Loading legal…
Legal
How Allocatin, Inc. collects, uses, shares, and transfers personal information when you use AllocatIN.
This Privacy Policy explains our practices for the AllocatIN website, web workspace, iOS and Android apps, emails, and related professional services. It is written for users and firms in the United States (including California and other comprehensive state laws), Canada (PIPEDA and Quebec Law 25), the United Kingdom (UK GDPR and the Data Protection Act 2018), and the European Union / EEA (GDPR).
The controller is Allocatin, Inc., a corporation organized under the laws of England and Wales, United Kingdom. Contact the privacy team at privacy@allocatin.com. Our privacy officer for Canadian and Quebec purposes is reachable at the same address.
If Article 27 GDPR or UK GDPR requires an EU or UK representative, we will publish that representative here and provide details on request.
We act in two roles:
Counterparties you choose to connect with become independent controllers of what you send them. Their practices are not this policy.
Company email, name, title, firm, role (manager or allocator), authentication tokens, and seat or organization membership. We ask for a company domain so we can verify you are authorized to represent the firm.
Suitability and mandate fields you choose to store or publish: asset classes, ticket guidance, geography, structure, manager stage, domicile, sector tags, fundraising or allocation context, visibility rules, and verification status. These are professional, institutional fields — not a retail investor questionnaire.
Connection requests, saves, skips, pipeline stages, quota use, messages and attachments after mutual consent, meeting or scheduling metadata, support tickets, and emails you send us.
IP address, approximate location derived from IP, browser or app version, device type, language, crash or performance logs, and, if you enable alerts, a push token. The iOS app may store preferences on device. We do not use tracking pixels in the iOS app for advertising, and we do not declare unused camera, photos, or Face ID permissions.
Subscription tier, Stripe customer and subscription identifiers, and billing email. We use approximate country from your IP (CDN geo headers) to choose whether to show and charge GBP, EUR, or USD — not your browser language. Payment-card data is collected by Stripe, not stored on our servers.
We compile firm and, where relevant, publicly named professional information from public sources such as regulatory filings, firm websites, official reports, and news. Unclaimed rows are labeled unclaimed in the member workspace. This can include names and titles of people who already appear in public professional contexts. The in-product directory is available to verified members, not as an open public search.
We do not ask for government ID numbers, precise geolocation, biometric templates, health data, or children’s data. Do not upload special-category data or material non-public information unless you have a lawful basis and a business need, and your visibility rules keep it off the public profile.
We do not sell personal information. We do not use personal information to train public foundation models.
| Purpose | Legal basis |
|---|---|
| Create and run your account, seats, and paid subscription | Contract (Art. 6(1)(b)) |
| Matching, messaging, and workspace features you use | Contract |
| Security, fraud prevention, quota integrity | Legitimate interests (Art. 6(1)(f)); legal obligation where applicable |
| Public professional directory compiled from public sources | Legitimate interests — operating a B2B information service for institutional markets |
| Optional analytics cookies | Consent (Art. 6(1)(a); PECR / ePrivacy) |
| Optional push notifications | Consent |
| Claim or marketing email to a firm address | Consent or, where permitted, legitimate interests plus PECR/CASL rules |
| Tax, accounting, and regulatory requests | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we balance those interests against your rights. You may object, including to the use of your public professional listing. For Quebec, we seek the consent Law 25 requires and identify this policy as our public confidentiality policy.
Matching uses rules and models to filter and rank professional profiles. That is profiling. It does not produce a legal or similarly significant decision about you without a human. You decide whether to connect, message, allocate, or decline. We do not use automated decision-making of the kind described in GDPR Article 22 or equivalent US state rules to deny you a legal right or a similarly significant financial service. More detail: AI transparency.
We do not sell personal information or share it for cross-context behavioral advertising. See Your privacy choices.
Allocatin, Inc. is established in the United Kingdom. If you use the services from outside the UK, your information is transferred to the United Kingdom and may be processed in other countries where our subprocessors operate (including the United States).
For GDPR and UK GDPR, we use the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum (or UK IDTA) with processors, plus supplementary measures where appropriate. Customers can execute the DPA to document those transfers for Customer Content.
US national-security and law-enforcement access to data held in the United States is a known residual risk. We limit vendor access, encrypt data in transit and at rest, and review subprocessors. You can ask us for a current transfer summary at privacy@allocatin.com.
We use encryption in transit and at rest, tenant isolation, role-based access, field-level visibility, and audit logging for sensitive actions. Paid manager seats enroll MFA under Profile → Security; Connect, Save, and CRM require it after checkout. SSO is on the roadmap. Details: Security. No method of transmission is perfectly secure. Please use a unique password manager workflow and tell us promptly about suspected unauthorized access at security@allocatin.com.
You may request access, rectification, erasure, restriction, portability, and objection (including to legitimate-interest processing and to profiling used for matching). Where we rely on consent, you may withdraw it without affecting prior processing. You may lodge a complaint with your supervisory authority. In the UK that is the Information Commissioner’s Office (ICO). In the EU, complain to your lead or local authority; we will cooperate.
You may request access and correction under PIPEDA, and you may challenge our compliance with our privacy officer. Quebec residents have additional rights under Law 25, including to be informed of processing, to withdraw consent, and (as the law phases in) data portability. You may complain to the Office of the Privacy Commissioner of Canada or, in Quebec, the Commission d’accès à l’information.
If you are a consumer under the CCPA/CPRA or a similar state law (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as they apply), you may request to know / access, correct, delete, and obtain a portable copy of personal information, and to opt out of sale or sharing and of targeted advertising. We do not sell or share personal information as those laws define those terms, and we do not use sensitive personal information to infer characteristics. We will not discriminate against you for exercising a right.
Authorized agents may submit requests with proof of authority. We will verify requests using the email and firm affiliation we have on file. Appeal a denial by replying to our decision email. California residents may also contact the California Attorney General. Shine-the-Light: we do not disclose personal information to third parties for their direct marketing.
Use the privacy request form or email privacy@allocatin.com from your company address and tell us which right you want to exercise and which region you are in. Objection and erasure remove matching person listings from Discover, Connect, and CircleIN when we can match the work email or a unique name and firm; we email a confirmation link to that address unless you are already signed in. We keep a suppression record so a later import does not put the row back. We will respond to other requests within the period the applicable law requires (generally 30 days under GDPR/UK GDPR and PIPEDA; 45 days under CPRA, extendable once). You can also export or delete a seat from Profile → Privacy.
The services are for professionals 18 or older. We do not knowingly collect personal information from children. If you believe we have, write to privacy@allocatin.com and we will delete it.
Necessary cookies run the site and keep you signed in. Optional analytics cookies load only after you accept, and never if your browser sends a Global Privacy Control signal. The iOS app does not use advertising cookies. Full detail: Cookie Policy.
The iOS and Android apps support DiscoverIN, ConnectIN, CircleIN, and MessagIN. They may store on-device preferences and, if you enable alerts, a push token with Apple or Google. They collect email, a user identifier, and a device identifier for app functionality only. We do not track you across third-party apps for advertising. You can delete the app at any time; to delete the underlying account, use the web workspace, the privacy request form, or email privacy@allocatin.com.
Service emails (security, billing, legal changes) are not optional while you have an account. Marketing and claim emails include unsubscribe, honor CASL/PECR/CAN-SPAM consent rules, and are suppressed on request. Push alerts are off until you enable them on the device.
We will post updates on this page and change the “Last updated” date. Material changes will be notified by email or in-product notice where required.
Allocatin, Inc.
Privacy officer
privacy@allocatin.com
Security incidents: security@allocatin.com
Registered-office details are available on request at the same address.