Legal
Privacy Policy
Version 1, draft pending counsel review. Last updated May 10, 2026.
This policy describes how RepReady, Inc. ("RepReady," "we," "us") collects, uses, shares, and protects personal information.
It applies in three settings:
- Reps: financial professionals who subscribe to RepReady and use the platform to operate their practice. For Reps, RepReady is the controller of the Rep's account data.
- End clients of Reps: members of the public who visit a Rep's hosted site, submit a lead or contact form, schedule a meeting, or otherwise interact with a Rep through the platform. For end-client data, the Rep is the controller and RepReady is the processor. End-client questions should go first to the Rep whose site you used; we will route requests to them when we receive them directly.
- Marketing site visitors: anyone who visits
repready.builditself. For these visitors, RepReady is the controller.
The Data Processing Addendum at repready.build/dpa governs the legal mechanics of the Rep-as-controller / RepReady-as-processor relationship in setting (2).
1. What we collect
1.1 From Reps (controller: RepReady)
- Account info: name, email, password (hashed), phone, photo, professional title, designations, languages, business address.
- Identity / registration: FINRA CRD number, state license list, BrokerCheck snapshots, disclosure events.
- Firm info: broker-dealer name and CRD, supervising principal name and email, branch office address.
- Billing: Stripe customer ID and last-4 of payment method. We do not store full card numbers; Stripe does.
- Usage: dashboard activity, content authored, feature flags, plan tier, login records, IP addresses, device and browser metadata.
- Communications: emails to and from
support@repready.buildandcompliance@repready.build, in-app messages.
1.2 From end clients of Reps (controller: the Rep)
If you are a member of the public interacting with a Rep's hosted site, the Rep decides what to collect through their forms. Typical fields include name, email, phone, message, services of interest, preferred contact time. The Rep, not RepReady, sets the form fields and retains the data.
We process this data only to provide platform features the Rep has enabled: routing the form submission to the Rep's CRM, sending the Rep a notification, applying compliance and anti-spam controls, and producing aggregate analytics for the Rep.
1.3 From marketing site visitors
- Pages viewed, referring URL, IP address, device and browser metadata, cookie identifiers (essential and analytics).
- Information you submit through a contact, demo, or signup form.
1.4 From third parties
- FINRA BrokerCheck for Rep registration history and disclosures.
- Stripe for billing status and payment events.
- OAuth integrations you connect (LinkedIn, Meta, Google Ads, Google Business Profile, CRMs, ESPs) for the limited fields necessary to operate the integration.
- Plausible Analytics for privacy-respecting aggregate site analytics; no cross-site tracking.
2. How we use the information
For Rep account data we use the information to:
- Operate the platform and deliver the features described in the Terms of Service.
- Verify registration status via BrokerCheck and surface relevant disclosure events to the supervising Principal.
- Send transactional emails (billing, security, system events) and product emails you have not unsubscribed from.
- Detect, investigate, and prevent fraud, security incidents, abuse, and violations of the Acceptable Use Policy.
- Comply with regulatory retention requirements (FINRA Rule 4511, SEC Rule 17a-4, applicable state rules).
- Improve the platform (aggregated and anonymized usage metrics; specifically not the rep's content for model training without separate consent).
For end-client data processed on behalf of a Rep we use the information solely to provide the platform features the Rep has enabled, on the Rep's documented instructions.
For marketing-site data we use the information to operate repready.build, respond to inquiries, and measure aggregate engagement.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use Rep's end-client data to train AI models.
3. How we share information
We share information only with:
- The Rep's supervising firm and Principal, as needed for the supervisory workflow contemplated by the Compliance Acknowledgment.
- Subprocessors we engage to provide the platform, each under a data-processing agreement consistent with this policy. Current subprocessors are listed at
repready.build/subprocessors(TBD; full list to be published before launch). The current list includes Supabase (database, storage, auth), Vercel (hosting), Stripe (billing), Resend (email), Anthropic (AI inference for content generation; with no training on customer content), and Plausible (analytics). - Service partners you explicitly connect via OAuth (LinkedIn, Meta, Google Ads, Google Business Profile, CRMs, ESPs), to the extent necessary to operate the integration you authorized.
- Regulators (FINRA, SEC, state securities regulators) on lawful request, as described in the Compliance Acknowledgment.
- Law enforcement in response to a valid legal demand, court order, or subpoena, with notice to you unless legally prohibited.
- Successors in connection with a merger, acquisition, or sale of all or substantially all of our assets, subject to the obligations in this policy carrying over.
4. Retention
We retain:
- Active account data for the duration of the subscription.
- Audit and compliance records for the longer of (a) the term of the subscription plus 7 years, or (b) any longer period required by the applicable regulatory rule (FINRA Rule 4511, SEC Rule 17a-4, state rules) or by the Firm's written supervisory procedures.
- Marketing-site data for the period the user remains opted-in plus 90 days.
- Backups on a rolling 35-day window.
When the retention period ends, we delete the data from active systems and from backups when the backup rotation cycles past.
5. Your rights
Depending on where you live and which relationship applies to you, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate personal information.
- Request deletion (subject to our regulatory retention obligations, which override the right to delete for the relevant records).
- Object to or restrict certain processing.
- Receive your data in a portable format.
- Withdraw consent where processing is based on consent.
- Opt out of certain disclosures of personal information.
To exercise a right, email privacy@repready.build. Identity verification is required.
End clients of a Rep should contact the Rep whose site you used, or contact us and we will route the request. For requests we receive directly about end-client data, our standard response time is 30 days, extendable to 45 days under GDPR / CPRA where applicable.
If you are in the EU/UK, you may lodge a complaint with your supervisory authority. We will appoint an EU representative once we have any EU presence; until then EU residents may contact us at privacy@repready.build.
6. Security
We maintain administrative, technical, and physical safeguards designed to protect personal information. Highlights:
- Encryption in transit (TLS) and at rest (Supabase, AES-256).
- Row-level security policies in the database to enforce tenant isolation.
- Append-only triggers on audit and compliance tables.
- Encrypted secrets handling for OAuth tokens and credentials.
- Penetration testing on an annual cadence after general availability.
- Incident response: we will notify affected users and the supervising Principal within 72 hours of confirming a breach involving personal information.
No system is perfectly secure. We do not warrant that breaches will not occur.
7. Children
The platform is not designed for or directed at children under 16. We do not knowingly collect personal information from children. If you become aware that a child has provided us personal information, contact privacy@repready.build and we will delete it.
8. International transfers
Our infrastructure runs in the United States. If you access the platform from outside the United States, you understand that your information will be transferred to and processed in the United States. For EU/UK personal data, we rely on the EU Standard Contractual Clauses and the UK addendum, supplemented by our internal transfer impact assessment. Where the DPA applies, those clauses are incorporated there.
9. Cookies
The platform uses essential cookies (for session, security, and load balancing) and a minimal set of preference cookies. We use Plausible Analytics for privacy-respecting aggregate analytics. We do not use cross-site tracking cookies or set advertising identifiers.
A Rep may, at their option, add additional analytics to their own Rep Site (for example, a connected Google Analytics 4 property). When they do, the Rep's cookie banner discloses that addition and obtains consent where required.
10. Changes
We may update this policy. Material changes will be notified by email (Reps) and posted on the marketing site at least 30 days before they take effect. Non-material changes (typos, contact updates) take effect on posting.
11. Contact
Privacy questions: privacy@repready.build
Compliance questions: compliance@repready.build
Postal: RepReady, Inc., [address TBD]
Versioning: bump on every counsel revision. Current: Draft v1 / 2026-05-10.
See also the Terms of Service.