This summary is provided for readability. The sections below govern.
This Privacy Policy describes how personal data is handled in connection with the website at thevcpowerboard.com (the "Site"), which is operated by Nicholas Baksht ("the Operator"). It applies to visitors to the Site, to registered account holders, and to individuals whose professional information appears in the Site's published data.
The Site is a static website. Its pages, rankings, scores and data files are delivered directly to your browser and all analysis is computed locally on your device. Accounts are the single exception: they are handled by a hosted authentication and database service described in Section 5.
This Policy does not apply to third-party websites linked from the Site. Those sites have their own privacy practices.
Accounts are optional. All published data on the Site - every firm, partner, ranking, score and chart - is freely accessible without signing in, and nothing is hidden behind registration.
An account exists so that your Shortlist follows you between devices and survives clearing your browser. Without an account the Shortlist still works; it is simply stored on the one device, as described in Section 4. An account is also what a Power Network profile attaches to, if you choose to create one; the table below covers registration alone, and everything a profile adds is set out separately in Sections 16 to 19.
| Data | Why it exists | Source |
|---|---|---|
| Email address | Identifies the account and receives the one-time sign-in link | You provide it |
| Account identifier | An internal random identifier linking your saved Shortlist to your account | Generated automatically |
| Timestamps | Account creation and most recent sign-in, for security and abuse prevention | Recorded automatically |
| Your Shortlist | The firms you saved and any notes you attached to them | You create it |
| Your fundraising workspace | The raises you create, the investors you add to them, the stage and relationship you record for each, your private notes, tags, intro sources, logged meetings and activity, your next actions, and any commitment amounts you choose to enter | You create it |
Sign-in works by sending a single-use link to your email address. The Site never asks you to create a password, never stores one, and cannot leak one. If you can read your email, you can sign in.
Your email address is used to send sign-in links and, where strictly necessary, to contact you about your own account or a security matter affecting it. It is not used for marketing, newsletters, product announcements, or any other unsolicited mail. It is never sold, rented, licensed, shared, or disclosed to any third party for that party's own purposes. No profiling, scoring or segmentation of individual account holders is performed, and no account is analysed to build a picture of the person behind it. The product events described in Section 3 are read in aggregate, to count how many people complete a step, not to characterise who they are.
Whether or not you hold an account, the Operator does not collect, receive, store, sell, share, or rent any of the following:
The Site contains no third-party analytics software, no tag manager, no advertising or conversion pixel, no session recording or heatmap tool, no A/B testing tool, and no third-party marketing script. No outside company receives any record of your use of the Site.
Conflict Check compares a description of your company, or a pitch deck you choose to open, against the portfolio companies recorded on this Site. It is the most sensitive thing anyone hands the Site, so it is worth being exact about what happens to it.
The file never leaves your browser. When you choose a deck, it is read by your own browser using the standard file-reading interface, and the text is compared against data already downloaded to the page. Nothing is uploaded, because there is nowhere to upload it to: the Site is a set of static files with no server that accepts a file, no upload endpoint, and no storage bucket. The Operator cannot read your deck, and could not produce it if asked to.
The extracted text is held in the page's memory for as long as the tab is open and is discarded when you close or reload it. Neither the file, its name, its text, nor the description you type is written to your device, sent to the Operator's database, or transmitted to any third party. The results shown to you are produced entirely on your own machine.
The only thing recorded is that the Conflict Check page was opened and that a check finished running, as two counts with no content attached. Neither carries the deck, the description, or the result. That is set out in the table below.
The Operator records a limited set of first-party product events in order to understand whether the Site actually helps founders find investors: how many people begin Power Match, how many finish it, and whether recommendations are opened, saved or acted on. This data is stored in the Operator's own database (see Section 5) and is never sent to an advertising network, a data broker, or any analytics vendor.
| Recorded | Not recorded |
|---|---|
| A random identifier generated in your browser, not derived from you or your device | Your name or email address alongside that identifier, unless you are signed in and the event concerns your own saved data |
| Which product step you reached, such as starting or completing Power Match | The answers you gave Power Match, in any form |
| Which firm pages you opened, by firm identifier | The text of your searches, filters or notes |
| Whether you saved, followed, or recorded a private outcome for a firm | The private outcome itself, which remains visible only to you as described in Section 2 |
| Whether you marked a recommendation useful or not useful, and the reason if you gave one | Any free text; the reason is chosen from a fixed list |
| That the Conflict Check page was opened, and that a check finished running | Your pitch deck, its file name, its text, the description you typed, or which companies the check matched |
| That a strategic angel recommendation was shown, opened, saved, followed or messaged | The content of any message you send, which is covered by Section 17 |
No cookies are used for measurement, no fingerprinting is performed, and nothing tracks you across other websites. If your browser sends a Do Not Track or Global Privacy Control signal, no product events are recorded at all, as described in Section 12.
The Site sets no advertising or tracking cookies. Session information for signed-in users is held in your browser's local storage rather than in a cookie, as described in Section 4.
The Site uses your browser's local storage for the following, and nothing else. Everything here stays on the device that wrote it unless the row says otherwise.
| Stored item | Purpose | Applies to |
|---|---|---|
| Shortlist | Remembers your saved firms and notes on this device | Everyone |
| Session token | Keeps you signed in between visits so you do not need a new link each time | Signed-in users only |
| Measurement identifier | A random value that lets the Operator count a visit once rather than many times. It is not derived from you or your device and is never shared | Everyone, unless Do Not Track or Global Privacy Control is set |
| Power Match answers | The stage, sector and needs you selected, kept so that returning to Power Match does not make you answer again. It stays on this device and is not sent to the Operator; only the fact that a step was completed is counted, as Section 3 describes | Everyone who uses Power Match |
| Where to return after sign-in | The page you were on when you asked for a sign-in link, so the link returns you there instead of to the homepage. Cleared as soon as it is used | Anyone requesting a sign-in link |
| Dismissal flags | Whether you closed the profile prompt or the signals banner, so they are not shown again. Each is a single yes or no | Everyone |
The local Shortlist is never transmitted anywhere unless you are signed in, in which case it is synchronised to your account so it is available on your other devices. The session token is sent only to the authentication provider in Section 5, to prove you are you.
Nothing in this table is a cookie, and none of it is readable by any other website. Your pitch deck is deliberately absent from this list: as Section 3 explains, Conflict Check never writes it anywhere.
You can clear all of it at any time by signing out, by clearing site data for thevcpowerboard.com in your browser settings, or by using private browsing, in which nothing is retained after the window closes. Signing out removes the session token from your device but does not delete your account; Section 8 covers deletion.
Accounts are provided using Supabase, operated by Supabase, Inc. Supabase hosts the authentication system and the database in which your email address, account identifier, and saved Shortlist are stored. It sends the one-time sign-in links to your inbox.
Supabase acts as a processor on the Operator's behalf: it holds this data to provide the service and is not permitted to use it for its own purposes. The database region is eu-west-2 (West Europe, London). Supabase's own handling of data is governed by the Supabase Privacy Policy.
Supabase is the only processor with access to account data. There are no other subprocessors, no CRM, no email marketing platform, and no customer analytics tool.
The Site is hosted on GitHub Pages, a service of GitHub, Inc. (a subsidiary of Microsoft Corporation). When your browser requests a page, that request necessarily reaches GitHub's servers and includes your IP address, the page requested, the time of the request, and your browser's user agent string.
GitHub collects and processes this information as the hosting provider, under its own privacy practices and for its own purposes, principally security, abuse prevention, and service operation. The Operator does not receive these logs, has no access to them, and cannot query them.
GitHub's handling of this data is governed by the GitHub General Privacy Statement.
Some of the Site's assets are loaded from third-party servers rather than from thevcpowerboard.com. Because your browser must connect to those servers directly to fetch the files, each receives your IP address, your user agent, and the address of the page making the request. This happens on page load and is not something the Operator can observe.
Typefaces used throughout the Site (Inter and IBM Plex Mono) are loaded from fonts.googleapis.com and fonts.gstatic.com, operated by Google LLC. Google states that it does not use these requests to set cookies or build advertising profiles, but it does log them. Governed by the Google Privacy Policy.
The D3.js visualisation library and the Supabase browser client are loaded from public code delivery networks operated by Cloudflare, Inc. and jsDelivr. They receive only the technical metadata inherent in serving a file, and no information about what you do on the Site.
If you stop using an account it simply remains until you delete it. The Operator does not mine dormant accounts, and holds no data about you beyond what Section 2 lists.
Separately from visitor and account privacy, the Site publishes information about identifiable people: venture capital partners and executives. This section explains that processing, which is unrelated to and unaffected by accounts.
Professional information - name, current job title, current and former employers, professional history, education, board service, and dated career milestones, together with links to the public sources those facts came from. Where a licence permits it, a photograph of the person may also appear; the next subsection sets out exactly when, and when not.
Most profiles carry no photograph. Where one does appear, it is published because a specific licence permits it: a firm's own press or media kit granting editorial use, or a portrait released by its copyright holder under terms that allow republication. The credit and the licence are printed beneath every photograph on the page itself, so the basis for showing it can be checked where it appears rather than merely asserted here.
Where no such licence exists, the Site displays a plain tile bearing the person's initials. That tile is not a placeholder for a photograph the Operator intends to acquire later. It is what the Site shows for anyone whose likeness it has no right to publish, which is the great majority of the people described.
No image on the Site is processed biometrically. The Operator does not perform facial recognition, does not create or store face templates, faceprints, or any other biometric identifier, does not match photographs against any other image or dataset, and does not use any image to train a model. A photograph is displayed as a picture beside a name and is used for nothing else. Nothing in this policy permits the Operator to begin doing any of those things; each would be a change of purpose requiring its own notice under Section 24.
Beyond the limits on photographs above, the Site does not publish home addresses, personal telephone numbers, personal email addresses, dates of birth, government identifiers, family or relationship information, health information, financial account information, compensation, or any special category of personal data.
All such information is obtained from sources already public: firms' own websites and team pages, regulatory filings and adviser disclosures, and published journalism. Nothing is obtained from private databases, purchased lists, data brokers, or non-public sources. Where a fact cannot be confirmed in a public source, the Site's editorial policy is to leave the field empty rather than infer a value, which is why many profiles are deliberately sparse.
The purpose is to publish accurate reference information about the venture capital industry and the professionals who lead it, in their public professional capacities. To the extent the UK GDPR or EU GDPR applies, the Operator relies on legitimate interests under Article 6(1)(f) - the public interest in accurate, sourced information about the professional activities of people acting in a public business capacity - balanced against the limited, strictly professional scope described above. A photograph is more personal than a job title, so it does not rest on that balance alone: it is published only where a licence already contemplates publication, it is confined to the person's professional context, and it is removed on request without condition, as set out under "Removing a photograph" below. To the extent the processing constitutes journalism, the Operator additionally relies on the exemptions available for journalistic and academic expression.
For account data, by contrast, the lawful basis is performance of a contract under Article 6(1)(b): you asked for an account, and the email address is what makes one possible.
If you are pictured on the Site and would rather not be, write to legal@thevcpowerboard.com and the photograph will be removed. You do not need to give a reason, cite a statute, prove who you are, or establish who owns the copyright. Your profile will then show the initials tile, exactly as most profiles already do.
This is deliberately a lower bar than the one that applies to the professional facts in Section 10. Those facts are the Site's purpose and are defended when they are accurate and publicly sourced. A likeness is not: the Site is complete without it, so there is nothing to weigh against your preference.
If you are described on the Site and something about your entry is wrong, out of date, or you believe should not appear, write to the address in Section 25.
This section concerns the professional facts in a profile. A request to take down a photograph is not weighed in the way described below and is simply honoured; see "Removing a photograph" in Section 9.
A request is handled fastest when it includes the page address, the specific field at issue, the correct value, and where available a public source confirming it. The Operator will acknowledge and review every such request in good faith and will correct any demonstrable factual error promptly. Where the Operator declines to remove information - for example because it is accurate, publicly sourced, and concerns a public professional role - the Operator will say so and explain why, and will inform you of your right to complain to a supervisory authority if one has jurisdiction.
You do not need to invoke any statute for a correction request to be taken seriously. Accuracy is the Site's stated purpose, and a correction is useful to the Operator regardless of who asks.
The Site is a professional research tool intended for adults. It is not directed to children, and accounts are not knowingly offered to anyone under 16. The Operator does not knowingly collect personal data from children. If you believe a child has created an account, write to the address in Section 25 and it will be deleted.
Some browsers transmit a "Do Not Track" header or a Global Privacy Control signal. The Site honours both. If either signal is present, no product events are recorded for your visit at all: the measurement described in Section 3 is switched off rather than reduced, and no measurement identifier is stored on your device.
The Site serves no advertising and does not sell or share personal information, so there is nothing further for such a signal to change. Every feature continues to work normally when the signal is set.
If you are in the European Economic Area, the United Kingdom, or Switzerland, data protection law gives you rights of access, rectification, erasure, restriction, objection, and portability, and the right to lodge a complaint with your supervisory authority.
As a visitor without an account, the Operator holds no personal data about you and has nothing to disclose, correct, delete, or export. Data arising from your visit is held by GitHub as described in Section 6, and requests concerning it should be directed there.
As an account holder, these rights apply to your email address and Shortlist. Section 8 lets you exercise access, portability, rectification and erasure yourself, immediately, without making a request. You may also write to the address in Section 25, and the Operator will respond within one month.
As an individual described in the Site's data, these rights apply to your published profile, and Section 10 sets out how to exercise them. You may object to the processing described in Section 9 at any time on grounds relating to your particular situation.
The Site is operated from the United States. Account data is stored in the region stated in Section 5, and accessing the Site involves an international transfer of the technical request data described in Sections 6 and 7.
Under the California Consumer Privacy Act as amended, California residents have rights to know, delete, correct, and opt out of the sale or sharing of personal information, and not to be discriminated against for exercising them.
In the preceding twelve months, the only category of personal information collected is identifiers - an email address and an account identifier - and only from people who chose to create an account. It is collected to operate the account, retained until you delete the account, and disclosed to no one except the processor named in Section 5.
The Operator has never sold or shared personal information, does not do so now, and does not use personal information for cross-context behavioural advertising. There is accordingly no "Do Not Sell or Share My Personal Information" mechanism, because there is no sale or sharing to opt out of. Exercising any right will never degrade your access to the Site, which is free and identical for everyone.
California residents whose professional information appears in the Site's published data may exercise their rights as described in Section 10.
The Site is served over HTTPS. Because sign-in uses one-time email links, there are no passwords stored anywhere in the system - the single most common cause of credential breaches does not apply here.
Account data is held by the processor in Section 5 under database access rules that restrict every record to the account that owns it, so one account cannot read another's data. The published research dataset contains no personal data about visitors and is public by design.
No transmission over the internet can be guaranteed completely secure, and no absolute guarantee is made. If a breach affecting account data occurs, affected account holders will be notified by email at the address on file, and supervisory authorities will be notified where the law requires it.
Power Network is an optional part of the Service. Nothing in this section applies unless you choose to create a Network profile, and creating one is never a condition of using the research on the Site.
A Network profile is written entirely by you. The Operator does not import it, enrich it, infer it, or copy it from any other site. It may contain your name, a username, a headline, your current role and employer, your location, a photograph, your stated expertise, what you say you can help with, what you say you are looking for, and what you use Power Board for. Education and experience entries you add are stored alongside it.
This is the sharpest distinction in this policy: information in a Network profile is self-described and unverified, and is stored separately from the sourced research described in Section 9. The Operator does not check it, does not vouch for it, and does not merge it with sourced research about the same person.
A profile is private until you publish it. Once published it is visible to anyone who can reach the Site, including people who are not signed in, and may be indexed by search engines. Your location appears only if you switch it on. Unpublishing removes it from view; deleting your account removes it entirely, as set out in Section 19.
A profile photograph you upload is stored by the Operator's hosting provider and served publicly while your profile is published. It is your own image, uploaded by you, and is governed by this section rather than by the licensing rules in Section 9, which concern photographs of people who do not hold accounts.
Following another member, following a firm, or saving a person or a firm to a shortlist is recorded against your account so the Service can show you what you saved. Who you follow is not published as a follower count or a public list, and it is never used to rank anybody: the recommendation features described on the Site deliberately ignore popularity.
Members can send each other direct messages. The Operator stores the message text, who sent it, who received it, and when, for as long as the conversation exists. Access is enforced at the database level: only the participants in a conversation can read it. The Operator does not read messages in the ordinary course of running the Service, does not use them for advertising, does not use them to train any model, and does not sell or share them.
Two consequences follow from this that you should understand before you use the feature. A message you send exists in the recipient's account as well as your own, so deleting your account does not withdraw a message the other person has already received. And the Operator may access specific messages where it is necessary to investigate a report made under Section 18, to comply with a legal obligation, or to address a security incident. That access is by exception, not by routine.
The Service records notifications for you, such as a new follower or a new message. These are written by the database when the underlying event happens and are readable only by you.
You can block another member. The block is recorded against your account and prevents a conversation between you and that person. A blocked member is not told that you blocked them.
You can report a profile or a message. A report records what you reported, the reason you gave, and that you were the person who made it. Reports are read by the Operator in order to act on them. Your identity as reporter is not disclosed to the person you reported.
Every profile carries a moderation state. A profile that is being reviewed, or that has been removed for breaching the Terms of Service, stops appearing anywhere in the Service. Moderation decisions are made by the Operator, a single person, and are not automated. If your profile is moderated you may ask why, and you may ask for the decision to be reconsidered, using the contact address in Section 25.
Three different actions are available and they do different things, so this section states plainly which is which.
Unpublishing hides your profile from the Site. The record remains in your account so you can publish it again, and nothing else is deleted.
Deleting your profile removes the profile record, your uploaded photograph, your education and experience entries, your follows, and your saved items. Your account remains, and you can create a new profile later.
Deleting your account removes everything above and the account itself. What survives is narrow and is listed here rather than left vague: messages you already sent remain readable by the people who received them, because those messages are their data as well as yours; and a report you filed remains, without your profile attached to it, so that a moderation decision made about somebody else does not silently reverse itself.
Product measurement events described in Section 3 are not tied to your profile and are not affected. To delete an account, use the account settings on the Site, or write to the address in Section 25 and it will be done for you.
REQUIRES LEGAL REVIEW. This section describes behaviour that is implemented in the product. It has not been reviewed by a lawyer, and should be before launch.
A Workspace is a shared space that a founder can create and invite people into. Creating one does not move or share anything you already had. Your existing raise, pipeline, notes, saved searches and shortlist remain yours alone unless you explicitly move or share them, and each of those is a separate, deliberate action.
When you share a raise with a Workspace, the people in that Workspace can see the investors in it, the stage of each conversation, the relationship context, partner contacts, tags, activity history, next actions, commitment amounts and pass reasons. They cannot see your notes. Notes are private to their author by default and stay private through a move; sharing an individual note is a separate choice you make for that note.
Activity in a shared raise records which member performed it, so a team can tell who did what. That record is retained after a member leaves, because removing it would misattribute work that person actually did.
Workspace administrators can see the email addresses of members and pending invitees of that Workspace, and an administrative history of membership, role and ownership changes. That history is written by the database and cannot be edited by anyone, including administrators.
An invitation grants no access until it is accepted. Before acceptance, an invited person can see only the name of the Workspace they were invited to.
REQUIRES LEGAL REVIEW.
You can create API keys to read data programmatically. A key is shown to you once, at creation, and only a cryptographic hash of it is stored. It cannot be recovered afterwards by anyone, including the Operator. If you lose a key, revoke it and create another.
A key can never read more than the person who created it can read in the product. Keys carry explicit scopes, and access to private notes requires a separate scope that general access does not grant. A key issued for a Workspace stops working if its creator leaves that Workspace.
Key creation, revocation, and the time a key was last used are recorded. The content of API requests is not logged. Request volume is counted per key for rate limiting and is not associated with the data returned.
REQUIRES LEGAL REVIEW.
You can register a URL to receive notifications about events in your own Workspace. Doing so sends data to a destination you choose, operated by you or by a third party, and once it leaves the Site it is governed by whatever handles it there.
Webhook payloads carry identifiers, event types and timestamps. They do not carry note content, commitment amounts, email addresses, or the names of investors. A recipient that needs more detail must request it through the API using a key with the appropriate scope.
Delivery attempts, response codes and failures are recorded so a failing endpoint can be diagnosed. Endpoints that fail repeatedly are disabled automatically.
REQUIRES LEGAL REVIEW. No third-party integration is enabled at the time of writing. This section describes how one will behave when enabled.
Connecting an outside service such as a calendar or CRM uses that provider's own authorisation flow. You are never asked for a password for another service, and none is ever stored. The access and refresh tokens the provider issues are held encrypted and are not readable by the Site's front end or through the API.
A connection requests the narrowest permissions that make the feature work. Data brought in from a connected service is treated as your private workflow information. It never alters Power Board's published research: an outside system's opinion about an investor does not change what the research records.
Disconnecting a service deletes the stored tokens and the record of which external objects were linked to which Power Board records, and stops any scheduled synchronisation. Where the provider supports it, the token is also revoked with the provider. Data already brought into your Workspace before disconnection remains there until you remove it.
A history of synchronisation runs is kept, recording when a run happened, whether it succeeded, and how many records it touched. It does not retain the content of records exchanged with the provider.
This Policy may be revised. The "Last revised" date at the top records when the current version took effect. If the Site begins collecting a category of data not listed here - analytics, payments, or anything else - this Policy will be updated before that change goes live, and the summary at the top will be corrected to reflect it. The Operator will not quietly begin collecting data under a policy that says otherwise.
Privacy questions, account enquiries, requests concerning information about a named individual, and data protection matters may be sent to:
Email sent to this address, and the address it was sent from, is retained only for as long as needed to handle the matter raised.