Effective 30 July 2026

Privacy notice

What we hold, why we are allowed to, and how to get yourself out of it. No cookie banner, because there are no tracking cookies.

Visual Stack Inc. ("we") operates WhoImports. This notice explains what we do with information about companies and, where relevant, about people. We have tried to write it in plain language rather than to obscure.

1. Company data versus personal data

Most of what we hold is not personal data at all: it is information about legal entities — a company's registered name, tax identifier, address, activity code, regulated-sector authorisations and the product categories it imports. Data protection law generally protects natural persons, not corporations.

There are two situations where the distinction narrows, and we treat both as personal data:

  • Sole proprietors. In Mexico and Argentina an importer may be an individual trading in their own name. Their identifier is personal data. We exclude these records from any public page and restrict their use.
  • Named business contacts. Where a deliverable identifies a person by name and role, that is personal data about an identifiable individual acting in a professional capacity.

2. What we process, and why

CategoryExamplesPurpose
Company identityRegistered name, tax identifier, address, activity code, corporate statusTo identify importing companies accurately and avoid mismatching
Trade behaviourProduct categories imported, operation counts, declared value, activity windowTo tell a client which companies buy the product they sell
Business contact pointsCompany telephone, website, general company email addressTo let a client make a business approach
Named business contactName, job title, professional email, professional profile linkTo direct a business approach to the right function, where available
Enquiry dataWhat you send us through the form on this siteTo answer you and send the sample you asked for

We do not knowingly process special-category data, data about children, personal financial data, or any information about an individual's private life. We do not use the data to profile individuals or to make automated decisions about them.

3. Our legal basis

For business-to-business information we rely on legitimate interest: enabling companies to identify commercial counterparties is a recognised and expected use of business information, and the impact on an individual acting in a professional capacity is limited. We balance that interest against those rights, which is why we restrict sole-proprietor records, publish no personal data on public pages, and honour objections without argument.

For your enquiry to us, our basis is performing the request you made. For anything else we would ask your consent.

We take account of Mexico's Ley Federal de Protección de Datos Personales en Posesión de los Particulares, Brazil's Lei Geral de Proteção de Dados, Argentina's Ley 25.326, and — where a client or an individual is in the European Union or United Kingdom — the GDPR and UK GDPR.

4. Your rights, and how to use them

Depending on where you are, you may have the right to access the information we hold about you, correct it, have it erased, restrict or object to its processing, withdraw consent, or receive a copy in portable form. In Mexico these are the ARCO rights; in Brazil, the rights under Article 18 LGPD.

The short version: if you do not want to be in our data, tell us and you will be removed. Use the data removal page or write to [email protected]. We do not require you to explain why, and we do not charge for it.

We respond within 10 business days. When we remove a record we also add it to a permanent suppression list, so that it does not reappear the next time we refresh from source. We cannot recall a deliverable already supplied to a client before your request, but we will exclude you from every deliverable issued afterwards.

5. Website visitors

This site is deliberately simple. It sets no advertising or tracking cookies and embeds no third-party analytics, advertising pixels or social widgets — which is also why it has no cookie banner to click away.

When you submit the form, we receive what you typed plus your country and the page you came from, and we email it to ourselves so we can reply. Our infrastructure provider processes standard server logs, including IP address, for security and abuse prevention.

6. Who we share with

We do not sell, rent or trade personal data. We share information only with:

We are based in the United States and our providers may process data in the United States and the European Union. Where a transfer requires a safeguard, we rely on the appropriate mechanism for that jurisdiction.

7. Retention and security

We keep company records while they remain commercially relevant and refresh them from source; superseded snapshots are retained for accuracy and audit. Enquiry data is kept for as long as needed to deal with your request and for a reasonable period afterwards. Suppression entries are kept indefinitely, because their whole purpose is to keep you out.

Access is restricted to people who need it, credentials are held as secrets rather than in code, and data in transit is encrypted. No system is perfect and we do not claim otherwise.

8. Contact

Visual Stack Inc., Miami, Florida, United States.
[email protected] · +1 (305) 404-6438.

If you are unhappy with how we handled your request you may complain to your national data protection authority — in Mexico the INAI, in Brazil the ANPD, in Argentina the AAIP, or your supervisory authority in the EU or UK.