Privacy Policy

How Vantage handles
your information.

Last updated April 26, 2026. This policy describes how Vantage42, Inc. ("Vantage") collects, uses, and protects information from customers and visitors to vantage42.com.

What we collect

Customer data: Documents, metrics, notes, and other content that customers upload, paste, or otherwise submit to the Vantage product. This includes founder updates, valuation letters, capital call notices, K-1s, and analyst notes. Customer data belongs to the customer and is held only to provide the service.

Account information: Name, work email, role, and the firm a user belongs to. Used for authentication and access control.

Usage data: Method invocations, page navigation events, error logs. Captured server side, retained for 90 days, used for operational monitoring and product improvement. No third party analytics, no session replay, no cross site tracking.

Marketing site visitors: Page views are counted server side via aggregated request logs. No cookies set on vantage42.com for visitors who do not request access. The marketing site does not use Google Analytics, Hotjar, Segment, Meta pixels, or other third party trackers.

What we don't do

We do not train AI models on customer data. Founder updates, valuation letters, and personal investment data flow through inference only pipelines. No fine tuning, no embedding corpus training, no transfer to model providers' training corpora.

We do not sell customer data, share it with data brokers, or use it to power benchmarking products consumed by other customers without explicit opt in.

We do not place advertising trackers, session replay tools, or third party analytics on the marketing site or in the product.

Sub processors

Vantage uses the following third parties to operate the service. Each is contractually bound to maintain the same data handling standards Vantage commits to in this policy.

  • MindStudio. Application platform powering Vantage's backend, managed database, and AI orchestration. SOC 2 certified and GDPR compliant; all AI inference is routed for zero retention, and customer data is never used to train models.
  • Amazon Web Services. Primary infrastructure provider (US-East-1 default; EU-West-2 for European customers).
  • Anthropic, OpenAI, Google. AI model providers used for document parsing and synthesis. All configured for zero retention inference; customer data is not retained or used for training by these providers.
  • Postmark. Transactional email delivery for system notifications and customer facing emails.
  • Cloudflare. DNS, WAF, and CDN services.

Customers are notified at least 30 days before any sub processor change. The current list is also available on request.

Security

Encryption: TLS 1.3 in transit, AES-256 at rest with per tenant key isolation. Vantage is built on MindStudio, a SOC 2 Type I and Type II certified platform, and inherits its certified infrastructure; Vantage's own SOC 2 Type II is in progress (target Q3 2026). Annual third party penetration testing.

Audit logs of every read and write are maintained per tenant, available to customer administrators, and exportable on demand as CSV for internal audit, external auditors, or board review. Users sign in with passwordless, single use email verification codes. Access is governed by role based controls with strict per tenant isolation, and customer administrators provision, deprovision, and set the role of every user in their firm.

Data export and deletion

Customers may request a full data export at any time. We deliver in machine readable form (JSON + the original document files) within 14 days of a verified request. We delete customer data, including replicas and backups, within 30 days of a verified deletion request.

Contact

Questions, data subject access requests, and deletion requests should be sent to privacy@vantage42.com. EU representative information available on request.