Legal · Privacy

Privacy Policy

Last updated 2026-06-30

On this page
  1. 01Who we are
  2. 02What we collect
  3. 03How we use it
  4. 04Google API data handling
  5. 05Microsoft Graph data handling
  6. 06Sharing
  7. 07Retention
  8. 08Your rights
  9. 09Security
  10. 10Children
  11. 11Changes
  12. 12Contact

01Who we are

Vantage Data Room (the "Service") is operated by Vantage Businesses Inc. ("Vantage", "we", "us"). The Service provides a secure, AI-assisted investor data room used by property developers and their authorised sales representatives to share materials with prospective investors.

Contact: dev@vantagebusinesses.com.

02What we collect

Account data — name, email address, password hash, organisation, role.

Workspace data — your business profile, project details, regional knowledge, comparable transactions, investor records, meeting notes, sales activity events.

Investor data — for each investor you invite: name, email address, NDA acceptance state, session activity in the data room (pages viewed, documents downloaded, time spent), notes you record about them, and any reply correspondence you initiate through the Service.

Connected services — when you connect Gmail, Outlook, HubSpot, Salesforce, or other integrations, we store the OAuth tokens required to call those services on your behalf. Tokens are encrypted at rest.

Operational telemetry — request logs, error reports, performance metrics. No content of the data room is included in operational logs.

03How we use it

Operate the Service — provision your workspace, render the data room to investors you invite, deliver email sent via the Service, sync data to your connected CRMs.

AI assistance — your workspace data and the investor activity you've recorded feed our AI assistants (Vantage Intelligence) to generate briefs, conversational responses, and email drafts inside your workspace only. We do not train shared AI models on your data.

Improve the Service — aggregated, de-identified usage telemetry informs reliability and product decisions.

Legal compliance — we may process or retain data when required by applicable law.

04Google API data handling

If you connect a Google account, Vantage receives Gmail permissions (gmail.send, gmail.modify, userinfo.email, userinfo.profile) so that approved drafts originating in your workspace are sent from your mailbox and so that reply notifications can be threaded against the originating message.

Vantage's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to third parties except as necessary to provide or improve user-facing features, comply with applicable law, or as part of a merger, acquisition or sale of assets with notice to users.

We do not use Google user data for advertising. We do not allow humans to read Google user data unless we have your explicit consent for specific messages, doing so is necessary for security purposes (such as investigating abuse), to comply with applicable law, or our use is for internal operations and the data have been aggregated and anonymized.

AI and machine learning. Vantage does not use data obtained through Google Workspace APIs to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models. Mailbox content is never sent to a model provider for training, and it is never used to train models that serve any other customer. Where our AI assistants reference a message in order to draft a reply for you, that processing happens for your workspace only, at your request, and the output is shown to you for approval before anything is sent.

What each permission is used for. gmail.send sends a follow-up that a person in your workspace has explicitly approved — nothing is ever sent automatically without that approval. gmail.modify is used to read message history so that an investor’s reply can be matched to the conversation it belongs to and any running sequence can be stopped; we do not delete your mail. userinfo.email and userinfo.profile identify which mailbox has been connected so you can see and revoke it.

Revoking access and deleting the data. You can disconnect a mailbox at any time from your profile page in the application, or from your Google Account under Security → Third-party apps with account access. Disconnecting revokes the token with Google and deletes our stored access and refresh tokens for that mailbox immediately. Message metadata we retained for reply matching is deleted with the workspace, or sooner on request to the address below.

05Microsoft Graph data handling

If you connect a Microsoft account, Vantage receives Mail.Send, Mail.ReadBasic, and User.Read permissions for the same purposes as the Google integration: outbound drafts sent from your mailbox, reply notifications. Mail.ReadBasic is deliberately narrower than full mail access — it returns message metadata and does not give us the bodies of your messages. The same Limited Use posture applies.

As with Google, we do not use data obtained through Microsoft Graph to develop, improve, or train generalized or non-personalized AI or machine learning models. You can disconnect a mailbox from your profile page, or revoke access from your Microsoft account privacy settings; disconnecting deletes our stored tokens for that mailbox.

06Sharing

We do not sell personal data.

Service providers — we use Supabase (database + storage), Vercel (hosting), Postmark / Resend (email delivery fallback), OpenRouter (AI model routing), Mapbox (mapping), and the CRM providers you choose to connect. Each is contractually bound to handle data only on our instructions.

Workspace boundaries — data inside your workspace is visible only to administrators of that workspace and to investors you invite by name. Vantage staff have access only when necessary for support and only with audit-logged escalation.

07Retention

Account + workspace data is retained while your subscription is active. On termination, we delete or anonymize all workspace data within 30 days, except where retention is required by law.

Operational logs are retained for 90 days.

AI brief outputs and meeting note extractions are retained as part of workspace data.

08Your rights

You may request access, correction, deletion, or export of personal data we hold about you by emailing dev@vantagebusinesses.com.

Investors invited into a workspace may at any time view what we have stored about their session activity via the in-room "What we have on file" surface. They may also request removal of their record by writing to the workspace administrator who invited them or to us directly.

CASL (Canada) — recipients of any communication sent through the Service have an unsubscribe option in every email. Withdrawals are sticky.

09Security

All traffic is encrypted in transit (TLS 1.2+). All connected-service tokens are encrypted at rest using AES-256-GCM with workspace-scoped envelope encryption. Database backups are encrypted. Access to production systems is gated by multi-factor authentication and reviewed quarterly.

10Children

The Service is not intended for users under the age of 16. We do not knowingly collect personal data from children.

11Changes

We may update this policy. We will notify workspace administrators by email at least 14 days in advance of any material change.

12Contact

Questions, complaints, or rights requests: dev@vantagebusinesses.com.