← Return to portal
PRIVACY NOTICE

How referral information is handled

Version dated July 20, 2026

Implementation notice: The platform’s legal operator, privacy contact, retention periods, and final data-sharing terms must be confirmed before live personal information is processed. This page documents the controls already implemented and the remaining disclosures that require approval.

Information collected

The portal records the referred client’s first and last name, email address, Amazon storefront URL, referring partner, current assignment, referral date, qualification confirmations, scheduling activity, call-attendance status, and client outcome.

Why it is collected

The information is used to administer an authorized business referral, arrange a strategy call, maintain referral attribution, show permitted users the referral’s progress, resolve attribution questions, and maintain security and audit records.

Where the information comes from

Referral information is submitted by an invited referral partner. The current program is intended for leads already present in Flippa’s directory. A partner must be authorized to submit the information and must provide this notice to the client.

Who receives it

Access is limited by role to authorized referral partners, managers, administrators, and the Super Administrator. Scheduling information is passed to Calendly and the currently linked GNO Partners calendar. Supabase supports passwordless authentication, and the hosting platform stores portal records.

International processing

Service providers may process information outside the client’s country. The operator must document relevant hosting locations and safeguards before production use.

Retention and individual requests

Information will be retained only for the approved referral-attribution, program-administration, legal, and security periods. A person may request access, correction, or deletion through the data-request process. Final retention periods and the operator’s privacy contact remain to be published.

Security

The portal uses invitation-only authentication, server-enforced role permissions, restricted team views, validation, and an append-only administrative audit history. No online system can guarantee absolute security.