Legal
Privacy Policy
Last updated: June 30, 2026
This Privacy Policy explains how CapDaddy collects, uses, shares, and protects information when companies and their invited users use the service. The service handles sensitive cap table, governance, stakeholder, tax, document, and signature records, so this policy is intentionally specific about those data flows.
1. Roles
A company or other organization using the service is the customer. For most cap table, stakeholder, governance, document, and portfolio records, the customer decides what information is entered, who may access it, and how it should be used. We process that Customer Data to provide the service.
We also process some information for our own operational purposes, such as account security, billing, service administration, fraud prevention, support, and legal compliance.
2. Information we collect
- Account and administrator information. Names, email addresses, Google account identifiers, organization memberships, roles, passkey credential metadata, TOTP enrollment metadata, email confirmation state, session records, IP addresses, and user agents.
- Company and cap table records. Organization names, issuer details, equity plans, stock classes, securities, grants, vesting schedules, transactions, stakeholder rosters, director and officer information, board and stockholder approvals, meetings, compliance tasks, fundraising records, exports, and import files.
- Stakeholder and signer information. Names, email addresses, stakeholder roles, security holdings, acceptance status, signature records, magic-link audit evidence, portfolio-link access records, and related communications.
- Sensitive tax and identity information. Where a customer chooses to use tax or identity workflows, the service may store tax identifiers, dates of birth, tax-form data, and related compliance records.
- Documents and generated records. Uploaded files, generated drafts, final documents, executed records, document hashes, timestamps, signature certificates, audit certificates, and document metadata.
- Billing information. Stripe customer IDs, subscription IDs, plan state, invoice/payment status, and billing-portal activity. Payment card details are handled by Stripe, not stored directly by CapDaddy.
- Communications and support. Emails we send or receive, support requests, delivery status, and operational notices.
- Technical information. Server logs, request metadata, error references, device/browser metadata, security events, and limited cookies described below.
3. Cookies and similar technologies
We use an opaque session cookie to keep signed-in administrators authenticated, short-lived cookies for security workflows such as OAuth and passkey ceremonies, and a theme cookie to remember light or dark mode. Cloudflare may run its RUM/Web Analytics beacon on proxied pages to collect performance metrics. We do not currently use advertising cookies or third-party behavioral advertising analytics.
4. How we use information
- Provide, operate, secure, debug, and improve the service.
- Authenticate users, enforce roles, support passkeys and step-up checks, and prevent unauthorized access.
- Maintain cap table, governance, document, signature, compliance, import, export, and portfolio workflows.
- Send invitations, magic links, reminders, confirmations, notifications, billing notices, and support messages.
- Process subscriptions and billing through Stripe.
- Create audit logs, document hashes, final records, and security evidence needed for trust and compliance.
- Respond to support requests, investigate abuse, enforce terms, and comply with law.
5. How information is shared
We do not sell personal information. We also do not share personal information for cross-context behavioral advertising.
- Within a customer workspace. Customer administrators and authorized members can access records according to their role. Invited stakeholders, directors, stockholders, signers, and portfolio viewers can access the limited records made available to them.
- Service providers. We use providers for hosting and databases, payment processing, authentication, email delivery, bot protection, timestamping, logging, monitoring, and similar operations. Current or supported providers include Railway/Postgres, Stripe, Google OAuth and Gmail/Google Workspace, Resend, Cloudflare Turnstile, Cloudflare RUM/Web Analytics, timestamp authorities, and configured observability/logging providers.
- Customer-directed exports and integrations. Customers may export or share records with their lawyers, accountants, investors, auditors, employees, service providers, or other recipients.
- Legal and safety reasons. We may disclose information if needed to comply with law, enforce agreements, protect rights or safety, investigate security issues, or respond to lawful requests.
- Business transactions. Information may be disclosed in connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality protections.
6. Security
We use technical and organizational safeguards designed for sensitive business records, including role-based access, row-level tenant isolation, append-only audit history, passkey and step-up controls for sensitive actions, hashed tokens, immutable final-document controls, encryption for selected sensitive fields, and monitored operational logs. No system can be guaranteed perfectly secure, and customers are responsible for securing their own accounts, devices, email inboxes, and authorized users.
7. Retention
We retain information for as long as needed to provide the service, maintain company records, preserve audit integrity, comply with legal obligations, resolve disputes, enforce agreements, maintain backups, and support customer exports. Because the service is designed around corporate records, final documents, transaction history, signature evidence, and audit logs may be retained or made immutable even when other information can be corrected, deleted, or de-identified.
8. Your choices and rights
Depending on where you live and how you use the service, you may have rights to know, access, correct, delete, restrict, object to, or export personal information. You may also have the right not to be discriminated against for exercising privacy rights.
Because much of the data in the service belongs to a customer workspace, we may direct requests from stakeholders, employees, directors, investors, or other invited users to the relevant customer unless we are required to respond directly. To make a request, contact [email protected].
9. International use
The service is operated from the United States. If you use it from outside the United States, information may be processed in the United States or other locations where we or our service providers operate.
10. Children
The service is intended for business use and is not directed to children. We do not knowingly collect personal information from children under 13. If you believe a child provided personal information to the service, contact us so we can address it.
11. Changes
We may update this Privacy Policy from time to time. If changes are material, we will provide notice through the service, email, or another reasonable method. The date at the top shows when this policy was last updated.
12. Contact
Questions or requests about privacy can be sent to [email protected].