Privacy Notice
This notice explains what personal information Beacon collects about you, why, and the choices you have. It covers our website, our communications, and your use of the Beacon product. It is written to be read — plain where it can be, precise where it must be.
On this page
1 · Who we are
Beacon is operated by Startup Academy LLC, a company registered in the State of California, United States, trading as Beacon Revenue®. For the personal information described in this notice, Startup Academy LLC is the data controller.
You can reach us about privacy at privacy@beaconrevenue.io, or by post at 548 Market St PMB 419537, San Francisco, California 94104, United States.
Not yet in canonEU/UK representative under GDPR Art. 27 and the named lead supervisory authority. A US-based controller serving individuals in the EU/UK generally needs an appointed representative — this is the one item our internal standards flag to counsel rather than decide. Name + address to insert here once appointed.2 · Who this notice covers
This notice applies to the personal information we handle as a controller — that is, information about you as a person: visitors to our website, people who contact us or receive our communications, and the individual users of a Beacon workspace.
It is separate from the business data a customer connects to Beacon — for example, records from their billing or CRM systems. Where those records contain personal information, Beacon processes them on the customer's instructions, as a processor, under our Data Processing Agreement — the customer, not Beacon, decides how that data is used. If you're an individual whose data reached Beacon because a company you deal with connected their systems, please contact that company; we act on their behalf. Section 5 explains this split.
3 · What we collect
Information you give us
- Contact & enquiry details — your name, work email, company, and anything you write to us in a form, email, or a booked call.
- Account details — the identity you sign up with (handled by our authentication provider, Clerk) and your workspace settings.
- Billing details — for paid plans, the billing contact and, where needed, billing address and tax ID for your invoices. Card payments are processed by Stripe; we do not store full card numbers.
Information we collect automatically
- Product usage — how you use Beacon (pages viewed, features used, actions taken), to run and improve the service.
- Technical & device data — IP address, browser and device type, and similar diagnostics, including through cookies (Section 7).
We do not ask for special-category data (such as health, race, or political views), and ask that you don't send it to us.
4 · How and why we use it
We use personal information to:
- Provide and run Beacon — create your account, deliver the service, and support you. Legal basis: performance of a contract.
- Communicate with you — answer enquiries, send service messages, and (where you've asked or where permitted) share relevant updates. Legal basis: legitimate interests, or consent where required.
- Keep Beacon secure — detect, prevent and investigate abuse, fraud and security incidents. Legal basis: legitimate interests and legal obligations.
- Improve the product — understand usage and fix problems, using aggregated or de-identified data wherever possible. Legal basis: legitimate interests.
- Meet legal and accounting obligations — billing records, tax, and lawful requests. Legal basis: legal obligation.
Where we rely on legitimate interests, we've weighed them against your rights; you can object at any time (Section 11). Where we rely on consent, you can withdraw it at any time.
5 · Data you bring into Beacon
Beacon reads from the systems a customer connects — billing, and optionally CRM and others — to produce that company's revenue intelligence. Some of those records may contain personal information (for example, a customer contact's name and email).
For this data, the customer is the controller and Beacon is the processor. We only act on the customer's documented instructions, under the Data Processing Agreement. We keep the derived shape we need and link back to the source; raw records stay in the customer's own systems. We never sell it, never use it to build a profile of any individual, and — importantly — Beacon's AI never invents or recomputes a figure; every number is produced by a fixed, reproducible calculation the customer can trace to the source.
If you are an individual and want to know how a particular company uses Beacon with your data, contact that company directly.
6 · The benchmark network
Beacon offers anonymised peer benchmarks — so a company can see how its growth and retention compare to similar companies. This runs on a strict, opt-in basis, and it's worth being exact about what it does and doesn't involve.
- Only aggregated statistics ever leave a workspace — pre-computed figures per metric and peer group. Raw records never leave. Your customers, your individual prices, and your company's identity are never shared or made identifiable.
- Nothing publishes until a group is large enough to protect it — a peer figure is only ever shown once at least seven companies are in a group, so no single one can be picked out.
- Contributing and viewing are separate choices — on paid plans a company can contribute its anonymised data, view the community benchmarks, both, or neither, and can leave the network at any time.
- On the Free plan, contributing anonymised aggregates is a condition of the plan — it's what makes Free free — and this is stated plainly, as an explicit consent step, at sign-up. On paid plans it's a reciprocal choice: contribute and you receive the full benchmark intelligence; opt out and benchmarks stay off.
- It's off until switched on, and it respects each customer's data-residency boundary.
Because these figures are aggregated and non-identifying, they are not "personal data" about you. The point of this section is to be transparent about how the network works. The exact consent language shown at sign-up is covered in our benchmark consent terms.
7 · Cookies & analytics
We use a small number of cookies and similar technologies to run the site, remember your preferences, and understand how the site and product are used. Where the law requires it, we ask for your consent before setting non-essential cookies, and you can change your choice at any time.
Not yet speccedConfirm the cookie-consent banner provider and any analytics beyond first-party, so we can name categories and providers here (or link a dedicated Cookie Policy if you'd prefer one).8 · Who we share with
We don't sell your personal information. We share it only with the service providers who help us run Beacon, under contracts that require them to protect it and use it only for us:
- Airtable and Notion — the secure data layer where your workspace lives.
- Anthropic (Claude) — the AI that powers Beacon's reasoning and drafting features.
- Clerk — sign-in and account security.
- Stripe — payment processing for paid plans.
- Vercel and Railway — hosting for the app and its services.
- Resend — transactional email (alerts, reports, service messages).
- Sentry — error monitoring, to keep the product reliable.
- Mintlify — our documentation.
- HubSpot — our customer and marketing communications.
We also share information with professional advisers and authorities where we're legally required to or to protect our rights, and with a successor in the event of a merger, acquisition or reorganisation (subject to this notice). The complete, current subprocessor list — with each provider's role and hosting region — is maintained in our Data Processing Agreement.
9 · Where your data is held
By default, Beacon hosts data in the United States. EU data residency — hosted in Frankfurt, with backups in Dublin — is available for customers on the appropriate plan. We host in-region or we tell you plainly that we can't; we never quietly host your data somewhere it shouldn't be.
Because we're US-based and use the service providers above, some personal information may be processed outside your country. Where we transfer personal information across borders — including from the EU/UK to the US — we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses.
Verify before publishData-layer regions (US default; EU Frankfurt/Dublin on Enterprise) are set in canon. The specific hosting regions of the other providers, and which offer EU processing, are confirmed provider-by-provider in the DPA annex — worth a final check there before launch.10 · How long we keep it
We keep personal information only as long as we need it, then delete or anonymise it. In practice, retention is set per type of data and per purpose, and where more than one rule could apply, the strictest governs. A few specifics:
- Account & workspace data — kept while your workspace is active. A free workspace that goes idle is automatically paused after 60 days, and inactive data is cleaned up on a defined schedule.
- Enquiries & marketing — until you unsubscribe or ask us to stop, and a reasonable period after.
- Billing & legal records — for the period required by law (typically several years for tax).
- On erasure — when you ask us to delete your personal information, we do. Where that information sat inside a sealed, reproducible financial record, we remove the personal details but keep a de-identified aggregate, so the historical record still reconciles without identifying you.
- Anonymised benchmark aggregates — retained in non-identifying form; because they can't be traced to you, they aren't deleted when an account closes.
11 · Your rights
Depending on where you live, you have rights over your personal information. For people in the EU/UK, these include the right to access your data, correct it, delete it, restrict or object to processing, request portability, and withdraw consent. You can also complain to your data protection authority.
For California residents, the CCPA/CPRA gives you the right to know what we collect, to delete it, to correct it, and to opt out of "sale" or "sharing" of personal information — we do not sell your personal information. We won't discriminate against you for exercising these rights.
To exercise any of these, email privacy@beaconrevenue.io. We'll verify your request and respond within the time the law allows.
12 · Security
We protect personal information with technical and organisational measures appropriate to the risk. A few things are structural to how Beacon is built: we never hold your source-system credentials — you connect each system in its own login screen and can revoke access there at any time; Beacon is read-first and writes back only with a person's approval; and access to data is scoped by role, with sensitive data an explicit, separate grant. Our full posture is described in our Security statement.
Not yet speccedEncryption specifics (in transit / at rest) and certification status (SOC 2 / ISO 27001) — the CTO brief intentionally leaves these blank pending verified facts. State current status only, no forward-looking claims; assume none-yet unless confirmed.13 · Children
Beacon is a business product and is not directed to children. We don't knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we'll delete it.
14 · Changes & contact
We may update this notice as Beacon evolves or the law changes. We'll post the new version here with an updated date, and for material changes we'll give you reasonable notice. For any question about this notice or your data, contact privacy@beaconrevenue.io.