Privacy
2 details on this page have still to be supplied by the publisher. They are marked in the text.
The short version
We hold two quite different kinds of personal data, and they work differently.
The first is information about you as a reader: your email address if you have an account, the companies you follow, and how you have said you want to hear about them. You gave us that, and you can remove it.
The second is information about people who appear in the index — founders, investors and operators named on company and fund records. Those people did not give us anything. That data is compiled from public sources, and the section on it below explains the basis we rely on and how to object.
What we hold about account holders
Your email address, held by our authentication provider so that a sign-in link can be sent to it. There is no password, so we store no password.
The companies you follow, stored against your account so your watchlist survives a sign-out.
Your digest frequency and which kinds of event you want alerts about. Where this deployment has a mail provider configured, a digest goes to the address on your account at the frequency you chose, and it is built from the records you follow and the kinds of event you ticked — nothing else. If nothing happened to anything you follow, no message is sent at all. Every message carries a one-click unsubscribe that works without signing in, and it stops everything we send to that address, not just the kind you were reading when you pressed it. Choosing a frequency again on your watchlist starts it back up.
The searches you save, and which companies we have already told you started matching them. Where this deployment has a mail provider configured, a saved search is re-run on the same schedule the digest goes out on, at the same frequency you chose — daily, or weekly on a Monday — and if companies have entered it since the last time, a message names them. If none have, nothing is sent. If you have asked to hear about major events only, no saved-search alert is sent at all: a company entering a filter is not one. The list of companies we hold against a saved search is not a history of what you read: it is what stops the same company being reported to you twice, and it is never shared or shown to anybody else. It goes when you delete that saved search, and when you delete your account.
A record of the mail we sent you: the address it went to, the subject line, when it was sent, and whether the provider accepted it. It is what lets us answer you if you tell us a message never arrived. You can see your own and nobody else can; it goes when your account does, and is trimmed after ninety days in any case.
Any company you have submitted, and any company you have claimed. A claim records which account holds the record and when it was made, and that association is shown publicly on the record as a verified claim.
How the pages perform, and which pages are read. This deployment measures page views and loading speed through our hosting provider so we can tell whether the site is fast for the people actually reading it — which, for a Nepali index served from a datacentre that is not in Nepal, is a question we cannot answer any other way. It is counted, not tracked: no cookie is set for it, nothing follows you to other sites, and there is no identifier that could be used to pick your visits out from anyone else's.
If you follow a link to apply for a job listed here, we add one to a count kept against that role, so the company that posted it can tell whether the listing is getting any interest. The count is the whole of what happens. Nothing is recorded about who followed the link — not your account if you have one, not your address, not a cookie, not an identifier of any kind, and not the time you did it — so nothing here can say that it was you, and nothing can tell whether two follows were one person or two. The company sees a number and never a name, and it is told plainly that the number counts clicks rather than applicants. We never learn whether you applied: that happens on the employer’s own site, which is not ours. If your browser will not send the count, or you have JavaScript off, the link works exactly the same and nothing is counted at all.
If you apply to a role through this site’s own apply form, rather than through a link that sends you to the employer’s site, we hold the name, email, resume link and note you gave us, against the role you applied to. You do not need an account to use this form, and applying does not create one; if you are signed in when you apply, the application is linked to your account as well. It is read only by the company that claimed the role you applied to, and by nobody else here — not the research desk, not another company, nobody. Deleting your account removes it, the same as your comments and votes; if you applied without an account and want it removed, write to the data protection address in the imprint and name the role and the email you applied with.
We use no advertising cookies and sell nothing to anybody. The only cookies set are the ones your session needs to keep you signed in.
What we publish about people in the index
A person record may carry a name, a role, an employer, a location, a public career history and investments that have been publicly announced. We do not publish home addresses, personal contact details, or anything about anyone who is not a participant in the market this index covers.
Which data protection law covers a record follows the person in it, not us. The index lists companies and the people around them wherever they are, so more than one regime can apply to the same page at once: the GDPR for people in the EU and the EEA, whose market is on the roadmap, and the law of whichever country a person is in otherwise. We do not claim that one of them governs the rest, and the rights described here are offered to everyone regardless of which does.
Where a lawful basis has to be named, ours is legitimate interest: a public record of who builds and funds companies is the entire purpose of the index, and it cannot be assembled by asking each person for consent first. We have weighed that against the interests of the people listed, which is why the records are limited to professional information that is already public.
You can object to being listed. Write to the data protection address in the imprint and say which record is yours. We will remove or restrict it unless we can show compelling grounds that override your interests, and we will tell you either way. You do not have to explain why, and you do not need an account.
You can also ask for a copy of what we hold about you, ask us to correct it, or ask us to send it elsewhere. Corrections we act on immediately — an index that argues about a factual error deserves neither the record nor the reader.
Where the data is held
The database and the authentication service are operated by Supabase, in the Asia Pacific (Tokyo) region — ap-northeast-1. Everything described above is stored there, and read from there when you use the site.
This passage used to call that a defect and promise a move to Europe. It read that way because the index assumed the companies and the readers were European. They are not: the first market is Asia, so the data now sits near most of the people it is about. For anyone in the EU or the EEA it is still storage outside the European Economic Area, and that transfer relies on the standard contractual clauses in our processor agreement. If Tokyo stops being the right home for this data, this page will say where it went before it goes.
The site itself is served by Vercel from a global content network. Pages that everyone sees are cached and served from the edge; pages that are yours are rendered per request.
How long we keep it
Account data for as long as the account exists. Deleting it is a control on your own dashboard, and it takes effect at once rather than becoming a request somebody works through.
Deleting the account removes the account itself and the email address behind it, your watchlist, your digest and alert preferences, your saved searches, the lists you made, the votes you cast on launches, the comments you posted under them, and any application you filed to a role while signed in.
What stays is the index. A company record you claimed and corrected is a record about a company, not about you, so it stays — but the claim linking it to your account goes with the account, and the record returns to unclaimed. A company you submitted stays in the queue with your name taken off it. A person record about you is not yours to delete from here either: that is the objection above, which is a different question with a different answer, needs no account, and is answered whether or not you ever had one.
Records in the index are kept indefinitely, because a research index whose history disappears is not one. A person record removed on objection stays removed.
Complaints
If you think we have handled your data badly, tell us first at to be supplied — it is usually quicker. You can also complain to the data protection authority for the country you live in, whichever that is; if you are in the EU or the EEA that includes your national authority under the GDPR. Where a complaint has to reach our own regulator instead, it is to be supplied.