Privacy Policy
This policy explains how Christopher Leigh Studios, LLC, operating DealSherpa, handles personal information on this website and in the application at app.dealsherpa.co. It sits alongside ourTerms of Service.
The short version: the documents you upload are yours, we process them to give you the analysis you asked for, we do not sell them, and we do not use them to train public AI models.
1. What we collect
Information you give us
- Account details — your name, email address, password (stored only as a hash), and the organization you belong to.
- Deal content — the documents you upload and everything you type into a deal: financial statements, contracts, leases, notes, your buying criteria, your questions to Sherpa. These frequently contain other people’s personal and financial information — a seller’s, an employee’s, a landlord’s — and you decide what to put in.
- Billing details — your plan, your order history, and the contact record our billing provider keeps. Card numbers go to the payment processor and never reach our servers.
- What you write to us — support email and anything you send with it.
Information we collect automatically
- Usage — pages viewed, features used, actions taken, and coarse device and browser information, collected through our product analytics.
- Technical logs — IP address, timestamps, and error reports including stack traces, kept to keep the Service running and secure.
- Email engagement — whether a transactional email was delivered, bounced or reported as spam, so we can tell when our mail is not arriving.
We do not buy personal information about you from data brokers, and we do not run advertising trackers on this site.
2. Why we use it
- To run the Service — analyse your documents, produce grades and answers, keep your workspace working. This is performance of our contract with you.
- To bill you and keep the records a business has to keep.
- To secure the Service — detect abuse, investigate incidents, enforce our Terms. This is our legitimate interest in a service that is not being attacked.
- To improve the Service — understand which features earn their place, in aggregate. Our legitimate interest in building something that works.
- To contact you about your account, security, and material changes to these policies. Marketing email, if we ever send it, is separately consented to and separately unsubscribable.
- To comply with the law when we are required to.
3. How your documents are processed by AI
When you upload a document, it is stored, then read by a large language model operated by our AI provider to extract figures and terms, spot issues and answer your questions. The relevant content — and only what the task needs — is sent to that provider for that purpose.
We do not permit our AI provider to train its models on your content, and we do not train models on it ourselves. Our provider may retain content briefly for abuse monitoring under its own enterprise terms.
AI output can be wrong. The Service links extractions back to their source and cites evidence for its answers so you can check them, and our Terms explain why checking is your job, not ours.
4. Who processes it for us
We do not sell personal information and we do not share it for cross-context behavioural advertising. We do use service providers, each bound to handle it only on our instructions:
- Vercel — Hosts the website and the application.
- Neon — Hosts the Postgres database where your account and deal records live.
- Cloudflare R2 — Stores the documents you upload.
- OpenAI — Reads your documents and questions to produce extractions, grades and answers.
- Inngest — Runs the background jobs that process documents after you upload them.
- Resend — Sends transactional email — password resets and account notices.
- Keap — Processes subscriptions and holds billing and contact records.
- PostHog — Product analytics: which features get used, and where people get stuck.
- Sentry — Error monitoring, so we hear about a crash before you have to report it.
We may also disclose information where the law requires it, to enforce our Terms or protect someone’s safety, and to an acquirer if the business is sold — in which case this policy travels with it or you get notice before anything changes.
Other members of your organization can see that organization’s deals and documents. That is the point of a shared workspace, and it is worth remembering before you upload something personal to one.
5. Where it is processed
We are based in the United States and our infrastructure runs there. If you are in the European Economic Area, the United Kingdom or Switzerland, using the Service means your information is transferred to the United States, and we rely on Standard Contractual Clauses or an equivalent mechanism with the providers listed above.
6. How long we keep it
- Deal content — for as long as your account is open, and deleted when you delete the deal or the organization it belongs to.
- After you close an account — we delete or de-identify your account and deal content within 90 days, other than what we must keep for tax, accounting or legal reasons.
- Backups roll off on their own schedule, generally within 35 days.
- Billing records are kept as long as the law requires, typically seven years.
Ask us to delete something sooner and we will, subject to those obligations.
7. Security
Traffic is encrypted in transit and data is encrypted at rest. Every tenant-scoped record carries its organization, and isolation is enforced both in the application and in the database itself, so one customer’s query cannot reach another’s rows. Passwords are hashed, never stored. Access to production is limited to people who need it.
No system is perfectly secure. If a breach affects your information we will tell you and the relevant regulator as the law requires.
8. Cookies
We use a small number, and none of them are for advertising:
- Session cookies keep you signed in and protect forms against cross-site request forgery. The Service does not work without them.
- Analytics cookies let our product analytics recognise a returning browser. Browser-level “Do Not Track” and global privacy control signals are honoured where we receive them.
9. Your choices and rights
Depending on where you live — and under the GDPR and UK GDPR, and under California’s CCPA and similar U.S. state laws — you may have the right to:
- know what we hold about you and get a copy of it;
- correct it;
- delete it;
- object to or restrict certain processing, and withdraw consent where we relied on it;
- take it elsewhere in a portable format;
- not be discriminated against for exercising any of these.
Much of this you can do yourself inside the app. For the rest, write tosupport@dealsherpa.co and we will respond within the time the law allows, normally 30 days. We may need to verify who you are first. You can also complain to your data protection authority, though we would rather you told us first.
Where we process content on behalf of your organization, we act as a processor and your organization as the controller — we will route a request to them where that is the right answer.
10. Children
The Service is for adults buying businesses. It is not directed at children, and we do not knowingly collect information from anyone under 18. If we learn we have, we delete it.
11. Changes
We will update this policy as the Service changes. Material changes get notice by email or in the app before they take effect, and the effective date at the top always tells you which version you are reading.
12. Contact
Privacy questions and requests go to support@dealsherpa.co.