Venture Hub

Legal Document

Privacy Policy & Data Terms

Effective Date: April 18, 2026 · Venturehubsystem LLC · vhs.capital

[ 1. Introduction & Controller Identity ]

This Privacy Policy (“Policy”) describes how Venturehubsystem LLC (“VHS,” “we,” “us,” or “our”), a Delaware limited liability company, collects, uses, discloses, retains, and protects personal data in connection with the platform accessible at vhs.capital (the “Platform”).

This Policy applies to all registered users, applicants, visitors, and any other individuals whose personal data is processed in connection with the Platform. By accessing or using the Platform, you acknowledge that you have read and understood this Policy.

Data Controller: Venturehubsystem LLC, contactable at duckm4573r@vhs.capital

[ 2. Definitions ]

"Personal Data" means any information that relates to an identified or identifiable natural person.

"Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.

"Sub-Processor" means a third-party service provider engaged by VHS to process Personal Data on our behalf.

"User" means any individual who registers for and accesses the Platform.

"Deal Flow Data" means data relating to a User's review decisions (Yeah, Maybe, Nope) on companies presented on the Platform.

"Company Information" means publicly available information about third-party companies compiled by VHS for investment research purposes.

"GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council.

"CCPA" means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (CPRA).

[ 3. Personal Data We Collect ]

3.1 Account and Authentication Data

When you register for or access the Platform, we collect the following data via Google OAuth 2.0 authentication or email-based magic link authentication:

  • Full name (as provided by your Google account or entered during registration)
  • Primary email address
  • Profile photograph (as provided by your Google account, where applicable)
  • Authentication tokens and session identifiers (for maintaining your login state)
  • Account creation timestamp and last-updated timestamp

We do not collect or store passwords. All authentication is delegated to Google OAuth or to time-limited email magic links.

3.2 Profile and Questionnaire Data

During onboarding and subsequent profile editing, you may voluntarily provide the following additional data:

  • Display name, job title, company represented, and city
  • LinkedIn URL, Twitter/X handle, and personal website URL
  • Short biography
  • Investment preference data: target industries, preferred investment stages, geographic focus, and minimum/maximum investment check size (in USD)
  • Additional investment thesis notes and contact information
  • Language preference (English, Traditional Chinese, or Japanese)

All profile fields other than display name are optional. You may control the public visibility of each field through your privacy settings. The platform defaults to anonymous mode (all profile fields hidden from other users).

3.3 Deal Flow Interaction Data

When you review companies presented in the weekly deal flow, we collect:

  • Your decision for each company: Yeah (high interest), Maybe (moderate interest), or Nope (no interest)
  • The timestamp of each decision
  • Your weekly Yeah vote count and remaining weekly limit

Deal Flow Interaction Data is associated with your account and is visible to Platform administrators (non-anonymized). Aggregate statistics (total Yeah, Maybe, and Nope counts per company) are compiled at the close of each weekly batch and stored in anonymized Weekly Reports. VHS commits that Deal Flow Interaction Data will not be sold, licensed, or used for long-term behavioral profiling of individual users.

3.4 Deal Room and NDA Data

If you participate in a deal room, we additionally collect:

  • Your NDA acceptance status and timestamp
  • Legal name and institutional affiliation (captured at the time of NDA signing)
  • Your deal participation decision (Confirmed In or Confirmed Out) and the associated timestamp

3.5 Payment and Subscription Data

Subscription payments are processed by Stripe, Inc. VHS does not store full payment card details on its own servers. We retain the following payment-related data:

  • Stripe Customer ID and Stripe Subscription ID
  • Subscription status (Trial, Active, Past Due, Cancelled, or None)
  • Subscription plan type (monthly or annual)
  • Trial start date and trial end date
  • Payment event history as received via Stripe webhooks (subscription created, updated, deleted, invoice payment failed)

3.6 Game and Leaderboard Data (Cyberloafing Feature)

If you participate in the Cyberloafing idle game feature, we collect:

  • Your chosen in-game nickname
  • Virtual portfolio balance, investment history, and in-game performance metrics
  • Monthly ranking position and return-on-investment (ROI) percentage

Monthly leaderboard summaries, which include user account identifiers alongside in-game performance data, are transmitted to Platform administrators for review. In-game nicknames are user-chosen and do not need to reflect your real identity.

3.7 Communications Data

We retain records of emails sent to you through the Platform, including:

  • Account registration and approval notifications
  • Weekly deal flow notifications (sent every Monday)
  • Midweek review reminders (sent every Wednesday)
  • Trial expiry reminders
  • Transactional and administrative notices

3.8 Technical and Session Data

When you access the Platform, we automatically collect certain technical data:

  • Session tokens (stored as HTTP cookies for authentication purposes)
  • Language preference cookie (NEXT_LOCALE)
  • Browser type and version, operating system, and device type (where collected by third-party services)
  • IP address (processed by infrastructure providers; not retained in our primary database)
[ 4. Legal Basis for Processing (GDPR) ]

For users located in the European Economic Area (EEA), the United Kingdom, or Switzerland, we rely on the following legal bases for processing Personal Data:

Performance of a Contract (Art. 6(1)(b) GDPR)

Processing of Account Data, Profile Data, Deal Flow Data, and Payment Data is necessary to provide the subscription service you have contracted for.

Legitimate Interests (Art. 6(1)(f) GDPR)

Processing of technical data, platform security measures, and aggregated analytics is based on our legitimate interest in operating and improving the Platform securely and effectively.

Consent (Art. 6(1)(a) GDPR)

Processing of optional profile information beyond what is necessary for service delivery is based on your consent, which you may withdraw at any time by updating your privacy settings.

Compliance with Legal Obligations (Art. 6(1)(c) GDPR)

Retention of transaction records for tax and accounting purposes is required by applicable law.

[ 5. How We Use Your Personal Data ]

We use the Personal Data we collect for the following purposes:

  1. To verify your identity and manage your account
  2. To provide, operate, and maintain the Platform and its features
  3. To process subscription payments and manage your subscription lifecycle
  4. To generate and present weekly deal flow batches tailored to your investment preferences
  5. To compile anonymized aggregate statistics for weekly reports
  6. To send transactional emails (notifications, reminders, approvals)
  7. To detect, investigate, and prevent fraud, abuse, and security incidents
  8. To comply with applicable laws and legal obligations
  9. To enforce our Terms of Service
  10. To improve the Platform's features and user experience (using aggregate, non-identifying data)
[ 6. Data Sharing & Sub-Processors ]

6.1 Sub-Processors

VHS engages the following third-party Sub-Processors who may process Personal Data on our behalf:

ProviderPurposePrivacy
Google LLCAuthentication (OAuth 2.0)google.com/privacy
Stripe, Inc.Payment Processingstripe.com/privacy
Resend, Inc.Transactional Emailresend.com/privacy
Anthropic, PBCAI-Assisted Translationanthropic.com/privacy
Supabase, Inc.Database & Infrastructuresupabase.com/privacy

We do not sell, rent, or otherwise disclose your Personal Data to third parties for their own marketing purposes.

6.2 Administrative Access

Platform administrators and authorized operational staff may access non-anonymized user data, including Deal Flow Interaction Data and deal room participation records, for the purposes of platform operations, dispute resolution, and compliance monitoring. Such access is limited to individuals with a need to know and is subject to confidentiality obligations.

6.3 Legal Disclosures

We may disclose Personal Data if required to do so by law, court order, or governmental authority, or where we reasonably believe that disclosure is necessary to protect the rights, property, or safety of VHS, our users, or the public.

[ 7. Data Retention ]

We retain Personal Data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. The following retention periods apply:

Account and Profile Data: Retained for the duration of your active account. Upon account deletion, profile data is permanently deleted within thirty (30) days, subject to legal hold obligations.

Deal Flow Interaction Data (individual votes): Raw voting records are retained for twelve (12) months from the date of collection. Anonymized aggregate statistics (compiled weekly reports) are retained indefinitely.

Deal Room and NDA Records: Retained for seven (7) years from the date of deal room closure, for compliance and legal purposes.

Payment and Transaction Records: Retained for seven (7) years in accordance with applicable tax and accounting law. Stripe retains its own records subject to Stripe's data retention policy.

Email Communication Logs: Retained for two (2) years from the date of transmission.

Session and Authentication Tokens: Session tokens expire upon logout or after a maximum of thirty (30) days of inactivity.

Game and Leaderboard Data: In-game performance data is retained for the duration of your active account. Monthly leaderboard summaries transmitted to administrators are retained for two (2) years.

[ 8. International Data Transfers ]

VHS is based in the United States. If you access the Platform from outside the United States, including from the European Economic Area (EEA), the United Kingdom, or Switzerland, please be aware that your Personal Data will be transferred to, processed in, and stored in the United States.

For transfers of Personal Data from the EEA or the United Kingdom to the United States, we rely on Standard Contractual Clauses (SCCs) as adopted by the European Commission, where applicable, or other lawful transfer mechanisms. By using the Platform, users located outside the United States expressly consent to the transfer of their Personal Data to the United States in accordance with this Policy.

[ 9. Your Privacy Rights ]

9.1 Rights Under GDPR (EEA, UK, and Swiss Users)

If you are located in the EEA, UK, or Switzerland, you have the following rights with respect to your Personal Data:

  • Right of Access: to obtain a copy of the Personal Data we hold about you
  • Right to Rectification: to request correction of inaccurate or incomplete data
  • Right to Erasure ('Right to be Forgotten'): to request deletion of your data, subject to legal retention obligations
  • Right to Restriction of Processing: to request that we limit the processing of your data in certain circumstances
  • Right to Data Portability: to receive your data in a structured, commonly used, machine-readable format
  • Right to Object: to object to processing based on legitimate interests
  • Right to Withdraw Consent: to withdraw consent at any time without affecting the lawfulness of prior processing
  • Right to Lodge a Complaint: with the supervisory authority in your country of residence

9.2 Rights Under CCPA (California Residents)

California residents have the right to:

  • Know what Personal Data is collected, used, shared, or sold
  • Delete Personal Data we hold about you, subject to certain exceptions
  • Opt out of the sale or sharing of Personal Data (VHS does not sell Personal Data)
  • Non-discrimination for exercising your privacy rights
  • Correct inaccurate Personal Data
  • Limit use and disclosure of sensitive Personal Data

9.3 How to Exercise Your Rights

To exercise any of the rights described above, please submit a written request to duckm4573r@vhs.capital. We will respond within thirty (30) days for CCPA requests and within one (1) calendar month for GDPR requests. We may request verification of your identity before processing your request.

[ 10. Data Security ]

We implement and maintain appropriate technical and organizational security measures designed to protect Personal Data against unauthorized access, disclosure, alteration, or destruction. These measures include:

  • Encryption of data in transit using TLS/HTTPS protocols
  • Encryption of data at rest on our database infrastructure
  • Access controls limiting data access to authorized personnel only
  • Secure session management using time-limited authentication tokens
  • Separation of environment credentials and use of environment variables for secrets management

In the event of a Personal Data breach that is likely to result in a risk to your rights and freedoms, we will notify you and, where required, the relevant supervisory authority, within seventy-two (72) hours of becoming aware of the breach. To report a suspected security vulnerability, please contact duckm4573r@vhs.capital.

[ 11. Cookies & Session Tokens ]

The Platform uses the following cookies and browser storage mechanisms:

next-auth.session-token (Strictly Necessary)

Authentication — stores your authenticated session. Expires after 30 days of inactivity or upon logout.

NEXT_LOCALE (Functional)

Language Preference — stores your preferred display language (en, zh, ja). Expires after 1 year.

CSRF Token (Strictly Necessary)

Security — prevents cross-site request forgery attacks. Session-scoped.

We do not use advertising cookies, cross-site tracking cookies, or analytics cookies that profile your behavior across third-party websites. If you disable cookies, authentication functionality will not operate.

[ 12. Third-Party Company Information ]

The Platform presents information about third-party companies for investment research purposes. Such Company Information is compiled from publicly available sources. VHS makes no representations or warranties regarding the accuracy, completeness, or currency of Company Information.

Any company that does not wish to have its publicly available information displayed on the Platform may submit a removal request to duckm4573r@vhs.capital. We will process removal requests within fourteen (14) business days.

VHS does not claim any copyright or proprietary interest in Company Information sourced from third parties. All such information is used on a transformative basis to provide aggregated investment research insights and does not constitute reproduction of copyrighted material.

[ 13. Children's Privacy ]

The Platform is intended solely for adult users who are qualified investors or investment professionals. We do not knowingly collect Personal Data from individuals under the age of eighteen (18). If we become aware that we have inadvertently collected Personal Data from a minor, we will take prompt steps to delete such data. If you believe that a minor has registered for the Platform, please contact us immediately at duckm4573r@vhs.capital.

[ 14. Changes to This Policy ]

We may update this Policy from time to time to reflect changes in our data practices, applicable laws, or Platform features. When we make material changes, we will post the updated Policy on the Platform with a revised effective date and, where feasible, send a notification to registered users at their email address on file. Your continued use of the Platform after the effective date of any revision constitutes your acceptance of the updated Policy.

[ 15. Contact & Complaints ]

For any questions, requests, or complaints relating to this Policy or the processing of your Personal Data, please contact:

Venturehubsystem LLC

Data Controller

Incorporated in the State of Delaware, United States

Email: duckm4573r@vhs.capital

Domain: vhs.capital

If you are located in the EEA and believe that we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local data protection supervisory authority.