Marketplace Privacy Notice
Effective August 12, 2026
Ubiquity Prospector is operated by INVENTUM DIGITAL, INC., which sells the marketplace service. Contact: prospector@ubq.fi
Prototype and European review gate
This notice describes the marketplace prototype for a controlled beta, if offered. Any controlled beta access is limited testing; it is not public publication, general availability, or approval by Ubiquity, LinkedIn, a store, or a regulator. A qualified legal review is required before a launch in Europe, including the European Economic Area, the United Kingdom, and Switzerland. This notice is not a confirmation that the prototype is ready for that launch.
Who this notice covers
It covers a buyer who requests People or standalone Account records, a contributor who opts in to capture assigned records, and an account that uses the Assistant, the Chrome extension, Checkout, or the public Example results. It supplements the existing account and workspace notice for features outside the marketplace. If the two notices conflict, the more specific marketplace notice applies to marketplace processing.
Information we collect
- Account and connection data: app account, session, workspace and role, extension installation, bounded LinkedIn identity observation, display name, connection times, consent or eligibility state, and account status. The server stores only the permitted protected identity match and display name. It does not receive or store LinkedIn credentials, cookies, authenticated HTML, MHTML, raw page snapshot, or browser session. A Prospector application bearer token is used for application authentication when bounded parsed records and client metadata cross from the extension.
-
Buyer request and result data: the audience prompt, the Assistant's
raw answer, typed search plan, approximations, filter readback, quote, quantity,
price cap, order and cancellation state, returned People and Account records, and
employment history used for Account coverage. A result can be marked
pending,captured,inaccessible, orunresolvable. - Contributor and browser data: a node's opt-in state, assigned search and page checkpoints, visible canonical IDs, parsed bounded records, capture outcome, retry and lease events, and accepted reward decisions. LinkedIn navigation, DOM parsing, extraction, retries, and local backups remain in the extension.
- Payments and credits: Checkout and webhook receipts, quote and order references, reservations, charges, releases, refunds, purchased credits, subscription credits, signup credits, streamed credits, earned credits, promotional credits, and platform-funded rewards. Stripe processes payment details on its hosted payment page.
- Platform-wide Example results: professional records observed on the platform within the previous 90 days may be projected as labelled Example results. Before an example is shown, we remove workspace membership, collector identity, notes, tags, campaigns, exports, source URLs, private fields, and diagnostics. Example results are not a buyer's order and are not a promise that a record is available for delivery.
Credit records
The contributor onboarding/node flow issues the one-time 100-credit signup grant lazily when an eligible contributor node is first started or subsequently read; the grant does not expire. Marketplace records also include streamed or earned contributor credits. Signup, streamed, and earned credits are non-cash, non-transferable, non-resalable, and non-redeemable. Eligibility depends on the product surface that grants or uses a balance; this notice does not state a product-wide spend order or promise that a signup grant funds a Marketplace order.
Assistant prompts, answers, and example reuse
The Assistant uses the audience text to produce an editable typed plan. We retain the raw Assistant prompt and raw Assistant answer for service operation, support, abuse review, cost accounting, and audit. We record example IDs, provider cost, and whether a semantically equivalent prompt reused an existing example. An equivalent example can be reused at the configured similarity threshold; the account receives no more than four example searches, 25 profiles per search, and 100 unique example profiles in its lifetime. We keep earlier examples and chat available after that allowance is used.
Security and acquisition telemetry
For fraud prevention, rate-limit enforcement, security investigation, abuse analysis, reliability, provider-cost accounting, and aggregate acquisition reporting, we may append subsidy and platform-funded action events. Relevant events can include account and session, source, landing path, campaign tags, action, outcome, replay identity, latency, retries, provider and model, input and output token counts, estimated provider cost, credit reservations, charges, releases, rewards, example IDs, semantic reuse, verification, page discovery, Account enrichment, duplicate rewards, the exact server-observed IP address, a security fingerprint, and an observational cluster identifier.
Exact IP addresses, security fingerprints, and cluster identifiers are restricted to Admin telemetry and security operations. They are observational evidence only. Product code does not read risk scores or cluster evidence, and these values cannot change a user's limits, price, credits, access, order results, or onboarding. Ordinary user APIs do not return them. A public presence map shows only delayed, coarse regions and healthy eligible counts; it never shows an exact IP, account, security fingerprint, or cluster.
Why we use information
- To create and explain typed plans, quotes, orders, result delivery, and cancellation.
- To assign bounded browser work, settle accepted records, prevent duplicate charges, and pay internal rewards.
- To provide labelled Example results without exposing a workspace or contributor identity.
- To authenticate accounts, bind the permitted extension and LinkedIn observation, and protect the browser boundary.
- To prevent fraud and abuse, measure reliability and provider cost, answer support requests, and meet legal duties.
Sharing and access
We share the minimum information needed with hosting, authentication, AI, push notification, payment, and support providers. Providers act for the service under their applicable terms. We do not sell marketplace records, raw prompts, raw answers, exact IP addresses, security fingerprints, or cluster evidence. A contributor sees the work needed for the assigned capture, not the buyer's identity or prompt. A buyer receives accepted order records, not contributor identity or private diagnostics. Admins with the existing Admin role may inspect acquisition telemetry. An impersonation session cannot access it. Admin raw inspection is audited without copying the inspected raw value into that audit event.
Retention
Raw sensitive telemetry includes raw Assistant prompts, raw Assistant answers, normalized exact server-observed IP addresses, security fingerprints, and observational cluster identifiers. We retain that raw sensitive telemetry for 13 months for the purposes above. A scheduled database pass purges expired raw values. After purge, only non-sensitive aggregates needed for lifetime totals, accounting, fraud controls, and legal duties remain. Accounting, audit, reward, order, payment, and legal records, including accepted People and Account records and credit ledgers, may be retained as needed for delivery, dispute handling, accounting, security, and legal obligations. Local extension backups follow the contributor's browser storage controls and are not a server copy of a LinkedIn session.
Your choices and requests
You may stop contributing, cancel a pending order, and ask the support channel for access, correction, or deletion where applicable. We may retain records that are needed for a payment dispute, security investigation, legal obligation, or an auditable credit or reward settlement. We will explain a refusal or limitation where applicable. We may update this notice when the service or legal requirements change and will update its effective date.