Privacy Policy.
This policy explains what information Trussdee collects, how we use it, who can access it, and the rights you have regarding your data.
1. Introduction
Trussdee, Inc. ("we," "us," or "our") operates the Trussdee financial performance tracking and consolidation application (the "App") and the Trussdee website, waitlist, and related support pages (the "Site"). The App and Site are referred to together as the "Services."
This Privacy Policy explains what information we collect through the Services, how we use and disclose it, how access is governed, and the choices and rights that may be available to you. Your use of the App is also governed by the agreement that applies to your workspace or subscription.
2. Who This Policy Covers
This policy applies to the following categories of individuals:
Family Office Users — Authorized staff, advisors, and administrators at a family office who use the App to manage, consolidate, and report on financial information on behalf of a family.
Family Members — Individual members of a family whose financial information is managed or viewed within the App. Family members may have their own login credentials, or their data may be entered and managed by family office staff on their behalf.
Household Users — Individuals who create or join a Trussdee Household workspace to organize their own or a partner's financial information.
Site Visitors and Prospective Customers — People who browse the Site, join the waitlist, request support, or otherwise communicate with us.
These categories are referred to collectively as "you" or "users" throughout this policy.
For a family-office or other organization-managed workspace, that organization generally determines why and how information is processed, and Trussdee acts as its service provider or processor. For a direct Household subscription, waitlist submission, or other direct relationship, Trussdee may determine the relevant processing purposes. If your information is controlled by an organization, we may refer a privacy request to that organization and assist it in responding.
3. Information We Collect
We collect information necessary to provide a comprehensive financial consolidation and performance tracking experience. The categories of information we collect include:
3.1 Financial, Portfolio, and Property Data
Bank, Credit, Brokerage, and Digital-Asset Accounts: Account identifiers, institutions, balances, limits, transaction histories, holdings, positions, lots, cost basis, income, fees, and performance data.
Real Estate, Private Investments, and Other Assets or Liabilities: Property addresses, valuations, acquisition costs, ownership details, rents and lease dates, debts, private-company interests and grants, capital commitments and calls, tax assumptions, invoices and calculation workpapers, and performance data for alternative or illiquid assets.
3.2 Information You or Your Organization Provide
Authorized users may enter data manually or upload files, including asset descriptions, valuations, cost basis information, notes, transaction imports, entity and household structures, ownership allocations, beneficiary or key-person details, contact information, and customer documents.
Customer documents may include wills, birth certificates, passports or other identification, tax or Social Security number records, powers of attorney, health-care directives, estate-planning records, tax documents, and financial statements. The App does not require every category from every user. You and your organization are responsible for submitting only information you are authorized to provide and that is reasonably necessary for the selected feature.
3.3 Information from Third-Party Data Partners
Where you authorize it, Trussdee connects to financial institutions and other supported services through third-party providers to import or process account, transaction, market, reference, valuation, or connected-service data. The applicable flow depends on the feature and provider you choose:
Provider categories include financial connectivity and aggregation, transaction categorization and enrichment, connected digital-asset services, market and reference data, and valuation data. Our maintained Provider and Subprocessor Page identifies the current providers, their purposes, and whether they are part of Trussdee's core service or are enabled at a customer's direction.
By connecting an account or enabling an integration, you direct us to use the applicable supported provider and authorize the access, retrieval, transmission, storage, and processing needed for that feature. Customer-directed providers may also operate under separate terms and privacy practices between you or your organization and that provider.
3.4 Account, Agreement, and Billing Information
We process names, email addresses, workspace roles and memberships, user and organization identifiers, authentication and session state, and security events. Our identity provider handles end-user authentication credentials; Trussdee receives the identifiers and session information needed to authorize access. When you connect a financial provider or supported exchange, Trussdee may store an encrypted access token, API key, or similar read credential.
We also process agreement-acceptance evidence, such as the accepted document version and hash, signer name and capacity, timestamp, IP address, user agent, and acceptance screen details. For paid plans, we process subscription, plan, invoice, payment-status, and Stripe customer or subscription identifiers. Payment card details are entered into and handled by Stripe rather than stored in Trussdee's application database.
3.5 Waitlist, Support, and Communications
If you join the Site waitlist, we collect your first and last name, email address, phone number, title, company or family office, and any notes you submit. The Site sends that submission through Twilio SendGrid to authorized Trussdee recipients. We also process the contents and routing information of support, privacy, security, and other communications you send to us.
3.6 Technical Data, Cookies, and Similar Technologies
When you use the Services, Trussdee and its hosting, identity, support, and connectivity providers may process IP address, device and browser information, request and session timestamps, routes or features accessed, referring page, request identifiers, and operational or security events. IP addresses may indicate an approximate area, but the Services do not request precise device geolocation.
The App and embedded connection or authentication flows use cookies, browser storage, or similar technologies that are necessary for authentication, session continuity, security, and a feature you request. We do not currently deploy advertising pixels or use cookies to sell personal information, share it for cross-context behavioral advertising, or track your activity over time across unrelated websites.
The Site loads fonts from Google Fonts, so a visitor's browser makes requests to Google's font-serving domains. The Site also loads the Productlane support widget so visitors can search help, chat, or submit feedback without leaving the page; when you use that widget, Productlane processes the information you submit. The Services also link to a Productlane-hosted help center and other external services; when you follow an external link, the destination's privacy practices apply. Our current providers and their purposes are listed on the Provider and Subprocessor Page.
Do Not Track and Global Privacy Control: Because we do not currently sell personal information, share it for cross-context behavioral advertising, or conduct the cross-site tracking described above, browser Do Not Track or Global Privacy Control signals do not change our current processing. If our practices change, we will respond to legally recognized preference signals as required by applicable law.
3.7 Personal Information Categories — California Reference
The table below summarizes categories that may be processed through the Services. Whether information is "sensitive personal information" under California law depends on the specific information and how it is used; ordinary balances or holdings are not automatically sensitive personal information merely because they are financial.
The retention criteria in Section 8 apply to each category below. Actual periods vary by the purpose, customer relationship, provider lifecycle, legal or agreement requirement, and whether the information is needed for security, billing, dispute, or acceptance records.
| Category | Examples in Trussdee | Collected | Notes |
|---|---|---|---|
| Identifiers and Contact Information | Name, email, phone number, IP address, user, workspace, account, and provider identifiers | Yes | Account-login or financial-account information combined with credentials that permit access may be sensitive personal information. |
| Financial and Commercial Information | Balances, holdings, transactions, cost basis, valuations, debts, subscriptions, and invoice or payment status | Yes | Some credential combinations or uploaded records may be sensitive personal information. |
| Customer Content and Relationships | Documents, notes, property addresses, entity, household, ownership, beneficiary, and key-person details | Yes | May include government identifiers, health-related information, or other sensitive content if an authorized user uploads it. |
| Internet or Electronic Network Activity | Request and session timestamps, routes or features accessed, device and browser type, and security events | Yes | Used for operation, security, troubleshooting, and scoped audit purposes. |
| Professional and Role Information | Title, company or family office, workspace role, and administrative capacity | Yes | Provided by you, your organization, or the identity provider. |
| Derived Information and Inferences | Transaction categories, performance calculations, cost basis, ownership allocations, alerts, and reports | Yes | Generated to provide the financial organization and reporting features you request. |
| Approximate Location | Approximate area inferred from an IP address | May be processed | We do not request precise device geolocation. |
| Government, Health, or Biometric Information | Not dedicated profile fields; government or health information may appear in uploaded documents. Biometric templates are not an App data field. | Content-dependent | Submit only information that is authorized and necessary. |
4. How We Use Your Information
We use the information we collect for the following purposes:
- To provide and operate the Services — Consolidating, organizing, and displaying financial data and customer content across authorized scopes, accounts, and asset classes.
- To generate reports and performance analytics — Producing financial summaries, portfolio performance views, workpapers, alerts, and other reports requested by authorized users.
- To authenticate users and maintain account security — Verifying identities, managing access controls, and protecting against unauthorized access.
- To connect to financial institutions and supported services — Facilitating authorized data flows through providers in the categories described in Section 3.3 and on our maintained Provider and Subprocessor Page.
- To improve the App — Using operational telemetry and information that has been de-identified so that it cannot reasonably be linked to you, your organization or household, an account, or another individual to diagnose issues, improve reliability, and enhance features. We do not attempt to re-identify this information.
- To communicate with you — Responding to waitlist and support requests and sending account, connection, security, billing, and policy notices.
- To comply with legal obligations — Retaining records and responding to lawful requests where required by applicable law.
We do not use your financial data to serve advertising, sell personal information, or train machine learning or artificial intelligence models. Truly de-identified information may be used only to operate, secure, analyze, and improve Trussdee, not to create commercial data products.
5. Who Has Access to Your Information
Access within the App is governed by workspace role, account-management scope, ownership or reporting scope, household membership, document target, and any sharing or access decision made through the App. A workspace role does not by itself make every record visible.
| Role | Access Level |
|---|---|
| Workspace Administrators and Managers | Can manage family-office-scoped data and workspace functions for the organization they administer. Records marked as personally managed remain limited to the personal controller unless they are shared or moved into family-office management through an authorized App flow. |
| Family Office Staff and Other Workspace Users | Access to family-office-managed information and functions based on their workspace role and the reporting, ownership, household, document, or account scopes that apply to them. |
| Family Members and Household Users | Access to their own personally managed information, information shared with a household to which they belong, and family-office-managed information available through their authorized reporting or ownership scope. |
| Trussdee, Inc. Personnel | Access only as needed to provide technical support, investigate security incidents, or fulfill legal obligations. Privileged platform-administrator access, document listing/view/download activity, security and identity events, and material data or configuration changes are logged; not every read of customer information is logged. |
7. Data Security
We maintain safeguards designed to protect information based on its sensitivity and the risks presented, including:
- Encryption in transit using TLS and encryption at rest for managed data stores
- Application-layer authenticated encryption for stored provider access credentials
- Role-, tenant-, ownership-, and account-scope controls designed to limit data access
- Authentication and session controls, including multi-factor authentication capabilities through our identity provider
- Audit logging for privileged administrator access, document activity, security and identity events, and material mutations
- Operational monitoring for service health, job and provider failures, and security-relevant anomalies
- Routine backups and documented restoration procedures, without a promised recovery point or recovery time
Scope of this statement: The safeguards above are a general description, not a warranty or certification. This Policy does not claim that every read is logged, promise a recovery time or recovery point, represent that Trussdee has completed a SOC 2 audit or other certification, or represent that Trussdee is currently subject to the Gramm-Leach-Bliley Act or the FTC Safeguards Rule. Any additional security commitments are governed by an executed agreement with the applicable customer.
Despite these measures, no system is completely immune from security risks. We encourage you to use a strong, unique password and to contact us immediately if you suspect unauthorized access to your account. Please see Section 13 for information on how we respond to security incidents.
8. Data Retention
We retain financial, account, identity, website, communication, and technical information while an account or relationship is active and as reasonably necessary to provide the Services, maintain business, agreement-acceptance, billing, audit, and security records, resolve disputes, enforce our agreements, and comply with applicable law.
This Policy does not promise a fixed post-closure deletion schedule or a general self-service deletion feature. Information may remain in routine backups until those backups expire or are overwritten in the ordinary provider lifecycle. Legal holds and legal, billing, agreement, security, and fraud-prevention needs may require us to retain some records after other information is deleted.
You can review or update some information through the App. You may also contact us to request access, correction, export, or deletion. We verify identity and authority before acting. If an organization controls the information, we may direct the request to that organization. We honor requests when required by applicable law and subject to its exceptions; we may also honor a request voluntarily.
9. Children's Privacy
The Services are not directed to children. The App is not offered for an individual under 18 to create and use on their own, and the Site waitlist is intended for adult business contacts. We do not knowingly collect personal information directly from a child under 13.
In a family-office or household context, an authorized adult or organization may submit information about a minor who is a family member, beneficiary, or related person. The submitting customer is responsible for having appropriate authority and for limiting that information to what is reasonably necessary.
If you believe a child has submitted personal information directly through the Services, please contact us using the privacy email link so we can assess and address it.
10. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices, technology, providers, or legal requirements. We will post the updated version and revise the effective or last-updated date. For material changes, we will provide any additional or advance notice, and obtain renewed consent, when required by applicable law or an agreement that applies to you.
Material changes apply prospectively. Your use of the App remains subject to the change and acceptance terms in your applicable agreement.
11. California Disclosures and Privacy Rights
California's Online Privacy Protection Act requires disclosures about information collected through commercial websites and online services. Sections 3 through 6 describe the information and sources, purposes, and provider categories relevant to the Services; Section 8 describes review and request options; Section 10 describes policy changes; and Section 3.6 describes third-party collection, browser signals, and our current absence of cross-site advertising tracking.
The California Consumer Privacy Act, as amended by the CPRA, applies only to businesses that meet its statutory applicability criteria, including revenue, data-volume, sale, or sharing thresholds and related requirements. Trussdee does not currently represent that it meets those criteria. If and to the extent the CCPA applies to Trussdee or a particular processing activity, this section describes the rights available to covered California consumers.
Note on sensitive personal information: California's definition includes, among other things, an account login or financial-account number combined with credentials that allow account access, precise geolocation, government identifiers, certain health information, and certain personal information of known consumers under 16. Customer documents or provider credentials may contain sensitive personal information. Trussdee does not use sensitive personal information to infer characteristics, serve advertising, sell data, or train models. Information that has been truly de-identified as described in Section 4 is not personal information and may be used only to operate, secure, analyze, and improve the Services.
Rights When the CCPA Applies
- Right to KnowYou have the right to request disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources, our business purpose, and the categories of third parties with whom we share it. See Section 3.7 for our category disclosures.
- Right to DeleteYou have the right to request deletion of your personal information, subject to certain exceptions — for example, where retention is required by law or necessary to complete a service you requested.
- Right to CorrectYou have the right to request correction of inaccurate personal information that we maintain about you.
- Right to Limit Use of Sensitive Personal InformationYou may have the right to limit certain uses or disclosures of sensitive personal information beyond purposes permitted by California law. We do not currently use sensitive personal information for purposes that require a limit-use opt-out.
- Right to Opt Out of Sale or SharingWe do not sell personal information or share it for cross-context behavioral advertising.
- Right to Non-DiscriminationWe will not discriminate against you for exercising any of your CCPA/CPRA rights — including denying services, charging different prices, or providing a different level of service.
How to Submit a Request
Contact our Privacy Officer using the information in Section 14. We will verify your identity and authority before acting. When the CCPA applies, we will follow its required response process and timing, including the rules for authorized agents, extensions, and manifestly unfounded or excessive requests.
12. Utah Privacy Rights — If Applicable
The Utah Consumer Privacy Act (Utah Code §13-61-101 et seq.) applies only to controllers and processors that meet its statutory revenue, data-volume, and related applicability criteria. Trussdee does not currently represent that it meets those criteria. If and to the extent the UCPA applies to Trussdee or a particular processing activity, covered Utah consumers have the rights described below.
Note: The UCPA provides different rights than the CCPA/CPRA. Rights under either statute depend on that statute applying to Trussdee and the relevant processing activity.
Rights When the UCPA Applies
- Right to Access — You may request confirmation of whether Trussdee is processing your personal data and request access to that data.
- Right to Delete — You may request deletion of personal data that you provided to us, subject to exceptions where retention is required by law or necessary to complete a service you requested.
- Right to Data Portability — You may request a copy of your personal data in a portable, readily usable format, to the extent technically feasible.
- Right to Correct — You may request correction of inaccuracies in your personal data, taking into account the nature of the data and the purposes for which it is processed.
- Right to Opt Out of Sale — You may opt out of the sale of your personal data. Trussdee does not sell personal data.
- Right to Opt Out of Targeted Advertising — You may opt out of the processing of your personal data for targeted advertising. Trussdee does not process personal data for targeted advertising purposes.
How to Submit a UCPA Request
Contact our Privacy Officer using the information in Section 14. We will verify your identity and authority before acting. When the UCPA applies, we will follow its required response process and timing, including applicable extension, appeal, authentication, and statutory-exception rules.
13. Security Incidents & Breach Notification
Despite our safeguards, no system is completely risk-free. In the event of a security incident that results in unauthorized access to or acquisition of your personal information, Trussdee will respond as follows:
Our Response Process
- Detect & Contain Take reasonable steps to identify and contain the incident, preserve evidence for investigation, and reduce the risk of further unauthorized access.
- Assess Determine the nature and scope of the breach — what information was affected, whose information, and the likely impact.
- Notify Affected Individuals Notify affected users as required by applicable law or an agreement that applies to the incident. The content and timing of a notice depend on those requirements and the information available at the time.
- Notify Regulators and Partners Report to relevant regulatory authorities and affected providers or subprocessors as required by law and applicable contracts.
- Remediate & Review Address identified root causes and update our security program as appropriate to reduce the risk of recurrence.
Notification Timing
We notify affected individuals, customers, regulators, consumer reporting agencies, and providers when and within the time required by applicable law or an agreement that applies to the incident. Notice duties depend on the type of information, whether the legal definition and risk threshold for a reportable breach are met, the affected jurisdiction, law-enforcement needs, and whether Trussdee acts as the owner/controller or as a processor for a customer.
A business customer may have a separate contractual notification period measured from confirmation of a defined security incident. That agreement-specific period applies only to the covered customer and incident; this Policy does not create a universal fixed notification deadline.
If you suspect your Trussdee account has been compromised, please contact us immediately using the privacy email link. Prompt reporting helps us respond quickly and minimize potential harm.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal information — including exercising any rights described in Sections 11 or 12 — please reach out to our Privacy Officer: