One of the first companies I contacted was Crunchbase, a well-known database of technology startups. On August 17, I emailed the company’s privacy address to request access to my personal data. My message clearly explained the rights I wanted to exercise and explicitly stated that I was not requesting data deletion: “You have not requested deletion at this time. Please do not treat this as a deletion request.”
Two days later, a Crunchbase support representative responded. The entire message read: “Thank you for your patience. Your account has been permanently removed from Crunchbase. If you need anything else, please let us know.”
I immediately followed up and reiterated that I wanted access to my information—not deletion. In response, Crunchbase clarified: “Your Crunchbase user account has been deleted. No other data on Crunchbase has been deleted.” The company added that I would need to register again if I wanted to use the service.
When I contacted Crunchbase for comment, a spokesperson said the mistake resulted from a “processing error” and confirmed that the company would continue handling my original data access request. The spokesperson also said the incorrect responses were sent by members of the company’s customer success team rather than by a generative AI tool.
My experience with BeenVerified, a searchable database that compiles public records, revealed similar problems when submitting a personal data access request.
On the morning of August 19, I emailed BeenVerified’s dedicated CCPA compliance address. I explained that I was a California resident submitting a request to access my personal information—not a request to delete it. The response, however, went in the opposite direction.
Two days later, a BeenVerified support representative told me that my information had been removed. “It appears your people report has already been removed from people search results,” the response stated. “In addition, we have removed the requested phone number and email address from search results. This change should take effect within 24 hours.” That was not the request I had submitted.
I replied to explain that I had requested access to my data rather than its deletion. Fifteen minutes later, a support representative responded by denying my claim and stating that the company could not verify my identity. The explanation was confusing because the earlier message had already referenced some of my personal details, and the representative did not explain what additional information I needed to provide for identity verification.
Source: arstechnica.com


