Venture Track — Privacy Policy
Effective date: [DATE] Last updated: [DATE]
DRAFT — NOT LEGAL ADVICE. Generated by an AI assistant and not reviewed by a lawyer. The subprocessor list was assembled from the codebase and must be verified before publishing. See
docs/legal/README.md.
This policy explains how [LEGAL ENTITY NAME] ("Venture Track", "we") collects, uses, and protects personal information in connection with the Venture Track platform.
1. Scope
This policy covers:
- Account data — information about the people who use Venture Track.
- Customer Data — the portfolio and company information our customers put into the platform.
- Website data — information collected from our public marketing site.
Where we process Customer Data on a customer's behalf, we act as a processor (or "service provider") and the customer is the controller. Our Data Processing Agreement governs that relationship.
2. What we collect
2.1 Information you give us
| Category | Examples | Why |
|---|---|---|
| Account information | Name, work email, firm name, role | Create and secure your account |
| Firm information | Firm name, website, description | Set up your organization |
| Invite requests | Name, work email, firm name and website, role, portfolio size band, what you're trying to solve, how you heard about us | Evaluate and respond to invitation requests |
| Customer Data | Companies you track, positions, notes, uploaded documents, chat messages, watchlist configuration | Provide the Service |
| Billing information | Billing contact, billing address, tax details | Process subscriptions |
| Support correspondence | Emails you send us | Respond to you |
We do not collect or store full payment card numbers. Card details go directly to Stripe.
2.2 Information collected automatically
- Usage data — features used, analyses run, timestamps. Used for billing limits, product improvement, and abuse prevention.
- Technical data — IP address, browser and device type, and error diagnostics. IP addresses are used for security and rate limiting.
- Authentication data — session records and single-use sign-in tokens.
2.3 Information from third parties
The Service ingests information about companies from public and licensed sources — news, academic research, patents, regulatory filings, policy documents, and market data. This may include personal information about company personnel where it appears in those public sources (for example, an executive named in a funding announcement).
3. How we use information
- Provide, maintain, and secure the Service
- Authenticate users and prevent unauthorized access
- Process payments and enforce plan limits
- Send transactional email — sign-in links, signal alerts, digests, billing notices, and service announcements
- Respond to support requests and invitation requests
- Detect, investigate, and prevent abuse, fraud, and security incidents
- Analyze aggregate usage to improve the product
- Comply with legal obligations
3.1 Legal bases (EEA/UK)
Where GDPR applies, we rely on: contract (providing the Service you signed up for), legitimate interests (security, abuse prevention, product improvement — balanced against your rights), consent (marketing email, where required), and legal obligation (tax and accounting records).
4. Machine learning and automated processing
The Service uses large language models to summarize sources and produce analysis.
We do not use Customer Data or account data to train machine-learning models, and our agreements with model providers prohibit them from training on data we submit through their APIs.
VERIFY BEFORE PUBLISHING. This statement must be confirmed against the current terms of every model provider in use under your actual plan. If any provider trains on API inputs by default, either change that setting or change this statement.
The Service does not make decisions producing legal or similarly significant effects about individuals without human involvement.
5. How we share information
We do not sell personal information. We do not share Customer Data between customers. We disclose information only as follows:
5.1 Subprocessors
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Supabase | Primary database hosting | Account data, Customer Data |
| Amazon Web Services (S3) | Document and snapshot storage | Uploaded documents, stored articles |
| Amazon Web Services (EKS) | Application hosting | All data in transit and processing |
| Redis (in-cluster) | Caching, sessions, rate limiting | Session and usage data |
| Stripe | Payment processing | Billing contact, payment details |
| Resend | Transactional email | Recipient email addresses, message content |
| Anthropic | Language model analysis and summarization | Company and signal content sent for analysis |
| OpenAI | Language model analysis | Company and signal content sent for analysis |
| Perplexity | Real-time search | Search queries derived from company data |
| Echo (BlankCut) | Signal procurement and scoring | Company identifiers and watchlist configuration |
VERIFY BEFORE PUBLISHING. This list was compiled from the application's configuration. Confirm it is complete and current, and add Calendly if the scheduling integration is enabled at launch.
We will give notice before adding a subprocessor that materially changes how Customer Data is processed, as set out in the DPA.
5.2 Other disclosures
- Legal — where required by law, or to establish or defend legal claims. We will notify affected customers unless legally prohibited.
- Business transfer — in a merger, acquisition, or sale of assets, subject to this policy continuing to apply.
- With your direction — where you ask us to share.
6. International transfers
We process data in the United States. If you are in the EEA, UK, or Switzerland, your information will be transferred outside your jurisdiction. We rely on Standard Contractual Clauses and equivalent mechanisms for those transfers, as detailed in the DPA.
7. Retention
| Data | Retention |
|---|---|
| Account data | While the account is active |
| Customer Data | While the subscription is active, plus 30 days after termination |
| Sign-in tokens | 15 minutes; deleted on use |
| Usage records | 24 months, for billing history and product analytics |
| Billing records | 7 years, or as tax law requires |
| Security and access logs | 12 months |
| Invite requests | 12 months from submission, unless converted to an account |
After the retention period, data is deleted or irreversibly anonymized. Backups are purged on their own rotation, no later than [BACKUP RETENTION PERIOD] after deletion.
8. Security
Measures in place include: encryption in transit (TLS) and at rest; role-based access control with tenant isolation enforced at the query layer; passwordless authentication with single-use, expiring sign-in links; secrets held in a managed secret store rather than in code; and least-privilege access for staff, granted only where operationally necessary and logged.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you without undue delay and as required by law.
Report a vulnerability to [SECURITY EMAIL].
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, restrict, or object to processing of your personal information, and to withdraw consent.
If you are a user of a customer's account, direct requests about Customer Data to that customer — they control it. We will assist them in responding.
To exercise rights over data we control, contact [PRIVACY EMAIL]. We respond within 30 days. We will not discriminate against you for exercising these rights.
California
California residents have rights under the CCPA/CPRA, including to know, delete, and correct personal information, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined by the CCPA.
EEA/UK
You may lodge a complaint with your supervisory authority.
10. Cookies
We use cookies that are strictly necessary for the Service to function — authentication, session management, and security. We do not use advertising cookies. Any analytics cookies on the marketing site are described in the consent banner, where one is required.
11. Children
The Service is for business use and is not directed at anyone under 18. We do not knowingly collect information from children.
12. Changes
We may update this policy. Material changes will be notified by email or in-product at least 30 days before taking effect. The "last updated" date above always reflects the current version.
Contact: [PRIVACY EMAIL] · [LEGAL ENTITY NAME], [REGISTERED ADDRESS]