Quick Summary / Key Points at a Glance
- We're a B2B SaaS platform — your financial and CRM data is yours; we process it on your behalf.
- We do NOT sell or "share" your personal information (as defined under CCPA/CPRA).
- We do NOT use your identifiable Customer Data to train AI models shared with other customers.
- We use industry-standard security (encryption in transit and at rest, access controls aligned with SOC 2 principles).
- You have rights to access, correct, delete, and port your data — see Section 10.
Table of Contents
- 1. Introduction
- 2. Information We Collect
- 3. How We Use Your Information
- 4. AI and Automated Processing
- 5. Cookies and Tracking Technologies
- 6. How We Share Information
- 7. Data Security
- 8. Data Retention
- 9. International Data Transfers
- 10. Your Privacy Rights
- 11. Children's Privacy
- 12. Third-Party Links and Services
- 13. Our Role: Controller vs. Processor
- 14. Changes to This Privacy Policy
- 15. Contact Us
Definitions
"Recurved," "we," "us," "our" — Recurved, Inc.
"Service" or "Platform" — Recurved's website, application, and related services.
"Customer" — the business/organization that subscribes to Recurved.
"Customer Data" — financial, CRM, accounting, and operational data submitted to or ingested by the Service from the Customer's connected systems.
"Personal Information" / "Personal Data" — information that identifies, relates to, or could reasonably be linked to an identifiable individual.
"You" — an individual user of the Service or a website visitor.
1. Introduction
Recurved, Inc. ("Recurved," "we," "us," or "our") provides an AI-powered predictive financial forecasting platform that auto-updates business plans in real time by integrating with customers' CRM and accounting systems. Our Service helps CEOs, founders, executives, and investors translate complex financial and operational data into investor-ready forecasts and benchmarks.
This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit www.getrecurved.com, use the Recurved application or platform, or otherwise interact with our Service. It applies to (a) visitors to our website, (b) authorized users of the Recurved Platform, and (c) prospective customers and business contacts. It does not apply to third-party websites, applications, or services that you may access through the Service.
By using the Service, you acknowledge that you have read and understood this Privacy Policy.
2. Information We Collect
2.1 Information You Provide Directly
- Account & Profile Information: name, business email address, job title, company name, phone number, password, and profile photo.
- Billing & Payment Information: billing contact, billing address, tax ID, and payment method details (processed by our payment processor; we do not store full card numbers).
- Communications: emails, support tickets, chat messages, survey responses, and feedback.
- User-Generated Content: forecasts, scenarios, models, notes, comments, file uploads, and other inputs you submit to the Platform.
2.2 Information from Integrations (Customer Data)
When a Customer connects third-party systems to Recurved (such as QuickBooks, Xero, HubSpot, Salesforce, NetSuite, Stripe, or bank feeds), we ingest data from those systems to power forecasting and benchmarking features. This may include:
- Financial transactions, revenue, expenses, accounts receivable/payable, general ledger entries, and tax data
- CRM data such as accounts, contacts, opportunities, deals, pipeline stages, and activity history
- Subscription and billing data
- Employee, headcount, and payroll-related data (where connected)
- Customer lists and product/SKU information
We refer to this collectively as "Customer Data." Customer Data is controlled by the Customer organization that authorized the integration. Recurved processes Customer Data on the Customer's behalf in accordance with our agreement with that Customer.
2.3 Information Collected Automatically
When you access the Service, we automatically collect:
- Device and connection data: IP address, device type, operating system, browser type and version, language preferences
- Usage data: pages and features accessed, clicks, session duration, referring/exit URLs, timestamps, error logs
- Cookie and similar identifiers (see Section 5)
2.4 Information from Third Parties
We may receive information from:
- Identity and authentication providers (e.g., Google, Microsoft SSO) when you sign in
- Payment processors (e.g., Stripe) for transaction confirmation
- Marketing and analytics partners
- Publicly available sources and business data enrichment providers (e.g., for prospect research and account context)
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, maintain, and improve the Service
- Generate forecasts, predictions, scenario models, risk signals, and benchmarks (see Section 4)
- Personalize your experience and recommendations
- Manage your account, authenticate users, and provide customer support
- Process payments and manage billing
- Detect, prevent, and respond to fraud, abuse, and security incidents
- Communicate with you about product updates, security notices, and administrative matters
- Send marketing communications (you may opt out at any time)
- Comply with legal obligations, enforce our agreements, and protect our rights
4. AI and Automated Processing
Recurved uses artificial intelligence and machine learning to deliver core features, including financial forecasting, scenario modeling, risk prediction, and peer benchmarking.
- No cross-customer training on identifiable data. We do not use identifiable Customer Data to train AI models that are shared across customers.
- Aggregated and de-identified data. We may use aggregated, de-identified, and anonymized data to improve our models, build benchmarking features, and conduct research. Such data does not identify any individual or Customer.
- Human review. Where required by law (including GDPR Article 22), you may request human review of decisions made solely by automated means that produce legal or similarly significant effects. Most outputs of the Recurved Platform are decision-support tools, not final decisions; a human user remains responsible for acting on them.
- Third-party AI services. We may use third-party AI infrastructure providers under contractual obligations that prohibit them from using Customer Data to train their own foundation models.
5. Cookies and Tracking Technologies
We and our service providers use cookies, pixels, local storage, and similar technologies ("cookies") to operate and improve the Service. We use:
- Strictly necessary cookies — required for authentication, security, and core functionality
- Performance/analytics cookies — to understand how the Service is used
- Functional cookies — to remember preferences (e.g., language, settings)
- Advertising cookies — limited use on marketing pages to measure campaign performance
Most cookies persist for up to 365 days from your last visit, or are session-based. You can manage cookies through your browser settings or the cookie preferences link in the footer of our website. We honor Global Privacy Control (GPC) signals as an opt-out of "sale" and "sharing" where required by law.
6. How We Share Information
We share information only as described below. We do not sell or "share" (as those terms are defined under the CCPA/CPRA) your personal information.
- Service providers and sub-processors — including cloud hosting (e.g., AWS, Google Cloud), database providers, analytics, email delivery, payment processing (Stripe), customer support tools, and security vendors. These parties are bound by contract to process information only on our instructions and to protect it appropriately. A current list of sub-processors is available upon request or at a URL we publish.
- Within the Customer organization — authorized users from the same Customer organization may access shared workspaces, forecasts, and data.
- Business transfers — in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, with appropriate confidentiality protections.
- Legal and compliance — when required by law, subpoena, court order, or government request, or to protect the rights, property, or safety of Recurved, our customers, or others.
- With your consent — when you direct or authorize us to share information.
7. Data Security
We implement administrative, technical, and physical safeguards designed to protect information, aligned with industry standards (including SOC 2 principles). These include:
- Encryption in transit (TLS 1.2 or higher) and at rest (AES-256)
- Role-based access controls and least-privilege principles
- Multi-factor authentication for administrative access
- Regular vulnerability scanning, penetration testing, and security monitoring
- Secure software development lifecycle practices
- PCI DSS compliance via our payment processor (Stripe) — we do not store full payment card numbers on our systems
- Incident response procedures and a commitment to notify affected Customers and regulators of security incidents as required by applicable law
No system is perfectly secure. You are responsible for safeguarding your credentials and notifying us promptly of any suspected unauthorized access.
8. Data Retention
We retain Customer Data and Personal Information for as long as your account is active or as needed to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements.
After account termination or upon a verified deletion request, we will delete or de-identify Customer Data within a reasonable period — typically 30 to 90 days — subject to legal retention requirements. Backup copies are purged on a rolling cycle. We may retain aggregated, de-identified data indefinitely.
9. International Data Transfers
Recurved is based in the United States, and we primarily process information in the United States. If you access the Service from the European Economic Area (EEA), the United Kingdom, or Switzerland, your information will be transferred to and processed in the United States.
For such transfers, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum (IDTA), and the Swiss equivalent, as applicable.
10. Your Privacy Rights
10.1 California Residents (CCPA / CPRA)
California residents have the right to:
- Know what personal information we collect, use, disclose, and retain
- Request deletion of personal information
- Correct inaccurate personal information
- Opt out of "sale" or "sharing" of personal information — note: we do not sell or share your personal information
- Limit the use and disclosure of sensitive personal information
- Non-discrimination for exercising your rights
- Designate an authorized agent to make requests on your behalf
10.2 European Economic Area / United Kingdom (GDPR / UK GDPR)
If you are in the EEA or UK, you have the rights to:
- Access your personal data
- Rectify inaccurate or incomplete data
- Erase your data ("right to be forgotten")
- Restrict or object to processing
- Data portability
- Withdraw consent at any time (where processing is based on consent)
- Lodge a complaint with your local supervisory authority
Our legal bases for processing include: performance of a contract, our legitimate interests (e.g., operating and improving the Service, securing our platform), your consent (where applicable), and compliance with legal obligations.
10.3 Other U.S. States
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), and other states with comprehensive privacy laws have similar rights, including the rights to access, correct, delete, port their personal data, and opt out of targeted advertising, sale, and certain profiling, subject to the specific requirements of each state's law.
10.4 How to Exercise Your Rights
To exercise any of these rights, contact us at support@getrecurved.com. We will verify your identity before fulfilling your request and respond within the timeframes required by applicable law (generally 30–45 days). If you are an authorized user of a Customer's Recurved account, please direct requests regarding Customer Data to that Customer; we will support them in responding.
11. Children's Privacy
The Service is not directed to individuals under 18 years of age, and we do not knowingly collect personal information from children under 16. If we learn that we have collected personal information from a child under 16 without verified parental consent, we will delete it.
12. Third-Party Links and Services
The Service may contain links to, or integrations with, third-party websites, applications, or services that we do not own or control (including the integrations described in Section 2.2). We are not responsible for the privacy practices or content of those third parties. We encourage you to review their privacy policies before providing them with information.
13. Our Role: Controller vs. Processor
- Recurved as Processor. When we process Customer Data on behalf of a Customer organization (for example, data ingested from a Customer's QuickBooks, Salesforce, or banking integration), the Customer is the data controller and Recurved acts as a data processor (or service provider under U.S. law). Our processing is governed by the Customer's agreement with us, including any data processing addendum (DPA).
- Recurved as Controller. When we collect information directly from website visitors, prospects, billing contacts, and for our own marketing, security, and operational purposes, Recurved acts as the data controller (or business under U.S. law).
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email (to the address associated with your account) or through an in-product notice or banner before the changes take effect. The "Last Updated" date at the top of this policy indicates when it was most recently revised. Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.
15. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
Recurved, Inc.
Attn: Privacy Team
Email: support@getrecurved.com
Mailing Address: 2803 Philadelphia Pike, Suite B #288, Claymont, DE 19703
Website: https://www.getrecurved.com