Privacy Policy

Last updated July 9, 2026

Surdi Family Office ("we", "us") is a private, invitation-only wealth dashboard operated by the Surdi family. This policy describes what information we collect, how we use it, and the choices available to authorized users.

1. Who this applies to

This application is not open to the public. Access is limited to family members and pre-authorized advisors, accountants, and bookkeepers who have been individually provisioned by the account owner. Public sign-up is disabled.

2. Information we collect

  • Account info: your email address and the role assigned to you (owner, family, advisor, accountant, bookkeeper).
  • Financial data you or the owner enter: entities, manual assets, valuations, notes.
  • Financial data pulled from linked providers: bank balances and transactions via Plaid, brokerage holdings and cost basis via SnapTrade, crypto holdings via CoinStats. We do not receive or store online-banking credentials — those are handled directly by Plaid/SnapTrade.
  • Operational data: sync timestamps, error logs, and basic security telemetry.

3. How we use it

Data is used solely to display the family's consolidated net worth, holdings, and performance to authorized users. We do not sell, rent, advertise against, or share this data with third parties except the service providers listed below, and only to the extent required to deliver the service.

4. Service providers (subprocessors)

  • Supabase — database, authentication, and secret storage (SOC 2 Type II).
  • Cloudflare / Lovable — hosting, TLS termination, DDoS protection.
  • Plaid — bank account aggregation.
  • SnapTrade — brokerage account aggregation.
  • CoinStats — crypto portfolio aggregation.

5. Security

All traffic uses TLS 1.2+ with HSTS. Row-level security is enforced on every database table. Provider access tokens and API secrets are stored server-side only and are not readable by application users. See our Information Security Policy.

6. Retention and deletion

See our Data Deletion & Retention Policy for how long data is kept and how to request deletion.

7. Your choices

Authorized users may disconnect any linked institution at any time from the app, which revokes the provider token and removes the linked balances on the next sync. To request full deletion of your account, contact the owner.

8. Contact

Questions? Email bensurdi@gmail.com.