Privacy Policy
Last updated: 2026-08-18
The short version
We never sell, rent, or trade your data — period. Your financial information is encrypted with AES-256 at rest and TLS in transit, isolated via row-level security, and only shared with the subprocessors needed to run the platform (Clerk, Supabase, Stripe, Vercel, Anthropic, Resend, Sentry, Upstash). You can export your data at any time. Integrations transmit account data only after you connect and authorize them: Plaid for bank transaction import, Google Drive and Gmail, Microsoft Outlook and OneDrive, Dropbox, and configured sponsor-portal adapters such as Carta and CrowdStreet. When you close your account in Settings by typing DELETE MY ACCOUNT, Stripe billing is cancelled and your profile is anonymised immediately. Portfolio records, documents, and exports are kept for at least 30 days so support can reverse a mistake. Full erasure of those records is carried out on request rather than automatically: send a request through the in-app help form and we complete it within 30 days of that request. Audit, legal and consent, compliance, and billing-notice evidence is deliberately retained. Data shared into a workspace stays with that workspace; closing-user identifiers on those shared rows are redacted when the erasure is carried out. If you cannot sign in, submit an erasure request through the contact form; identity verification still applies.
Quantified Holdings LLC, a West Virginia limited liability company doing business as SyndTrack (“we”, “us”, or “our”) is the controller of the personal information described in this policy, and is committed to protecting the privacy of our users. This Privacy Policy describes how we collect, use, and safeguard your information when you use the SyndTrack platform.
Information We Collect
Account Information
When you create an account, we collect your name and email address through our authentication provider, Clerk. We do not store passwords directly — authentication is handled entirely by Clerk.
Financial Data
You may enter information about your real estate syndication investments, including deal details, capital calls, distributions, and related documents. This data is stored securely in our database hosted on Supabase (PostgreSQL) with row-level security enabled.
Payment Information
If you subscribe to a paid plan, payment processing is handled by Stripe. We do not store credit card numbers or bank account details on our servers. Stripe's privacy policy governs the handling of your payment information.
Usage Data
We collect basic usage analytics (page views, feature usage) to improve the product. This data is aggregated and does not include your financial information.
Email Import Data
None. There is no email import: the syndtrack.io domain now accepts mail at the MX edge, but we have not verified end-to-end inbox processing or delivery into SyndTrack. Do not send documents by email expecting an import workflow. We therefore receive, parse, store, and retain no email content or email attachments through an import path. Documents reach SyndTrack only when you upload them or import a CSV, which is covered below. Our email provider, Resend, sends outbound mail only. If an import-by-email path ever ships, this policy will be updated before it is switched on.
AI Document Parsing and Deal Scoring Data
Documents you upload are sent to our AI provider, Anthropic, to extract structured data (amounts, dates, deal identifiers) from the document text. If you use AI Deal Scoring, your deal data (including deal details, financial terms, and operator information you have entered) is also sent to Anthropic to generate scores and analysis. Anthropic states that commercial API data is not used to train its models by default; customer opt-in or deliberate feedback may create an exception. Extracted fields, scores, sub-scores, and AI-generated reasoning are stored in your account. See our AI methodology page for details on how scoring works.
How We Use Your Information
- To provide and maintain the SyndTrack platform
- To process your subscription and payments
- To send transactional emails (e.g., capital call alerts)
- To extract data from documents you upload, and to generate AI deal scores when you request them (both via Anthropic)
- To improve our product and user experience
- To respond to support requests
Data Storage & Security
All data is encrypted in transit (TLS) and at rest (AES-256). Our database uses Supabase with row-level security, ensuring users can only access their own data. We regularly review our infrastructure and document our current controls on our security page.
We Do Not Sell Your Data
Based on how the product operates, we do not sell personal information. We disclose information to service providers needed to operate the platform, including Clerk for authentication, Supabase for database hosting and storage, Stripe for billing, Vercel for application hosting, Anthropic for document parsing and deal scoring, Resend for outbound transactional email, Sentry for error monitoring, and Upstash for rate limiting, idempotency, and webhook deduplication. Integrations transmit account data only after you connect and authorize them: Plaid for bank transaction import; Google Drive and Gmail; Microsoft Outlook and OneDrive; Dropbox; and configured sponsor-portal adapters such as Carta and CrowdStreet. See our security page for the full subprocessor list. We update this subprocessor list and note the change in our public changelog before a new subprocessor receives customer data.
Data Retention
We retain your data for as long as your account is active. When you close your account through Settings with the required typed confirmation, Stripe billing is cancelled immediately and your profile (name, email, avatar) is anonymised. Portfolio records, transactions, uploaded documents, and generated exports are kept for at least 30 days so support can reverse a mistaken closure. Full erasure of those records is carried out on request rather than automatically: send a request through the in-app help form and we complete it within 30 days of that request. Audit, legal and consent, compliance, billing-notice, and webhook records are deliberately retained. Data shared into a workspace stays with that workspace; closing-user identifiers on those shared rows are redacted when the erasure is carried out.
Cross-account benchmarking
Consent is recorded, but no cross-account pooling or comparison runs today. If we switch it on, your deal financials contribute only in aggregate and only once a cohort reaches at least 10 opted-in accounts and 50 contributed data points. The peer benchmark cache holds aggregate statistics only; it holds no user or deal identifiers. Consent is opt-in and withdrawable in one click from Reporting → Cross-account benchmarking, and withdrawal invalidates the cache immediately. This policy will be updated before any pooling is switched on.
Your Data Rights
These are the things you can do today and how:
- Access and export your personal data through Settings → Download data export. The JSON export includes your portfolio records, profile data, document metadata, temporary links for owned storage files, and up to 5,000 audit-log rows.
- Correct your information by editing portfolio records through the dashboard. Identity fields are managed by our authentication provider, Clerk, and synchronized to your profile.
- Close your account in Settings by typing DELETE MY ACCOUNT. Stripe billing is cancelled and your profile is anonymised immediately; portfolio records, documents, and exports are kept for at least 30 days, and full erasure of those records is carried out on request rather than automatically, within 30 days of that request. If you cannot sign in, submit an erasure request through the contact form on our help page; identity verification applies.
- Request restriction of processing or object to processing through the same help channels. We do not provide a separate restriction or objection preference center.
To exercise a right, use our help page. We may need to verify your identity before acting on a request.
California Privacy Rights
We collect identifiers and account information such as your name, email address, and authentication identifiers; commercial and financial information such as deal records, capital calls, distributions, transactions, subscriptions, and payment-related information; internet or electronic activity information such as account and product usage; professional or operator-entered information; and document contents and extracted information when you upload documents or use document parsing. We do not sell personal information based on how the product operates.
California residents may request access to or deletion of personal information, and may request correction where applicable. Submit a request through our help page. You may submit a request through an authorized agent using the same channel. We do not discriminate against you for exercising these rights.
Cookies
We use application cookies, identity-provider cookies, and infrastructure cookies. The signed-out public experience we observed set the following cookies:
ab_hero_cta_copy: product measurement for an experiment on homepage call-to-action wording; 90 days.syndtrack.onboarding.completed: remembers onboarding completion; one year when set.syndtrack-demo-origin: remembers entry to the public demo experience; 30 days when set.oauth_state,outlook_oauth_state,google_drive_oauth_state,onedrive_oauth_state,gmail_oauth_state, anddropbox_oauth_state: OAuth security state; 10 minutes when set.__client_uatand the suffixed__client_uat_<instance-suffix>form, observed as__client_uat_imnCTLjM: Clerk identity-provider cookies on.syndtrack.io; the observed signed-out expiry was September 13, 2027.__client: Clerk identity-provider cookie on.clerk.syndtrack.io; the observed expiry was around September 13, 2027._cfuvid: Cloudflare infrastructure cookie on.clerk.syndtrack.io; a session cookie in the observed session.__cf_bm: Cloudflare infrastructure cookie on.clerk.syndtrack.io; the observed lifetime was approximately 30 minutes.
The Clerk and Cloudflare cookies on .clerk.syndtrack.io are not application-owned cookies on www.syndtrack.io. We did not observe a Stripe-domain cookie from the public pricing page. This enumeration reflects the signed-out experience. Additional authentication cookies are set when you sign in.
We do not currently provide a cookie banner, consent manager, or cookie preference center, and cookie setting is not gated on an in-product consent choice. You can control cookies through your browser settings. We do not use third-party advertising cookies.
Security Incidents
One operator handles incidents personally; we do not staff a round-the-clock rotation. If we confirm an incident that affected your personal information, we email the address on your account (Resend is our only outbound path) and publish a note on the public changelog when more than one account is affected. We send notice within 7 days of confirming which accounts were affected. We notify regulators or others only where the law requires it. Internal steps live in our incident-response runbook.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the “Last updated” date.
Contact Us
If you have questions about this Privacy Policy, or want to exercise any of your privacy rights, please contact us via our help page.