a residential address;
  • an estimated age or age range, derived from a date of birth returned by a people-search provider;
  • professional profile information, including employment and tenure history; and
  • publicly reported information about the business, such as estimated revenue, headcount, entity type, and review history.

We do not seek to collect special category data — information revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health, or sex life or sexual orientation — and we do not use it as a criterion.

6.2 Where we obtained it

We did not obtain this information from you. It comes from the following categories of source, and we will tell you the specific providers behind any of them on request:

  • public business registries and corporate filings;
  • mapping and business-listing data;
  • professional networking profiles;
  • company websites and publicly accessible web pages, retrieved by automated crawlers; and
  • commercial people-search databases, which are the source of personal contact details and date of birth.

6.3 How we use it

  • to build a research profile of the business for buyers using Portwatch;
  • to score how well the business matches a given buyer’s acquisition criteria; and
  • to enable a buyer to contact the owner about a possible acquisition.

We do not sell these profiles as a data product. Our Terms of Service §5 prohibit users from redistributing or reselling research output, or using it for any employment, credit, insurance or tenancy decision, and §7 requires them to comply with applicable anti-spam law and to honour opt-out requests.

6.4 Automated profiling and scoring

Profiles and match scores are generated automatically, without a person reviewing each one. Among the signals the score uses is the owner’s estimated age, alongside factors such as length of tenure, entity type, estimated revenue, and business review trend. The purpose is to estimate how likely a business is to be approaching a succession or sale decision.

The score ranks businesses for a buyer’s consideration. It does not by itself produce any legal or similarly significant effect: a human decides whether to make contact, and being contacted is an enquiry you are free to ignore. You may nonetheless object to this profiling at any time, and we will stop it in respect of you.

6.5 Your rights, and how to remove yourself

You have the rights set out in section 8, including access, correction, erasure, and objection. Specifically, on request we will:

  • tell you what we hold about you and which source categories it came from;
  • correct anything inaccurate;
  • delete your record; and
  • add you to our do-not-contact list, so that no Portwatch user can contact you through the service again.

We handle these requests manually and aim to complete them within 30 days. Requests are handled by Nicholas Lazares, who is our point of contact for all privacy matters.

7. How we share information

We do not sell personal information. We share it with the service providers needed to run Portwatch, each bound by a written agreement to process it only on our instructions.

Category of providerWhat they process
Hosting and infrastructureAll request data in transit; job queues and caching
Database, authentication and file storageAccount details, your criteria and uploads, company and contact records
Email deliveryAccount email such as invitations and password resets, and enquiries submitted through our website
Google (Gmail API)Sends the outreach you approved, from your own mailbox, at your direction — see section 5
AI language processingSearch criteria, public information about target companies, and outreach drafts
Business and company dataCompany identifiers and search terms, to retrieve business records and listings
People-search and contact dataAn individual’s name and location, to retrieve the contact records described in section 6.2
Secrets managementAPI keys and configuration only, not personal information

We will name the specific providers in any of these categories on request — email nick@portwatch.ai. We do not permit our AI providers to use data we send them to train their models, and Google user data is never used for model training (section 5.3).

We may also disclose information where required by law or valid legal process, to enforce our terms, to protect the rights and safety of any person, or in connection with a merger, acquisition or sale of assets — in which case we will notify you before your information becomes subject to a different privacy policy.

8. Your rights and choices

Depending on where you live, you may have the right to:

  • access a copy of the personal information we hold about you;
  • correct information that is inaccurate or incomplete;
  • delete your information, subject to legal retention requirements;
  • export your information in a portable format;
  • object to or restrict processing, including the profiling described in section 6.4;
  • withdraw consent where we rely on it; and
  • not be discriminated against for exercising these rights.

To exercise any of these, email nick@portwatch.ai. These requests are handled manually rather than through a self-service tool. We will acknowledge promptly and respond within the period applicable law requires, normally 30 days. We may need to verify your identity before disclosing or deleting information, and will ask only for what is necessary to do so.

If you are not satisfied with our response, you may raise it with the Attorney General or consumer protection authority in your state.

9. US state privacy rights

If you are a resident of California, Virginia, Colorado, Connecticut, Texas, Oregon, or another state with a comprehensive privacy law, you have rights to know, access, correct, delete, and to opt out of the sale of personal information or its use for targeted advertising.

We do not sell personal information, and we do not share it for cross-context behavioural advertising or targeted advertising. We use no advertising technology and no analytics.

The categories of personal information we collect about business owners are identifiers, professional or employment information, and commercial information, as described in section 6. We collect these from the sources listed in section 6.2, for the purposes in section 6.3, and we disclose them to the service providers listed on our categories of provider listed in section 7. Exercise any of these rights at nick@portwatch.ai. You may use an authorised agent, and we will not discriminate against you for exercising a right.

10. Security and data separation

We protect information in transit with TLS and at rest with encryption, restrict internal access to those who need it, store third-party credentials such as OAuth tokens encrypted and separately from application data, and keep audit logs of administrative access. No system is completely secure, but we work to keep protection appropriate to the risk. If a breach affects your personal information we will notify you and any regulator as applicable law requires.

How customer data is separated. Your account details, acquisition criteria, uploads, notes, scores and outreach are private to your organisation and not visible to other customers. The underlying directory of companies and contacts, however, is shared infrastructure common to all customers rather than a separate copy per account, with access controlled at the application layer. So a company researched for one customer may be surfaced to another; what remains private is your criteria, your enrichment, your scoring and your correspondence.

To report a vulnerability, email nick@portwatch.ai. We will acknowledge within 5 business days and will not pursue legal action for good-faith research that respects user privacy and avoids service disruption.

11. Where we operate

Portwatch is operated from the United States, offered to users in the United States, and researches businesses located in the United States. Our service providers process information in the United States.

We do not currently offer the service to, or direct it at, people outside the United States. If that changes we will update this policy first, because doing so brings obligations under other countries’ privacy laws that this policy does not presently address.

12. Children

Portwatch is a business tool intended for people aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

13. Changes to this policy

We may update this policy as the product changes. We will post the new version here with an updated date, and for material changes we will notify users by email or in the product before they take effect.

14. Contact us

Portwatch, operated by Nicholas Lazares
For privacy requests, security reports, or anything else: nick@portwatch.ai