Skip to content

Privacy policy

Last updated . Questions: mail@warplabs.co

This policy explains what information Warplabs LLC ("WarpExit", "we") collects, why, who can see it, and how long we keep it. The short version: we collect what we need to run deal rooms, we never sell data, and we delete a room's data within 30 days of the room being deleted.

What we collect

From sellers

  • Account details: name, email address, and sign-in information.
  • Purchase records. Payments are processed by Stripe; we do not receive or store full card numbers.
  • Files you upload, notes you write, the teaser, and answers to buyer questions.
  • Read-only financial data from the sources you connect: from Stripe, customers, subscriptions, invoices, charges, payouts and balance history; from RevenueCat, app subscription metrics such as MRR, active subscriptions, revenue, churn and refunds, as totals rather than per customer; from Mercury, account balances and transactions.
  • The credentials for those connections: a Stripe restricted key, a RevenueCat v2 secret key and project ID, and a Mercury read-only token.
  • Bank statements you upload, as PDF or CSV: the transactions, balances and account details printed on them. We use Anthropic's API to read the transactions from PDF statements.
  • Emails you send to your room's private address in reply to our monthly update: the sender, subject and attachments. Postmark receives these emails for us. Replies that don't come from the room owner's address with a valid room token are discarded.

From buyers

  • If a buyer chooses to have their ID checked: the result, the name on the document, the document type and the issuing country. Stripe Identity handles the document and selfie; we never receive them.
  • Email address, confirmed with a code when you first open a room link.
  • At NDA signing: your name, email address, IP address, browser user agent, the time of signing, and the version of the NDA you signed.
  • View analytics: which sections and files you opened in a room, when, and for how long. These are shown to the seller of that room.
  • Questions you ask in a room.

From visitors to our website

We use Umami, self-hosted, for website analytics. It does not use cookies for marketing analytics and does not track you across other sites. It gives us aggregate counts such as page views and referrers.

Your customers' data

Data from a seller's Stripe account can include the seller's customers' names and email addresses. We process that data on the seller's behalf and only to show it in the seller's room. Customer names stay hidden from buyers until the seller marks that buyer "LOI signed". The seller decides whether sharing is lawful and appropriate.

How we use information

  • To run rooms: syncing connected data, showing it to the right buyers at the right stage, recording NDA signatures, and watermarking files with the buyer's email, the time and the room ID.
  • To show sellers who viewed what and for how long.
  • To send service emails, such as sign-in links, NDA confirmations and notices about your room.
  • To keep the service secure and to investigate misuse.
  • To meet legal, tax and accounting obligations.

We do not use room data to advertise.

Who can see what

  • Sellers see their own rooms, including buyer names, emails, NDA records and view analytics.
  • Buyers see only what the seller has shared at their current stage, and never other buyers' identities or activity.
  • Our service providers process data on our behalf to host, store, email, sign and read uploaded statements. They are listed on our subprocessors page.
  • We may disclose information if the law requires it, and will tell the affected user first where we are allowed to.

We do not sell data

We do not sell, rent or trade personal information or financial data, to anyone, for any purpose.

How we protect it

  • Connection credentials use envelope encryption: each one is sealed with its own AES-256-GCM data key, which is wrapped by a master key kept outside the database. They are never logged and are decrypted only in the sync worker.
  • Every connection is read-only. We ask for the narrowest access each source offers and never for credentials that can move money.
  • Data is sent over encrypted connections.
  • Files are shown view-only with a per-buyer watermark.
  • Room links are per buyer and can be revoked by the seller at any time.

How long we keep it

  • When a seller deletes a room, we delete its data, including connected-source data, files, NDA records and view analytics, within 30 days.
  • When a plan ends, the room closes to buyers and its data stays saved until the seller deletes it. Stored credentials are deleted within 7 days of the plan ending.
  • When you delete your account, we delete stored credentials within 7 days and your rooms as above. We keep purchase records for as long as tax and accounting law requires.

Cookies

We use only the cookies needed to keep you signed in and to keep a buyer's session in a room secure. We do not use advertising or marketing cookies.

Your rights

Depending on where you live, you may have rights to access, correct, export or delete your personal information, and to object to some uses of it. Email mail@warplabs.co and we will respond. If you are a buyer and want information removed from a seller's room, we may need to involve the seller, because the room is theirs.

Changes to this policy

We will update the date at the top when this policy changes, and email account holders about material changes before they take effect.

Contact

Privacy questions: mail@warplabs.co. By post: Warplabs LLC, 1111B S Governors Ave STE 34986, Dover, DE 19904, USA.