Privacy Policy
True North Holdings, LLC ("True North," "we," "us," or "our") is committed to protecting the privacy of our investors and platform users. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our platform at truenorthinvest.com and related services.
By using our platform, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use our services.
1. Information We Collect
Information You Provide
- Account registration data: name, email address, phone number, password
- Identity verification data: government-issued ID, selfie photograph, date of birth, address, and last 4 digits of SSN/Tax ID (processed by our document review partner, Persona)
- Financial data: bank account information (processed via Plaid), investment amounts, distribution preferences
- Communications: support tickets, emails, chat messages, and feedback you send us
Information Collected Automatically
- Device and browser information: IP address, browser type, operating system
- Usage data: pages visited, features used, session duration, click patterns
- Transaction data: investment history, distribution records, fee payments
- Cookies and similar tracking technologies (see Section 7)
2. How We Use Your Information
We use your personal information to:
- Provide, operate, and maintain the True North investment platform
- Verify your identity and comply with document review / AML regulations
- Process investments, distributions, and financial transactions
- Send you account statements, fund reports, and distribution notifications
- Comply with SEC Regulation CF, Regulation D, and other applicable securities laws
- Detect, prevent, and investigate fraud, money laundering, and security incidents
- Improve our platform, develop new features, and analyze usage patterns
- Send marketing communications (only with your consent, and you may opt out at any time)
- Respond to support requests and communications
3. Information Sharing
We do not sell your personal information. We share your information only in the following circumstances:
- Service providers: Identity verification (Persona), banking and ACH (Plaid, Dwolla), cloud hosting (AWS), analytics (Google Analytics), email delivery (SendGrid). All providers are bound by data processing agreements.
- Fund sponsors: Investment details shared with fund sponsors as necessary to process and manage your investment, subject to confidentiality agreements.
- Legal requirements: When required by law, court order, or regulatory authority including the SEC, FinCEN, and state securities regulators.
- Business transfers: In connection with a merger, acquisition, or sale of assets, with appropriate notice and protections.
- With your consent: For any other purpose with your explicit authorization.
4. Data Security
We implement industry-standard technical and organizational security measures including:
- TLS 1.3 encryption for all data transmitted between your browser and our servers
- AES-256 encryption for sensitive data stored at rest
- SOC 2 Type II compliance for our infrastructure and processes
- Multi-factor authentication required for all investor accounts
- Regular third-party security audits and penetration testing
- Automatic deletion of identity documents after document review completes
No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
5. Data Retention
We retain your personal information for as long as necessary to provide our services and comply with legal obligations. Specifically:
- Account data: retained for the duration of your account plus 7 years after closure (required for securities law compliance)
- Investment records: retained for 10 years as required by SEC recordkeeping rules
- Identity verification documents: deleted immediately after successful document review
- Marketing preferences: until you opt out or delete your account
6. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate personal data
- Deletion: Request deletion of your personal data (subject to legal retention requirements)
- Portability: Request your data in a machine-readable format
- Objection: Object to certain processing activities, including direct marketing
- Restriction: Request restriction of processing in certain circumstances
To exercise any of these rights, contact us at privacy@truenorthinvest.com. We will respond within 30 days.
7. Cookies and Tracking
We use cookies and similar technologies to operate our platform, analyze usage, and personalize your experience. Essential cookies are required for platform functionality. Analytics cookies (Google Analytics) and marketing cookies are optional and can be managed via your browser settings or our cookie preference center.
8. International Data Transfers
Your information may be transferred to and processed in the United States and other countries. When we transfer data from the European Economic Area, United Kingdom, or other jurisdictions with data protection laws, we use appropriate safeguards such as Standard Contractual Clauses.
9. Contact Us
For privacy-related questions, requests, or concerns:
- Email: privacy@truenorthinvest.com
- Mail: True North Holdings, LLC, Attn: Privacy, [Address], Delaware, USA
We may update this Privacy Policy periodically. Significant changes will be communicated via email and platform notification. Continued use of our services after changes constitutes acceptance of the updated policy.