Privacy
Controller: Michele Mattei · Contact: info@buildersinfintech.ai
Builders in Fintech is a publication: daily news, a weekly newsletter, a podcast, and a public database of fintech companies, investors, people, funding rounds and events. This notice explains what personal data we handle, why, and what you can ask us to do with it. We collect as little as we can.
If you read the site
- No cookies for readers. Reading the site sets no cookies and needs no account.
- Analytics. We use Plausible Analytics, which counts page views without cookies and without collecting personal data or tracking you across sites. See Plausible's data policy.
- Server logs. Our hosting provider keeps standard technical logs (IP address, browser type, page requested, time) for security and troubleshooting. Legal basis: our legitimate interest in keeping the site secure (Art. 6(1)(f) GDPR).
- Images and thumbnails from other sites. Some article images, podcast thumbnails and newsletter images are loaded directly from the publisher's or platform's server (for example a news site, YouTube or Substack). When your browser loads them, that server receives your IP address and browser details, as with any web request. We do not receive or control that data; the other site's own privacy policy applies.
- Embedded players. Podcast videos are shown as a still image until you press play; only then does YouTube load and may set its own cookies.
If you write to us or send a pitch
- Email. If you write to info@buildersinfintech.ai we keep your message and address for as long as needed to reply and for our records. Legal basis: our legitimate interest in answering and keeping correspondence (Art. 6(1)(f)).
- Pitch form. We keep what you submit (company, your name and email, links and your message) to review it and, if there is a fit, to talk to you. Legal basis: steps you ask us to take before a possible agreement (Art. 6(1)(b)) and our legitimate interest in evaluating proposals (Art. 6(1)(f)). Pitches we pass on are deleted after 24 months, and every pitch is deleted after 36 months at the latest. To prevent abuse we store a one-way hash of your IP address, never the address itself.
- Embargo Desk submissions. When you submit an announcement under embargo, we store the details you provide (company, press release, embargo time, and your name, role, work email and optional phone) to prepare and publish our coverage. Your contact details are deleted 12 months after publication or after we decline the submission. We store a hashed version of your IP address to prevent abuse; we cannot reverse it.
- Product listings. When you submit a product for listing, we store the details you provide (company, product information, and your name, role and work email) to review and publish the listing. Your contact details are deleted 12 months after we approve or decline the submission. We store a hashed version of your IP address to prevent abuse; we cannot reverse it.
If you are named in our database
The database lists people in their professional role in fintech: founders, executives, investors and podcast guests.
- What we hold: your name, job title and organisation, your role in companies, funding rounds or events we cover, links to your public professional profiles, and the articles, newsletter issues or episodes that mention you. We do not hold contact details, private information or any special category of data.
- Where it comes from: public sources only — company and investor announcements, press releases, regulatory filings, reputable press, your public professional profiles, and what you said as a podcast guest.
- Why and on what basis: to report on the fintech industry and keep an accurate public record of who is building it. We rely on the freedom of expression and information for journalistic purposes (Art. 85 GDPR and the Italian Privacy Code, Articles 136–139) and on our legitimate interest in publishing that record (Art. 6(1)(f)).
- Who can see it: anyone. The records are public on the site, in our open dataset files and through our MCP connector, which AI assistants can query.
- How long: for as long as the information stays relevant to the record of the industry. We correct or remove it when it is shown to be wrong, or when your objection outweighs the public interest in the record.
- Your right to object: you can object at any time to being listed, or ask us to correct or remove information about you, by writing to info@buildersinfintech.ai. We answer within one month.
Who processes data for us
- Supabase (database and file storage; servers in the EU, Frankfurt).
- Lovable (database and file storage; servers in the EU, Frankfurt).
- Plausible Analytics (cookieless page counts; EU-based).
These providers act on our instructions under data processing agreements.
Subscribing to the newsletter happens on Substack; listening to the podcast happens on Spotify, Apple Podcasts, YouTube or other platforms. Those services have their own privacy policies, which apply when you use them.
What we do not do
We do not sell or share personal data, run advertising, or use tracking pixels. The admin area of this site is used only by the publisher and uses an authentication cookie limited to that area.
The MCP connector
Calls to our MCP connector are counted so that the daily limits can be applied. For each caller we store an irreversible, salted hash — of the connection token, or of the IP address when the client keeps no session — together with the number of calls made that day. Those per-caller counters are deleted automatically after two days. Separately we keep a daily count of how often each tool was used, which identifies nobody. We never store the arguments of a call, its results, or a readable IP address.
Your rights
Under the GDPR you can ask what personal data we hold about you, and ask for it to be corrected, deleted or restricted, or object to its use. Write to info@buildersinfintech.ai; we answer within one month. You also have the right to lodge a complaint with your national data protection authority — in Italy, the Garante per la protezione dei dati personali.
Changes
We update this notice when the site changes. The date of the latest version is shown below.
Last updated: 28 September 2026
The MCP connector
Calls to our MCP connector are counted so that the daily limit can be applied. For each caller we store an irreversible, salted hash — of the connection token, or of the IP address when the client keeps no session — together with the number of calls made that day. Those per-caller counters are deleted automatically after two days. Separately we keep a daily count of how often each tool was used, which identifies nobody. We never store the arguments of a call, its results, or a readable IP address.