Privacy Policy
Last updated 2026-08-24.
This is the privacy policy for EarlyBird (“EarlyBird,” “we,” “us”), operator of investearlybird.com. It explains what personal information we collect, how we use it, who we share it with, and the rights you have over it.
EarlyBird is pre-launch. Today the only services we provide are this marketing site, the email waitlist, and an authenticated dashboard. The EarlyBird Card and the rewards-allocation investing service have not launched. When they launch, this policy will be updated and you will be notified by email before the new practices take effect. Until then, this policy describes only the data we actually collect today, with forward-references to what will change at launch.
Not legal advice. This document is provided for transparency. It is not legal advice, and reading it does not create an attorney–client relationship. Before relying on it for any decision, consult your own counsel.
At a glance
- We collect your email and, if you create an account, the limited profile data Clerk passes us (display name, email, phone if you add it).
- We do not sell your personal information. We use the Meta (Facebook) pixel on our public marketing pages to measure our advertising — some state laws call that “sharing” — and a Global Privacy Control signal opts your browser out of it entirely. The pixel never runs on signed-in pages.
- We use vendors (listed below) to run the site, send transactional email, monitor errors, and measure product analytics. PII is stripped from error and analytics streams.
- When the EarlyBird Card and investing service launch, we will collect more (investment objectives, risk tolerance, bank link tokens via Plaid), and identity-verification data will be collected by our regulated partners on their own systems — not held by EarlyBird.
- You have rights to access, correct, delete, and port your data, plus state-specific rights described below. Email support@investearlybird.com to exercise them.
Who we are
EarlyBird is a Delaware company building a credit card whose interchange rewards will be allocated by an affiliated investment adviser into curated early-stage offerings exempt under Regulation Crowdfunding (Reg CF) and other exemptions. EarlyBird Advisors LLC is registered with the SEC as an investment adviser under the Investment Advisers Act of 1940 (a federally covered, Series 65–led RIA). The investing service is in pre-launch.
If you have questions about this policy:
- Email support@investearlybird.com.
- A mailing address will be added before the EarlyBird Card and investing service launch.
Information we collect today
We only collect what we actually need to run the waitlist and the authenticated dashboard.
What you give us directly
- Waitlist signup. Email address. On the
/waitlistpage we also collect your first and last name, and — only if you tick the box — your consent to receive our newsletter, which is delivered by beehiiv under its own privacy policy. - Merch drop (optional). A US mailing address, if you choose to give us one after joining the waitlist. We use it to ship merch and nothing else: it is not an identity or KYC address, we do not verify it, and it is not shared with our advertising or analytics vendors. You can skip this and stay on the waitlist. Email support@investearlybird.com to have it removed at any time.
- Account creation (Clerk). Email address, display name, and — if you choose to add it — phone number. If you sign in with Google, we receive your Google profile email and name from Clerk; we do not receive your Google password.
- Investor profile (forward-looking). When the investing service launches, we will collect the information required to give you suitable advice under FINRA Rule 2111 and our fiduciary duty as a federally covered RIA — investment objectives, risk tolerance, time horizon, financial situation as you describe it, and similar suitability data. We will retain it as part of our Form ADV and books-and-records obligations.
What gets collected automatically
- Server and product analytics. PostHog records anonymous funnel events (page views, button clicks, signup conversions). We have configured PostHog to block IP capture and to create profiles only for users who are already identified by Clerk. We do not record sessions.
- Traffic analytics. Google Analytics 4 records aggregate traffic measurement (page views, referral source, approximate location, device type) on our public marketing pages. We run it with Google Consent Mode and all advertising signals permanently denied, so it does not feed Google’s advertising products and no remarketing audiences are built. We have not enabled Google Signals or any advertising features.
- Error monitoring. Sentry receives stack traces and error metadata when something breaks. We have set
sendDefaultPii: false, which means IP addresses, request bodies, cookies, and headers are not sent to Sentry. - Cookies and similar technologies. See “Cookies and tracking technologies” below.
What we do not hold
So you know what is and is not in our systems:
- No Social Security numbers. SSNs are collected by our regulated partners (currently planned: North Capital for KYC/AML/OFAC) and held on their systems. EarlyBird never stores your SSN.
- No government ID images. Identity-verification photos are uploaded directly to our KYC partner.
- No raw bank account or routing numbers. When we add bank linking, we will use Plaid; EarlyBird stores only the Plaid item or access token, not the underlying account numbers.
- No credit-pull data, income, or net-worth verification. Where these are collected (for example, to confirm Reg CF investment limits), they are collected by our regulated partners and reported back to EarlyBird only at the granularity needed to make allocations.
What changes at launch
When the EarlyBird Card and the investing service launch, additional categories will apply:
- KYC/AML data (collected by North Capital): legal name, date of birth, residential address, SSN, government ID. Held by North Capital subject to its own privacy notice. EarlyBird receives only a verification status and a customer ID.
- Bank account link (via Plaid): an institution identifier and a Plaid access token used to initiate ACH transfers. Plaid’s end-user privacy policy is at plaid.com/legal/#end-user-privacy-policy.
- Investment activity (collected by EarlyBird and recorded by North Capital as our books-and-records partner): allocations, holdings, statements, tax reporting data.
When this happens, we will publish an updated version of this policy and a separate Financial Privacy Notice under the Gramm–Leach–Bliley Act (GLBA) using the regulator-mandated “FACTS” format. We will email you before the change takes effect.
How we use your information
We use personal information for these purposes:
- To run the waitlist and the authenticated dashboard.
- To send you transactional email about your account (sign-in, security, and product updates from EarlyBird itself). We use Resend as our email vendor.
- To send you launch updates about EarlyBird if you have asked to be on the waitlist. You can unsubscribe at any time using the link in any email.
- To detect, prevent, and respond to fraud, abuse, and security incidents.
- To comply with legal obligations, including, after launch, recordkeeping under the Investment Advisers Act, FINRA rules applicable to our partners, the Bank Secrecy Act, the CARD Act, the Truth in Lending Act, the Electronic Fund Transfer Act (Regulation E), the ESIGN Act, and applicable state law.
- To improve the product through aggregated, de-identified analytics.
- For business transactions, including evaluating, negotiating, or completing a corporate financing, merger, acquisition, or sale of assets, with appropriate confidentiality protections.
We do not sell your personal information for money or other valuable consideration. Our only advertising use is the Meta pixel described under “Advertising measurement” below; beyond that we do not use your information for cross-context behavioral advertising.
How we share your information
We share personal information only in the following circumstances.
Service providers acting on our behalf
Vendors that process data only under our instructions and under written contract. Today this includes:
- Clerk — authentication and identity. clerk.com/legal/privacy-policy
- Resend — transactional email delivery. resend.com/legal/privacy-policy
- PostHog — product analytics, with IP capture disabled and identified-only profiles. posthog.com/privacy
- Sentry — error monitoring, with
sendDefaultPii: false. sentry.io/privacy - Google Analytics — aggregate traffic measurement, with all advertising signals denied and no advertising features enabled. policies.google.com/privacy
- Vercel — web hosting and CDN. vercel.com/legal/privacy-policy
- Railway — API hosting. railway.com/legal/privacy
- Neon — managed Postgres database. neon.com/privacy-policy
- Cloudflare — DNS and edge caching. cloudflare.com/privacypolicy
Advertising measurement (Meta pixel)
We run ads on Meta platforms (Facebook and Instagram), and we use the Meta pixel to know whether those ads work. In plain terms: on our public marketing pages only, a small Meta script records that a page was viewed and, if you join the waitlist, that a signup happened. That lets Meta count conversions and improve who sees our ads.
What the pixel involves, exactly:
- It runs only on public pages (the marketing site, blog, legal pages, and the waitlist and sign-up forms). It never loads on signed-in pages, so Meta never sees your dashboard, portfolio, account, or activity.
- When you join the waitlist, we pass your email to the pixel, which converts it to an irreversible hash before sending — Meta uses the hash to match the conversion to an ad click. We never send your name, phone number, or any financial information.
- Automatic form-field collection is disabled; the pixel sends only the events we explicitly fire.
- Visitors in the EEA and the UK are served without the pixel entirely.
- A Global Privacy Control signal from your browser stops the pixel from loading at all, everywhere.
Meta processes this data under its own privacy policy: facebook.com/privacy/policy.
Regulated partners (after launch)
When the EarlyBird Card and investing service launch, we will share account, identity, and transaction data with North Capital (KYC/AML, money movement, books-and-records) so they can perform their regulated functions. Plaid will receive bank-link information that you affirmatively initiate. The post-launch GLBA Financial Privacy Notice will describe these flows in the regulator’s “FACTS” format.
Issuers and offerings (after launch)
If you direct allocations into a Reg CF or other exempt offering, the issuer and the offering’s funding portal or broker-dealer will receive the information they need to record your investment and meet their own disclosure obligations.
Legal, safety, and compliance
We may disclose information when required by law (subpoena, court order, regulator request), to comply with a legal obligation, to investigate fraud or security incidents, to protect the rights or safety of EarlyBird or others, or to defend legal claims.
Corporate transactions
In connection with a financing, merger, acquisition, sale of assets, or bankruptcy, in which case the recipient must honor commitments materially consistent with this policy.
With your consent
Any other sharing only with your consent.
We do not have a public sub-processor registry today; the list above is the full set of vendors we use that touch personal information. After launch, we will maintain a sub-processor list available on request.
Cookies and tracking technologies
We use a small number of cookies and similar technologies:
- Strictly necessary — session cookies set by Clerk to keep you signed in.
- Functional — preferences such as your selected theme.
- Analytics — PostHog uses a cookie to attribute repeat events to a single anonymous visitor, configured to ignore IP addresses. Google Analytics sets a cookie on our public marketing pages to count returning visitors. Visitors in the EEA and the UK are served without that cookie at all, because we deny analytics storage in those regions by default.
- Advertising measurement — the Meta pixel sets a cookie (
_fbp) on our public marketing pages so Meta can attribute a waitlist signup to one of our ads. It is never set on signed-in pages, never set for EEA/UK visitors, and never set when your browser sends a Global Privacy Control signal. We also store the campaign tags from the ad link you clicked (utm_*parameters and Meta’s click ID) in a first-party cookie so we can measure our own ads without relying on Meta’s numbers.
The Meta pixel is the only third-party advertising technology we use; Google Analytics runs with all advertising signals denied. Our PostHog deployment is reverse-proxied through /ingest on our own domain so that ad-blockers do not double as analytics-blockers; you can still opt out using your browser, your operating system’s ad-tracking controls, or by sending a Global Privacy Control signal — which also disables the Meta pixel entirely.
Do Not Track and Global Privacy Control
Browsers vary in how they signal user preferences.
- Do Not Track (DNT). There is no industry consensus on how to interpret DNT, so we do not respond to DNT headers.
- Global Privacy Control (GPC). We honor GPC everywhere, not only in the states that legally require it (California, Colorado, Connecticut, and, beginning in 2026, Oregon). When your browser sends a GPC signal, the Meta pixel never loads — no advertising cookie is set and nothing is transmitted to Meta from that browser, in any state or country. This is our opt-out mechanism for the “sharing” described under Advertising measurement; you do not need to submit a separate request, though you may always email support@investearlybird.com instead.
Your privacy rights
We honor data-subject rights for everyone who interacts with EarlyBird, regardless of where you live, with state-specific additions where applicable.
Rights everyone has
- Access — request a copy of the personal information we hold about you.
- Correction — ask us to correct inaccurate or incomplete information.
- Deletion — ask us to delete your information, subject to legal hold and recordkeeping carve-outs (for example, after launch we are required by SEC and FINRA rules to retain advisory and brokerage records for several years even if you ask us to delete).
- Portability — receive a structured copy of the information you have provided to us.
- Withdraw consent — where we rely on consent, withdraw it at any time.
- Non-discrimination — we will not deny services, charge different prices, or provide a different level of service because you exercised a right.
To exercise any right, email support@investearlybird.com from the email associated with your account, or use the “Delete account” control in the dashboard once it is available. We may need to verify your identity before acting; we will not require more information than is necessary to do so.
You also have the right to lodge a complaint with your state attorney general or, where applicable, the Consumer Financial Protection Bureau, the SEC, or the FTC.
State-specific rights
We currently process the personal information of residents in all 50 U.S. states. The following states have comprehensive consumer privacy laws as of 2026; the rights described above apply to residents of each, with the additional notes below.
- California (CCPA / CPRA). California residents have the rights described above plus the right to limit the use and disclosure of “sensitive personal information,” the right to know the categories and sources of personal information we collect, and the right to opt out of any “sale” or “sharing.” We do not sell personal information. Our use of the Meta pixel for advertising measurement may constitute “sharing” as the CCPA defines it; we honor Global Privacy Control as a frictionless opt-out of that sharing (see above), and you may also opt out by emailing support@investearlybird.com. We have not knowingly sold or shared the personal information of consumers under 16. An authorized agent may submit a request on your behalf with your written authorization.
- Colorado (CPA), Connecticut (CTDPA), Virginia (VCDPA), Utah (UCPA). You have the rights described above. You may also opt out of profiling that produces legal or similarly significant effects; the rewards-allocation engine, when it launches, will not produce such effects without your express direction.
- Oregon (OCPA), Texas (TDPSA), Montana (MTCDPA), Iowa (ICDPA), Indiana (INCDPA), Tennessee (TIPA), Delaware (DPDPA), New Jersey (NJDPA), New Hampshire, Kentucky, Maryland (MODPA), Minnesota (MNCDPA), Rhode Island, Nebraska (NDPA). You have the rights described above to the extent the applicable state law grants them. Effective dates vary; we honor each state’s rights from its effective date.
- Vermont. Under the GLBA Financial Privacy Notice that will apply after launch, we will not share your nonpublic personal information with non-affiliates for marketing purposes without your authorization.
- Nevada. You may opt out of the sale of certain personal information for monetary consideration. We do not sell personal information.
If your state recognizes a Global Privacy Control or Universal Opt-Out Mechanism as a valid opt-out signal, we honor it as described under “Do Not Track and Global Privacy Control.”
If we deny a rights request, you may appeal by replying to our denial email; in states with a statutory appeal right (Colorado, Connecticut, Virginia, and others), we will respond within the period required by that state’s law.
Children
EarlyBird is not directed to children under 18, and you must be at least 18 (and the age of majority in your state) to create an account or join the waitlist. We do not knowingly collect personal information from anyone under 18. If you believe a child under 18 has provided us information, email support@investearlybird.com and we will delete it.
Data retention
We retain personal information for as long as we need it to provide the services, comply with our legal and regulatory obligations, resolve disputes, and enforce our agreements.
- Waitlist email addresses are retained until you ask us to delete them or for the period needed to demonstrate consent.
- Authenticated account data is retained while your account is active and for a reasonable period afterward.
- After launch, advisory and brokerage records will be retained for the period required by SEC and FINRA rules (generally five to seven years), even if you delete your account.
- Error logs and aggregated analytics are retained for shorter, vendor-defined periods.
Security
We use commercially reasonable administrative, technical, and physical safeguards: TLS in transit, encrypted databases at rest, access controls and least-privilege roles, audit logs, vendor risk review, and continuous error monitoring. No system is perfectly secure, and we cannot guarantee that information will never be accessed by an unauthorized party. If we discover a security incident affecting your information, we will notify you and the appropriate regulators as required by applicable law.
International users
EarlyBird is intended for U.S. residents. We do not target or knowingly accept users outside the United States. If you access the site from outside the United States, your information will be transferred to and processed in the United States.
Changes to this policy
We will update this policy when our practices change. The “Last updated” date at the top reflects the most recent change. For material changes — including the changes that will accompany the launch of the EarlyBird Card and the investing service — we will email registered users in advance and will not apply the new practices retroactively to data already collected.
Contact
- Email support@investearlybird.com.
- Web investearlybird.com.
- After launch, the postal address of EarlyBird’s registered office and the name of our Chief Compliance Officer (Comrie Flinn) will be listed here.
If you cannot resolve a concern with us directly, you may contact your state attorney general or, where applicable, the Consumer Financial Protection Bureau (consumerfinance.gov), the Securities and Exchange Commission (sec.gov), or the Federal Trade Commission (ftc.gov).