Privacy Policy

Last updated March 17, 2026

Introduction

InvestLyft, Inc. ("InvestLyft," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our investor management platform.

Effective Date: March 17, 2026

Information We Collect

Account Information

When you create an account, we collect your name, email address, and password. If you sign up through Google or Microsoft OAuth, we receive your name and email from those providers.

Organization Information

When you create or join a tenant (startup, fund, or investment club), we collect organization name, type, and related business information such as share classes, shareholders, investors, and financial data you enter.

Usage Data

We automatically collect information about how you interact with the platform, including pages visited, features used, and session duration. This helps us improve the product.

Payment Information

Payment processing is handled by Stripe. We do not store your credit card numbers. Stripe provides us with limited information such as the last four digits of your card and billing address.

How We Use Your Information

  • To provide and maintain the InvestLyft platform
  • To process your subscription and billing
  • To send transactional emails (account confirmation, password reset, investor updates)
  • To send behavioral emails related to onboarding and product adoption (you can unsubscribe)
  • To provide AI-powered assistance through our platform agent
  • To improve our product based on aggregated usage patterns
  • To comply with legal obligations

Third-Party Services

We use the following third-party services to operate InvestLyft:

  • Supabase -- Database hosting, authentication, and file storage. Your data is stored in Supabase-managed PostgreSQL databases with row-level security.
  • Stripe -- Payment processing for subscriptions. Stripe handles all credit card data per PCI DSS standards.
  • Resend -- Transactional and behavioral email delivery.
  • Vercel -- Application hosting and deployment.
  • Anthropic (Claude) -- AI-powered platform agent for contextual guidance. Conversation data is processed but not used for model training.
  • OpenAI -- Text embeddings for knowledge base search. Article content is embedded but not used for model training.

Data Sharing

We do not sell your personal information. We share data only with the third-party services listed above, as necessary to operate the platform. We may disclose information if required by law or to protect our legal rights.

Data Retention

We retain your account data for as long as your account is active. If you request account deletion, we initiate a 30-day grace period during which you can reactivate. After the grace period, your data is permanently deleted.

Your Rights

You have the right to:

  • Access your data -- Use the Data Export feature in Settings to download all your data as CSV files.
  • Delete your account -- Use the Account Deletion feature in Settings. A 30-day grace period applies.
  • Update your information -- Edit your profile, email, and password in Settings.
  • Object to processing -- Contact us at privacy@investlyft.com.

Cookies

We use cookies for authentication, session management, and user preferences. See our Cookie Policy for details.

Security

We implement industry-standard security measures including encryption in transit (TLS), encryption at rest, row-level security on all tenant data, and regular security reviews. Tax IDs and sensitive financial data are encrypted at rest.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a new effective date.

Contact Us

If you have questions about this Privacy Policy, contact us at privacy@investlyft.com.