Privacy Policy
Version 2.3 · Effective September 4, 2026
PRIVACY POLICY
Verity Intelligence, LLC
Effective Date: September 4, 2026 · Last Updated: September 4, 2026 · Version 2.3
Platform: verityintelligence.co · Contact: privacy@verityintelligence.co
YOUR DATA WORKS FOR YOU — ONLY YOU. Documents you upload, answers you provide, and questions you ask are processed exclusively within Verity's contracted infrastructure to generate your results. Your information is never used to train AI models, never shared with third parties for their own purposes, never sold, and never used to benefit anyone other than you.
1. Introduction
Verity Intelligence, LLC ("Verity," "we," "us," or "our") operates an AI-powered software platform for service business acquisition analysis at verityintelligence.co (the "Platform"). This Privacy Policy explains what information we collect, how we use it, who we share it with, and what rights you have over it.
This policy applies to:
-
Direct users — Searcher, Operator, and Advisor subscribers who access the Platform directly
-
Team Members — people invited to a subscriber's workspace under the Teams add-on
-
End-Users — clients of Advisor subscribers who access the Platform through an Advisor's workspace
-
Sellers and seller representatives — people who provide documents through an upload link sent by a Verity user, without holding a Verity account
-
Visitors — people who visit verityintelligence.co without creating an account
This policy does not apply to third-party websites or services linked from the Platform.
2. Who We Are
Verity Intelligence, LLC is a Nevada limited liability company and the operator of the Platform. We are the controller of personal information collected through the Platform. For privacy inquiries, contact us at privacy@verityintelligence.co.
3. Information We Collect
We collect information in four ways: information you provide directly, information generated by your use of the Platform, information collected automatically, and information provided by sellers through upload links.
3.1 Information You Provide
Account information. When you create an account, we collect your name, email address, and password. If you subscribe to a paid tier, billing information is processed directly by Stripe (our payment processor) and is not stored by Verity.
Onboarding profile information. When you complete onboarding, we collect information about your acquisition goals, business type preferences, geographic markets of interest, financial parameters (SDE range, asking price limits), deal structure preferences, risk tolerance, and acquisition timeline. This information personalizes your Platform experience and calibrates AI analyses to your declared criteria.
Deal and document information. When you use the Platform to evaluate businesses, we collect information you enter about potential acquisitions — including business details, financial figures, operational notes, and your own observations. When you upload documents (tax returns, profit and loss statements, seller packages, due diligence materials), we store those documents in your secure workspace.
Pasted correspondence. You may paste the text of an email or other written communication into a deal record as evidence. We store that text as you provided it. Pasted correspondence is recorded as a distinct and lower tier of evidence than an original source document, and the Platform will tell you so.
Knowledge Base content. When you add entries to your Verity Brain Knowledge Base, we store that content and use it to personalize AI responses to your queries.
Community posts. When you post in the Verity Community, we store that content. Community posts are visible to all Verity Community members. We operate automated PII detection and scrubbing on all Community posts before storage — see Section 7.
Support and feedback. When you contact us for support or submit feedback, we collect the content of those communications.
3.2 Information Generated by Platform Use
Usage data. We record how you interact with the Platform — pages visited, features used, analyses run, documents uploaded, actions taken, and referral attribution where applicable. This information is processed by PostHog, our analytics provider — see Section 5.
AI interaction data. When you interact with Verity Brain, your queries and the AI responses are stored in your workspace, and your conversation thread persists for the duration of your browser session across Platform features. You may save individual AI answers or full conversations to your workspace library; saved items are stored as immutable records linked to your workspace (and, optionally, to a specific deal), and you may delete saved items at any time. Saved Brain content linked to a deal is retained even if the deal itself is deleted. These interactions are processed by Anthropic's API to generate responses — see Section 6.1.
Deal locations and market footprint. When you add a deal, we collect the business's location and normalize it to a metro-level label. Your "market footprint" shown in the Platform is derived from the locations of your own deals.
Evaluator configurations and results. When you run the Opportunity Evaluator, we store your configured criteria, the inputs you provided, and the Pass/Fail result generated. A Pass/Fail result reflects whether a deal meets your configured criteria — it does not constitute a recommendation to acquire.
Contested facts. Where the Platform finds that a document and a stated claim about the same business disagree, we record both values, the source of each, and — if you resolve the disagreement — the value you selected and the basis you gave for selecting it.
3.3 Information Collected Automatically
Cookies and similar technologies. We and our analytics provider (PostHog) use cookies and similar technologies to recognize your session, maintain authentication, and collect usage data. See Section 5 for details on PostHog.
Log data. Our servers and our network infrastructure provider automatically record technical information when you access the Platform, including your IP address, browser type, operating system, referring URL, and access timestamps. This information is used for security monitoring, abuse prevention, and troubleshooting.
3.4 Information Provided by Sellers
A Verity user evaluating a business may send an upload link to the seller of that business or the seller's representative. A person who uses such a link does not hold a Verity account.
When documents are provided through an upload link, we collect the documents themselves and their contents, the file name and size of each document, the date and time of the upload, whether the upload succeeded, and a one-way cryptographic hash of the uploader's IP address. We do not store the uploader's IP address itself. Where the uploader provides a name or email address when accepting the Seller Upload Terms, we collect those together with a timestamped record of that acceptance.
Documents provided this way are delivered into the private workspace of the user who sent the link, and are processed in the same manner as documents that user uploads directly — including AI extraction of figures and comparison against information already recorded about the business.
Documents provided during a business sale frequently contain personal information about people who are not parties to the transaction, such as employees and customers. We ask uploaders to consider redacting individual names, and we ask Verity users who request such documents to request no more personal information than the evaluation requires.
4. How We Use Your Information
Providing the Platform. To authenticate your account, maintain your workspace, process your subscription, and deliver the features you use — including deal evaluation, document analysis, financial modeling, AI analyses, and community access.
Generating AI analyses. To produce AI-powered outputs calibrated to your declared criteria. When you use AI features, your inputs — including onboarding profile data, Knowledge Base content, deal information, and uploaded documents — are transmitted to Anthropic's API to generate responses. Anthropic processes this data as a contracted sub-processor and does not use it to train AI models. See Section 6.1.
Personalizing your experience. To apply your declared criteria, Knowledge Base content, and usage patterns to make Platform outputs more relevant to your specific situation and goals.
Analytics and product improvement. To understand how the Platform is used, identify areas for improvement, and develop new features. Usage data is processed by PostHog — see Section 5.
Security and fraud prevention. To monitor for unauthorized access, detect and prevent abuse, and protect the integrity of the Platform and its users.
Legal compliance. To comply with applicable laws, respond to lawful requests from authorities, and enforce our Terms of Service.
Communication. To send you transactional communications related to your account — subscription confirmations, payment receipts, billing notices, security alerts, and service updates. Transactional email is delivered by Postmark, our email delivery sub-processor — see Section 6.9. We do not send marketing emails.
5. Analytics — PostHog
We use PostHog to collect and analyze usage data about how the Platform is used. PostHog collects information including pages visited, features used, events triggered, session duration, and browser and device information. PostHog session recording is enabled on both our marketing website (verityintelligence.co) and the Platform's web application (app.verityintelligence.co): it captures a replay of your interactions (such as navigation and interface activity) to help us diagnose issues and improve the product; sensitive input fields are masked. PostHog processes this data on our behalf as a service provider and does not sell it to third parties or use it for its own advertising purposes.
PostHog is not a "sale" of personal information under Nevada Revised Statutes Chapter 603A (Nevada SB 220) or the California Consumer Privacy Act (CCPA). PostHog processes usage data solely to provide analytics services to Verity, and no monetary consideration flows from PostHog in exchange for your data.
Access to session recordings is restricted. Verity personnel view a recording only to diagnose an issue you have reported to us, or to conduct product and user-experience research aimed at improving the website and the Platform. We do not use session recordings for marketing, advertising, or profiling, and we never sell or share them with third parties. Recordings are automatically deleted after 30 days.
6. Third-Party Sub-Processors
Your information is processed only by Verity and the following contracted sub-processors. Each sub-processor is bound by data processing obligations consistent with this Privacy Policy. Full details of each relationship are set out in our Sub-Processor Data Processing Agreement at verityintelligence.co/data-processing-agreement.
6.1 Anthropic (AI Processing)
When you use AI features — including document analysis, Opportunity Evaluator AI narratives, Verity Brain Knowledge Base queries, and Brain Chat — your inputs are transmitted to Anthropic's API to generate AI responses.
Anthropic receives: query content, document content, onboarding profile data used as context, and Knowledge Base content included in prompts.
Anthropic does not use your data to train its AI models, does not share it with third parties, and does not retain it beyond what is necessary to generate your response.
Anthropic's privacy policy: anthropic.com/legal/privacy
6.2 Supabase (Storage, Database, and Authentication)
All Platform data — user accounts, onboarding profiles, deal records, uploaded documents, Knowledge Base entries, Community posts, Evaluator configurations and results, and AI interaction history — is stored in Supabase's managed PostgreSQL database and object storage.
Row-level security (RLS) is enforced at the database level, ensuring users can only access their own data. Advisor client workspaces are fully isolated from each other and from the Advisor's own workspace.
Supabase's privacy policy: supabase.com/privacy
6.3 Cloudflare (Network and Delivery Infrastructure)
The Platform is delivered through Cloudflare's network. Every request to the Platform passes through Cloudflare's infrastructure, which processes connection metadata including IP address, request headers, and timing information in order to route traffic, terminate TLS connections, and provide security and denial-of-service protection.
Cloudflare's privacy policy: cloudflare.com/privacypolicy
6.4 Lovable (Marketing Site Hosting)
Verity's marketing website (verityintelligence.co) is built and served through Lovable's hosting infrastructure; Lovable processes delivery and deployment data in the course of serving that site to your browser. The Platform's web application itself (app.verityintelligence.co) is served through Cloudflare's infrastructure as described in Section 6.3.
Lovable's privacy policy: lovable.dev/privacy
6.5 PostHog (Analytics)
As described in Section 5, PostHog processes usage analytics data on our behalf.
PostHog's privacy policy: posthog.com/privacy
6.6 Stripe (Payment Processing)
Payment processing is handled by Stripe. Your payment card information is entered directly into Stripe's secure payment interface and is not stored by Verity. Verity retains only your subscription status, tier, and billing history.
Stripe's privacy policy: stripe.com/privacy
6.7 DocuSign (Document Execution — Add-On)
If you connect DocuSign, documents you prepare for electronic signature are transmitted to DocuSign for execution. Verity facilitates the document execution process only and does not review, endorse, or recommend executing any document.
DocuSign's privacy policy: docusign.com/company/privacy-policy
6.8 Google (Fonts, Drive, and Gmail)
Google serves the typefaces used throughout the Platform. Every page you load requests these font files from Google, which discloses your IP address and browser characteristics to Google. This happens for every visitor, whether or not you hold a Google account. Separately, if you connect the Google Drive or Gmail integration, Verity accesses your Google account data to the extent you authorize through Google's OAuth process. Verity does not store Google account credentials.
Google's privacy policy: policies.google.com/privacy
6.9 Postmark (Transactional Email)
Transactional email — such as billing notices, subscription confirmations, and security alerts — is delivered through Postmark (ActiveCampaign, LLC). Postmark receives your name, email address, and the content of the transactional message (which may include high-level workspace activity counts, such as the number of documents or evaluations in your workspace, but never document contents). Postmark processes this data solely to deliver email on Verity's behalf.
Postmark's privacy policy: postmarkapp.com/privacy-policy
6.10 OpenStreetMap (Maps and Location Lookup)
Map features are rendered using imagery from OpenStreetMap, and deal locations are converted to map coordinates using the OpenStreetMap Nominatim service. These requests are made from your browser and disclose your IP address, the map area you are viewing, and the location text associated with a deal to the OpenStreetMap Foundation. No account information or document content is sent.
OpenStreetMap's privacy policy: osmfoundation.org/wiki/Privacy_Policy
7. Community Data
The Verity Community is a semi-public space within the Platform. Questions and responses you post in the Community are visible to all Verity Community members — not to the general public, but to other registered Verity users.
7.1 PII Detection and Scrubbing
To protect your privacy and the privacy of third parties mentioned in your posts, we operate automated PII detection on all Community posts before storage:
-
Client-side detection. Common patterns (email addresses, phone numbers, SSNs, EINs, street addresses, account numbers) are flagged before submission. Posts containing detected PII cannot be submitted until the flagged content is removed.
-
Server-side detection. Posts exceeding 50 characters are processed by an AI detection system before storage. Any personally identifiable information identified is replaced with [REDACTED] before the post is written to our database. The original text containing PII is never stored.
Do not include names, phone numbers, addresses, email addresses, tax identifiers, or any information that could identify a specific person or business in Community posts. Share the situation, not the specifics. Your private workspace is the appropriate place for deal-specific details.
8. Advisor and End-User Data
8.1 Advisor Subscribers
If you subscribe to the Advisor tier, you may create Client Workspaces for your clients (End-Users). As an Advisor, you are contractually obligated under the Advisor Agreement to ensure that your clients are made aware of this Privacy Policy and accept Verity's End-User Terms of Service before they access the Platform or receive any Platform outputs. Verity stores timestamped records of End-User acceptance.
8.2 End-Users (Advisor Clients)
If you access the Platform as an End-User through an Advisor's workspace, this Privacy Policy governs the processing of your personal information by Verity. Your information is processed in the same manner as direct user information described in this policy.
Your workspace data is fully isolated from other clients of the same Advisor and from all other Platform users. Your Advisor can access your workspace data as part of providing advisory services to you.
Verity is the underlying platform provider. Your Advisor uses Verity's Platform to provide services to you. Verity is not a party to your advisory relationship and does not direct how your Advisor uses the Platform to serve you.
Regardless of any white-label branding your Advisor has applied, "Powered by Verity Intelligence, LLC" appears in the Platform footer, and Verity is identified as the underlying platform at the moment you accept the End-User Terms.
9. Seller-Provided Documents
9.1 The relationship
Where a Verity user sends an upload link to a seller or a seller's representative, Verity is the controller of the personal information collected through that link. The user who sent the link is the recipient of the documents and determines what to request; Verity operates the platform on which the documents are stored and analyzed.
Verity has no advisory or professional relationship with a seller who uses an upload link, provides no service to that seller, and is not a party to any transaction between the seller and the user who sent the link.
9.2 Legal basis
Verity processes seller-provided information on the basis of its legitimate interests and those of the user who requested the documents — namely, enabling the evaluation of a prospective business acquisition using materials the seller chose to provide. Verity does not rely on consent as the basis for this processing.
9.3 Rights and limits
A person who has provided documents through an upload link may contact privacy@verityintelligence.co to request access to, correction of, or deletion of that information. Verity will act on such a request where it is able to.
Verity may be unable to delete documents where the user who received them has an ongoing legitimate business need for them — for example, where they form part of a transaction in progress — or where retention is required by law. Where Verity cannot act on a request, it will say so and explain why, rather than leaving the request unanswered.
9.4 What Verity does not do
Seller-provided documents are never sold, never shared with third parties for their own purposes, and never used to train AI models. They are subject to the same sub-processor arrangements, isolation controls, retention practice, and security measures as all other workspace data described in this policy.
10. Data Retention
We retain your personal information for as long as your account is active and for a reasonable period thereafter to allow account reactivation and to comply with legal obligations.
-
Account deletion. When you close your account, you may request deletion of your personal information by contacting privacy@verityintelligence.co. Verity acts on such requests where it is able to. Deletion is not automatic on closure, and some information is retained where retention is required by law (such as billing records, retained for 7 years as required by applicable tax law).
-
Uploaded documents. Retained while your account remains open, and deleted on request to privacy@verityintelligence.co, subject to the limits described in Section 9.3. This includes documents provided by sellers through upload links.
-
Community posts. Scrubbed versions are retained after account deletion (PII has already been removed before storage). Posts may have been referenced by other community members.
-
Analytics data. Retained per PostHog's data retention policies.
11. Data Security
We implement reasonable technical and organizational measures to protect your information, including:
-
Encryption of data in transit (TLS) and at rest (AES-256)
-
Row-level security (RLS) enforcing user-level data isolation at the database level
-
Server-side API key management — the Anthropic API key is stored as a server-side secret and never exposed to client-side code
-
Authentication and session management via Supabase Auth
-
Time-limited, revocable upload links for seller document requests, with server-side validation of every upload attempt
No system is completely secure. If you believe your account has been compromised, contact us immediately at privacy@verityintelligence.co.
12. Your Privacy Rights
12.1 Nevada Residents — Nevada SB 220 (NRS 603A)
Nevada law (NRS 603A.340) gives Nevada residents the right to opt out of the sale of covered personal information. Verity does not sell your personal information. We do not exchange your personal information for monetary consideration with any party. Our sub-processors process your data only to provide services to Verity.
Nevada residents may submit a verified opt-out request to privacy@verityintelligence.co. We will respond within 60 days. Because we do not sell personal information, such a request will be confirmed but will not result in any change to existing data practices.
12.2 California Residents — CCPA / CPRA
California residents have the following rights:
-
Right to know. Request information about categories and specific pieces of personal information we collect, purposes for which we use it, and categories of third parties with whom we share it.
-
Right to delete. Request deletion of personal information we have collected, subject to certain exceptions.
-
Right to correct. Request correction of inaccurate personal information.
-
Right to opt out of sale or sharing. We do not sell or share personal information for cross-context behavioral advertising. No opt-out mechanism is required, but you may confirm this by contacting privacy@verityintelligence.co.
-
Right to limit use of sensitive personal information. We do not use sensitive personal information beyond what is necessary to provide the Platform.
-
Right to non-discrimination. We will not discriminate against you for exercising your privacy rights.
To submit a CCPA request: email privacy@verityintelligence.co with subject line "CCPA Privacy Request." We will verify your identity and respond within 45 days (extendable by an additional 45 days with notice).
12.3 All Users
Regardless of location, you may:
-
Access and update account information through your account settings
-
Delete your account by contacting privacy@verityintelligence.co
-
Request a copy of your personal information by contacting privacy@verityintelligence.co
12.4 Sellers and Other Non-Account Holders
If you provided documents through an upload link and do not hold a Verity account, you may exercise the rights described in this Section by contacting privacy@verityintelligence.co. Because you do not hold an account, we may need additional information to verify your identity and locate the records in question. Section 9.3 describes the circumstances in which we may be unable to act on a deletion request.
13. Children's Privacy
The Platform is designed for adults engaged in business acquisition activities. We do not knowingly collect personal information from anyone under the age of 18. If we become aware that we have collected personal information from a minor, we will delete it promptly. If you believe a minor has provided information through the Platform, contact us at privacy@verityintelligence.co.
14. Do Not Track
Verity does not currently respond to Do Not Track signals. There is no industry consensus on how such signals should be interpreted, and we do not alter our analytics collection based on them.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
-
Update the "Last Updated" date at the top of this policy
-
Notify active subscribers by email at least 30 days before material changes take effect
-
For changes that materially affect how we use your data, require fresh acceptance of the updated policy before continued use
Your continued use of the Platform after the effective date of any changes constitutes acceptance of the updated policy.
16. Contact
For privacy questions, requests, or concerns:
Email: privacy@verityintelligence.co
Mail: Verity Intelligence, LLC, 732 S 6th St, Ste N, Las Vegas, Nevada 89101
Nevada SB 220 opt-out requests: privacy@verityintelligence.co — Subject: "Nevada Privacy Opt-Out"
CCPA requests: privacy@verityintelligence.co — Subject: "CCPA Privacy Request"
We will respond to all verified privacy requests within the timeframes required by applicable law.
Verity Intelligence, LLC | verityintelligence.co | Nevada
This Privacy Policy does not constitute legal advice. Verity provides calculation tools and AI analysis — not financial, investment, or legal advice.