Legal
Privacy Policy
Effective date: July 2, 2026
Hubbs Enterprises, LLC ("Hubbs Enterprises," "we," "us," or "our") operates the Why Not Buy research platform and website (the "Service"). This Privacy Policy explains how we collect, use, share, and protect information when you use the Service. It is incorporated into our Terms of Service. We keep this deliberately plain. By using the Service, you acknowledge this Privacy Policy.
Whose information this covers
- Business users and prospects — people who contact us, create a client account, or design and commission a study.
- Research participants — people who take part in an interview through the Service.
- Website visitors — anyone who browses our site.
Information we collect
From business users and prospects. The name, work email, company, and any message you provide through our contact or intake forms; account credentials; the study configuration you provide (category, brand, competitors, and screening criteria); and billing and correspondence records.
From research participants. When you are referred to us by a research panel and take part in an interview, we collect:
- Referral and screening information passed to us by the panel, which may include a panelist identifier and attributes such as age, gender, and postal (ZIP) code.
- Screening responses, such as your age band, gender (including a self-described value if you provide one), general region, household role, and your recent purchase in the study category.
- Interview content — the transcript of your interview and the structured data we code from it. Interviews are conducted as free-text conversation, so a transcript may contain any personal information you choose to type. Please avoid sharing sensitive personal information about yourself or others.
Automatically. Basic technical information needed to operate and secure the Service, such as log data, device and browser information, and IP address, and information collected through cookies and similar technologies (see "Cookies" below). For signed-in client-portal users, we also keep a first-party log of product usage — which pages and features you use (for example, viewing a report, asking a question of your data, or exporting your study) and when — associated with your account. This log records the type of action, not the content of what you view or type, and we use it to understand how the Service is used, provide support, and improve the product. We do not use third-party advertising trackers, and we do not apply this product-usage logging to research participants.
How you found us. When you first visit our website we store, in a first-party cookie on your browser, the page you landed on, the website that referred you (the site's address only — never the full link or any search terms), and any campaign tags in the web address. If you later create an account, we save that information with your account so we understand which channels bring people to us. We ask the same question directly when you set up your workspace, and answering is optional. This is a single first-party cookie — no third-party analytics or advertising scripts — and it is never applied to research participants. You can clear it at any time through your browser settings.
From support chats. If you use our in-product support chat (available on our website and in the client portal), we collect and log the messages you send and our AI-assisted responses, together with any contact email you provide so we can follow up. We use these records to answer your question, route it to a person when a human is needed, and monitor and improve the quality of our support. The chat is AI-assisted; please avoid sharing sensitive personal information in it.
Where research participants come from
Interview participants are sourced through third-party research panels that verify a participant actually purchased in the relevant category (via omni-channel purchase receipts) before that participant is ever routed to us. Participation is voluntary and consented, and participants may withdraw from an interview at any time.
How we use information
We use information to:
- operate the Service — design and run studies, recruit and route qualified participants, conduct interviews, produce reports, provide support, process payments, and communicate with you;
- maintain the security, integrity, and reliability of the Service, and detect and prevent fraud and abuse;
- comply with law and enforce our agreements; and
- develop and improve the Service. We use de-identified information to develop, evaluate, and improve our models, methods, and processes. When we create outputs we make available beyond an individual study — such as benchmarks or cross-client synthetic personas — we do so only in de-identified form aggregated across multiple studies, never predominantly from a single client's study, and not in a way that identifies any participant, client, or individual study. We treat each study as the commissioning client's primary research: we do not resell it or reuse it for another client. At a client's request we may build a persona or model from that client's own study for its exclusive use, as part of its deliverables.
We rely on our legitimate business interests in operating and improving the Service, on performance of our contracts, on consent where required, and on compliance with legal obligations, as bases for these uses.
De-identification
Before any interview transcript is made available to the client who commissioned the study, it is run through a de-identification process that removes directly-identifying and quasi-identifying personal information — including names, email addresses, phone numbers, street addresses, specific cities or neighborhoods, employer and school names, and account-type identifiers. Some information is intentionally retained because it is research signal rather than an identifier — for example, brand and product names, generic place references ("the grocery store"), broad regions or states, and demographics expressed generally. Clients receive de-identified transcripts and synthesized reports, not raw personal data.
How we share information
- With the commissioning client. We share de-identified transcripts and synthesized reports with the client that commissioned the study. Clients do not receive raw, identifiable interview records.
- With service providers. We use trusted providers to operate the Service — for example, hosting and infrastructure, research-panel, communications, and payment providers, and our artificial-intelligence provider (Anthropic, PBC), which processes interview and related content on our behalf to power AI-moderated interviewing and analysis. These providers are bound by confidentiality and data-protection obligations and may use the information only to provide services to us.
- For legal reasons. We may disclose information where we believe it is required by law or legal process, to protect our rights, property, or safety or those of others, or to enforce our agreements.
- In a business transfer. We may transfer information in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to this Privacy Policy.
We do not sell your personal information. We may create and use de-identified information aggregated across many studies (not any single study) to improve and offer the Service; because it does not identify you, this is not a sale of personal information.
Data ownership
Rather than claim ownership of the underlying interview data (which is participants' personal data), our Terms of Service allocate it this way: the client owns its Client Materials, its raw study responses, and the report we prepare for it. The coded analytics our methodology produces (scores, codings, classifications, and structured captures) are our intellectual property, licensed to the client for its business use. The client grants us a license to use its de-identified data and those analytics to improve the Service and to create learnings aggregated across many studies; and at its request we may build a persona or model from its own study for its exclusive use. We retain our platform, panel, and models. Participants grant us the rights we need to operate and improve the Service, subject to these commitments. These arrangements do not change the commitments we make in this Privacy Policy about how we handle personal information.
Security
We use reasonable technical and organizational measures to protect information. Information is encrypted in transit, and certain sensitive fields (such as gender and region) are encrypted at rest. We restrict access to personal information to people and providers who need it, and each client's data is logically isolated from other clients' data. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Retention
We retain personal information for as long as needed to provide the Service and for the purposes described in this Privacy Policy, and as required to comply with our legal obligations, resolve disputes, and enforce our agreements. A completed study's deliverables remain available to the commissioning client for 12 months, and we do not retain identifiable interview records longer than needed for the purposes above. We may retain aggregated, de-identified, and derived data, which is not identifiable, for longer.
Your rights and choices
You may request access to, correction of, or deletion of the personal information we hold about you by contacting us using the details below, and participants may withdraw from an interview at any time. Depending on where you live, you may have additional rights under applicable law — such as the rights to know, access, correct, delete, and limit certain uses of your personal information, and the right not to be discriminated against for exercising those rights. We will verify and respond to requests as required by law. If you are a California resident, you may request information about the categories of personal information we disclosed for direct-marketing purposes in the prior year. Because some information is stored only in de-identified form, we may be unable to associate a request with a specific individual.
Cookies
We use cookies and similar technologies to operate the site, remember your session, understand usage, and improve the Service. Some browsers offer a "Do Not Track" setting; because there is no common standard, we do not currently respond to those signals. You can control cookies through your browser settings, though some features may not work without them.
Children
The Service is intended for adults and for business use. It is not directed to children, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.
U.S.-based service
The Service is operated from the United States and is currently offered to U.S. participants and clients. If you access it from outside the United States, you understand that your information will be processed in the United States.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Effective date" above and, where appropriate, by additional notice. Your continued use of the Service after changes become effective constitutes your acceptance of the updated policy.
Contact
Questions about this policy, or want to exercise a privacy right? Email us at privacy@hubbsenterprises.com or reach us through our contact page. You can also write to: Hubbs Enterprises, LLC, Attn: Privacy, 238 Humphrey Street, Marblehead, MA 01945 USA.