Privacy Policy
Last updated · Circo, Inc.
In plain English
- Companies use Capable to keep their cap tables. That means we hold personal data about their employees and investors, such as names, addresses, tax IDs, and equity.
- For that stakeholder data, the company is in charge and we act on its instructions as a processor. For your own account and our marketing, we are the controller.
- We do not sell or share personal data for advertising, and AI model providers may not train on it.
- Data is hosted in the United States. Transfers from Europe and the UK rely on Standard Contractual Clauses.
- You can ask to access, correct, delete, or export your data. If a company uploaded your data, contact that company first; we will help it respond.
- Write to privacy@capable.so with any question or request.
This summary helps you read the document. The numbered sections below are what bind.
Contents
- 1.Who we are and what this policy covers
- 2.Our role: processor or controller
- 3.Personal data we collect
- 4.Where the data comes from
- 5.How we use personal data and our legal bases
- 6.AI features and model providers
- 7.How we share personal data
- 8.Sub-processors
- 9.International transfers
- 10.How long we keep data
- 11.Security
- 12.Your rights in the EEA, UK, and Switzerland
- 13.Your rights under US state privacy laws
- 14.Marketing email and cookies
- 15.Children
- 16.Changes to this policy
- 17.Contact
1. Who we are and what this policy covers
Capable is operated by Circo, Inc., a Delaware corporation at 1625 San Carlos Ave, Unit D, San Carlos, CA 94070 (“we”, “us”). This policy explains how we handle personal data when you visit capable.so, create an account, use the Capable application or stakeholder portal, connect Capable to an AI assistant, or contact us.
It does not cover how our customers handle personal data in their own systems, or third-party services you reach from Capable, which have their own policies.
2. Our role: processor or controller
Processor (service provider) for Customer Data. When a company (our “Customer”) uploads or imports information about its stakeholders, such as employees, founders, advisors, and investors, the Customer is the controller of that data and decides why and how it is used. We process it only to provide Capable on the Customer’s instructions, under our Data Processing Addendum. In US state privacy law terms, we are the Customer’s service provider.
Controller for everything else. We are the controller for data about the people who hold Capable accounts, website visitors, people who contact us or ask for a migration, and billing contacts, as well as the security and operational records we keep to run the Service.
If you are a stakeholder and have questions about data a company keeps about you, please contact that company. If you contact us, we will pass your request to the company and support it in responding.
3. Personal data we collect
- Account and identity data: name, email address, sign-in method, Google profile identifier if you use Google sign-in, two-factor settings, company memberships and roles, and single sign-on identifiers where your company uses SSO.
- Stakeholder and cap table data (processed for Customers): names, email and postal addresses, phone numbers, stakeholder type and relationship, tax identification numbers such as Social Security numbers, tax residency, employment dates and termination dates, share, option, SAFE, note, and warrant holdings, vesting schedules, exercise and repurchase records, board and stockholder approvals, certificates, and uploaded documents.
- Electronic signature data: signed documents, typed or drawn signatures, consent to transact electronically, IP address, browser details, and timestamps recorded in the signature audit trail.
- HR system data: if a Customer connects its HR or payroll system through Finch, employee names, work emails, job titles, and employment dates.
- Billing data: billing contact name and email, company name and address, plan, invoices, and payment status. Stripe collects and holds card and bank details; we do not store full payment numbers.
- AI feature data: the questions you ask the assistant or connector, the data retrieved to answer them, and the outputs, including proposed changes and their approval records.
- Migration and inquiry data: details you give us when requesting help, such as name, email, company, and the export files you send from a previous provider.
- Support communications: messages you send us and our replies.
- Device and usage data: IP address, browser and device type, pages and features used, error logs, and security and audit events such as sign-ins, exports, and downloads.
- Cookies: the strictly necessary cookies described in our Cookie Policy. We do not use advertising cookies.
Capable is not designed for special categories of personal data, such as health data. Please do not upload it.
4. Where the data comes from
- From you, when you sign up, fill in forms, upload files, sign documents, or contact us.
- From the Customer and its admins, who add stakeholders, import cap tables, and invite users.
- From systems a Customer connects, such as HR platforms through Finch, and from exports of a previous cap table provider.
- From Google, if you choose to sign in with Google, and from your company’s identity provider if it uses SSO.
- From Stripe, about the status of payments.
- Automatically, from your browser or device when you use the Service.
5. How we use personal data and our legal bases
Where the GDPR or UK GDPR applies, we rely on the legal bases below for data we control. For Customer Data, the Customer determines the legal basis, and we act on its instructions.
| Purpose | Legal basis |
|---|---|
| Create and secure accounts, sign you in, and provide the Service you or your company signed up for | Performance of a contract; legitimate interests in serving our Customers’ users |
| Send transactional email: sign-in links, invitations, signature requests, task reminders, and service notices | Performance of a contract; legitimate interests |
| Bill subscriptions and keep financial records | Performance of a contract; legal obligation |
| Provide AI features you choose to use | Performance of a contract |
| Answer support requests and carry out migrations you request | Performance of a contract; legitimate interests |
| Detect, prevent, and investigate fraud, abuse, and security incidents; keep audit logs | Legitimate interests in protecting the Service and its users; legal obligation |
| Understand how features are used and fix problems, using operational data rather than cap table contents | Legitimate interests in improving the Service |
| Send product news to account holders and people who ask for it | Legitimate interests, or consent where the law requires it; you can opt out at any time |
| Comply with law, respond to lawful requests, and establish or defend legal claims | Legal obligation; legitimate interests |
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. We do not use personal data to train AI models.
6. AI features and model providers
When you use an AI feature, we send only the data needed for that request through Vercel AI Gateway to a model provider, currently OpenAI or Anthropic. The providers process it to return an answer, under terms that prohibit them from training models on it.
If you connect Capable to a third-party AI assistant such as Claude or ChatGPT, the assistant receives the data it retrieves on your behalf. That provider handles it under its own privacy policy and your agreement with it. You can revoke the connection at any time.
8. Sub-processors
These companies process personal data for us. The sub-processor page gives more detail and explains how we announce changes.
- Vercel (United States): application hosting, content delivery, legacy file storage, and the AI Gateway that routes AI requests to model providers.
- Turso (United States (AWS us-west-2)): primary database.
- Railway (United States): private S3-compatible file storage and Redis cache.
- Stripe (United States): subscription billing and payment processing.
- Resend (United States): transactional email delivery.
- OpenAI (United States): aI model provider for the in-app assistant, import mapping, and connector features, reached through Vercel AI Gateway.
- Anthropic (United States): aI model provider for the in-app assistant, import mapping, and connector features, reached through Vercel AI Gateway.
- Google (United States): sign in with Google.
- Finch (United States): hRIS and payroll connectivity, only for companies that connect an HR system.
- Cloudflare (Global network): dNS for capable.so.
9. International transfers
We are based in the United States and host the Service there. If you are in the European Economic Area, the United Kingdom, or Switzerland, your personal data is transferred to the United States.
For those transfers, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss equivalents, which are built into our Data Processing Addendum and our agreements with sub-processors. We add the security measures described there. You can ask for a copy of the relevant safeguards at privacy@capable.so.
10. How long we keep data
- Customer Data is kept while the Customer’s workspace is active. After termination, it remains exportable for 90 days, and we delete it from production systems within 30 days after that. Backups expire within a further 30 days.
- Account data is kept while your account is active. When you close your account and belong to no active company, we delete it within 30 days, except for records we must keep.
- Signature audit trails and company audit logs are part of Customer Data and follow the Customer’s retention.
- Billing and tax records are kept for as long as tax and accounting law requires, generally seven years.
- Security logs are kept for up to 12 months.
- Migration files you send us are deleted within 30 days after the migration is complete, once the data lives in your workspace.
- Support and inquiry records are kept for up to three years after the last contact.
11. Security
We protect personal data with encryption in transit and at rest, two-factor authentication that companies can require, per-company role-based access, private file storage with no public links, a complete audit log, and point-in-time database backups. No system is perfectly secure. If a breach affects your data, we will notify the affected Customer, and where we are the controller, you and the authorities, as the law requires. Read more on our Security page and in the security annex of our DPA.
12. Your rights in the EEA, UK, and Switzerland
Subject to legal conditions, you have the right to:
- access the personal data we hold about you and receive a copy;
- correct inaccurate data;
- have data deleted;
- restrict or object to processing, including processing based on legitimate interests and all direct marketing;
- receive data you provided in a portable format;
- withdraw consent at any time, where we rely on consent; and
- complain to your data protection authority. We would appreciate the chance to address your concern first.
Where we process your data as a processor for a Customer, please send your request to that Customer. We will assist it as our DPA requires.
13. Your rights under US state privacy laws
This section applies to residents of California and other US states with comprehensive privacy laws, including under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA).
Categories collected in the last 12 months: identifiers (name, email, IP address); customer records and financial information (billing details, equity holdings); professional or employment information (job title, employment dates); commercial information (plan and purchase history); internet activity (usage and audit logs); sensitive personal information (tax identification numbers and account sign-in credentials). We do not draw inferences to build profiles about you. Sources and purposes are described in Sections 4 and 5. Retention is described in Section 10.
No sale or sharing. We have not sold personal information or shared it for cross-context behavioral advertising in the last 12 months, and we do not knowingly do so for anyone under 16. We use sensitive personal information only for purposes the CCPA permits, such as providing the Service, and not to infer characteristics about you. We honor Global Privacy Control signals as a request to opt out of sale and sharing.
Your rights. You may ask to know what personal information we collected about you, to receive a copy, to correct it, and to delete it. We will not discriminate against you for exercising these rights.
How to ask. Email privacy@capable.so. We will verify your identity, usually by confirming control of the email address on the account, and respond within 45 days, or tell you if we need more time as the law allows. You may use an authorized agent; we will ask for proof of the agent’s authority and may ask you to verify your identity directly. If we deny your request, you may appeal by replying to our decision, and we will answer the appeal within the period your state requires.
If a Customer holds your data in Capable, we act as its service provider. We will refer your request to the Customer and help it respond.
14. Marketing email and cookies
Transactional messages, such as sign-in links and signature requests, are part of the Service. You can unsubscribe from product news at any time with the link in the email. We use only strictly necessary cookies, described in our Cookie Policy, so we do not show a consent banner. If we ever add optional cookies, we will ask first where the law requires.
15. Children
Capable is a business service for adults. It is not directed to children under 16, and we do not knowingly collect their personal data from them. If a Customer records a minor as a stakeholder, for example as a beneficiary of a gift of shares, the Customer is responsible for that data. If you believe a child has given us personal data, contact privacy@capable.so and we will delete it.
16. Changes to this policy
We will post updates on this page and change the date at the top. For material changes, we will notify account owners by email or in the app at least 30 days before they take effect, unless a change is required sooner by law.
17. Contact
Privacy questions and requests: privacy@capable.so.
Security issues: security@capable.so. General support: support@capable.so.
By mail: Circo, Inc., Attn: Privacy, 1625 San Carlos Ave, Unit D, San Carlos, CA 94070, USA.