Privacy Policy

Last updated July 9, 2026

Cendron Wealth ("we", "us") is a private wealth platform for families and the advisors they invite. Each client has its own walled-off workspace. This policy describes what information we collect, how we use it, and the choices available to users.

1. Who this applies to

This policy applies to everyone who signs in to Cendron Wealth: the owner of a workspace and the family members, advisors, accountants, and bookkeepers that owner invites. Each person can only see the workspace they belong to.

2. Information we collect

  • Account info: your email address, the workspace you belong to, and the role assigned to you (owner, family, advisor, accountant, bookkeeper).
  • Financial data you or the owner enter: entities, manual assets, valuations, notes.
  • Financial data pulled from linked providers: bank balances and transactions via Plaid, brokerage holdings and cost basis via SnapTrade, crypto holdings via CoinStats. We do not receive or store online-banking credentials — those are handled directly by Plaid/SnapTrade.
  • Operational data: sync timestamps, error logs, and basic security telemetry.

3. How we use it

Data is used solely to display a workspace's consolidated net worth, holdings, and performance to the people authorized in that workspace. We do not sell, rent, advertise against, or share this data with third parties except the service providers listed below, and only to the extent required to deliver the service.

4. Service providers (subprocessors)

  • Supabase — database, authentication, and secret storage (SOC 2 Type II).
  • Cloudflare / Lovable — hosting, TLS termination, DDoS protection.
  • Plaid — bank account aggregation.
  • SnapTrade — brokerage account aggregation.
  • CoinStats — crypto portfolio aggregation.

5. Security

All traffic uses TLS 1.2+ with HSTS. Row-level security is enforced on every database table. Provider access tokens and API secrets are stored server-side only and are not readable by application users. See our Information Security Policy.

6. Retention and deletion

See our Data Deletion & Retention Policy for how long data is kept and how to request deletion.

7. Your choices

Authorized users may disconnect any linked institution at any time from the app, which revokes the provider token and removes the linked balances on the next sync. To request full deletion of your account, contact us at the address below.

8. Contact

Questions? Email support@cendronwealth.com.