Overview
This Privacy Policy ("Policy") applies to QuestionPilot.com and Question Pilot LLC ("Company," "we," "us," or "our") and governs how we collect, use, and protect information. By using the Question Pilot platform, you consent to the data practices described in this Policy.
Question Pilot is a software-as-a-service platform used by transaction advisory professionals to manage structured diligence processes. Given the sensitive nature of deal data processed on our platform, we take data confidentiality seriously and have designed our practices accordingly.
Information We Collect
Account Information. When you create an account, we collect your name, email address, firm name, and account credentials.
Payment Information. When you purchase a deal plan, billing and payment information is collected and processed by our payment processor, Stripe, Inc. Question Pilot LLC does not store full credit card numbers or sensitive payment credentials on our systems.
Deal Data. Transaction information, diligence questions, responses, and related materials you upload or generate within the Platform. See Section 4 for how we treat this data.
Usage Information. We may automatically collect information about how you interact with the Platform, including IP address, browser type, pages visited, and access timestamps. This information is used to maintain service quality and improve the Platform.
We do not collect personal information unless voluntarily provided by you in connection with your use of the Platform.
How We Use Information
We use the information we collect for the following purposes:
- To create and manage your account and provide Platform services
- To process payments and fulfill your deal portal purchases
- To communicate with you regarding your account, transactions, and Platform updates
- To provide customer support and respond to inquiries
- To improve and maintain the Platform
- To comply with applicable legal obligations
We will not use your information for purposes materially different from those described in this Policy without your consent.
Deal Data & Confidentiality
Deal data, including transaction information, diligence questions, and responses, remains the sole property of the subscribing firm at all times.
Question Pilot LLC acknowledges that Deal Data may contain material non-public information and confidential business information. We will not access, view, or use Deal Data except as necessary to provide Platform services or as required by law. We will not disclose Deal Data to third parties without your express written consent, except to subprocessors bound by equivalent confidentiality obligations.
AI Processing
Question Pilot uses artificial intelligence features powered by Anthropic, PBC to assist with question import and column mapping. When you use AI-assisted features, only column headers and a small number of truncated sample cell values are transmitted to Anthropic's API, we do not send deal names, counterparty names, full question text, response content, or internal notes.
Question Pilot LLC does not use your Deal Data to train AI models. We contractually require that our AI service providers not use your Deal Data for model training purposes. AI processing is used solely to provide the import assistance features you have requested.
For full details on our AI data practices, see our AI Terms of Use.
Subprocessors
Question Pilot LLC works with the following third-party service providers ("subprocessors") in delivering the Platform. Each is bound by data handling and confidentiality obligations consistent with this Policy:
| Provider | Purpose | Data Processed |
|---|---|---|
| Supabase, Inc. | Database infrastructure, authentication, and file storage | All user and deal data |
| Netlify, Inc. | Web application hosting and CDN | Web traffic logs, IP addresses |
| Stripe, Inc. | Payment processing | Payment card data, transaction records |
| Resend | Transactional email delivery | Email addresses, email content |
| Anthropic, PBC | AI-assisted column mapping during import | Column headers and truncated sample cell values only |
| Microsoft Corporation | Business email services | Support correspondence |
We will update this list as subprocessors are added or removed. We do not sell, rent, or lease customer data to third parties.
Sharing Information
We do not sell, rent, or lease your personal information or Deal Data to third parties.
We may share information with trusted service providers who assist us in operating the Platform, subject to confidentiality obligations. We may disclose information when required by law, legal process, or governmental request, or to protect the rights and safety of the Company or its users.
Data Retention
We retain account information for as long as your account is active. Deal Data associated with active deal portals is retained for the duration of the portal access period. Upon account termination or portal expiration, data may be retained for up to 90 days for backup and recovery purposes, after which it is permanently deleted from our systems.
You may request deletion of your personal information or Deal Data at any time by contacting . We will fulfill deletion requests subject to any legal obligations to retain certain records.
Security
We implement commercially reasonable technical and organizational security measures to protect your information from unauthorized access, disclosure, alteration, or destruction. These measures include SSL/TLS encryption for data in transit, row-level security policies on all database tables, and industry-standard security practices at our infrastructure providers.
No data transmission over the Internet can be guaranteed 100% secure. You acknowledge that there are inherent security limitations to Internet-based services. In the event of a security incident affecting your data, we will notify you in accordance with applicable law.
Cookies
The Platform uses cookies to maintain session state and keep you logged in. These are authentication cookies set by Supabase and are essential for the Platform to function. We do not use advertising cookies, tracking cookies, or third-party analytics cookies. We do not use Google Analytics or similar tracking services.
You may configure your browser to decline cookies, though doing so will prevent you from logging into the Platform.
California Privacy Rights (CCPA / CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act and California Privacy Rights Act:
Children
The Platform is intended for use by professional business users. Question Pilot LLC does not knowingly collect personal information from individuals under the age of 18. If we become aware that we have inadvertently collected such information, we will promptly delete it.
Email Communications
We may contact you by email to provide transactional notices, account updates, and service-related communications. If you wish to stop receiving marketing or promotional communications, you may opt out by clicking the unsubscribe link in any such email or by contacting us directly. Transactional and account-related emails cannot be opted out of while your account is active.
Changes to This Policy
We reserve the right to update this Policy from time to time to reflect changes in our services, data practices, or applicable law. When material changes are made, we will notify you via email or by prominent notice on the Platform. Your continued use of the Platform after such notice constitutes your acceptance of the revised Policy.