1. Scope, controller, and acceptance
Hub or Dub Inc. is the data controller (and, where applicable, the “business” under U.S. state privacy laws and the “consumer reporting agency” under the FCRA) responsible for personal information processed through the Services. By accessing or using the Services, you acknowledge that you have read, understood, and agreed to this Policy, the Terms of Service, and the Terms of Use.
2. Information we collect
2.1 Information you provide
- Account and identity data: name, date of birth, address, email, phone, profile photo, government-issued identifier where required to satisfy anti-fraud, know-your-customer, sanctions, and consumer-reporting obligations.
- Billing data: billing address, tax identifier, and tokenized payment credentials (card details are never stored on our servers in plaintext).
- Submissions and evidence: reports, responses, disputes, appeals, correspondence, and any documents, links, images, videos, or other evidence you attach.
- Communications: support tickets, survey responses, and correspondence.
2.2 Information collected automatically
- Device, browser, IP address, operating system, language, timezone, referrer, session identifiers, cookies, and similar telemetry.
- Usage events: pages viewed, features used, reports accessed, submissions made, and timestamps.
- Security events: authentication activity, sanctions screening outcomes, and abuse detection signals.
2.3 Information gathered by HOD Engine
HOD Engine indexes lawfully accessible public sources worldwide, including court records, regulatory filings, sanctions and watchlists, corporate registries, public news media, public business listings, archived web pages, licensed public-record databases, and other lawfully accessible sources. We do not collect information that is private, access-restricted, or unlawfully obtained. Every finding is linked to its underlying source and is subject to manual Back Office review before it can influence an HOD Report or HOD Score.
2.4 Global identity registry
To ensure each person and each business has exactly one permanent HOD profile worldwide, we operate a Global Identity Registry keyed off national identifiers (SSN in the United States, FEIN for U.S. businesses, and the equivalent official national identification or business registration number in other jurisdictions). The raw identifier is normalized, salted, and irreversibly SHA-256 hashed for lookup, and separately AES-256-GCM encrypted at rest server-side with a key stored outside the database. Only the last four characters are retained in plain form for user-facing display ("ending in ••1234"). The full raw value is never logged, never returned to the browser, and is accessible only through narrowly scoped, individually audited privileged operations. Every lookup is recorded with the requesting user, timestamp, permissible purpose, IP address, and match outcome, and rate-limited per user. This registry prevents duplicate or conflicting reports across jurisdictions, strengthens fraud prevention and identity verification, and enables real-time global lookup of the single authoritative HOD profile.
3. How we use information
- To operate, secure, monitor, and improve the Services.
- To verify submissions and evidence through mandatory manual review by our Back Office.
- To generate, update in real time, score, and deliver HOD Reports, HOD Scores, and HOD Certificates.
- To process payments, prevent fraud, detect abuse, and enforce our agreements.
- To honor consumer reporting rights, including free file disclosures, disputes, adverse action support, and security freezes.
- To comply with legal obligations, court orders, regulatory requests, sanctions screening, and anti-money-laundering requirements.
4. Legal bases
Where GDPR, UK GDPR, LGPD, or comparable laws apply, we rely on: (i) performance of a contract, (ii) legitimate interests (including operating and securing the Services, preventing fraud, processing lawfully accessible public information for reputation intelligence, and journalistic or public-interest processing under Article 85 GDPR and equivalents), (iii) legal obligation (including FCRA, tax, accounting, sanctions, and AML), and (iv) consent (for biometric processing, non-essential cookies, and marketing).
5. Sharing and disclosure
- Verified subjects and their authorized representatives receive the report content that pertains to them.
- Users of an HOD Report who have certified a permissible purpose receive the report they requested.
- Service providers (hosting, analytics, payments, email, identity verification, sanctions screening, fraud prevention, customer support) are bound by written data-processing terms. See the Subprocessors list.
- Professional advisors, auditors, insurers, and successors in interest in connection with corporate transactions.
- Regulators, courts, and law enforcement acting under valid legal process, or where necessary to protect rights, property, or safety.
We do not sell personal information for monetary consideration and do not share it for cross-context behavioral advertising.
6. Consumer reporting agency disclosures (United States)
Hub or Dub operates as a consumer reporting agency (“CRA”) under Section 603(f) of the Fair Credit Reporting Act, 15 U.S.C. § 1681a(f). When an HOD Report is furnished for a permissible purpose under 15 U.S.C. § 1681b, it is a “consumer report.” Consumer rights include:
- Free file disclosure once every twelve months and additional disclosures in the circumstances required by 15 U.S.C. § 1681j.
- Dispute and reinvestigation under 15 U.S.C. § 1681i, completed within thirty (30) days (up to forty-five (45) days if additional information is supplied during the investigation).
- Adverse action notices from users of a consumer report under 15 U.S.C. § 1681m, including our name, address, and toll-free contact channel.
- Security freezes and fraud alerts under 15 U.S.C. § 1681c-1 at no cost.
- Identity theft rights, including the ability to block information resulting from identity theft under 15 U.S.C. § 1681c-2.
- Additional rights under equivalent state statutes, including the California Consumer Credit Reporting Agencies Act, the New York Fair Credit Reporting Act, the Maine Fair Credit Reporting Act, and comparable state laws.
Detailed procedures and the required Summary of Rights are set out in the FCRA & CRA Compliance page and in every adverse action notice we generate.
7. U.S. state privacy rights
Residents of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and Washington (in relevant scope) have rights to know, access, delete, correct, port, opt out of profiling for legally significant decisions, opt out of targeted advertising, opt out of sale or sharing, and appeal denials. We honor Global Privacy Control (GPC) signals as valid opt-out requests. Sensitive data is processed only for purposes permitted by law. Rights that would require deletion or modification of a lawfully retained consumer report are handled through the FCRA dispute and correction process rather than deletion. See the U.S. State Privacy Rights page.
8. International rights
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have rights under the GDPR, UK GDPR, or FADP to access, rectify, erase (subject to journalistic and public-interest exemptions under Article 85 GDPR and equivalents), restrict, object, port, and withdraw consent. Automated decision-making producing legal or similarly significant effects is subject to Article 22 safeguards, including the right to obtain meaningful information about the logic involved and to request human review. Every HOD Report is subject to mandatory manual Back Office review prior to publication. Additional jurisdiction-specific disclosures, including the identity of our EU representative and UK representative, are set out in the International Privacy & Data Protection Disclosures.
9. Cross-border transfers
The Services operate globally. Personal information may be processed and stored in the United States and in other jurisdictions where our infrastructure operates, in each case with contractual and technical safeguards including EU Standard Contractual Clauses, the UK International Data Transfer Addendum, Swiss FADP addenda, Brazilian ANPD-approved transfer mechanisms, and analogous instruments. Where required, we perform transfer impact assessments and apply supplementary measures.
10. Biometric and identity-verification data
To activate your account we perform identity verification, which may include comparison of a live selfie to a government-issued photo ID. Where this constitutes biometric information under the Illinois Biometric Information Privacy Act (740 ILCS 14), the Texas Capture or Use of Biometric Identifier Act, the Washington biometric law, EU GDPR Article 9, or comparable laws, we (i) obtain your written consent through a separate biometric consent disclosure logged with a timestamp, (ii) use the data solely for identity verification and fraud prevention, (iii) never sell or profit from it, and (iv) retain it only for the period reasonably necessary and no longer than three (3) years after your last account interaction unless a longer period is required by law. You may request deletion of biometric templates at any time by writing to privacy@hubordub.com.
11. HOD Wallet and financial data
Purchases, credit top-ups, deductions, refunds, and adjustments are recorded in an append-only ledger visible in your account. Card details are tokenized by our payment processor and are never stored on Hub or Dub servers in plaintext. Financial records are retained for the period required by tax, accounting, and anti-money-laundering laws (typically seven (7) years).
12. Retention and deletion
We retain personal information only for as long as necessary for the purpose described in this Policy or as required by law. Verified findings, source references, dispute records, and audit trails that form part of our consumer reporting activity are retained for the period required by the FCRA (including the seven- and ten-year windows under 15 U.S.C. § 1681c), by comparable international laws, and by our reasonable business need to demonstrate the integrity of the record. Account-level data is retained for as long as necessary to provide the Services, comply with law, resolve disputes, and enforce our agreements. Deletion requests are honored through the process described in Section 7 and the Privacy Rights page.
13. Security
We apply administrative, technical, and physical safeguards including encryption in transit (TLS 1.2+) and at rest (AES-256), key rotation, role-based access controls, least-privilege enforcement, network segmentation, logging, continuous monitoring, and independent testing. No system is perfectly secure. Detailed controls are set out in the Security & Trust Standards.
14. Breach notification
If we determine that a personal-data breach is reasonably likely to result in a risk to your rights or freedoms, we will notify the relevant supervisory authorities and, where required, affected individuals without undue delay and, where feasible, within the statutory windows applicable to the breach (including 72 hours under GDPR Article 33 and applicable U.S. state breach notification laws). We maintain an incident response plan, retain forensic evidence, and cooperate with regulators.
15. Your choices and rights
Subject to applicable law, you may exercise access, correction, portability, restriction, objection, deletion (subject to CRA retention obligations), and withdrawal-of-consent rights through your account, through Privacy Center, through the Disputes flow (for factual corrections to findings), or by writing to privacy@hubordub.com. We respond within the statutory timeline applicable to your jurisdiction (typically forty-five (45) days under U.S. state privacy laws, with one permitted extension; thirty (30) days under GDPR/UK GDPR with permitted extension for complex requests). You may also lodge a complaint with your local data protection authority or consumer regulator at no cost.
16. Source records and audit trail
For every finding, we retain a reference to the underlying source (URL, citation, capture timestamp, and cryptographic hash where applicable) so that the finding can be independently re-verified by you, by us, and through the dispute process. Reviewer decisions and system events are written to an immutable audit log.
17. Cookies and similar technologies
We use strictly-necessary, functional, analytics, and (with your consent where required) preference cookies. Details, categories, and controls are described in the Cookie Policy. You can manage preferences at any time from the “Cookie settings” control in the site footer.
18. Children
The Services are not directed to individuals under eighteen (18). We do not knowingly collect personal information from minors. If you believe we have inadvertently collected such information, contact privacy@hubordub.com.
19. No implied endorsements
We do not use celebrity names, photos, voices, or other likenesses to imply sponsorship or endorsement. This restriction is enforced across marketing and product surfaces.
20. Changes to this Policy
We may update this Policy from time to time. Material changes will be announced through the Services and, where required, by email. Continued use after the effective date constitutes acceptance.
21. Contact and regulatory representatives
Hub or Dub Inc., Privacy Office, privacy@hubordub.com. EU and UK representatives are identified in the International Disclosures page. Data protection authority contact details for your jurisdiction are also listed there.
