Privacy Policy
Effective date: 2026-07-01
1.What we collect
CFO Shortlist (cfoshortlist.com) collects three narrow categories of data. Account data: your email address, used for magic-link sign-in and service emails. Company profile inputs: the evaluation context you enter — ERP, revenue tier, team size, requirements, notes, and scorecards — used to personalize vendor scoring. Usage data: first-party product events (pages visited, features used) and standard technical logs (IP address, browser type) used to operate and improve the Service. We do not collect payment card numbers ourselves; Stripe processes payments directly.
2.How we use it, and our legal bases
We use your data to provide the Service (authentication, personalized shortlists, saved work), to communicate with you about your account, to secure and debug the platform, and to understand aggregate product usage. Under the GDPR our legal bases are: performance of a contract (running your account and subscription), legitimate interests (security, fraud prevention, first-party product analytics), consent (optional analytics cookies, marketing email if you opt in), and legal obligation (tax and accounting records). We do not use your personal data for automated decisions with legal effect, and we never sell personal data or share it for cross-context behavioral advertising.
3.Processors we use
We share personal data only with service providers acting on our instructions: Supabase (database and authentication hosting), Resend (transactional email delivery, e.g. magic links), and Stripe (payment processing). We use Anthropic models to precompute the vendor research and assessments that power the platform — that pipeline runs on vendor data, and your personal data and profile inputs are not sent to model providers at runtime (the in-product copilot is currently disabled). We may also disclose data if required by law or to protect our rights, and in a merger or acquisition subject to this policy.
4.Retention
We keep account and profile data for as long as your account is active. If you delete your account, we delete or anonymize your personal data within 30 days, except records we must retain for legal, tax, or dispute purposes, which we keep only as long as required. Usage logs are retained for up to 24 months in identifiable form, then deleted or aggregated.
5.Your rights
Depending on where you live, you may have the right to access, correct, export, restrict, object to the processing of, or delete your personal data, and to withdraw consent at any time. To exercise any right, email rob@cfoshortlist.com and we will respond within the legally required period (30 days under GDPR, 45 days under CCPA). We will verify requests using the email associated with your account and will never discriminate against you for exercising your rights.
EEA/UK (GDPR): you may also lodge a complaint with your local supervisory authority. California (CCPA/CPRA): we do not sell or share personal information as those terms are defined by the CPRA, and we collect only the categories listed in Section 1 for the purposes in Section 2. You may designate an authorized agent to submit requests on your behalf.
6.Cookies
We use essential cookies and local storage that the Service needs to function — session authentication and your saved workspace state. Analytics cookies load only if you choose “Accept analytics” in the consent banner; choosing “Essential only” keeps them off, and you can clear your browser storage at any time to be asked again. We do not use third-party advertising cookies.
7.International transfers
Our infrastructure and processors are primarily located in the United States. If you access the Service from the EEA, UK, or Switzerland, your data is transferred to the US under appropriate safeguards — our processors participate in the EU–US Data Privacy Framework or use Standard Contractual Clauses.
8.Security and children
Data is encrypted in transit and at rest, access is restricted on a need-to-know basis, and authentication is passwordless by design (no password database to breach). No system is perfectly secure; if a breach affects your personal data, we will notify you as required by law. The Service is a business tool for finance professionals and is not directed to anyone under 16; we do not knowingly collect children’s data.
9.Changes and contact
We will post any changes to this policy here and update the effective date; material changes will be announced by email or in-product notice before they take effect. Data controller: CFO Shortlist, reachable at rob@cfoshortlist.com. See also our Terms of Service.
