California privacy notice

Effective date: September 8, 2026

This notice supplements our Privacy Policy.

Scope

This notice applies to California residents and describes our practices under the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA" / "CPRA").

Categories collected, sources, and disclosures

In the preceding 12 months we collected the categories below. For each we state where it came from, why we collect it, and the categories of third parties we disclose it to for a business purpose. Every named recipient appears on our subprocessors page.

CategoryExamplesSourceDisclosed to
IdentifiersName, email, account ID, IP addressYou; your deviceHosting, database, email, analytics providers
Customer records (§ 1798.80(e))Contact details, employer or firm affiliationYouHosting, database providers
Commercial informationSubscription plan, billing and transaction historyYou; payment processorPayment processor; hosting
Internet or network activityUsage logs, device and browser data, pages viewedYour device automaticallyHosting, analytics providers
Geolocation (approximate)City or region inferred from IP addressYour device automaticallyAnalytics providers
Professional informationTitle, employer, industry context you provideYouHosting, database providers
Financial information you enterHoldings, transactions, tax lots, documents you uploadYou; accounts you choose to linkHosting and database providers only
InferencesProduct interest and usage patternsDerived from the aboveAnalytics providers

Sensitive personal information. Account credentials are sensitive personal information under the CPRA and we collect them to authenticate you. We use and disclose sensitive personal information only for purposes permitted by § 1798.121(a) — providing the Service you requested, security, and preventing fraud — and never to infer characteristics about you. Because of that, we are not required to offer a "Limit the Use of My Sensitive Personal Information" link, and we do not display one. Financial data you enter is treated with the same protections whether or not the statute classifies it as sensitive. If our practices change, we will update this notice and provide any required control before the change takes effect.

Purposes for collection and use

We use each category for business purposes that reasonably align with the expectations of a user of a financial software platform, including:

  • Operating, maintaining, and securing the Service
  • Processing payments and fulfilling contracts
  • Customer support and communications
  • Analytics, product improvement, and debugging
  • Compliance with law and protection of rights

Sale, sharing, and targeted advertising

We do not sell personal information for monetary consideration, and we have not done so in the preceding 12 months. We do not share personal information for cross-context behavioral advertising as defined under the CPRA. We do not sell or share the personal information of consumers we know to be under 16.

Global Privacy Control. We honor the GPC browser signal as a valid opt-out request for the browser that sends it. Our public marketing site runs analytics, visitor-identification, and support-chat scripts — Google Analytics, Google Tag Manager, Apollo.io, and Thunderbolt — which some regulators treat as "sharing" regardless of how we characterize it. Rather than argue the point, we apply the opt-out. A GPC signal is browser-specific and will not carry across your devices; email us if you want the opt-out applied account-wide.

Financial incentives. We do not offer financial incentives or price differences in exchange for personal information. Founding-rate pricing is available on the same terms to anyone who qualifies and is not conditioned on any data-sharing choice. Exercising a privacy right never changes your price or your access.

Retention

The CPRA requires us to state how long we keep each category rather than say "as long as necessary". Account and profile records are kept for the life of the account and deleted or anonymized within 90 days of closure. Product data you create is kept for the life of the account and is exportable at any time. Billing and transaction records are kept up to 7 years to meet tax and accounting law. Server, security, and AI activity logs are kept up to 12 months. Support correspondence is kept up to 24 months after the matter closes. Marketing-site analytics follow the provider default, generally 14 months or less. Encrypted backups roll off on roughly a 35-day cycle.

The full schedule, including how deletion interacts with backups, is in our Privacy policy.

Your California rights

Subject to exceptions, California residents may request:

  • Access to specific pieces and categories of personal information we hold
  • Deletion of personal information
  • Correction of inaccurate personal information
  • Information about certain disclosures for business purposes

We will not discriminate against you for exercising these rights. We may need to verify your identity before fulfilling a request.

How to submit a request: email support@quantridge.net with the subject line "California privacy request", or use our contact form. An authorized agent may submit on your behalf with written permission signed by you, or under a valid power of attorney; we may still contact you to confirm.

Timing. We confirm receipt within 10 business days and respond within 45 days, extendable once by a further 45 days where the request is complex. We will tell you before extending. Requests are free unless manifestly unfounded or repetitive.

If we deny your request, we will tell you which statutory exception applies. You may appeal by replying with the subject "Privacy appeal"; a different reviewer will respond within 45 days. You may also complain to the California Privacy Protection Agency or the California Attorney General at any time, including before appealing.

Contact

support@quantridge.net