Privacy policy
Last updated 2026-10-04.
This policy explains what personal information nodilist collects and why. It covers two groups of people:
- People who use our site: visitors, people who join a waitlist or request a free sample, buyers and anyone who contacts us (Part A).
- People and businesses in our data files (Part B).
nodilist is run by Nodior LLC, 30 N Gould St, Sheridan, WY 82801 ("we", "us"). We sell business contact data, so California and some other states treat us as a data broker. How to opt out or ask for deletion is explained on data removal.
To opt out or have your data deleted, use the data removal page, or email info@nodilist.com. We honor removal requests from anyone, whatever state you live in.
Part A. People who use our site
What we collect and why
| What | From whom | Why |
|---|---|---|
| Email address, the list you chose, the request type (waitlist or sample), the state if you chose one, the time of the request, and a salted hash of your IP address | People who join a waitlist or request a sample | To tell you when the list is released or to send the sample when it is ready, plus at most two follow-up emails about that list. The IP hash is used only to limit abuse (see below). |
| Name, email, billing details, order details | Buyers | To take payment, build and deliver your file, send removal notices about records you bought, handle refunds and keep tax and accounting records. Stripe processes card details. We never see or store your card number. |
| Checkout purpose statement and acceptance of our terms | Buyers | To record your commitments under our terms. |
| Name, email, message | People who contact us | To answer you. |
| Pages viewed, referrer, approximate location (city/region), device and browser, events such as "waitlist form sent" | Visitors, through Google Analytics 4 cookies | To see which pages work and fix the site. |
| IP address, request logs | Visitors | Security, preventing abuse, running the site. |
Waitlist and sample requests
When you join a waitlist or request a sample on our site, we store:
- your email address
- the list you chose and the request type (waitlist or sample)
- the state, if you chose one
- the date and time of the request
- a salted hash of your IP address
Why. We use your email, the list and the state to email you the sample you asked for, to tell people who joined a waitlist before ordering opened that the list can now be ordered, and to send at most two follow-up emails about that list. We use the IP hash only to limit how many requests one connection can send in an hour and to spot abuse. The first email after a request asks you to confirm your address; we send nothing else until you do.
The IP hash is personal data. We never store your IP address itself. We store a SHA-256 hash of it combined with a secret value (a salt). The salt is kept next to the requests, so anyone holding both could test whether a known IP address made a request. That makes the hash pseudonymous personal data, not anonymous data, and we protect it the same way as your email address. The rate limit also keeps a small file per hashed connection, which we delete within 30 days.
Where. In a file on our web host (Namecheap), in a folder outside the public website, readable only by our hosting account. The form sends no email itself.
How long. 24 months after your last request, or until you ask us to delete it. A removal request for your email address also deletes your waitlist and sample requests.
Sharing. We don't sell or share these requests, and we don't add them to the lists we sell.
Emails we send you
After a waitlist or sample request, the first email asks you to confirm your address; we send nothing else until you do. After you confirm, we email you the sample you asked for, or tell you that the list you joined a waitlist for can now be ordered, and at most twice more about that list. Each email says why you are getting it, includes our postal address and has an unsubscribe link. We act on an unsubscribe within 10 business days. Order emails (the email with your file, a notice that we cancelled a hold, refunds and removal notices about records you bought) are part of your purchase and are sent even if you unsubscribe from marketing.
Analytics and cookies
We use Google Analytics 4 to measure site use. Advertising features, Google Signals and remarketing are off, so we don't use your visits for targeted ads. You can block analytics cookies in your browser or with Google's opt-out add-on. We don't use advertising cookies. If we add them later, we will update this policy and honor Global Privacy Control signals as an opt-out.
Who receives this information
We don't sell or share information about site visitors, sample requesters or buyers. We disclose it only to service providers that act for us under contract:
- Stripe (payments; Stripe receives your card and billing details at checkout, and we never see the card number)
- Namecheap (website hosting, including stored waitlist and sample requests)
- Google (Gmail and Google Drive, to email order files)
- Google (analytics)
We also disclose information where the law requires it, and to a buyer of our business if it is sold.
How long we keep it
- Waitlist and sample requests: 24 months after your last request, or until you ask us to delete it. Rate-limit files: up to 30 days. After an unsubscribe we keep only the email address, so that we don't email you again.
- Buyers: order and payment records for 7 years (tax and accounting). The list of records sent to you is kept for as long as removal notices may need to reach you.
- Contact messages: 24 months.
- Analytics: 14 months (the GA4 retention setting).
- Server logs: 90 days.
Free sample: notice of financial incentive
California law treats some offers made in exchange for personal information as a "financial incentive". We give a free 25-row sample to people who enter an email address, so we describe it here.
- The offer: a free sample file of 25 rows. We email it, usually within one business day.
- What you give: your email address. We may use it to email you at most twice more about the list.
- How to withdraw: unsubscribe from any email, or ask us to delete your address. You keep the sample.
Part B. People and businesses in our data files
What our files contain
We compile directory files about US businesses and organizations, such as dental practices, and sell them to other businesses. Each row is one practice or organization. Some practices are run by one person, such as a dentist in solo practice, so some rows contain information about an individual in a professional role.
| Category (CCPA) | Examples in our files | Collected in the past 12 months | Sold in the past 12 months | Disclosed for a business purpose |
|---|---|---|---|---|
| Identifiers | Practice or organization name (which can include a practitioner's name when the practice is named after one); business address; business phone; business email; website; NPI, CRD, USDOT or CMS Certification Number | Yes | No | Yes, to service providers |
| Professional information | Specialty or provider type, public job title, registration or authority status | Yes | No | Yes, to service providers |
| Other information about the record | The web page where an email was published, the date it was last verified, email status (valid, catch-all, unknown), email type (role or personal), phone line type (landline, mobile, VoIP; where the list offers it), the source record and its date | Yes | No | Yes, to service providers |
| Inferences | Segment labels such as "new practice in the last 90 days" or membership of a practice group | Yes | No | Yes, to service providers |
We don't collect sensitive personal information for our files. That means no Social Security, driver's license or passport numbers, account logins, financial account numbers, precise geolocation, health, biometric, racial or ethnic, union, sex-life or sexual-orientation data, and nothing about any individual's religious beliefs. Our church lists will hold church organizations' business contact data, including the denomination a church states on its own site; they won't record what any person believes. We don't collect dates of birth or home contact details on purpose. If a practice address turns out to be a residence, we remove it where we can detect it. We don't knowingly collect or sell information about anyone under 16.
Where it comes from
- Government registers. The CMS National Plan and Provider Enumeration System (NPPES), the SEC Investment Adviser Public Disclosure database and Form ADV data (registered and exempt reporting advisers), CMS Hospital General Information, the FMCSA motor carrier census and other official registers. Where an email comes from a register, the file names the register and its file date.
- Public websites of the businesses themselves. We collect an email only if it is published on a public page, and we record that page's address. We don't guess email addresses. Our crawler will skip pages that ask not to have their addresses collected.
Why we use it
- To compile, verify and update our business directory files.
- To sell or license those files to businesses for business-to-business marketing, sales prospecting and market research.
- To publish counts and statistics, such as the number of dental practices per state. These never identify anyone.
- To honor removal requests and keep removed records out of future files.
Who receives it
- Buyers. Businesses that buy our files. Examples are dental suppliers, practice-software companies, marketing agencies, and groups that acquire practices. This is a "sale" of personal information under California law. Every buyer must accept our terms and acceptable use policy. These limit use to business purposes, forbid resale and require buyers to apply our removal notices within 10 business days.
- Service providers. Hosting, storage, email verification and phone line-type lookup, under contracts that limit their use of the data.
- Authorities, where the law requires it.
How long we keep it
We keep a record while it appears in the current source or on the business's website. We drop records that the source removes or deactivates, or that we can no longer confirm, at the next release. Previous releases are kept for 24 months so we can answer questions about files we delivered. After a removal request, we keep only a scrambled (hashed) identifier, so the record stays out of future files.
Your rights
Everyone
Anyone can ask us to remove their business or personal details from our files, whatever state they live in. Use the data removal page. The removal applies to every future file, and we notify buyers who already received the record.
California residents
Under the California Consumer Privacy Act you have the right to:
- Know what personal information we have collected about you, where it came from, why we use it and who we sold or disclosed it to, and get a copy.
- Delete personal information we hold about you.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of your personal information. Our link for this is Do Not Sell or Share My Personal Information.
- Not be discriminated against for using these rights.
We do not use sensitive personal information, so the right to limit its use does not apply.
How to make a request
- Email: info@nodilist.com. The data removal page lists what to include.
Verification. For an opt-out we don't need to verify who you are. We match on the details you give us. For deletion we match your request to our records using the business email, phone or practice address you provide, and we may send a confirmation email to an address in our records. For a request to know or correct, we need a little more, such as a reply from the email address we hold. We never ask for a Social Security number or ID document to process a removal.
Authorized agents. Someone else can make a request for you with your signed permission. We may ask you to confirm the request directly.
Timing. We confirm a request to know, delete or correct within 10 business days, and complete it within 45 days. If we need up to 45 more days, we tell you why. We act on an opt-out of sale within 15 business days.
Request metrics
Each year by July 1 we publish the number of requests we received, complied with and denied in the previous calendar year, with the median and mean days to respond. The first report, for 2026, will appear here by July 1, 2027.
Security
We store files and records with access limits and encryption in transit. Order files are emailed to the buyer as an attachment or a Google Drive link shared with the buyer's address. Only people who run nodilist can reach the data. No system is perfectly secure. If a breach affects your personal information, we will notify you as the law requires.
Changes to this policy
We will post any change here and update the date at the top. If a change affects how we use information we already hold, we will say so on this page before it takes effect.
Contact
Nodior LLC, 30 N Gould St, Sheridan, WY 82801 Email: info@nodilist.com
