Privacy Policy

Last updated: August 15, 2026

What we collect and why, where the professional contact information in HiFive comes from, who we share data with, and what you can ask us to do about it. We do not sell personal information.

Who this policy covers

The privacy of your data (and it is your data, not ours) matters to us. This policy explains what we collect, why we collect it, how it is handled, and what rights you have over it. We have never sold personal information and we will not.

In this policy, "HiFinance", "we", "our", and "us" mean HiFinance, the company that builds and operates HiFive. "Services" means the HiFive application and anything we host alongside it.

This policy covers two groups of people, and it is worth being clear about the difference:

  • Users: people who sign in to a HiFive workspace on behalf of a customer organization, and people who visit our sites.
  • Professional contacts: people whose professional information appears inside HiFive because a customer imported it or because we enriched it from a data partner or a public professional source. These people do not have accounts with us. The section on contact information below is about them, and the section on your rights applies to them too.

Where a customer organization loads its own records into a HiFive workspace, we handle those records on that organization's instructions and under our agreement with it. If you are dealing with an organization that uses HiFive and you have questions about the records it holds, that organization is the right first stop, but you can also write to us at team@hifinance.ai and we will help.

What we collect and why

Our guiding principle is to collect only what we need. In practice that means:

Identity and access. When someone is given access to a HiFive workspace, we store their name, work email address, and the organization and workspace they belong to. That is what lets us authenticate them, apply the right permissions, personalize the product, and send essential service messages. Authentication is handled by our identity provider; we do not store passwords ourselves.

Product interactions. We store the content a workspace puts into HiFive (imported lists, people and company records, notes, search history, outreach drafts, email templates, and configuration). We keep it while the account is active so the product works as intended.

Professional contact information. This is the core of what HiFive does, and it gets its own section below.

General geolocation and access logs. We log IP addresses on sign-in and on API access for security and fraud prevention, and we keep those logs while the account is active.

Website and product analytics. We collect information about browsing activity (browser and operating system version, IP address, pages visited, load times, and referring site) to understand how the product is used and to improve it.

Cookies. We use first-party cookies to keep you signed in and to remember preferences such as your theme and whether the navigation rail is collapsed. You can block cookies in your browser settings, but the application will not work properly without them.

Voluntary correspondence. When you email us with a question or for help, we keep that correspondence, including your email address, so we have a history to refer back to.

Professional contact information about people who are not our users

HiFive helps organizations find and reach relevant people. To do that, it holds professional information about individuals (name, employer, job title, employment and education history, location, links to public professional profiles, and work contact details such as a business email address or phone number). Most of these people do not know HiFinance exists, so we want to be plain about how their information gets here and what happens to it.

Where it comes from. Three places:

  • Records a customer uploads or connects: for example a LinkedIn connections export, a CRM or spreadsheet sync, or a lead list a customer maintains.
  • Enrichment partners we query on a customer's behalf to fill in or verify employment details and work contact details.
  • Publicly available professional sources, such as company websites and public professional profiles.

Why we hold it. We hold it so that our customers can identify people who may be a fit for a role, a business relationship, a paid expert engagement, or a speaking invitation, and can reach them about it. We rely on legitimate interests in running a business-to-business service, balanced against the interests of the people concerned, which is why our Terms of Service limit customers to those four purposes and explicitly prohibit personal use, spam, and abuse.

What we do not do with it. We do not sell it. We do not publish it. We do not use it for advertising, and we do not use it to build profiles for any purpose beyond helping a customer evaluate professional fit and make contact.

Automated processing. We use AI models to summarize professional backgrounds, rank search results, and explain why a person may be a fit. These are aids to a human decision, not automated decisions in their own right, and they are sometimes wrong. Our Terms require customers to verify anything material before acting on it.

If you are one of these people. You can ask us what we hold about you, ask us to correct it, or ask us to delete it and stop processing it. Email team@hifinance.ai from the address you believe we hold, or tell us enough to identify the record. We will action it and confirm back to you. See the rights section below.

When we access or share information

To run the Services. We use third-party providers for the infrastructure and capabilities HiFive is built on. The providers that may process personal information on our behalf currently include:

  • Supabase: database, authentication, and file storage.
  • Railway: application hosting for the web app and API.
  • Anthropic: the AI models used for search, ranking, summaries, and drafting. Customer data sent to these models is not used to train them.
  • Clay: contact and company enrichment.
  • Google: Workspace and Sheets, where a customer connects a sheet as a source of lead lists.
  • Our email provider: delivery of transactional and notification email.

Each provider is bound to handle the data only as we instruct. We update this list as our providers change; check back here for the current set.

Between workspaces: never. Each customer organization has its own tenant. Records in one organization's workspace are not visible to another, and we do not pool customer-supplied records into a shared dataset.

To support you, with your permission. If we need to look at your workspace content to resolve a support case, we will ask you first.

To fix errors. When an automated process fails, we get an alert. Where we can fix it without looking at personal data, we do. Occasionally we have to look at a minimum amount of data to fix the root cause.

To investigate misuse. If we receive a credible report that Contact Information from HiFive is being used outside the limits in our Terms of Service, we may look at the relevant account activity. Accessing an account is a last resort, and we try to balance the privacy of our customer against the safety of the person who reported the problem.

Aggregated and de-identified data. We may aggregate or de-identify information and use it for any purpose, including improving the product.

When required by law. We do not respond to government requests for data unless compelled by valid legal process, or in a genuine emergency involving risk to life. Our policy is to notify the affected customer before disclosing anything, unless we are legally prohibited from doing so.

If the business changes hands. If HiFinance is ever acquired by or merges with another company, we will notify customers well before personal information is transferred or becomes subject to a different privacy policy.

Your rights over your information

We apply the same rights to everyone, wherever you are, and whether or not you are a HiFive user:

  • Right to know what personal information is collected, used, and shared. That is what this policy is for.
  • Right of access to the personal information we hold about you.
  • Right to correction of information that is wrong or out of date.
  • Right to erasure, subject to limits in applicable law. If you ask us to delete your professional contact information, we remove it and record enough to keep it from being re-added by a later enrichment run.
  • Right to restrict or object to processing, including opting out of being contacted through the Services. (We have never sold personal information and never will.)
  • Right to portability: to receive your information and have it sent elsewhere.
  • Right not to be subject to solely automated decision-making that has a legal or similarly significant effect on you.
  • Right to non-discrimination: exercising these rights will not get you worse service or a worse price.
  • Right to complain to your local supervisory or privacy authority. In Canada that is the Office of the Privacy Commissioner; in the EU and UK it is your national data protection authority.

To exercise any of these, email team@hifinance.ai. We may need to take reasonable steps to verify who you are before we act, usually confirming the email address associated with the record. If we cannot verify you, we may not be able to respond. If someone is acting on your behalf, we will need your written consent first.

Some information is exempt from these requests under applicable law, for example, records we must keep to meet a legal obligation or to defend a legal claim. If we deny a request, we will say why.

How we secure your data

Data is encrypted in transit with TLS between your browser and our servers, and between our servers and our providers. Databases and their backups are encrypted at rest. Access to production systems is limited to the people who need it, and each customer organization's data is isolated at the database layer by tenant, enforced on every query.

No system is perfectly secure. If you believe you have found a vulnerability, email team@hifinance.ai and we will look into it promptly. Please give us a reasonable chance to fix it before disclosing it publicly.

Deletion and retention

Content you delete inside a workspace is removed from the application immediately and purged from our active systems and logs within 30 days, and from backups within 60 days after that. Once purged, we cannot retrieve it.

If a customer organization cancels its account, its workspace content becomes inaccessible immediately and is purged in full within 60 days.

Otherwise we keep information for as long as it is needed for the purpose it was collected for, or as long as we need it to meet a legal obligation, resolve a dispute, or enforce our agreements.

Where the site and data live

The Services are operated from North America, and our infrastructure providers store and process data there. If you are located in the European Union, the United Kingdom, or elsewhere outside North America, be aware that any information you provide will be transferred to and stored in North America. By using the Services or providing us with personal information, you consent to that transfer.

Where personal data is transferred out of the EU or UK, we rely on Standard Contractual Clauses with the providers involved to keep the protection equivalent to what local law requires.

Changes and questions

We may update this policy to reflect new practices or to comply with regulation. When we make a significant change, we will refresh the date at the top of this page and take other reasonable steps to notify account holders.

Questions, comments, or concerns about this policy, your data, or your rights? Email team@hifinance.ai and we will be glad to answer.