Privacy policy
Effective August 14, 2026
This policy explains how FundLookup (“we”, “us”) handles personal data. It is written for Google’s OAuth verification and for people who use the product. If you have questions, email admin@fundlookup.co.
Who we are
FundLookup is a hosted finance ledger for performance-marketing teams. The service is operated by Devdabs. The product site is fundlookup.co. The signed-in application is app.fundlookup.co. Platform administration is admin.fundlookup.co.
What we collect from your FundLookup account
When you create an account or join a company, we store the information you provide: name, email, password hash, company identity, bank details you enter for invoices, buyer and publisher records, invoice amounts, expenses, and similar ledger data. We also store session cookies so you stay signed in, and server logs that may include IP address, timestamps, and URLs for security and debugging.
Google user data (Sheets import)
Connecting Google is optional. If you choose Connect Google Sheets, we request these Google scopes:
- spreadsheets.readonly: read cell values from a spreadsheet you pick
- drive.metadata.readonly: list spreadsheet names and ids so you can choose a file
- userinfo.email: show which Google account is connected
We use that access only to import historical buyer and publisher rows that you map and confirm. We store a refresh token for your company so you do not have to reconnect every import, plus the Google email of the connected account. We do not request write access. We do not scan your Drive. We do not read spreadsheets you never select in FundLookup.
After import, the copied ledger rows live in your FundLookup company like any other invoice data. The Google file itself stays in Google.
Google API Services User Data Policy and Limited Use
FundLookup’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- We use Google user data only to provide and improve the Sheets import feature you see in the app.
- We do not sell Google user data.
- We do not use Google user data for advertising, including retargeting, personalized ads, or ads measurement.
- We do not allow humans to read Google user data unless you give us permission, it is necessary for security or legal compliance, or the data is aggregated and no longer tied to you, all as allowed by Google’s Limited Use rules.
- We do not transfer Google user data to third parties except as needed to run the import feature on our hosting infrastructure, or as required by law.
How we use other data
Account and ledger data is used to operate FundLookup: invoices, emails you ask us to send, reports, access control, and support. We do not sell it. We do not use it to build advertising profiles.
Sharing
People in your company see data according to their role. We use infrastructure providers to host the app and database, and an email provider if you configure SMTP. Those processors see data only to provide that service. We may disclose information if required by law or to protect users from fraud or abuse.
Retention and deletion
Ledger data stays until your company deletes records or the account is closed. To disconnect Google, open Integrations in the app and choose Disconnect. That removes the stored Google refresh token and email from our database. Previously imported invoices are not automatically deleted; you can delete those in FundLookuplike other records. To request deletion of a company or account, email admin@fundlookup.co from the address on the account.
Security
Access is authenticated. Secrets such as Google refresh tokens are stored encrypted at rest where the app encrypts secrets. Transport uses HTTPS on the public site. No method is perfect; protect your password and invite links.
Cookies
We use a session cookie after you sign in to FundLookup. The marketing pages do not require that cookie. We do not use advertising cookies.
Children
FundLookup is for business use. It is not directed at children under 13, and we do not knowingly collect their data.
Your choices
You can access and update much of your data in Settings. You can disconnect Google. You can ask us for a copy or deletion of account data by emailing admin@fundlookup.co. If you are in a region with additional privacy rights, we will honor valid requests.
Changes
We may update this policy. The effective date at the top will change. Material changes that affect Google user data will be reflected here before we expand how that data is used.
Contact
Privacy requests: admin@fundlookup.co. Related: Terms of service.