Privacy
FundStamp is operated by FiBase Inc., a Delaware corporation, which is the controller of the personal data described here. This notice describes what the software does — not what it might do — and it is written to be checked against the product rather than taken on trust.
Effective September 7, 2026.
What FundStamp collects
- Your email address, used to sign in.
- The display name you type, and the time you supplied it. FundStamp does not verify this name against anything and performs no government-ID check against any authority or database. It stores no identity document, document number or biometric data of any kind. The one case where a document is read — an equity investor showing that they are not you — is described under Your equity investor below, and nothing from it is kept.
- From connected financial institutions: institution name, account names, masked account numbers, account type, balances and holdings. The access token used to read them is revoked within the same request and never stored.
- For two-step sign-in, which is required before any account can be connected: the public half of each passkey you register and a label for the device, an authenticator-app secret held encrypted with a key kept outside the database, and hashes of your recovery codes. None of these lets anyone sign in as you from a copy of our records.
- From a statement you or your equity investor uploads: the text of the document, held only for as long as the read takes and then deleted with the job; and, kept afterwards, the figures themselves, the short excerpt each figure was quoted from, the account type and masked last four digits as printed, the holder name as printed, and the statement period. The file itself is deleted with the job — see Files you upload below.
- What you tell us about a name on a statement, and the evidence behind it. If a statement is in the name of a company or a trust, FundStamp asks how you connect to it and stores your answer, the public-record link you give, and any document you provide. FundStamp opens the link you supply and reads the page, and a short summary of what that page said is stored and shown next to your own answer. Only the page at the address you give is read; nothing is submitted to it, and no address that is not reachable from the public internet is opened. What that record says decides what recipients are told: money held in a company’s or a trust’s name is included in your figure, and the row says whether what FundStamp read names you in a role connecting you to it, or only that you said so. FundStamp’s own explanation of why the money was or was not included is shown to recipients alongside what you stated. A document you provide as evidence is read and deleted in the same request unless you tick the box asking us to let recipients download it.
- A letter about your funds that you upload. A lender or investor support letter, a bank or brokerage attestation, an adviser’s letter about an account’s value: the document itself is kept rather than destroyed, because the people you send your verification to can download it, which is why you supplied it. FundStamp also keeps the figure read from it and the sentence that figure appears in. A bank or brokerage statement is not a letter and is not kept this way — it is deleted with the job unless you separately ask us to keep it. See Files you upload below for the full rule and for when each is deleted.
- The computed figures and the timestamp they were computed at.
- Your answers about your own accounts. An institution reports an account’s type and nothing more, and several types do not settle whether the money can fund a purchase — so FundStamp asks you, one question per account, and stores what you say. Those answers can include whether you have left an employer, whether you are 59½ or older, whether an account was inherited, and how much of a plan is vested. They are used to work out what counts and for nothing else, and they are deleted with the account they are about.
- The email address of a lender or equity investor you ask to confirm something. Used once, to send them the request, and never shown to anybody. The part after the @ is a different matter: it is shown to your recipients, because where a confirmation came from is the fact they can weigh. See What recipients see.
- What your equity investor tells us about their own money. If they connect an institution or upload a statement, the same figures and answers listed above are kept — including, where they hold retirement accounts, their answers about whether they have left an employer, whether they are 59½ or older, and how much of a plan has vested. Their balances are frozen onto the one confirmation they gave and are never linked to your own accounts.
- A record that your equity investor agreed to connect, and a single-use code. Where they use a bank connection, FundStamp records their consent against that one confirmation and emails them a short code to enter first. The code is stored only as a hash, expires in ten minutes, and is destroyed when used.
- If you write to support: your message and the page you were on when you sent it.
- A one-way keyed digest of each connected account, derived from the institution and the masked last four digits. It exists so the same account cannot back verifications for two different people. It contains no account number, cannot be reversed, and is deleted with your account.
- For each verification page load: an opaque browser identifier, the user agent, and whether the load looked like a person rather than a crawler. Nothing is limited by this count; it exists so the account holder can see whether their link has been opened.
- A record of your authorization to retrieve financial data: the version of the wording you agreed to, when, your browser, and a truncated network prefix (the first three groups of your address, not the address itself).
Your equity investor, if you ask one to show who they are
You may ask an equity investor to show that they are a different person from you — optional, required, or not asked at all, and it is your choice per investor. If you ask, they upload the document themselves and you never see it. That is deliberate: a check where the buyer supplies both sides is not a check.
Anything with their name on it works — a utility bill, a statement, a letter. FundStamp reads it inside the request, compares it against the name on your page, and deletes the file before the request finishes. It is never stored, never shown to anybody, and no model is asked to interpret it.
What is kept is one fact: whether your name was absent from their document. Not their name, not their address, not the document’s text, and not an image of it. If they chose to remain confidential, your recipients are told only that the check was satisfied; if they agreed to be named, their name appears because they agreed to it.
What FundStamp never collects
- Institution usernames or passwords.
- Identity document images, document numbers, selfies, or biometric templates. None is stored. No government-ID check is performed against any authority or database, and the single case where a document is read at all — an equity investor showing they are not you — keeps nothing but a yes or no. See above.
- Full account numbers.
What recipients see
Recipients see the display name you supplied — labeled as supplied by you and not verified — the verification statuses, when your balances were read, and either your verified total or a threshold you chose.
They are also told where each balance came from. A page built from connected institutions names the data provider and says the name on it is yours to supply. A page built from statements you uploaded says so, gives the span of dates printed on those statements rather than one date for the page, and says whether the name printed on them matches the name on the page. A page built from both says what is true of each, because one sentence covering both would have to understate the stronger half.
If you share your total, they also see a breakdown: one line per account. Each line gives the type of account, the institution holding it, the last four digits of the account number, and the amount counted from it — grouped by when that money becomes available. Where an account came from a statement in a company’s or a trust’s name, what you told us about how you connect to it travels with the line. The same lines can be downloaded as a spreadsheet. Where an account was left out, or is waiting on a question, the note explaining what to ask you for travels with it.
Where a confirmation came from, they see the domain and never the address. A lender or equity investor who confirms something for you is shown to your recipients as having answered from an address at, for example, firstcoastal.test — or, where it was a consumer mail provider, as “a personal email address”, without naming the provider. The address itself never leaves FundStamp. Where the person asked to remain confidential, the domain is withheld too and only the kind of address is shown, because a domain identifies a firm as surely as its letterhead does.
What that means for your privacy, stated plainly. A per-account breakdown discloses more than a single figure does, and it is the price of a figure a recipient can check rather than take on trust. Full account numbers, the account’s own name at the institution, and what any account holds are never disclosed. Accounts that cannot fund a purchase are not shown at all.
If you share a threshold instead, there is no breakdown. A recipient sees only that you are at or above the figure you picked: no accounts, no institutions, no last four digits, and no total.
Your verification is not on the public web
A verification link is not indexed by search engines and is not made available to crawlers that gather text for search results or for training artificial-intelligence models. The page tells every crawler not to index it, not to keep a cached copy, not to show a snippet of it, and not to use it for training — both in the page itself and in the HTTP response, so a crawler that never reads the page still receives the instruction. Search engines are separately told that no address beginning /v/ may be visited at all, and FundStamp’s sitemap cannot list a verification.
Those are requests, and honest about being requests. What does not depend on anyone honoring them: the address of your verification contains a long random token that cannot be guessed, no page on this site or anywhere else links to it, and it is served only to somebody who already has the address. Nothing about you is discoverable by searching for your name. You can revoke a link at any moment from your dashboard, after which it shows nothing to anybody, including anyone who saved the address.
The rest of the site — the home page, the guides, the sample verification and these legal pages — is deliberately open to search engines and to assistants, because that is how people find a product like this one. Nothing on any of those pages is about a real person.
Files you upload
We do not keep the statements you upload. From a PDF we read the text out on our own servers and destroy the file before anything else happens, so the document itself never leaves them. A photo or a scan has no text to read, so the image is sent to an OCR provider named below, which returns the text; what each of those providers keeps, and for how long, is set out beside their names. Either way we hold nothing afterwards, the file is never part of what a broker sees, and it is shared with nobody else.
One exception we make ourselves. A letter about funds is the one kind of document we keep without being asked, and we keep it because sharing it is the point: the people you send your verification to can download it. That means a lender or investor support letter, and a letter from a bank, broker or adviser stating what you hold. A bank or brokerage STATEMENT is not one of these and is never kept this way. A letter goes when you delete your account, when the claim it belongs to is deleted, and if the person who wrote it withdraws.
Files you upload are processed through the APIs of Anthropic, OpenAI, Google Cloud, Mistral, and no other AI provider. As of August 28, 2026, none of them uses API inputs or outputs to train their models under the terms we operate on. Providers may change their terms after that date — you can read the current versions using the links below.
What each of them keeps, as of August 28, 2026: Anthropic deletes what it receives within 30 days, and keeps it longer only where its own systems flag a policy violation; OpenAI keeps abuse-monitoring logs for up to 30 days, then deletes them; Google Cloud keeps no copy of the image: on the synchronous endpoint this product uses, Vision processes it in memory and does not write it to disk, though Google does log the time and size of the request for a period it does not state; Mistral keeps nothing beyond returning the result: we hold Zero Data Retention on this account.
- Anthropic · terms · privacy policy
- OpenAI — used only if Anthropic is unavailable · terms · privacy policy
- Google Cloud — used only for scanned or photographed documents, and only where it is configured; where it is not, Anthropic transcribes them instead · terms · privacy policy
- Mistral — used only if Google Cloud is configured and cannot read the document · terms · privacy policy
A figure read from a statement rests on a verbatim excerpt from the file the account holder uploaded. Unless they chose to share the document itself, we do not keep that file and cannot produce it. Either way we do not assess whether it is genuine: what is established is the figure and the name printed on it.
Sharing
Financial data is shared with the service providers required to operate the product: Plaid (account connections and balances), and the hosting and database providers. It is not sold, and it is not shared with brokers, sellers or marketplaces.
We take no payment, so there is no card and no payment record. FundStamp is free to use, you are never asked for a payment method, and no card details are ever entered, held or processed on your behalf by us or by anyone acting for us.
Messages about other services
The address you give when you publish is used for two things. We send your link there, and we may write to it once about lender financing for your purchase. That sentence is on the publish screen, and the version of it you saw is recorded with the date. Nothing else is sent to it without a further choice on your part.
Today we send you nothing but service notices about your own verification — confirming a link you published, or telling you a document could not be read. FundStamp offers one service and we are not marketing anything else to you.
In future we may email you about other services that help you buy a business — identity verification, background checks on a target, lender matching, buy-side search assistance and similar. None exists today. Any such message would go to the email address you signed in with, and where a provider pays us a referral fee we would say so at the point we introduce them.
Your financial information is not used to target these messages and is never disclosed to those providers. We do not tell a lender, a background-check provider or anyone else what your verified figure is, which institutions hold your money, or that you hold any particular amount. If you ask to be introduced to a provider, what we share is what you tell us to share.
Every one of these messages carries an unsubscribe link and opting out takes effect immediately. Opting out does not stop service notices about your own verification, such as a reminder that it is about to lapse — those are about the thing you are using and you stop receiving them by deleting your account.
We do not sell your personal information, and we do not share it with brokers, sellers or marketplaces. We also do not record which broker, if any, suggested FundStamp to you — there is no referral link and no referral code, so that is not something we could disclose even if asked.
Deleting your account
You can delete your account yourself, at any time, from your dashboard. It is immediate and irreversible, not a request queued for review: your sign-in, every connected institution, every account name and balance, your capacity figures, every share link including ones already sent and your authorization record are all erased. Anonymous counts that cannot be traced back to you — how many accounts reached each step of the product — are kept.
FundStamp holds no ongoing access to your financial institutions, because each connection is closed as soon as the balances have been read, so there is nothing left at your bank to revoke. Revoking a single link stops it being viewable immediately without deleting anything else.
Retention
Data that has not been deleted by you is deleted or de-identified automatically once it is no longer needed. These periods are maximums, enforced by a scheduled job (scripts/retention.mjs) rather than described and forgotten.
- Account-level balances and holdings — the individual account names, masked numbers and balances behind your figures — are deleted after 400 days. The aggregate totals a link displays are kept for as long as the link exists.
- Recipient browser identifiers are cleared after 90 days. The record that a view occurred is kept, so you can see whether your link was opened, but it stops being about a particular browser.
- Revoked links, and everything attached to them, are deleted a year after they were switched off. Links do not expire; one you have not switched off is kept.
- A verification you started but never published is deleted seven days after you began it, together with everything you uploaded for it. Publishing is when you give us an address; until then there is nothing to reach you at and nothing to keep.
- Sign-in sessions are deleted as soon as they expire.
Recipients
Recipients do not create accounts, and are never asked for anything. A browser identifier cookie is set on verification pages solely to avoid counting the same reader more than once a day in the account holder’s own view count. It is cleared from stored records after 90 days.
Your choices
- See it. Everything FundStamp holds about you is on your dashboard and your connect screen — the figures, every connected institution, every account and what it contributed, every link and who has opened it.
- Delete it. Deleting your account from the dashboard is immediate and irreversible. Your sign-in, every connection, every balance, every figure, every link including ones already sent, the answers you gave about your accounts and the record of your authorization are all erased. Only aggregate counts with no path back to a person survive.
- Correct it. The display name is editable from the dashboard; the answers you gave about your accounts can be changed at any time and your figure follows immediately.
- Withdraw it. Revoking a link stops it disclosing anything, immediately. Removing an institution stops its balances counting towards anything new.
Depending on where you live you may have additional rights — to a copy of your data in a portable form, to object to or restrict processing, or to complain to a supervisory authority. Write to the address below and we will action it.
Children
FundStamp is for people buying businesses and is not directed at children. We do not knowingly collect personal data from anyone under 18.
Changes to this notice
The effective date at the top of this page always reflects the current version. Where a change affects what is collected or who sees it, the consent wording shown before you connect an institution is re-versioned as well, so a consent recorded under an earlier version is never treated as consent to a later one.
Contact
Questions about this notice, or about the data FundStamp holds about you:
FiBase Inc.1317 Edgewater Dr, Ste 2402Orlando, FL 32804United StatesThe fastest route is the Support link at the foot of any signed-in page. We answer within one business day.