This document is an unreviewed draft. It still contains unfilled placeholders and has not been reviewed by legal counsel. It is not yet binding and must not be relied on.

Venture Track — Privacy Policy

Effective date: [DATE] Last updated: [DATE]

DRAFT — NOT LEGAL ADVICE. Generated by an AI assistant and not reviewed by a lawyer. The subprocessor list was assembled from the codebase and must be verified before publishing. See docs/legal/README.md.

This policy explains how [LEGAL ENTITY NAME] ("Venture Track", "we") collects, uses, and protects personal information in connection with the Venture Track platform.


1. Scope

This policy covers:

  • Account data — information about the people who use Venture Track.
  • Customer Data — the portfolio and company information our customers put into the platform.
  • Website data — information collected from our public marketing site.

Where we process Customer Data on a customer's behalf, we act as a processor (or "service provider") and the customer is the controller. Our Data Processing Agreement governs that relationship.


2. What we collect

2.1 Information you give us

CategoryExamplesWhy
Account informationName, work email, firm name, roleCreate and secure your account
Firm informationFirm name, website, descriptionSet up your organization
Invite requestsName, work email, firm name and website, role, portfolio size band, what you're trying to solve, how you heard about usEvaluate and respond to invitation requests
Customer DataCompanies you track, positions, notes, uploaded documents, chat messages, watchlist configurationProvide the Service
Billing informationBilling contact, billing address, tax detailsProcess subscriptions
Support correspondenceEmails you send usRespond to you

We do not collect or store full payment card numbers. Card details go directly to Stripe.

2.2 Information collected automatically

  • Usage data — features used, analyses run, timestamps. Used for billing limits, product improvement, and abuse prevention.
  • Technical data — IP address, browser and device type, and error diagnostics. IP addresses are used for security and rate limiting.
  • Authentication data — session records and single-use sign-in tokens.

2.3 Information from third parties

The Service ingests information about companies from public and licensed sources — news, academic research, patents, regulatory filings, policy documents, and market data. This may include personal information about company personnel where it appears in those public sources (for example, an executive named in a funding announcement).


3. How we use information

  • Provide, maintain, and secure the Service
  • Authenticate users and prevent unauthorized access
  • Process payments and enforce plan limits
  • Send transactional email — sign-in links, signal alerts, digests, billing notices, and service announcements
  • Respond to support requests and invitation requests
  • Detect, investigate, and prevent abuse, fraud, and security incidents
  • Analyze aggregate usage to improve the product
  • Comply with legal obligations

3.1 Legal bases (EEA/UK)

Where GDPR applies, we rely on: contract (providing the Service you signed up for), legitimate interests (security, abuse prevention, product improvement — balanced against your rights), consent (marketing email, where required), and legal obligation (tax and accounting records).


4. Machine learning and automated processing

The Service uses large language models to summarize sources and produce analysis.

We do not use Customer Data or account data to train machine-learning models, and our agreements with model providers prohibit them from training on data we submit through their APIs.

VERIFY BEFORE PUBLISHING. This statement must be confirmed against the current terms of every model provider in use under your actual plan. If any provider trains on API inputs by default, either change that setting or change this statement.

The Service does not make decisions producing legal or similarly significant effects about individuals without human involvement.


5. How we share information

We do not sell personal information. We do not share Customer Data between customers. We disclose information only as follows:

5.1 Subprocessors

SubprocessorPurposeData involved
SupabasePrimary database hostingAccount data, Customer Data
Amazon Web Services (S3)Document and snapshot storageUploaded documents, stored articles
Amazon Web Services (EKS)Application hostingAll data in transit and processing
Redis (in-cluster)Caching, sessions, rate limitingSession and usage data
StripePayment processingBilling contact, payment details
ResendTransactional emailRecipient email addresses, message content
AnthropicLanguage model analysis and summarizationCompany and signal content sent for analysis
OpenAILanguage model analysisCompany and signal content sent for analysis
PerplexityReal-time searchSearch queries derived from company data
Echo (BlankCut)Signal procurement and scoringCompany identifiers and watchlist configuration

VERIFY BEFORE PUBLISHING. This list was compiled from the application's configuration. Confirm it is complete and current, and add Calendly if the scheduling integration is enabled at launch.

We will give notice before adding a subprocessor that materially changes how Customer Data is processed, as set out in the DPA.

5.2 Other disclosures

  • Legal — where required by law, or to establish or defend legal claims. We will notify affected customers unless legally prohibited.
  • Business transfer — in a merger, acquisition, or sale of assets, subject to this policy continuing to apply.
  • With your direction — where you ask us to share.

6. International transfers

We process data in the United States. If you are in the EEA, UK, or Switzerland, your information will be transferred outside your jurisdiction. We rely on Standard Contractual Clauses and equivalent mechanisms for those transfers, as detailed in the DPA.


7. Retention

DataRetention
Account dataWhile the account is active
Customer DataWhile the subscription is active, plus 30 days after termination
Sign-in tokens15 minutes; deleted on use
Usage records24 months, for billing history and product analytics
Billing records7 years, or as tax law requires
Security and access logs12 months
Invite requests12 months from submission, unless converted to an account

After the retention period, data is deleted or irreversibly anonymized. Backups are purged on their own rotation, no later than [BACKUP RETENTION PERIOD] after deletion.


8. Security

Measures in place include: encryption in transit (TLS) and at rest; role-based access control with tenant isolation enforced at the query layer; passwordless authentication with single-use, expiring sign-in links; secrets held in a managed secret store rather than in code; and least-privilege access for staff, granted only where operationally necessary and logged.

No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you without undue delay and as required by law.

Report a vulnerability to [SECURITY EMAIL].


9. Your rights

Depending on where you live, you may have the right to access, correct, delete, port, restrict, or object to processing of your personal information, and to withdraw consent.

If you are a user of a customer's account, direct requests about Customer Data to that customer — they control it. We will assist them in responding.

To exercise rights over data we control, contact [PRIVACY EMAIL]. We respond within 30 days. We will not discriminate against you for exercising these rights.

California

California residents have rights under the CCPA/CPRA, including to know, delete, and correct personal information, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined by the CCPA.

EEA/UK

You may lodge a complaint with your supervisory authority.


10. Cookies

We use cookies that are strictly necessary for the Service to function — authentication, session management, and security. We do not use advertising cookies. Any analytics cookies on the marketing site are described in the consent banner, where one is required.


11. Children

The Service is for business use and is not directed at anyone under 18. We do not knowingly collect information from children.


12. Changes

We may update this policy. Material changes will be notified by email or in-product at least 30 days before taking effect. The "last updated" date above always reflects the current version.


Contact: [PRIVACY EMAIL] · [LEGAL ENTITY NAME], [REGISTERED ADDRESS]