Privacy
Last updated 5 August 2026
The short version. Companies and prospects Live Search finds — with where each fact came from and when — are stored on our server, because a real web search costs real money against your own provider key and cannot be safely left to a browser cache. We hold your account — name, email address and a hashed password — and every credential you connect, encrypted. We use no analytics, no advertising and no third-party trackers of any kind, and we never sell, share, or use your data to train anything.
Who we are
StarlineSales is operated at starlinecart.com. For anything in this policy, write to privacy@starlinecart.com.
Companies and prospects Live Search finds
Every company, prospect, search run and AI research pass Live Search produces is stored on our server against your account — the name, domain, website, industry and location it found, the exact source URL and confidence for each fact, and any notes or tags you add. This is a change from an earlier version of this product, where that data lived only in your browser; it moved to the server because provenance and search cost cannot be honestly tracked in a store we cannot see, and a repeated search would otherwise silently re-spend money against your own connected key.
This data is yours: exportable and deletable on request, never sold, shared, or used to train anything, and never made into a public or indexable page regardless of how it was found.
What we hold
Your account
- Name and email address, so you can sign in and we can reach you.
- A bcrypt hash of your password. We never store the password itself.
- Role and status, which determine what you can do.
- When the account was created, last updated, and last signed in.
- If you signed up yourself, the date your email address was confirmed.
Sessions and security records
- An identifier for each active session, your network address and browser user-agent, so you can see and end your own sessions.
- An audit log of sign-ins, sign-outs and account changes, with time and network address.
- Failed sign-in attempts, keyed to the email tried and the address it came from, to limit password guessing. Discarded after fifteen minutes.
- An email-verification or password-reset link, if you requested one: stored only as a one-way hash, never the link itself, and deleted the moment it is used or expires (24 hours for verification, one hour for a reset).
Credentials you connect
If you connect a mailbox, a search provider (Serper) or an AI provider (OpenAI), those credentials are encrypted with AES-256-GCM and stored outside the web root. They are used only to carry out actions you start, are never sent to the browser, and can be disconnected at any time in Settings.
What we do not do
- No analytics, no advertising, no tracking pixels, no third-party scripts.
- No selling, renting or sharing of personal data. There is no arrangement under which anyone else receives it.
- No profiling and no automated decisions with legal effects.
- No cookies beyond one strictly-necessary session cookie.
Cookies
One cookie, named starline_session. It keeps you signed in, is
marked Secure, HttpOnly and SameSite=Lax, and expires when you close your
browser. There is no cookie banner because there is nothing to consent to.
Email you send through the product
Messages are sent directly from the mailbox you connect to the recipient's mail server. They do not pass through our infrastructure and we keep no copy. Your mail provider's own privacy policy applies to them.
You are the data controller for the people you contact. You are responsible for having a lawful basis to email them and for honouring their requests. See the terms.
How long we keep things
- Account records — until the account is deleted.
- Companies, prospects, search history and research — until you delete them or your account, whichever comes first.
- Sessions — until you sign out, or 30 days without use.
- Audit log — retained for security. Tell us if you need it removed and we will explain what we can do.
- Failed sign-in attempts — fifteen minutes.
Your rights
If you are in the UK or EU, the UK GDPR and GDPR give you rights of access, correction, erasure, restriction, portability and objection. Write to privacy@starlinecart.com and we will respond within 30 days. You may also complain to your data protection authority; in the UK that is the ICO.
Our lawful basis for holding your account is performance of a contract — we cannot provide an account without it. For security logging it is legitimate interest in keeping accounts safe.
Where data is held
All account, company, prospect and research data is stored on servers operated by our hosting provider. Live Search itself calls out to your own connected search provider (Serper) and AI provider (OpenAI) to run searches and generate research and drafts — those providers process the query text and generated content under their own privacy policies.
Children
StarlineSales is a business tool and is not directed at anyone under 16.
Changes
If we change this policy in a way that affects you, we will email account holders before it takes effect. The date at the top always reflects the current version.
Beta notice. This policy describes what the software actually does today and has not yet been reviewed by a qualified lawyer. It will be before StarlineSales leaves invited beta.