Effective date: September 8, 2026
This notice supplements our Privacy Policy.
This notice applies to California residents and describes our practices under the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA" / "CPRA").
In the preceding 12 months we collected the categories below. For each we state where it came from, why we collect it, and the categories of third parties we disclose it to for a business purpose. Every named recipient appears on our subprocessors page.
| Category | Examples | Source | Disclosed to |
|---|---|---|---|
| Identifiers | Name, email, account ID, IP address | You; your device | Hosting, database, email, analytics providers |
| Customer records (§ 1798.80(e)) | Contact details, employer or firm affiliation | You | Hosting, database providers |
| Commercial information | Subscription plan, billing and transaction history | You; payment processor | Payment processor; hosting |
| Internet or network activity | Usage logs, device and browser data, pages viewed | Your device automatically | Hosting, analytics providers |
| Geolocation (approximate) | City or region inferred from IP address | Your device automatically | Analytics providers |
| Professional information | Title, employer, industry context you provide | You | Hosting, database providers |
| Financial information you enter | Holdings, transactions, tax lots, documents you upload | You; accounts you choose to link | Hosting and database providers only |
| Inferences | Product interest and usage patterns | Derived from the above | Analytics providers |
Sensitive personal information. Account credentials are sensitive personal information under the CPRA and we collect them to authenticate you. We use and disclose sensitive personal information only for purposes permitted by § 1798.121(a) — providing the Service you requested, security, and preventing fraud — and never to infer characteristics about you. Because of that, we are not required to offer a "Limit the Use of My Sensitive Personal Information" link, and we do not display one. Financial data you enter is treated with the same protections whether or not the statute classifies it as sensitive. If our practices change, we will update this notice and provide any required control before the change takes effect.
We use each category for business purposes that reasonably align with the expectations of a user of a financial software platform, including:
We do not sell personal information for monetary consideration, and we have not done so in the preceding 12 months. We do not share personal information for cross-context behavioral advertising as defined under the CPRA. We do not sell or share the personal information of consumers we know to be under 16.
Global Privacy Control. We honor the GPC browser signal as a valid opt-out request for the browser that sends it. Our public marketing site runs analytics, visitor-identification, and support-chat scripts — Google Analytics, Google Tag Manager, Apollo.io, and Thunderbolt — which some regulators treat as "sharing" regardless of how we characterize it. Rather than argue the point, we apply the opt-out. A GPC signal is browser-specific and will not carry across your devices; email us if you want the opt-out applied account-wide.
Financial incentives. We do not offer financial incentives or price differences in exchange for personal information. Founding-rate pricing is available on the same terms to anyone who qualifies and is not conditioned on any data-sharing choice. Exercising a privacy right never changes your price or your access.
The CPRA requires us to state how long we keep each category rather than say "as long as necessary". Account and profile records are kept for the life of the account and deleted or anonymized within 90 days of closure. Product data you create is kept for the life of the account and is exportable at any time. Billing and transaction records are kept up to 7 years to meet tax and accounting law. Server, security, and AI activity logs are kept up to 12 months. Support correspondence is kept up to 24 months after the matter closes. Marketing-site analytics follow the provider default, generally 14 months or less. Encrypted backups roll off on roughly a 35-day cycle.
The full schedule, including how deletion interacts with backups, is in our Privacy policy.
Subject to exceptions, California residents may request:
We will not discriminate against you for exercising these rights. We may need to verify your identity before fulfilling a request.
How to submit a request: email support@quantridge.net with the subject line "California privacy request", or use our contact form. An authorized agent may submit on your behalf with written permission signed by you, or under a valid power of attorney; we may still contact you to confirm.
Timing. We confirm receipt within 10 business days and respond within 45 days, extendable once by a further 45 days where the request is complex. We will tell you before extending. Requests are free unless manifestly unfounded or repetitive.
If we deny your request, we will tell you which statutory exception applies. You may appeal by replying with the subject "Privacy appeal"; a different reviewer will respond within 45 days. You may also complain to the California Privacy Protection Agency or the California Attorney General at any time, including before appealing.