Last updated: 2026-07-10. Nullify Group is a California-based company offering privacy removal services to high-net-worth individuals, executives, and public figures. This policy applies to our website, marketing, onboarding, and the ongoing delivery of our services.
By visiting nullifygroup.com, engaging with our intake process, or subscribing to our services, you agree to the data practices described below. If you have any questions about this policy, contact us at support@nullifygroup.com.
Data Collection
We collect only the information necessary to deliver, support, and bill for privacy removal services, and to improve our website experience for prospective clients.
Categories of information we collect:
- Identity and contact information — Name, email address, phone number, and mailing address. Collected during onboarding and used for account management and service correspondence.
- Payment information — Billing name and Stripe transaction records. Card data is processed by Stripe; Nullify Group does not store raw card numbers.
- Broker-finding data — Information about data broker sites where your profile appears, including listing URLs, screenshots, and removal status. Used exclusively to perform the privacy removal services you have requested.
- Website analytics — Anonymous visit data via a first-party beacon (see Cookies & Analytics below).
How we collect it: Most information is provided directly by you during onboarding, intake calls, or correspondence. Broker-finding data is generated by Nullify Group on your behalf during the performance of the service.
Data Retention & Storage
We retain your personal information only for as long as needed to provide the service or to comply with legal, tax, and accounting obligations.
- Account & service records — Retained for the duration of the subscription and up to 7 years after termination to satisfy recordkeeping obligations.
- Financial transaction records — Retained per applicable tax and accounting regulations. Not used for any purpose other than compliance and audit.
- Broker-finding data — Retained while you are an active subscriber so we can re-suppress listings that reappear after removal. Deleted within 90 days of account termination, unless you ask us to delete sooner.
- Marketing leads — Retained until you request deletion or until 24 months have elapsed since last contact, whichever comes first.
All data is stored in encrypted-at-rest PostgreSQL databases hosted on Neon (US region) and accessed only by authorized personnel subject to confidentiality obligations.
Third-Party Sharing
Nullify Group does not sell your personal information. We share information only with the narrow set of service providers needed to operate our business and with authorities when legally required.
- Payment processor (Stripe) — Processes your billing information under Stripe's own privacy policy. Card data is never stored on Nullify Group systems.
- Hosting and database providers (Render, Neon) — Store our application and database infrastructure. Each provider offers encrypted storage and access controls.
- Authentication provider (Clerk) — Powers the client portal login flow, including MFA and magic-link recovery.
- Law enforcement — We will disclose information only when legally required (e.g., valid subpoena, court order, or to prevent imminent harm).
We do not share data with advertisers, data brokers, marketing networks, or affiliates for promotional purposes.
Your Rights
You have a right to know what we hold, to correct inaccuracies, to request deletion, to limit sensitive data use, to opt out of any sale or sharing, and to receive a portable copy of your data.
For a full description of each right — including how to submit a request and our response timelines — see Your Privacy Rights.
- California residents: Rights under CCPA/CPRA apply.
- EU/EEA visitors: Rights under GDPR apply where relevant.
- All visitors: You may always contact support@nullifygroup.com with any privacy question or request.
Cookies & Analytics
Nullify Group uses a minimal, first-party analytics beacon. We do not use third-party advertising cookies or cross-site tracking.
- First-party beacon — A small JavaScript snippet loaded by our own infrastructure records anonymous visit IDs in your browser's localStorage. No cross-site identification, no advertising.
- Essential session cookies — Used to keep you signed in to the client portal. These expire when you log out.
- No third-party trackers — We do not embed Facebook, Google Ads, TikTok, or similar third-party pixels on nullifygroup.com.
You can clear our beacon by clearing your browser's localStorage for nullifygroup.com at any time. Doing so will not affect your ability to use the site or the client portal.
Security
We protect your information with industry-standard technical and organizational safeguards.
- Encryption in transit — All web traffic is served over HTTPS with TLS.
- Encryption at rest — Database storage is encrypted at rest by our hosting providers.
- Access control — Only authorized Nullify Group personnel with a business need can access client data, and access is logged.
- Authentication — Client portal access requires multi-factor authentication (MFA) via Clerk. Operator access requires HMAC-signed session cookies and, for sensitive endpoints, JWT bearer tokens.
No system is perfectly secure. If we ever become aware of a breach affecting your personal information, we will notify you and applicable authorities as required by law.
Children's Privacy
Nullify Group's services are intended for adults. We do not knowingly collect personal information from anyone under the age of 18.
If you believe we have collected information from a minor, please contact support@nullifygroup.com and we will delete it promptly.
Changes to This Policy
We may update this policy from time to time to reflect changes in our practices, our services, or applicable law. When we make material changes, we will:
- Update the "Last updated" date at the top of this page.
- Notify active subscribers via email at least 14 days before the change takes effect.
- Archive previous versions on request via support@nullifygroup.com.
Contact Information
For all privacy-related questions, requests, or concerns, contact our privacy team:
Email: support@nullifygroup.com
Response time: We aim to respond to all privacy inquiries within 30 days. For urgent matters — such as a suspected data breach or imminent safety concern — please indicate this in your subject line and we will prioritize accordingly.
If you are not satisfied with our response, California residents may contact the California Attorney General's office at oag.ca.gov/privacy.
Questions about this policy or your data?
support@nullifygroup.com