Privacy Policy

Effective Date: September 12, 2026

1. Information We Collect

ExitVelocity collects information that you provide directly to us, including:

  • Account & Profile Information: Name, business email, phone number, company name, and role (buyer, seller, or broker).
  • Business & Financial Data: Business listing details, historical revenues, EBITDA, balance sheets, and uploaded financial documentation.
  • Transaction & Deal Records: Signed non-disclosure agreements, inquiries, messages, offer parameters, and due diligence notes.
  • Billing Data: Billing contact information and transaction history managed through our payment processor, Stripe. We do not store raw credit card numbers.

2. How We Use Your Information

We use the data we collect for the following purposes:

  • Executing deterministic financial models (DCF and multiple-based valuation).
  • Generating AI-assisted acquisition insights, risk summaries, and synthesis via Anthropic Claude.
  • Facilitating secure buyer-seller messaging, document requests, and deal workflows.
  • Enforcing multi-tenant isolation and row-level security across organizations.
  • Sending critical transactional alerts (e.g., valuation completed, new offer received, search alerts).

3. Multi-Tenant Data Isolation & Security

ExitVelocity enforces database-level Row Level Security (RLS) and isolated tenant boundaries. Your confidential financial files stored in our secure storage vaults are encrypted in transit and at rest. Proprietary financial documents are only shared with authorized parties who have signed an active Non-Disclosure Agreement for that listing.

4. Third-Party Service Providers

We work with trusted infrastructure providers to deliver our platform:

  • Supabase: Authenticated sessions, relational PostgreSQL database, and encrypted object storage.
  • Stripe: Payment processing and subscription management.
  • Resend: Secure delivery of transactional notifications.
  • Anthropic: Claude AI processing for financial analysis (customer data is not used to train third-party foundation models).
  • Trigger.dev: Background asynchronous task orchestration.

5. Data Retention & Your Rights

You may request to review, update, or delete your account information at any time by navigating to your account settings or contacting us. If you request deletion of your account, we will remove personal identifiers from our active records, subject to legal and regulatory retention requirements.

6. Contact Us

If you have questions or concerns about this Privacy Policy or how your confidential data is handled, contact our privacy team at privacy@exitvelocity.ai or visit our Contact page.