Privacy Policy

How Stance 351, a service of Stance Capital LLC, handles information about you and about the clients whose portfolios you bring to it.

Last updated
September 9, 2026
Effective
September 9, 2026

1. Scope

This policy describes how Stance 351, a service of Stance Capital LLC, handles information. It covers two categories that should not be conflated: information about you, the investment professional using the Platform, and information about your clients that you enter or upload.

Stance Capital LLC also maintains a separate privacy notice for its advisory clients, available at stancecap.com. Same firm, different relationship: that notice governs an advisory engagement, this one governs your use of the Platform. Neither replaces the other.

2. What we collect

  • Account information: your work email address, name, title, and the firm you assert an affiliation with.
  • Authentication data: password hashes (we never store passwords in readable form) and multi-factor authentication enrolment state.
  • Client and portfolio information you provide: client names and contact details, account labels, entity type, custodian, and securities holdings including quantity, cost basis, and acquisition date.
  • Documents you upload, including holdings files and any documents you place in the document vault.
  • Usage data: pages viewed, funds viewed, actions taken, and technical logs used for security and debugging.

3. If you asked to be notified about Stance 351

If you left your email address on one of our pages to hear when a tool goes live, we use it for exactly that. Where you also ticked the box asking for product news and educational material about Section 351 exchanges, we use it for that too.

We do not sell or share that address, and you can stop the emails at any time by replying to one of them or writing to privacy@stancecap.com. Leaving your address does not create an account, an advisory relationship, or any obligation on either side.

4. Client information — you are the controller

Where you upload information about your clients, you determine what is collected and why. We process that information on your behalf and under your instruction in order to provide the Platform.

We ask you not to place account numbers, Social Security numbers, or other sensitive identifiers in free-text fields such as account labels. Account labels are disclosed to an ETF issuer when you submit a contribution, and the Platform warns you at the point of entry.

The Platform provides no field for a full account number. Account labels are free text that we store as you enter them — we do not mask or transform them, which is why what you type into that field matters.

5. How we use information

We do not sell personal information. We do not use client portfolio data to trade, and we do not share it with issuers other than the one you have selected for a given contribution.

  • To operate the Platform: running diversification and eligibility tests, modelling tax deferral, and coordinating contributions.
  • To share the specific information required to execute a contribution with the ETF issuer you select — and only after you commit.
  • To send operational email: contribution deadline reminders, conversion status changes, compliance alerts, and account notices.
  • To secure the Platform: detecting unauthorised access, debugging, and maintaining audit records.

6. Access controls

Access is enforced at the database level, not only in the application. By default your clients and portfolios are visible to you alone. Sharing with colleagues requires an explicit team, and firm-wide visibility is off unless a verified firm administrator enables it.

An ETF issuer can see a portfolio only through a contribution you have committed to one of their funds, and never the underlying client record.

7. Retention and deletion

We retain information for as long as your account is active and thereafter as required to meet legal, tax, and recordkeeping obligations. Records relating to a completed contribution may need to be retained for a period defined by applicable regulation.

Firm deletion requests are processed on a grace period rather than immediately, so that an accidental or unauthorised request can be reversed. Within that window the request can be cancelled; after it, account and client records are deleted from the live database, and remaining copies age out of encrypted backups on the retention cycle of our hosting provider.

Two things survive a deletion request, and only these: records we are required to keep by law or regulation — including records relating to a completed contribution — and security and audit logs, which are retained for a limited period and are not used to reconstruct deleted client data. Where you are subject to your own recordkeeping obligations as an adviser, meeting them remains your responsibility; deleting data here does not satisfy them for you.

8. Service providers

We use third-party providers to operate the Platform. Each processes information only as needed to provide its service to us, and none is permitted to use it for its own purposes. These providers may process information in the United States. If we add or replace a provider that handles personal information, this list changes with it.

  • Supabase — database, authentication, file storage, and server-side functions. This is where account, client, portfolio, and document data lives.
  • Netlify — application hosting and delivery of the web interface.
  • Resend — delivery of transactional and notification email.
  • Sentry — error and performance monitoring. Personal identifiers are deliberately left out of the reports our code sends, and the SDK is not configured to attach cookies or IP addresses; an error message can still incidentally contain data from the request that caused it.

9. Your rights

Depending on your jurisdiction you may have rights to access, correct, export, or delete personal information about you. Requests concerning your own account can be sent to privacy@stancecap.com.

Requests concerning an individual whose information you uploaded as a client should come to you first, as the party that determined what was collected; we will support you in responding.

10. Contact

Privacy questions: privacy@stancecap.com. Security concerns, including suspected unauthorised access: security@stancecap.com.

Stance 351 is a service of Stance Capital LLC, an investment adviser registered with the SEC; registration does not imply any level of skill or training. Nothing here is investment, tax or legal advice, or a recommendation to buy, sell or hold any security. Stance 351 reports whether a basket passes the tests it implements, on the data you supply. It does not determine whether a transaction qualifies under Section 351; that is a conclusion for your own tax counsel. A Section 351 exchange defers tax, it does not eliminate it. For advisory services, Form ADV, and firm disclosures, see stancecap.com.