Legal

Privacy Policy

Last updated 2 August 2026

VisibleFront measures how visible local businesses are to AI assistants. This policy explains, in plain English, what personal data we collect, why, who we share it with, and the rights you have over it. The short version: we collect only what we need to run the scan, the profile, the dashboard and the booking features; we never sell your data; our website analytics are cookieless; we hash IP addresses for rate-limiting and keep a short-term, auto-expiring security log (including raw IP) purely to prevent abuse of our intake endpoints; and you can reach us any time at hello@visiblefront.com.

Who we are and how to contact us

VisibleFront is run by VISIBLEFRONT LTD, a company registered in England & Wales under company number 17288404. Our registered office is 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.

For anything to do with this policy, your personal data, or to make a data-protection request, email us at hello@visiblefront.com.

For the personal data described in this policy, VISIBLEFRONT LTD is the data controller under the UK GDPR and the Data Protection Act 2018. There is one exception: when an end customer submits a booking request through a business's public profile, we act as a processor on behalf of that business, and the business is the controller of that booking data.

What VisibleFront does

We measure how visible a local business is to AI assistants such as ChatGPT, Google Gemini and Perplexity. We do this by asking those assistants the kinds of questions real customers ask, then scoring how often the business is recognised or recommended, on a 0 to 100 AI Visibility Score.

We offer a free AI-visibility scan with an emailed report, and a paid subscription that adds a hosted, machine-readable public business profile (at a /b/[slug] web address), help correcting and propagating the business's listing data, monthly rescans, a dashboard with an AI guide/concierge, and an optional booking button.

We also publish a public AI Visibility Index: monthly city-by-city rankings of local businesses by AI visibility, released as open data under the CC BY 4.0 licence (attribution to VisibleFront required).

What personal data we collect, why, and our lawful basis

We collect only the data we need for each feature. Here is each category, why we collect it, and the lawful basis we rely on under the UK GDPR.

  • Free scan request: the business name, city, the requester's email (so we can send the report), and the source/referrer. Lawful basis: consent and/or legitimate interest, because the person asked us to run the scan.
  • Pilot / design-partner signup: business name and email. Lawful basis: consent / legitimate interest.
  • Owner account (for someone who claims and publishes a profile): email and an authentication session, handled via Supabase Auth, with optional Google sign-in. Lawful basis: performance of a contract.
  • Business profile content: the business facts an owner confirms or edits, such as services, prices, opening hours, address and phone. The public profile shows only facts the owner has confirmed or edited (an honesty gate). Lawful basis: contract / legitimate interest.
  • Booking requests made through a business's public profile: the end customer's name, email and/or phone, requested time, the service, and any notes, submitted so the business can respond. We pass this to the business and act as its processor. Lawful basis: the requester's request and the business's legitimate interest.
  • Verified reviews: when you review a booking you made through VisibleFront, we collect your rating, your review text, the name you type, and the time you consented to publication, tied to that booking. The review is published on the business's public profile — and in its machine-readable data that AI assistants read — under your first name and last initial only. Lawful basis: consent, given by ticking the consent box (or, if your AI assistant submits for you, by the explicit confirmation you give it). You can withdraw consent and have the review removed at any time — see 'Verified reviews and removing yours'.
  • Optional Google Calendar connection (started by the owner): OAuth tokens used only to check free/busy and create events on the owner's own calendar. Lawful basis: consent, revocable at any time.
  • Measurement connections: you may grant us read-only access to your measurement tools (Bing Webmaster Tools, Google Search Console); we use that access solely to produce your reports, and you can revoke it at any time from within those tools — lawful basis: consent, revocable at any time.
  • Payments: handled by Stripe. We do not store full card numbers; Stripe processes the payment details. We receive subscription status and related metadata from Stripe. Lawful basis: performance of a contract.
  • Marketing outreach: we may process publicly available business contact details (B2B) to send a small number of cold emails to businesses in the US and UK. Every email says who we are and carries a one-click unsubscribe; a reply asking us to stop works just as well. In the UK the lawful basis is legitimate interest, and only where the recipient is a corporate subscriber under PECR regulation 22 — a limited company, LLP, plc, or other body corporate. UK individual subscribers under regulation 22 — sole traders, individuals, and partnerships that are not LLPs — need consent for marketing email, so we do not cold-email them at all. In the US we send under CAN-SPAM, which draws no such distinction. See “Cold outreach to businesses” below for who we email and who we do not.
  • Abuse-prevention logging: when a request is made to our public intake endpoints (the free scan and booking requests), we briefly log request metadata — the IP address, the network (ASN) and country your provider exposes, the user-agent, and the outcome. If a request is rejected by our anti-abuse filters, we may also keep a short sample of the specific submitted content that triggered the block (for example, a business-name field or booking note that contained a link or promotional text) as evidence; this is content the sender chose to include, and we do not attach your account email to it. We use all of this only to detect, investigate and prevent abuse of these endpoints. Lawful basis: legitimate interest (network and information security). These records auto-expire after 90 days.

Verified reviews and removing yours

Reviews on VisibleFront are verified: each one is tied to a booking made through us. To keep them trustworthy, published reviews are not edited — not by us, and never for money. The business owner may publish a public response, but cannot change or remove your words.

What we publish: your rating, your review text, your first name plus last initial (for example 'Sarah J.'), and the date. What we keep private: the full name you typed, the link to your booking, and the time you consented — these are never published.

You can have your own review removed at any time. Use the 'Remove my review' link next to your review on the business's profile page (it opens an email to support@visiblefront.com carrying your review's reference), or email hello@visiblefront.com describing the review. To protect you, we confirm the request comes from the person who wrote the review — normally by checking it was sent from, or confirmed via, the email address used for the booking. Once verified, we remove the review from the profile page, the machine-readable data, and any rating average within 30 days — usually much sooner.

Cold outreach to businesses

We send a small number of cold emails to local businesses in the UK and the US, about how AI assistants answer the questions their customers ask. The contact details we use come from public sources — the business's own website, its public listings and directory entries. We do not buy contact lists.

Where the recipient is a company, LLP or other corporate body, we rely on legitimate interest under the UK GDPR: we are writing to a business, at a contact address that business publishes, about that business's own public visibility. Under PECR regulation 22 — the UK rule that governs unsolicited marketing by email — a business of that kind is a “corporate subscriber”, and that is the basis we rely on for those emails.

Sole traders, individuals, and ordinary partnerships that are not LLPs are “individual subscribers” under PECR regulation 22, and we treat them as individuals. Regulation 22 requires their consent before unsolicited marketing email, and legitimate interest is not a substitute for it, so we do not cold-email them at all. They hear from us only where they asked to — for example by requesting a free scan — or have otherwise given consent.

So that the line means something in practice, we check company status before we send. Before a UK business goes on a send list, we look it up on the public register at Companies House (and, in regulated sectors, the regulator's public register, which names the entity that runs a practice). If the public register does not show a company, LLP or other body corporate behind the business, it does not get a cold email from us — it is dropped from the campaign, and we record that decision with the list.

In the United States we send under CAN-SPAM, which does not divide recipients into corporate and individual subscribers. Those emails carry the same identification, the same one-click unsubscribe, and the same permanent suppression described below.

Every message identifies us by name, company number and registered address, and gives you a way out: a one-click unsubscribe, and a plain reply asking us to stop, which works just as well.

Opting out is permanent. When you unsubscribe, reply asking us to stop, or report a message as spam, we mark your record as unsubscribed — and every system we send from reads that same record, so it ends outreach across all of our campaigns, not only the one you replied to. We keep that record for exactly one purpose: so that we can keep not contacting you.

You can object to this processing at any time, before or after we write, by emailing hello@visiblefront.com — we will stop, and we do not ask for a reason. You also have the right to complain to the Information Commissioner's Office; see “Your rights” below.

How we protect your privacy

We have built privacy into how the service works, not just into this policy:

  • Our website analytics is Cloudflare Web Analytics: privacy-first and cookieless, with no personal data and no cross-site tracking.
  • For rate-limiting, we identify a visitor by a SHA-256 hash of their IP — the rate-limit keys are date-scoped and expire automatically, not stored as raw IPs. Separately, for abuse prevention only, our intake endpoints keep a short-term security log that does include the raw IP alongside the hash; that log is access-restricted, used solely to detect and prevent abuse, and auto-expires after 90 days.
  • Business data passed to the AI guide/concierge is sanitised and fenced as reference-only, as a defence against prompt injection.
  • We use essential cookies only (login/session via Supabase Auth, and cookies Stripe may set during checkout). We use no advertising or tracking cookies.

Cookies

We use essential cookies only. These are the cookies needed to keep you logged in and to run your session (via Supabase Auth), and any cookies Stripe sets while you are going through checkout.

We do not use advertising or tracking cookies, and our analytics (Cloudflare Web Analytics) is cookieless, so it does not set cookies or track you across sites.

Who we share your data with (our sub-processors)

We do not sell your personal data. We share it only with the service providers we need to run VisibleFront. Each one acts on our behalf, or receives data only for the purpose listed below:

  • Cloudflare: hosting, CDN, edge compute, key-value storage, and privacy-first website analytics (Cloudflare Web Analytics).
  • Supabase: our database and authentication.
  • Stripe: payment processing.
  • Resend: transactional and notification email.
  • OpenRouter (and the underlying AI model providers it routes to): powers the dashboard AI guide/concierge.
  • The AI assistants we measure (OpenAI/ChatGPT, Google/Gemini, Perplexity): they receive public business queries during a scan, and they do not receive any end-customer personal data.
  • Google: OAuth, and only if an owner chooses to connect Google Calendar.

International transfers

Some of our sub-processors are located outside the UK and EEA, for example in the United States.

Where personal data is transferred internationally, we rely on appropriate safeguards, such as the UK International Data Transfer Agreement / Addendum, the EU Standard Contractual Clauses, or an adequacy decision.

How long we keep your data

We keep scan/lead and account data while the account or relationship is active, and for as long as we need it to meet our legal, tax and accounting obligations. After that, we delete or anonymise it.

The hashed keys we use to rate-limit the free scan are date-scoped and expire automatically. Our abuse-prevention security log of intake request metadata (including raw IP) auto-expires 90 days after each entry.

Your rights

Under the UK GDPR you have the following rights over your personal data:

  • Access: ask for a copy of the personal data we hold about you.
  • Rectification: ask us to correct data that is wrong or incomplete.
  • Erasure: ask us to delete your data.
  • Restriction: ask us to limit how we use your data.
  • Portability: ask for the data you gave us in a portable, machine-readable format.
  • Objection: object to our processing where we rely on legitimate interest, including the right to object to direct marketing at any time.
  • Withdraw consent: where we rely on your consent, you can withdraw it at any time, without affecting processing already carried out.

To exercise any of these rights, email us at hello@visiblefront.com. You also have the right to complain to the Information Commissioner's Office (ICO), the UK's data-protection regulator, at ico.org.uk. We would appreciate the chance to address your concern first, but you can go to the ICO at any time.

Children and under-18s

VisibleFront is a business-to-business service for local businesses and their owners. It is not directed at children, and we do not knowingly collect personal data from anyone under 18.

If you believe a child has provided us with personal data, contact us at hello@visiblefront.com and we will delete it.

Changes to this policy

We may update this policy from time to time. When we make a material change, we will update the “last updated” date shown at the top of this page and, where appropriate, notify users.

Questions? Email hello@visiblefront.com. See also our Terms of Service.