Privacy Policy

Effective June 11, 2026  ·  Last updated June 11, 2026

GDPR Compliant CCPA / CPRA Compliant SOC 2 Controls

Overview

Fundex, Inc. (“Fundex,” “we,” “us,” or “our”) operates the Fundex investor CRM platform at usefundex.comand its associated services (the “Service”). This Privacy Policy explains what information we collect, why we collect it, how we use and protect it, and your choices.

Fundex is a business-to-business (B2B) software platform. Our customers are fund managers, startups, and early-stage companies (“Customers”) who use our tools to manage investor relationships and fundraising pipelines. When our Customers store investor contact records in Fundex, they are the data controller for that contact data and we act as a data processor on their behalf.

Two privacy relationships: (1) Customers — organizations that subscribe to Fundex. We control and process their account data. (2) Investor contacts — third-party individuals whose data Customers enter into Fundex. Our Customers control that data; we process it per their instructions under our Data Processing Addendum.

Data We Collect

Account & Subscription Data

When you create a Fundex account or start a trial, we collect:

  • Full name, work email address, and password (hashed)
  • Company name, size, and industry
  • Billing address and payment method (processed by Stripe; we do not store raw card numbers)
  • Role, permissions, and team membership within your organization

CRM & Pipeline Data

When Customers use the platform to manage their fundraising pipeline, they may enter or import:

  • Investor names, email addresses, phone numbers, titles, and LinkedIn URLs
  • Fund names, AUM, investment thesis, and portfolio data
  • Meeting notes, call logs, email correspondence, and custom activity records
  • Pipeline stage, deal terms, and relationship health signals
  • Tags, lists, and custom fields defined by the Customer

Email & Calendar Integration Data

If you connect your email inbox or calendar (via our Nylas integration), we collect:

  • OAuth access tokens (encrypted at rest; scoped to send-on-behalf)
  • Sent message metadata: recipient, subject, timestamp, and thread ID
  • Email open and click tracking pixels and link redirects (only for outreach sequences you initiate)
  • Calendar event metadata: title, attendees, and time (for meeting logging)

Usage & Technical Data

  • IP address, browser type, operating system, and device identifiers
  • Pages viewed, features used, and session duration
  • API call logs and error reports
  • Cookies and similar tracking technologies (see Cookies)

How We Use Data

We use collected information for the following purposes:

Service delivery

Providing, operating, maintaining, and improving the Fundex platform and its features.

Account management

Creating accounts, authenticating users, managing subscriptions, and processing payments.

Email outreach

Sending investor emails on your behalf via your connected mailbox; tracking opens, clicks, and replies to measure campaign performance.

AI features

Powering AI-assisted drafting, email quality scoring, and investor recommendations. AI processing uses only the data you have provided and does not train public models.

Customer support

Responding to support requests, diagnosing bugs, and providing onboarding assistance.

Security & fraud prevention

Detecting and preventing unauthorized access, abuse, and fraudulent activity.

Legal compliance

Meeting our obligations under applicable law, responding to lawful requests, and enforcing our Terms of Service.

Analytics & product improvement

Aggregated, de-identified usage analytics to understand feature adoption and improve the product. We never sell this data.

Investor & CRM Data

Fundex is a data processor for investor contact data that Customers store in the platform. Our Customers—fund managers, startups, and advisors—are the data controllers for their investor records.

Customer responsibility: Customers are responsible for ensuring they have a lawful basis to store and process investor contact information in Fundex (e.g., legitimate interest in fundraising activities, or prior consent). Fundex provides tooling; the legal basis determination lies with the Customer.

Data Processing Addendum (DPA)

Enterprise and growth plan Customers may request a Data Processing Addendum covering sub-processor obligations, Standard Contractual Clauses (SCCs) for international transfers, and audit rights. Contact privacy@usefundex.com to request a DPA.

Tenant Isolation

Each Customer organization operates in a logically isolated tenant. Investor records, pipeline data, and communications of one Customer are never accessible to another Customer. All database queries are scoped by tenant_id at the application layer.

Central Investor Pool

Fundex maintains a read-only central pool of publicly available investor profiles (name, fund, and publicly listed contact information) sourced from publicly accessible databases. Customers may import these profiles into their private tenant. The central pool is never shared between Customer tenants.

Email Outreach & Tracking

Fundex enables Customers to send personalized outreach emails to investors via their own connected mailboxes (Gmail, Outlook / Microsoft 365). We integrate with Nylas to authenticate and send email on behalf of the connected account.

What we track

  • Open tracking: A 1×1 pixel image is embedded in outreach emails. When the recipient opens the email and images load, we record the open event and approximate time.
  • Click tracking: Links in outreach sequence emails may be rewritten to route through our tracking domain before redirecting to the target URL, recording the click event.
  • Reply detection: We detect replies using email thread metadata to automatically update pipeline stages and halt follow-up sequences.
  • Bounce & unsubscribe handling: Hard bounces and unsubscribe requests are automatically honoured and the contact is suppressed from future outreach.

Email tracking is a feature of the outreach sequences tool. Tracking pixels are only embedded in emails sent through Fundex sequences — not in emails sent directly from your email client. Investors may disable image loading in their email client to opt out of open tracking.

Mailbox permissions

Connecting your email account grants Fundex OAuth permissions scoped to sending email and reading thread metadata for sent messages only. We do not read your inbox, access received emails, or store email body content beyond what you explicitly compose in Fundex.

Data Sharing & Sub-processors

We do not sell your personal information. We share data only in the following circumstances:

Sub-processors

We engage the following categories of sub-processors to operate the Service:

Sub-processorPurposeLocation
Microsoft AzureCloud infrastructure, databases, and hostingUS / EU
NylasEmail sending and calendar integrationUS
StripePayment processing and subscription managementUS
OpenAI / AnthropicAI-assisted email drafting and recommendations (no training on customer data)US
Google Analytics (GA4)Anonymized website usage analyticsUS
ZeroBounceEmail address validation and deliverabilityUS
SentryApplication error monitoring and diagnosticsUS

Legal disclosures

We may disclose information if required by law, court order, or lawful government request, or when necessary to protect the safety, rights, or property of Fundex, our Customers, or others.

Business transfers

In the event of a merger, acquisition, or sale of assets, customer data may be transferred to the acquiring entity. We will provide notice before personal data becomes subject to a materially different privacy policy.

Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. Specific retention periods:

  • Account data: Retained while your subscription is active plus 90 days after cancellation to allow account reinstatement.
  • CRM and pipeline data: Available for export at any time; purged within 30 days of account termination upon written request.
  • Email tracking events: Retained for 36 months from the event date, then automatically deleted.
  • Billing and transaction records: Retained for 7 years for tax and legal compliance.
  • Security and audit logs: Retained for 12 months.
  • Backups: Point-in-time database backups are retained for 35 days and then overwritten.

You may request deletion of your data at any time by contacting privacy@usefundex.com. We will respond within 30 days.

Security

Fundex implements technical and organizational measures appropriate to the risk of processing personal data. These include:

Encryption in transit

All data transmitted between clients and our servers is encrypted using TLS 1.2+.

Encryption at rest

Database volumes and backups are encrypted using AES-256 at the storage layer.

Access controls

Role-based access control (RBAC) limits who can access customer data internally. Production access requires MFA and is logged.

Tenant isolation

All database queries are scoped by tenant ID. Cross-tenant data access is blocked at the application layer.

Vulnerability management

We run automated dependency scanning, static analysis, and periodic penetration testing.

Incident response

We maintain an incident response plan and will notify affected Customers without undue delay in the event of a data breach.

No method of electronic transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security. Please report security vulnerabilities to security@usefundex.com.

Your Rights

Depending on your location, you may have the following rights regarding your personal data:

Access: Request a copy of the personal data we hold about you.

Rectification: Request correction of inaccurate or incomplete data.

Erasure (Right to be Forgotten): Request deletion of your personal data, subject to legal retention obligations.

Portability: Request your data in a structured, machine-readable format (CSV or JSON).

Restriction of processing: Request that we limit how we use your data in certain circumstances.

Objection: Object to processing based on legitimate interests or for direct marketing purposes.

Withdraw consent: Where processing is based on consent, withdraw it at any time without affecting prior lawful processing.

To exercise any of these rights, email us at privacy@usefundex.com. We will respond within 30 days (GDPR) or 45 days (CCPA). We may need to verify your identity before processing your request.

GDPR

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) or equivalent UK/CH legislation applies to our processing of your personal data.

Legal bases for processing

  • Contract performance: Processing necessary to deliver the Service you have subscribed to.
  • Legitimate interests: Security monitoring, fraud prevention, product analytics, and improving the Service — balanced against your rights.
  • Consent: Marketing communications and certain cookie categories (you may withdraw at any time).
  • Legal obligation: Tax and accounting records.

International data transfers

Fundex is based in the United States. When we transfer personal data from the EEA/UK to the US, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission. Enterprise Customers may request SCCs as part of a Data Processing Addendum.

Data Protection Officer

For GDPR-specific inquiries, contact our privacy team at privacy@usefundex.com. You also have the right to lodge a complaint with your local supervisory authority.

CCPA / CPRA (California)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you additional rights:

  • Right to Know: Request information about the categories and specific pieces of personal information we have collected about you.
  • Right to Delete: Request deletion of your personal information (subject to exemptions).
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt Out of Sale / Sharing: We do not sell or share personal information for cross-context behavioral advertising.
  • Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal information beyond what is necessary for the Service.
  • Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

To submit a verified consumer request, email privacy@usefundex.com or use the Do Not Sell or Share My Personal Information link in the footer. We will respond within 45 calendar days.

Cookies & Tracking Technologies

We use cookies and similar technologies on our website and application. Categories:

Strictly necessary

Session authentication, CSRF protection, and security tokens. Cannot be disabled.

Functional

Remember your preferences, language settings, and UI state across sessions.

Analytics

Google Analytics 4 with IP anonymization to understand aggregate usage. You may opt out via browser settings or our cookie banner.

Marketing

We do not currently run behavioural advertising campaigns. No third-party ad tracking cookies are set.

You can control cookies through your browser settings or our consent banner. Disabling strictly necessary cookies may prevent the application from functioning.

Children's Privacy

The Fundex Service is not directed at children under the age of 18. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, please contact privacy@usefundex.com and we will promptly delete it.

Policy Changes

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of the page. For material changes, we will provide prominent notice via email or an in-app notification at least 30 days before the change takes effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

We encourage you to review this page periodically. Previous versions of this policy are available upon request.

Contact Us

If you have questions about this Privacy Policy, want to exercise your rights, or have a privacy concern, please reach out:

Privacy & Data Requests

privacy@usefundex.com

GDPR / CCPA requests, DPA inquiries, data deletion

Mailing Address

Fundex, Inc.
311 Post Road East, 2nd Floor
Westport, CT 06880
United States

For security vulnerabilities, please email security@usefundex.com — do not file public issues.