Skip to main content

Last updated: 5 October 2026

Business listings: where our lead data comes from

Socialligator helps founders find businesses that may need their product. To do that we keep a directory of businesses that publish their details online (the "lead pool"). This page explains what is in it, where it comes from and how to get your business out of it. To remove your business now, use the removal form — it takes effect immediately.

1. Who is responsible

[COMPANY NAME] (Socialligator) is the controller of the lead pool. A Socialligator customer who reveals a business's contact details or adds the business to their own contact list becomes the controller of that copy and is responsible for how they contact you.

2. What we collect

  • Listing details: business name, category, address, city, country, map position, phone number, website, and the rating and number of reviews shown on the listing.
  • Contact details published by the business: email addresses and social media profiles that appear on the business's own website (for example its contact, about or legal notice page).
  • Website signals: technologies, marketing tags and website builder the site uses, whether it has a contact form, and its public description.
  • A short AI summary of the above (what the business does), written from those facts only.

We only keep businesses that have a website, and only what the business itself made public. We do not collect private addresses, private phone numbers or data about employees beyond what the business publishes as its contact point.

3. Where it comes from

  • Public map listings (Google Maps), retrieved through a search API when a Socialligator customer searches for businesses of a given type in a given place.
  • The business's own website: its home page and up to three linked pages (contact, about, legal notice / imprint). We respect robots.txt.

4. Why, and on what basis

So that founders can find and contact relevant businesses about their products (business-to-business prospecting). Our legal basis is legitimate interest (GDPR art. 6(1)(f)): the data is business contact information the business chose to publish, used to contact it in its professional capacity. Contact details are hidden in the product until a customer pays to reveal them, every reveal is recorded, and outreach sent through Socialligator can carry a notice with a one-click unsubscribe link.

In countries where unsolicited business email needs prior consent (currently DE, AT), Socialligator blocks emails to businesses from the lead pool unless the sender records that they have a lawful basis for that contact.

5. How long we keep it

  • A business no customer revealed and that has not appeared in any search for 24 months is deleted.
  • Rating and review counts are refreshed when the listing is found again and are not kept as history.
  • Removal requests are kept for as long as the lead pool exists, so the business is never added again: the domain, a one-way hash of the email address, and the address itself on the do-not-email list only.

6. Who receives it

  • Socialligator customers: masked listings to every customer with a paid plan; contact details only to customers who revealed them.
  • Sub-processors: hosting in the European Union (Hetzner), the search API used to read public map listings, and the AI provider that writes the summary (it receives the public facts listed above, never email addresses or phone numbers).

7. Your rights and how to object

  • Remove your business: enter your website or email address on the removal form. We immediately erase its contact details, mark it as removed so it is never added again, and add the email address to a global do-not-email list that applies to every Socialligator account.
  • Unsubscribe: every outreach email with our notice has a one-click unsubscribe link.
  • Access, correction, erasure, objection: email support@socialligator.com. You can also complain to your data protection authority.

For data about Socialligator's own customers, see our Privacy Policy.