Contact usSign inDemo
Sign in Demo

Privacy Policy

StartSmartt · Effective Date: September 28, 2026

StartSmartt LLC, a Delaware limited liability company (“StartSmartt,” “we,” “us,” or “our”) operates the www.startsmartt.com website and provides certain services via the website and otherwise. We believe in the importance of earning and maintaining the trust of our clients and of others who visit the website or otherwise use or interact with our services (“you” or “your”). We are committed to protecting your privacy rights.

This Privacy Policy applies to this website and any other StartSmartt website (together, the “Website”), and to the paid and unpaid subscriptions, newsletters, platforms, programs, software, applications, events and services provided by StartSmartt (collectively, the “Services”) that reference, link to, or incorporate this Privacy Policy. Where any Service incorporates expressly different privacy terms, we will provide a link to those terms. If you have entered into a separate written agreement with StartSmartt governing your use of the Services (a “Master Services Agreement,” “Master Terms and Conditions,” “EULA,” “Statement of Work” or “Order”), any conflicting privacy terms of that agreement control as set out in it.

To the extent permitted by applicable law, by using the Services or by accepting a Master Services Agreement or a related Statement of Work or Order, you consent to the collection and use of the information you provide, the information that is legally or contractually provided to StartSmartt, and the information StartSmartt collects based on your use of the Services, in accordance with this Privacy Policy and the applicable agreement.

Who this policy is and is not about

StartSmartt’s Services are business-to-business. Most of the information in the platform is provided by our client organizations — sponsors, borrowers, lenders and their advisers — about transactions and about the individuals who work on them.

  • Where an individual’s information is submitted to the platform by a client organization, that organization determines why and how the information is used. In data-protection terms, the client is the controller and StartSmartt acts as a processor or service provider on its behalf, under the terms of the agreement with that client and its Data Processing Addendum. Requests about that information should be directed to the client organization. If you contact us, we will refer you to them.
  • Where StartSmartt collects information for its own purposes — visitors to the Website, prospective clients, people who contact us, people who receive our marketing, and individuals who register directly — StartSmartt is the controller, and this Privacy Policy governs.

Third-Party Links

The Services may contain links to websites or services operated by others. Those links are provided for reference and convenience and are the exclusive responsibility of their owners. We are not responsible for the content or operation of those websites or services, nor for the security or privacy of any information they collect. You should review the privacy statements applicable to those third-party websites or services.

Information We Collect

Information you provide. We collect personal information you voluntarily provide through your interaction with, or use of, the Website and the Services, or through third-party websites and applications when you request information about the Services. This may include your name, business email address, telephone number, employer and role, billing information, and your professional network profile.

Information provided by your organization. Some of the personal information we hold may not have been provided directly by you — for example, your name, business email address or role may be provided by your employer if it has purchased Services for you or has invited you to a transaction on the platform. You should not provide personal information about others unless you are authorized to do so. By submitting personal information about others, you represent that you have the necessary authority.

Transaction and platform content. When our clients use the platform, they submit information about transactions — including deal terms, documents, participant lists, correspondence and status. This may include personal information about the individuals involved. We process it on their instructions.

Usage information. When you access the Services we may automatically collect information about your usage, using various technologies. Examples include IP address, browser type, device and operating system, domain name, pages viewed, and aggregate statistical data. Where the Services include usage limits or metering, some information is collected to determine usage and attributed to your account.

Marketing information. For marketing purposes we collect information about your visits to and activity on the Website, the number of times you have viewed an advertisement or opened an email, and similar usage information. When you receive promotional email from us, we may use service providers, customized links or similar technologies to determine whether an email has been opened and which links were followed.

Communications. If you contact us to provide feedback, make an inquiry, or otherwise communicate in a way that requires a response, we record the personal information and other content you provide so that we can respond.

Payment information. If you purchase any of the Services, we collect the information necessary to process the transaction. Card and bank account details are collected and processed by our payment processor; StartSmartt does not store full payment card numbers on its own systems. Payment information is used for billing purposes only.

Information we do not seek. We do not seek, and ask that you do not submit, Social Security numbers, government identification numbers, financial account numbers, health information, or other sensitive personal information except where a Service expressly requires it and the field is provided for that purpose.

Use of Personal Information

Our goal is to provide our clients with the highest quality Services and to ensure their satisfaction. We use personal information for the following business purposes:

User registration and client support. To register and administer your subscription or account, provide technical support and training, verify your identity, and send you important information about your subscription, account and the Services.

Provision and personalization of the Services. Personal and aggregate information gathered from usage is used to analyze trends, understand how the Services are used, deliver and suggest relevant content, and personalize your experience. It is also used for internal research and development strictly related to improving and testing the features and functions of the Services.

Marketing communications. To deliver marketing communications across various channels. We will comply with applicable law, which may require your clear and unambiguous consent or another lawful basis. Marketing email includes instructions on how to opt out. Even if you opt out of marketing email, we may still send you information necessary to your subscription, account or use of the Services.

Security, fraud prevention and integrity. To secure the Services, authenticate users, detect and investigate suspected misuse, and maintain audit records.

Legal obligations. We may use and retain personal information for legal and compliance reasons — including the prevention, detection or investigation of a crime, loss prevention, or fraud — to meet internal and external audit requirements, for information security purposes, and as we otherwise believe necessary or appropriate: (a) under applicable law; (b) to respond to requests from courts, law enforcement, regulators and other public authorities; (c) to enforce our terms of service or other terms; and (d) to protect our rights, privacy, safety or property, or those of others.

Children’s privacy. The Services are not directed to anyone under the age of 13, and we do not knowingly collect personal information from anyone under 13. If you are a parent or guardian and become aware that a child has provided us with personal information, please contact us and we will take steps to remove it.

What we do not do. We do not sell personal information. We do not share personal information with third parties for cross-context behavioral advertising. We do not use the content our clients submit to the platform to train generative artificial intelligence models for the benefit of other clients or third parties.

Sharing Information

We share or disclose personal information only to the extent necessary to provide the Services, conduct our business operations, or where we believe applicable law permits or requires disclosure. When sharing personal information we abide by applicable privacy and security requirements. We may occasionally share non-personal, anonymized and statistical data with third parties. In the event of a merger, acquisition, consolidation, change of control, divestiture or dissolution in which we sell all or part of our business or assets, we will disclose necessary personal information, and that information will be governed by the privacy policies of the acquiring entity.

Our business operations are supported by StartSmartt personnel, and limited personal information is made available to them as necessary — for example for the provision of Services, client support, sales and marketing, technical support and product development. All StartSmartt personnel and agents are required to follow the Company’s data privacy and security policies when handling personal information.

We are supported by third parties which provide limited and necessary services on our behalf. These receive only the personal information necessary to fulfill the services they provide to us. They are not permitted to use that information for any purpose other than providing those services to us, and are required to maintain its confidentiality. Our current categories of service provider are:

CategoryPurposeLocation
Cloud hosting and infrastructureHosting the Services and storing dataMicrosoft Azure, East
Email and productivityBusiness communicationsMicrosoft
Payment processingBilling and collectionStripe
Customer support and ticketingResponding to requestsMonet
Product analyticsUnderstanding usage of the ServicesMicrosoft Azure
Marketing and email deliverySending communicationsMicrosoft Azure, Twilio, SendGrid
Error monitoring and loggingDiagnosing faultsMicrosoft Azure

Finally, we will share personal information where we believe it is legally required or necessary — for example where we believe in good faith that we are legally compelled to do so by order of a court of competent jurisdiction or other governmental body.

Data Storage and Security

We use Azure to host the Services and store information on servers located in the United States. By using the Services you agree to your data being stored on those servers. Our hosting provider is not permitted to access or use personal information except for the limited purpose of providing hosting and storage.

In addition, we use reasonable administrative, technical, personnel and physical measures to safeguard information against loss, theft and unauthorized use, as described in our Information Security Policy. To help us protect your privacy, always maintain the secrecy of your credentials. You acknowledge that no internet transmission can be guaranteed to be fully secure or error-free, and that any transmission of personal information over the internet in connection with the Services is at your own risk. If we or our service providers are required to notify you of unauthorized access to certain security systems, you agree that we may provide notice by posting it on the Website or sending it to an email address we have on file.

Retention

We retain personal information for as long as necessary to provide the Services, to comply with our legal, tax and regulatory obligations, to resolve disputes and to enforce our agreements. Client content submitted to the platform is retained and deleted in accordance with the agreement with the relevant client. Where information is no longer needed, it is deleted or de-identified.

Accessing and Controlling Your Information

We will review your requests for personal information and, where applicable, will correct, amend or delete it. While we will make reasonable commercial efforts to accommodate requests, we also reserve the right to impose restrictions and requirements on access requests, or to decline, where permitted by applicable law.

If you wish to know what personal information we hold about you, or want it removed from our systems, please contact us. In certain circumstances you have the right: (i) to access and receive a copy of the personal data we hold about you; (ii) to have inaccurate personal information corrected; and (iii) to request the deletion of your personal information. You may also have a right to data portability, allowing you to obtain a copy of your personal information in a commonly used electronic format.

To protect personal information, all requests are subject to relevant legal requirements and exemptions, including identity verification. Before providing any data — including before confirming whether we hold any data — we will ask for proof of identity and sufficient information about your interaction with us to locate the relevant data and confirm the request comes from you. We may charge a fee for providing a copy of your data, except where a fee is not permitted by applicable law.

In some jurisdictions you have the right to correct or amend your personal information if it is inaccurate or out of date. You may also have the right to request deletion, though this is not always possible because of legal requirements and other obligations. You may always contact the applicable government or regulatory authority in your jurisdiction.

Where the information was submitted by a client organization, please direct your request to that organization. We will assist our client in responding, as our agreement with them requires.

To opt out of marketing email, use the unsubscribe link in the email you received, or contact us as described below.

Cookies and Similar Technologies

A cookie is a small text file placed on a device in order to identify the user or device and collect limited information. StartSmartt and its service providers use cookies and similar technologies on the Website for purposes related to your use of and experience with the Services, including managing preferences, enabling content, and gathering website analytics.

We use both session cookies, which expire when the browser is closed, and persistent cookies, which remain until deleted. You can manage cookies in your browser settings, and you may accept, reject or delete them. If you change these settings, some functions and features may not work as intended. Browser settings differ, so refer to the relevant settings within your browser.

Our current cookie categories are:

CategoryPurposeCan you turn it off?
Strictly necessaryAuthentication, session management, securityNo — the Services will not function
PreferencesRemembering settingsYes
AnalyticsUnderstanding how the Website and Services are usedYes
MarketingMeasuring campaignsYes

State Privacy Rights — United States

StartSmartt is formed in Delaware. Delaware has a comprehensive consumer privacy statute, the Delaware Personal Data Privacy Act, which took effect on January 1, 2025. It has among the lowest applicability thresholds in the country and no minimum revenue threshold. Delaware also has a general data breach notification statute, 6 Del. C. § 12B-101 et seq.

Your rights, however, are not determined by where we are incorporated. State privacy laws apply based on where you reside. If you are a resident of a state with a comprehensive privacy law — including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island, or another state whose law has taken effect — you may have the rights described below, subject to that state’s thresholds, exemptions and verification requirements.

Depending on your state of residence, you may have the right to:

  • Confirm whether we process your personal information and access it;
  • Obtain a copy of your personal information in a portable format;
  • Correct inaccurate personal information;
  • Delete personal information we hold about you;
  • Opt out of the sale of personal information, of targeted advertising, and of certain profiling in furtherance of decisions producing legal or similarly significant effects;
  • Limit the use and disclosure of sensitive personal information; and
  • Not be discriminated against for exercising these rights.

Important B2B limitation. Most state comprehensive privacy laws — including Delaware’s — apply only to individuals acting in a personal or household capacity, and expressly exclude information about individuals acting in a commercial or employment context. Because StartSmartt’s Services are used by professionals in the course of their work, much of the information we hold falls outside the scope of those laws. California is the principal exception: the CCPA, as amended, does cover business-to-business and employment-context information.

Financial-institution exemption. Several state privacy laws, Delaware’s among them, exempt financial institutions subject to the Gramm-Leach-Bliley Act at the entity level, and most exempt GLBA-regulated data at the data level. Where a customer of ours is a financial institution, or where the information we hold constitutes non-public personal information under that Act, a different framework applies — the one set out in our agreement with that customer and its Data Processing Addendum.

How to exercise a right. Submit a request to admin@startsmartt.com. We will acknowledge receipt and respond within the period required by the applicable law — generally 45 days, extendable once where reasonably necessary. We will verify your identity before acting on a request. You may use an authorized agent where the applicable law permits.

Appeals. Several state laws give you the right to appeal a refusal to act on your request. To appeal, reply to our response or write to admin@startsmartt.com with the subject line “Privacy Appeal.” We will respond in writing within the period the applicable law requires and, if we deny the appeal, we will tell you how to contact your state Attorney General.

Delaware residents — additional note

The Delaware Personal Data Privacy Act applies to entities that conduct business in Delaware or target Delaware residents and that, in the prior calendar year, controlled or processed the personal data of at least 35,000 consumers, or of at least 10,000 consumers while deriving more than 20% of gross revenue from the sale of personal data. Whether and when we meet those thresholds depends on the volume of data we hold about individuals acting in a personal capacity, which excludes most of the professional-context data described above. Where the Act applies, Delaware consumers have the rights listed above, together with the right to obtain a list of the categories of third parties to whom we have disclosed their personal data. Enforcement is by the Delaware Department of Justice; there is no private right of action.

California residents — additional disclosures

This section supplements the information above and applies to residents of the State of California under the California Consumer Privacy Act, as amended.

In the preceding twelve (12) months we have collected the following categories of personal information:

CategoryExamplesCollected
A. IdentifiersReal name, alias, postal address, unique personal identifier, online identifier, IP address, email address, account nameYES
B. California Customer Records categories (Cal. Civ. Code § 1798.80(e))Name, signature, address, telephone number, employment, employment history, financial informationYES
C. Protected classification characteristicsAge, race, national origin, religion, marital status, disability, sex, sexual orientation, veteran or military statusNO
D. Commercial informationRecords of products or services purchased or considered, purchasing historiesYES
E. Biometric informationFingerprints, faceprints, voiceprints, iris scans, keystroke or other physical patternsNO
F. Internet or other network activityBrowsing history, search history, interaction with a website, application or advertisementYES
G. Geolocation dataPhysical location or movementsCOARSE
H. Sensory dataAudio, electronic, visual, thermal or similar informationYES
I. Professional or employment-related informationCurrent or past job history, employer, role, performance evaluationsYES
J. Non-public education informationEducation records maintained by an educational institutionNO
K. InferencesProfile reflecting preferences, characteristics, behavior, attitudes, abilities and aptitudesYES
L. Sensitive personal informationGovernment identifiers, account log-in credentials, precise geolocation, contents of mail or messages, biometric dataACCOUNT CREDENTIALS ONLY

Personal information does not include: publicly available information from government records; de-identified or aggregated consumer information; and information excluded from the CCPA’s scope, such as health or medical information covered by HIPAA and the California Confidentiality of Medical Information Act, and personal information covered by certain sector-specific privacy laws including the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act and the California Financial Information Privacy Act, and the Driver’s Privacy Protection Act of 1994.

We obtain the categories of personal information listed above from the following categories of sources: directly from you, through forms, submissions and communications; indirectly from you, through information we collect from our clients, vendors or other third parties in the course of providing the Services; directly and indirectly from your activity on our Website and applications; from third-party data providers and business partners; and from publicly available databases.

We may use or disclose the personal information we collect for one or more of the business purposes described in “Use of Personal Information” above.

We will not collect additional categories of personal information, or use personal information we have collected for materially different, unrelated or incompatible purposes, without providing you any required notice.

Disclosure for a business purpose. When we disclose personal information for a business purpose we enter into a contract that describes the purpose and requires the recipient to keep the information confidential and not use it for any purpose except performing the contract. In the preceding twelve months we may have disclosed categories A, B, D, F, G and I for a business purpose.

Sale or sharing. In the preceding twelve months we have not sold personal information, and have not shared personal information for cross-context behavioral advertising.

Retention. We retain each category of personal information for the period described in “Retention” above.

International Transfers

The Services are hosted in the United States. If you access the Services from outside the United States, you understand that your information will be transferred to, stored and processed in the United States, where data protection law may differ from that of your jurisdiction. Where we process personal data subject to the European Union or United Kingdom General Data Protection Regulation, we do so in accordance with the terms of the applicable Data Processing Addendum, including the Standard Contractual Clauses where they apply.

Questions Regarding this Policy and Your Information

You may contact us at:

StartSmartt, 745 Ellsworth Dr NW, Atlanta, GA 30318-1726 Attention: Stuart Smartt, CEO

Email: admin@startsmartt.com Website: www.startsmartt.com Telephone: 404.849.5711

Modifications to this Privacy Policy

We may modify this Privacy Policy from time to time. When we do, we will revise the Effective Date at the top of this page and, where the change is material, we will provide additional notice — by posting a notice on the Website or by contacting you at an email address we have on file. Your continued use of the Services after a modification takes effect constitutes your acceptance of the modified Privacy Policy.