99dots

99dots Privacy Policy

Last updated: July 26, 2026

This Privacy Policy explains how SnackSafe Inc. collects, uses, discloses, and safeguards personal information in connection with 99dots, our AI outbound sales platform available at 99dots.ai. Please read it carefully together with our Terms of Service. By creating an account or using the Service, you acknowledge the practices described in this Policy.

1. Introduction and Scope

SnackSafe Inc., a Delaware corporation with its registered address at 251 Little Falls Drive, Wilmington, DE 19808, USA ("SnackSafe," "we," "us," or "our"), operates 99dots, an AI outbound sales platform available at 99dots.ai (the "Service"). This Privacy Policy describes the categories of personal information we collect, the purposes for which we use it, the parties with whom we share it, and the choices and rights available to you.

This Policy applies to personal information we process about (a) visitors to our website; (b) individuals who register for, administer, or use accounts on the Service (collectively, "you" or "customers"); and (c) individuals whose business contact information is identified, assembled, verified, or contacted through the Service ("prospects" or "third parties"). This Policy does not govern the practices of any third-party website, product, or service that we do not own or control, including the sites and services of our customers, our subprocessors, or the recipients of outbound communications sent through the Service.

Certain features of the Service allow you to connect your own accounts and data sources, including email mailboxes and professional networking accounts. Where you do so, this Policy explains how we handle that data, and additional terms may apply as described in the sections below. If any provision of this Policy conflicts with a separately executed agreement between you and SnackSafe, that agreement controls to the extent of the conflict.

2. Our Roles: Controller and Processor

Data protection law distinguishes between a "controller," which determines the purposes and means of processing personal information, and a "processor," which processes personal information on behalf of and under the instructions of a controller. SnackSafe acts in different capacities depending on the data at issue.

With respect to information relating to your account, your use of our website, our billing relationship with you, and the operation and improvement of the Service generally, SnackSafe is the controller. We determine why and how that information is processed, and this Policy governs our practices for it.

With respect to the personal information contained in your outbound campaigns and in the mailboxes and other accounts you connect to the Service, including the identities and business contact details of the prospects you target, the content of messages you draft and send, and the replies you receive, you (the customer) are typically the controller and SnackSafe acts as your processor, processing that information on your behalf and in accordance with your instructions and our agreement. As the controller of that data, you are responsible for establishing a lawful basis for the processing, for providing any required notices, and for honoring the rights of the individuals concerned. A Data Processing Addendum reflecting this allocation of responsibilities is available on request by contacting support@99dots.ai.

3. Information We Collect From You

Account and profile information. When you register for and use the Service, we collect information such as your name, business email address, company name, job title, username, password credentials, account settings, and preferences. We also collect information you provide when you configure campaigns, describe your target market or ideal customer profile, and otherwise operate the Service.

Billing and payment information. We use Stripe, Inc. to process payments. When you subscribe to a paid plan, you provide payment details directly to Stripe, and no full payment card data touches our servers. We receive from Stripe limited billing information such as your billing name and contact details, the last four digits and brand of your card, transaction identifiers, subscription status, and invoice history, which we use to administer your subscription and maintain financial records.

Usage, device, and analytics information. When you access the Service, we automatically collect technical and usage information, which may include your IP address, browser type and version, device and operating system characteristics, referring and exit pages, pages and features viewed, actions taken, dates and times of access, and diagnostic and performance data. We use this information to operate, secure, analyze, and improve the Service.

Support and communications. When you contact us for support, respond to a survey, or otherwise communicate with us, we collect the content of your communications and any information you choose to provide, together with metadata such as the date, time, and channel of the communication.

Cookies and similar technologies. We and our service providers use cookies, pixels, local storage, and similar technologies to operate the website, remember your preferences, authenticate sessions, and understand usage. Please see the Cookies section below and the Cookies control available in the website footer for details and choices.

4. Information We Collect and Assemble About Prospects and Third Parties

A core function of the Service is to identify companies that match a target market or ideal customer profile you describe and to assemble and verify business contact information for decision-makers at those companies. In doing so, we collect, compile, and process information about individuals who are not our customers, which may include names, job titles and roles, professional and employer affiliations, work email addresses, publicly available professional profile links such as LinkedIn URLs, and related business contact data.

We obtain this information from sources that include publicly available web pages and directories and third-party and licensed data providers, and we use email verification and enrichment providers to validate and enhance it. The information we assemble in this manner is business contact information relating to individuals acting in their professional or commercial capacity, and we do not intend to collect special categories of data or consumer-level personal information through these features.

Lawful basis. Where and to the extent European Union, United Kingdom, or comparable data protection law applies to our own processing of prospect information as a controller, we rely on our legitimate interests, and the legitimate interests of our customers, in offering, operating, and improving a business-to-business sales and lead generation service, in identifying potentially relevant business contacts, and in facilitating professional outreach. We have assessed these interests against the interests, rights, and freedoms of the individuals concerned, taking into account that the data relates to individuals in a professional context and consists of business contact information.

Removal and opt-out. We maintain a standing mechanism through which any individual may request that their information be suppressed, removed, or opted out from the databases and processing we control. To exercise this option, or to object to our processing of your business contact information, contact support@99dots.ai, and we will action verified requests without undue delay and will add qualifying identifiers to a suppression list to prevent reintroduction. Where SnackSafe is acting as a processor on behalf of a customer with respect to particular prospect data, we will refer or forward the request to the relevant customer as the controller and reasonably assist the customer in responding.

5. Google User Data and Connected Mailboxes

The Service allows you to connect one or more Google Gmail mailboxes through Google OAuth so that 99dots can draft and send personalized outbound email on your behalf, run multi-step sequences, and read the replies to those messages. To provide these features, and only to the extent you authorize, we request the following restricted OAuth scopes: gmail.send (to send messages you compose or approve), gmail.readonly (to read messages such as replies to your campaigns), gmail.modify (to organize and update messages, for example applying labels or managing sequence state), and gmail.compose (to create and prepare messages and drafts).

When you connect a mailbox, we receive and process OAuth tokens and the Google user data necessary to operate these features, which may include message content, headers, metadata, thread and label information, and associated contact information within the connected mailbox. We access this Google user data solely to provide and improve the user-facing features described above, we store OAuth tokens securely, and you may disconnect a mailbox at any time within the Service or by revoking access through your Google account security settings, after which we will cease accessing the mailbox and will delete or de-identify associated Google user data in accordance with the retention practices described in this Policy, except where retention is required by law.

As described in the Roles section, with respect to the content of your connected mailboxes and your outbound campaigns, you are typically the controller and SnackSafe acts as your processor, handling that data on your behalf and under your instructions.

6. Compliance With the Google API Services User Data Policy and Limited Use Requirements

99dots' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In furtherance of these requirements, and specifically with respect to Google user data obtained through the restricted scopes described above, we affirm the following. We use Google user data only to provide and improve the user-facing features of 99dots that are prominent in the app, namely drafting and sending your outbound email, running sequences, and reading and managing replies to those messages. We do not transfer or sell Google user data to third parties, except as necessary to provide or improve those user-facing features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets after obtaining your explicit prior consent. We do not use Google user data for serving advertisements of any kind, including personalized, retargeted, or interest-based advertising. And we do not allow humans to read Google user data, unless we have your affirmative agreement to do so for specific messages, it is necessary for security purposes such as investigating abuse, it is necessary to comply with applicable law, or our use is limited to internal operations and the data (including derivatives) has been aggregated and anonymized.

If Google changes the applicable requirements, or if we introduce new features that use Google user data, we will update our practices and this Policy to remain compliant with the Google API Services User Data Policy and its Limited Use requirements.

7. How We Use Information and Our Legal Bases

We use the information described in this Policy to provide, operate, maintain, secure, and improve the Service; to identify companies and assemble and verify business contact information in accordance with your instructions and configuration; to draft, send, sequence, and manage outbound communications from the accounts you connect; to operate the website visitor identification feature and post alerts to the channels you connect; to authenticate users and administer accounts; to process payments and manage subscriptions; to provide customer support and respond to your communications; to monitor, analyze, and improve usage, performance, reliability, and security; to prevent, detect, and investigate fraud, abuse, and violations of our terms; to comply with legal obligations; and to establish, exercise, or defend legal claims.

Where the General Data Protection Regulation, the United Kingdom GDPR, or comparable law applies, we rely on the following legal bases. We process personal information as necessary to perform our contract with you or to take steps at your request before entering into a contract, for example to provide the Service and process payments. We process personal information on the basis of our legitimate interests, and those of our customers, for purposes such as operating and improving the Service, securing our systems, preventing abuse, and, as described above, offering business-to-business lead generation and outreach functionality, in each case where those interests are not overridden by the interests, rights, and freedoms of the individuals concerned. We rely on consent where required, for example for certain cookies and optional communications, and you may withdraw consent at any time without affecting the lawfulness of prior processing. And we process personal information where necessary to comply with a legal obligation to which we are subject.

8. How We Share Information and Our Subprocessors

We do not sell personal information for money. We share personal information only as described in this Policy, including with the categories of recipients set out below.

Service providers and subprocessors. We engage trusted third parties to process personal information on our behalf so that we can provide the Service, and we require them by contract to protect the information and to use it only for the purposes we specify. These include Google (for connected Gmail mailboxes and OAuth), Stripe (for payment processing), Amazon Web Services, Inc., including AWS Bedrock running Anthropic Claude models (for hosting, infrastructure, and AI features), data enrichment and email verification vendors (for assembling and validating business contact data), website visitor identification providers (for recognizing companies associated with anonymous visits to our own website), Slack Technologies (for posting alerts to your connected channels), Unipile (for optional LinkedIn research and outreach connectivity), and additional hosting and analytics providers. A current list of our subprocessors is available on request by contacting support@99dots.ai.

Other disclosures. We may disclose personal information to comply with applicable law, regulation, legal process, or an enforceable governmental or law enforcement request; to enforce our terms and protect the rights, property, safety, and security of SnackSafe, our users, and others; to detect, prevent, or address fraud, abuse, security, or technical issues; and in connection with, or during negotiations of, a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of our assets, in which case personal information may be transferred to the successor or acquirer subject to this Policy or a successor policy, and where required by the Google API Services User Data Policy, subject to your explicit prior consent with respect to Google user data. We may also share information that has been aggregated or de-identified such that it cannot reasonably be used to identify you.

9. International Data Transfers

SnackSafe is based in the United States, and we and our subprocessors may process, store, and transfer personal information in the United States and in other countries whose data protection laws may differ from those of your jurisdiction. Where we transfer personal information from the European Economic Area, the United Kingdom, or Switzerland to a country that has not been recognized as providing an adequate level of protection, we rely on appropriate safeguards, including the Standard Contractual Clauses approved by the European Commission and, for the United Kingdom, the International Data Transfer Agreement or Addendum, together with any supplementary measures reasonably necessary to protect the transferred data.

You may request further information about the safeguards we apply to international transfers, including a copy of the relevant Standard Contractual Clauses, by contacting support@99dots.ai.

If and to the extent Article 27 of the EU General Data Protection Regulation or Article 27 of the UK GDPR applies to our processing, individuals in the European Economic Area or the United Kingdom, and the relevant supervisory authorities, may contact us at support@99dots.ai regarding our representative, and we will designate and identify a representative where required by law.

10. Data Retention and Deletion

We retain personal information for as long as necessary to provide the Service, to fulfill the purposes described in this Policy, to maintain business and financial records, to resolve disputes, and to comply with our legal obligations. Retention periods vary depending on the type of information and the context in which it is processed.

Following termination or deletion of your account, we will delete or de-identify the personal information associated with your account within thirty (30) days, except for records that we are required to retain to comply with applicable law, including tax, accounting, and audit obligations, and except for information reasonably necessary to establish, exercise, or defend legal claims, to enforce our agreements, or to prevent fraud and abuse, which we will retain only for as long as necessary for those purposes and will then delete or de-identify. Where SnackSafe processes data as a processor on your behalf, we will delete or return that data in accordance with our agreement and your instructions.

Residual copies of personal information may persist in backup or archival systems for a limited period consistent with our backup cycles, after which they are overwritten or deleted in the ordinary course.

11. Security

We maintain reasonable technical and organizational measures designed to protect personal information against unauthorized access, disclosure, alteration, loss, and destruction, taking into account the nature of the information and the risks involved. These measures include, as appropriate, encryption in transit, access controls, authentication requirements, secure handling of OAuth tokens and credentials, logging and monitoring, and internal policies governing access to data.

No method of transmission over the internet or method of electronic storage is completely secure, however, and we cannot guarantee the absolute security of your information. You are responsible for maintaining the confidentiality of your account credentials and for the security of the accounts and data sources you connect to the Service. If you believe your account or any information has been compromised, please contact us promptly at support@99dots.ai.

12. Your Privacy Rights Under GDPR and UK GDPR

If you are located in the European Economic Area, the United Kingdom, or another jurisdiction that grants comparable rights, and where SnackSafe acts as a controller of your personal information, you have the right, subject to applicable law and to certain conditions and exemptions, to request access to the personal information we hold about you; to request rectification of inaccurate or incomplete information; to request erasure of your information; to request restriction of processing; to request portability of information you provided to us in a structured, commonly used, and machine-readable format; to object to processing based on our legitimate interests, including profiling, and to object at any time to processing for direct marketing purposes; and, where we rely on consent, to withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.

To exercise these rights, contact us at support@99dots.ai. We may need to verify your identity before responding, and we will respond within the timeframes required by applicable law. You also have the right to lodge a complaint with your local data protection supervisory authority, although we encourage you to contact us first so that we can seek to address your concerns.

Where SnackSafe processes your personal information as a processor on behalf of one of our customers, we will refer your request to the relevant customer, who is the controller responsible for responding, and we will provide reasonable assistance.

13. Your California and Other United States State Privacy Rights

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA/CPRA"), grants you certain rights regarding your personal information, subject to verification and to exceptions provided by law. These include the right to know and access the categories and specific pieces of personal information we have collected, the sources of that information, the purposes for collecting it, and the categories of third parties with whom we share it; the right to request deletion of your personal information; the right to request correction of inaccurate personal information; the right to opt out of the sale or sharing of your personal information; the right to limit the use and disclosure of sensitive personal information; and the right not to receive discriminatory treatment for exercising your rights.

We do not sell personal information for money. To the extent any disclosure of identifiers or online activity for cross-context behavioral advertising could be deemed "sharing" under the CCPA/CPRA, you may exercise your right to opt out. You can exercise your California rights by contacting support@99dots.ai or by using the Cookies control available in the website footer for advertising-related cookies, and you may use an authorized agent to submit requests on your behalf where permitted by law.

Residents of other United States states with comprehensive privacy laws, including without limitation Virginia, Colorado, Connecticut, Utah, and Texas, may have analogous rights to access, correct, delete, and obtain a copy of their personal information, and to opt out of targeted advertising, the sale of personal information, and certain profiling, subject to the terms and exemptions of the applicable state law. To exercise these rights, or to appeal a decision we make regarding your request, contact us at support@99dots.ai. We will verify and respond to requests as required by the applicable law.

14. Cookies and Similar Technologies

We and our service providers use cookies, pixels, local storage, and similar technologies on our website for purposes that include enabling core functionality and security, remembering your preferences, authenticating sessions, and measuring and analyzing usage and performance. Some of these technologies are strictly necessary for the website to function, while others are optional and used only where permitted or with your consent.

You can manage your preferences using the Cookies control available in the website footer, and you can also control cookies through your browser settings, although disabling certain cookies may affect the availability or functionality of parts of the website. This section supplements the information about automatically collected data in the section titled Information We Collect From You above.

Separately, the Service offers a website visitor pixel that our customers may deploy on their own websites to identify companies, and where available the people behind them together with business contact data, associated with otherwise anonymous visits. Where a customer deploys that pixel, the customer is the controller of the resulting data and is responsible for providing appropriate notices and obtaining any required consents, and SnackSafe acts as the customer's processor.

15. Website Visitor Identification on 99dots.ai

On our own website at 99dots.ai, we use cookies and similar technologies together with third-party data partners and vendors to recognize the companies, and where available the individuals, associated with otherwise anonymous visits, so that we can understand who is interested in 99dots and conduct our own business-to-business sales and marketing. With respect to this processing of visitors to our own website, SnackSafe is the controller.

When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email. We (or service providers on our behalf) may then send communications and marketing to these email addresses. You may opt out of receiving this advertising by visiting https://99dots.ai/optout.

You can also manage these technologies at any time using the Cookies control available in the website footer and through your browser settings.

This use of visitor identification on our own website is separate from the website visitor pixel we make available as a feature for customers to deploy on their own websites, described in the Cookies section above, for which the deploying customer is the controller.

16. Children's Privacy

The Service is intended for use by businesses and professionals and is not directed to individuals under the age of eighteen (18). We do not knowingly collect personal information from any individual under the age of sixteen (16). If we learn that we have collected personal information from a child under sixteen without appropriate authorization, we will take reasonable steps to delete that information. If you believe a child has provided us with personal information, please contact us at support@99dots.ai.

17. Automated Processing and Decision-Making

The Service uses automated processing, including artificial intelligence and machine learning models operated through AWS Bedrock, to perform tasks such as identifying candidate companies, assembling and scoring business contact data, and generating draft outbound messages for your review and use. These features are designed to assist you and operate under your direction and configuration.

We do not use these features to make decisions that produce legal effects concerning an individual, or that similarly significantly affect an individual, based solely on automated processing without meaningful human involvement. Outputs of the Service, including drafted messages and assembled contact data, are made available for your review, editing, and decision, and you remain responsible for how you use them.

18. Data Breach Practice

We maintain procedures designed to detect, investigate, and respond to security incidents affecting personal information. In the event of a personal data breach that triggers notification obligations under applicable law, we will notify the relevant supervisory authorities and affected individuals within the timeframes and in the manner required by law. Where SnackSafe acts as a processor on behalf of a customer, we will notify the affected customer without undue delay after becoming aware of a personal data breach affecting the data we process on that customer's behalf, and we will provide reasonable assistance to enable the customer to meet its own notification obligations.

19. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we make changes, we will revise the "updated" date at the top of this Policy and, where the changes are material, we will provide additional notice as required by law, such as by posting a notice on the website or notifying you through the Service or by email. Your continued use of the Service after the effective date of a revised Policy constitutes your acknowledgment of the updated Policy to the extent permitted by law. We encourage you to review this Policy periodically.

20. How to Contact Us

If you have any questions, requests, or concerns about this Privacy Policy or our handling of personal information, or if you wish to exercise any of your privacy rights, request a Data Processing Addendum, or request a current subprocessor list, you may contact us as follows.

By email at support@99dots.ai; by telephone at (415) 510-9335; or by mail at SnackSafe Inc., 251 Little Falls Drive, Wilmington, DE 19808, USA.