Privacy policy

What we collect, and why

This is a starting draft, written to be read, not to bury the answer. It covers founders using RaisePortal and investors opening a shared link. Replace the bracketed items with your own company details before relying on this page.

Draft notice. This page is a template. It has not been reviewed by a lawyer, does not name a real data controller, and does not currently offer a signed data processing addendum. [Company legal name — PLACEHOLDER], a company registered in [jurisdiction — PLACEHOLDER], is the entity you should fill in as the controller of this data.

Who this covers

Two kinds of people use RaisePortal: founders and teammates who run a portal, and investors who open a link someone sent them. What we collect is different for each.

Founders and team members

Name, title, work email, mobile number, password (hashed, never stored in plain text), and whatever you upload to your own data room. Your mobile number exists so we can alert you when someone opens a room you sent — nothing else.

Investors who open a room

If the founder turned on identity capture, we ask for a name and email before letting you in. Every visit records the approximate location from your IP address (city-level, the last part of the address itself is masked before a founder ever sees it), your device and browser, and which documents you opened and for how long. The room footer states this plainly at the point you enter: visits are recorded. Recognising a returning visitor uses a signed cookie and, as a fallback if that cookie is cleared, a low-entropy fingerprint of your browser (user agent, screen size, timezone) — this is a convenience for the founder, never used to identify you outside this product.

What we do not do

We do not sell personal data. We do not use investor visit data to advertise to you. A room's contents and its visit history belong to the startup that built it, not to us.

Retention

Our design intent, per the product specification, is to keep raw visit and document-view records for 24 months, after which only aggregated rollups (counts and totals, not individual visit rows) are kept. Account data is kept for as long as the portal exists, and is deleted or anonymised within 30 days of a founder deleting their portal.

Cookies

A session cookie keeps you signed in. A separate cookie remembers your light/dark preference for this site. On an investor room, a signed visitor cookie recognises a returning reader. None of these are used for third-party advertising.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data. To ask, email [email protected]. [Add your jurisdiction-specific rights language and any required regulator contact here — PLACEHOLDER.]

Contact

[Company legal name — PLACEHOLDER], [registered address — PLACEHOLDER]. [email protected]

Last updated: [date — PLACEHOLDER].