Privacy Policy
This Privacy Policy describes how Shizune, Inc. ("Shizune," "we," "us," or "our"), a Delaware corporation, collects, uses, shares, and protects your personal information when you use our website at shizune.co and our platform (collectively, the "Service"). Shizune is a platform that helps startup founders discover and connect with investors through a curated database, filters, and smart matching.
By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Service.
1. Information We Collect
Information You Provide Directly
- Account information. When you create an account, we collect your email address and password (or equivalent credentials through a third-party login provider).
- Startup profile information. During onboarding, we ask about your startup's industry (e.g., fintech), stage (e.g., seed), and country (e.g., United States). You may provide additional details to improve investor matching.
- Payment information. When you subscribe to a paid plan, payment is processed by our third-party payment processor, Paddle. We do not directly collect or store your credit card number. Paddle may share with us your name, billing address, and transaction details. For details on how Paddle handles your data, see Paddle's Privacy Policy.
- Communications. If you contact us via email or support channels, we collect the content of those communications.
Information Collected Through Third-Party Login
You may sign in using Google, Apple, or Twitter (X). When you do, we receive certain profile information from that provider, typically your name, email address, and profile picture, depending on the provider's policies and the permissions you grant. We do not receive your password from these providers.
Information Collected Automatically
- Usage data. We collect information about how you interact with the Service, such as pages visited, features used, search queries, and investor profiles viewed.
- Device and technical data. We collect your IP address, browser type and version, operating system, device identifiers, referring URLs, and time zone.
- Cookies and similar technologies. We use cookies, pixels, and similar tracking technologies to operate the Service and gather usage data. See Section 6 (Cookies and Tracking Technologies) for details.
2. How We Use Your Information
We use the information we collect for the following purposes:
- To provide and operate the Service, including creating your account, enabling investor search and matching, and processing payments.
- To personalize your experience, including tailoring investor recommendations based on your startup profile (industry, stage, and country).
- To communicate with you, including sending transactional emails (e.g., subscription confirmations), responding to support requests, and — with your consent where required — sending product updates or promotional communications.
- To analyze and improve the Service, including understanding usage patterns, diagnosing technical issues, and developing new features.
- To ensure security and prevent fraud, including monitoring for suspicious activity and enforcing our Terms of Service.
- To comply with legal obligations, including responding to lawful requests from government authorities.
3. Legal Bases for Processing (EEA, UK, and Swiss Users)
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, we process your personal data based on the following legal grounds under the General Data Protection Regulation (GDPR) or equivalent legislation:
- Performance of a contract. Processing necessary to provide you with the Service you signed up for (e.g., account creation, investor matching, payment processing).
- Legitimate interests. Processing for purposes such as improving the Service, analytics, fraud prevention, and marketing, where these interests are not overridden by your rights.
- Consent. Where required, we obtain your consent before processing (e.g., for certain cookies or marketing communications). You may withdraw consent at any time.
- Legal obligation. Processing necessary to comply with applicable laws or regulations.
4. How We Share Your Information
We do not sell your personal information. We share your data only in the following circumstances:
- Service providers. We share data with third-party vendors who perform services on our behalf, including:
- Paddle — payment processing
- Google Analytics — website and product analytics
- Amplitude — product analytics and user behavior analysis
- Google, Apple, and Twitter (X) — authentication services
- Legal requirements. We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
- Business transfers. If Shizune is involved in a merger, acquisition, asset sale, or bankruptcy, your personal information may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.
- With your consent. We may share your information for other purposes if you give us explicit consent to do so.
5. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you with the Service. After account deletion, we will delete or anonymize your personal data within 30 days, except where we are required to retain certain data for legal, tax, or accounting purposes (typically up to 7 years for financial records).
Usage data and analytics logs are retained in anonymized or aggregated form and are not linked back to individual users after deletion of your account.
6. Cookies and Tracking Technologies
We use the following categories of cookies and tracking technologies:
- Essential cookies. Required for the Service to function (e.g., session management, authentication). These cannot be disabled.
- Analytics cookies. Used by Google Analytics and Amplitude to understand how users interact with the Service. These help us measure traffic, identify popular features, and diagnose issues.
You can manage your cookie preferences through your browser settings. Note that disabling certain cookies may affect the functionality of the Service.
For users in the EEA and UK, we obtain consent before placing non-essential cookies, in accordance with applicable law.
7. Your Privacy Rights
Depending on your location, you may have certain rights regarding your personal data. We honor these rights regardless of where you live, to the extent practicable:
- Access. Request a copy of the personal data we hold about you.
- Correction. Request correction of inaccurate or incomplete data.
- Deletion. Request deletion of your personal data, subject to legal retention requirements.
- Data portability. Request a machine-readable copy of data you provided to us.
- Objection / Restriction. Object to or request restriction of certain processing activities.
- Withdraw consent. Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
- Opt out of marketing. Unsubscribe from promotional emails at any time using the link in those emails.
To exercise any of these rights, contact us at hello@shizune.co. We will respond within 30 days (or 45 days for CCPA-related requests, with notice of extension if needed).
Additional Rights for California Residents (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know what categories and specific pieces of personal information we have collected about you.
- Request deletion of your personal information.
- Opt out of the sale or sharing of your personal information. We do not sell or share your personal information as defined by the CCPA/CPRA.
- Non-discrimination for exercising your rights.
You may designate an authorized agent to make requests on your behalf. We may verify your identity before fulfilling any request.
8. International Data Transfers
Shizune is based in the United States. Your data is hosted on Hetzner infrastructure. If you access the Service from outside the United States, your information will be transferred to, stored, and processed on servers that may be located in the United States or Europe, where data protection laws may differ from those in your country.
For transfers of personal data from the EEA, UK, or Switzerland, we rely on appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission, to ensure your data is protected to an adequate standard.
9. Data Security
We implement commercially reasonable technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit (TLS/SSL), access controls, and regular security reviews.
However, no method of transmission over the Internet or electronic storage is completely secure. While we strive to protect your personal information, we cannot guarantee its absolute security.
10. Age Restrictions
The Service is intended for users who are at least 18 years of age. We do not knowingly collect personal information from anyone under 18. If we become aware that we have collected personal data from a person under 18, we will take steps to delete that information promptly. If you believe a child under 18 has provided us with personal information, please contact us at hello@shizune.co.
11. Third-Party Links
The Service may contain links to third-party websites, including investor profiles and external resources. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any external site you visit.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and/or by posting a prominent notice on the Service prior to the changes taking effect. The "Last Updated" date at the top of this policy indicates when it was most recently revised.
Your continued use of the Service after changes take effect constitutes your acceptance of the revised Privacy Policy.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Shizune, Inc.
hello@shizune.co
For GDPR-related inquiries, you also have the right to lodge a complaint with your local data protection supervisory authority.
14. Supplemental Notices
For EEA/UK Residents
Shizune, Inc. is the data controller for the purposes of GDPR. Our contact details are provided in Section 13. If you believe we have processed your data unlawfully, you have the right to complain to a supervisory authority in the EU/EEA member state where you live, work, or where the alleged infringement took place.
For California Residents
This Privacy Policy serves as our notice at collection under the CCPA/CPRA. The categories of personal information we collect and the purposes for which they are used are described in Sections 1 and 2 above. We do not sell or share personal information, and we do not use or disclose sensitive personal information for purposes other than those permitted by the CCPA/CPRA.