In effect since August 8, 2026 -- version 2026-08-08.1
Privacy Policy (DRAFT)
This is a structural draft, not yet reviewed by an attorney with US privacy-law expertise. Nothing below should be treated as final legal text. This is a SEPARATE instrument from the pt-BR Privacy Policy - it addresses US state privacy law (e.g. CCPA where applicable), not LGPD.
1. Who we are and what this policy covers
This policy covers the One Trinity Ventures platform (ventures.onetrinity.co). It does not cover onetrinity.co/startups, which has its own policy.
2. Data we collect
- Account: name, email, identity-provider id (Clerk).
- Venture: name, stage, sector, country, cap table scenarios, holders
(which may be hypothetical), instruments, simulated rounds.
- Assessment: your Reality Check and Venture Readiness responses, and the
score produced by the deterministic rubric.
- Platform activity: share-link views, master console access (with a
declared reason), audit trail (audit_log).
3. How we use it
We use your data to operate the tool: rendering your cap table, computing your score, enabling controlled sharing. We do not use venture data for the aggregate benchmark engine without separate, granular, revocable consent (see section 6, benchmark_aggregation) - that consent is never bundled into the Terms.
4. Who we share it with
- A third party you choose to share with via a share link (/s/[token]),
at the scope you set (summary or full), with an expiration.
- The platform master/admin role does not read your cap table by
default. It only reads it if you explicitly submit the venture (venture_submissions) or through an audited break-glass exception, always visible to you in a panel showing who viewed your venture.
- We do not sell personal data to third parties.
5. Your privacy rights
You may request access, correction, deletion, portability, and may revoke consent at any time. [DRAFT: formal request channel and response timeline to be defined with lawyer; applicable state law (e.g. CCPA/CPRA) to be confirmed.]
6. Granular consent
We record consent separately per type: terms, privacy, benchmark_aggregation, marketing_email. Each can be granted and revoked independently of the others, at /[locale]/consents.
7. Data retention
[DRAFT: retention period per data type to be defined with lawyer; audit_log and venture_scores are append-only by design, which has a retention implication to clarify.]
8. Security
Authentication via Clerk; venture access controlled by venture_members; every master read of a cap table records a reason and is visible to the founder.
9. Data of minors
This platform does not collect data from minors. One Trinity social program (ONE FUTURE / Instituto), which does process teenage participant data, is a separate system with a separate database and its own parental-consent flow, not yet built.
10. Contact
[DRAFT: privacy contact to be defined with lawyer.]
11. Changes to this policy
A change to the substance of this policy is a new VERSION. A recorded consent stores the version accepted.