Privacy Policy
Last Updated: May 7, 2025
We care deeply about privacy rights and are committed to using this Privacy Policy to transparently communicate how we gather, use, and protect your nonpublic personal information and other types of personal information (“Personal Information”).
If you have any questions or concerns about this Privacy Policy or your Personal Information, you can always email us at support@vested.co.
Introduction
This Privacy Policy explains how Vested, Inc., Vested Securities, LLC, and our affiliates (“Vested”, “we”, “us” and/or “our”) handle Personal Information that we collect in connection with individuals who visit our website, vested.co (the “Site”); access our products and services (together with the Site, the “Services”); use or evaluate our Site and/or Services; and otherwise engage in business with Vested (collectively, “Users”, “you” and/or “your”).
Our Privacy Policy and Terms of Service collectively govern your use of our Services. By proceeding as a User, you agree to be bound by them.
Please read these documents carefully. If any aspect of this Privacy Policy or the Terms of Service is unacceptable to you, please do not use the Services and do not provide your Personal Information.
Information Collection
We obtain Personal Information about you from various sources described below, including directly from you, automatically, or from others. We collect Personal Information in order to offer Services that you have requested; that we have a legitimate interest to believe are of interest to you; to manage the relationship we have with you and our partners; and to perform other activities based on your consent. You may choose not to provide Personal Information to us; however, this will prevent us from being able to offer the full range of Services to you.
Information You Provide and How Long We Keep It
You may provide us with Personal Information in a number of ways while using the Services, such as when you create your account, enter your profile information, fill out forms, or send us documents. Personal Information you may provide includes:
- Profile information, including your username, password, settings, and preferences (life of account + 7 yrs).
- Contact information, including your name, address, telephone number, email address, professional title, company affiliation, age, and other information confirming your identity that may be requested and/or required for the provision of the Services and/or legal or regulatory compliance (life of account + 7 yrs).
- Sensitive personal information, including your driver's license, social security number, bank account, and routing numbers (used only for KYC/AML, payments, and security) (life of account + 7 yrs).
- Payment information, including your Service-related billing information and transaction history, bank account information, and credit card information (life of account + 7 yrs).
- Financial information, including income information, net worth, credit information, tax information, equity information, external account information (including holdings and trading activity), and other financial information that may be requested and/or required for the provision of the Services and/or legal or regulatory compliance (life of account + 7 yrs).
- Communications, including information you provide when you contact us by telephone or email, receive customer support, or otherwise communicate with us (7 yrs after last interaction).
- Internet/device data, including cookies, IP, device ID, usage logs (24 mos).
- Other information that you choose to provide but is not specifically listed here, which we will use as described in this Privacy Policy or as otherwise disclosed at the time of collection.
Information Collected Automatically
We also collect Personal Information automatically in the course of your use of the Services. This helps us provide a smooth and personalized experience while using the Services. Personal Information we may collect automatically includes:
- Device data, including your desktop or mobile device’s operating system and version number, manufacturer and model, web browser type, IP address, language and regional settings, screen resolution, unique identifiers, and general geographic information.
- Usage data, including your interactions with the Services such as pages or screens you view, activity on a page or screen, amount of time spent on a page or screen, navigation paths between pages or screens, access times, and duration of access.
- Cookies and pixels, which enable us to uniquely identify Users and store associated settings and preferences, resulting in more efficiency and functionality in your use of the Services.
- Web beacons, pixel tags, or clear GIFs, which are small files that further help us review your use of the Services, including by indicating that a website was accessed or an email was opened.
- JavaScript libraries, which are snippets of code that execute when certain actions take place.
- Analytics, which record information regarding you and your activity with respect to the Services. This may include tools such as Google Analytics, Adobe Analytics, Nielsen, and comScore. You can opt out of these specific tools at the following links:
- Google Analytics: https://tools.google.com/dlpage/gaoptout?hl=en
- Adobe Analytics: https://www.d1.sc.omtrdc.net/optout.html
- Nielsen: https://www.nielsen-online.com/about_privacy.jsp
- comScore: https://www.scorecardresearch.com/privacy.aspx
Information from Third Parties
We also collect Personal Information from third parties to help fill out our picture of you the User. This includes third parties you directly authorize us to access and other information we access in the course of our business.
In your use of the Services, you may choose to enable features that pull information from accounts at other third-party businesses. In doing so, you may provide your username and password for, or otherwise grant access to, third-party websites and services. When you do so, Vested retrieves the account information maintained by the third-party business with which you have an existing relationship (“Third-Party Business Information”). By linking your accounts, you provide us with continuous access to the Third-Party Business Information, which may include account holdings and other financial information available to you. Portions of this information may be displayed on your Vested dashboard. We may use the Third-Party Business Information for any of the purposes described in the following section, entitled “Information Use.” By choosing to use our Services to access and review the Third-Party Business Information, you expressly authorize and direct Vested, on your behalf, to electronically retrieve all Third-Party Business Information associated with or available via the username and password that you use to link the account.
In addition, we may obtain Personal Information from sources such as other Users, social media platforms, other websites, and other third-party sources and use such information in conjunction with Personal Information you provide to us. For example, we may request Personal Information on your behalf from credit bureaus such as TransUnion, Experian, and Equifax.
Information from Prospective Employees
When you apply for an employment opportunity with Vested, you may provide Personal Information that may include information recorded on a resume, CV, or employment application form. Your provision of such Personal Information is voluntary; however, if you choose not to provide such information, it may affect whether we consider you for employment, unless our receipt of such information is prohibited by law.
Information Transfer
We store and process Personal Information primarily in the United States. When a service provider, contractor, or affiliate located outside the U.S. needs access, we protect the data with an approved cross-border mechanism—typically the EU Standard Contractual Clauses (2021/914, Modules 2 and 3) for EEA/Swiss data, the UK International Data Transfer Addendum for UK data, or another legally recognized safeguard such as an adequacy decision. You can request a copy of the relevant transfer terms by emailing support@vested.co.
Information Use
We use Personal Information we collect, as described in the previous section, throughout the operation of our Services, including providing the Services themselves, communicating with you, and improving the Services. More specifically, we use your Personal Information for the following purposes, and on the following basis:
- Providing the Services, including providing, operating, improving, enhancing, and personalizing the Services [Contract / Legitimate Interests]
- Communicating with you about the Services, including by sending you Service announcements, technical notices, updates, security alerts, and support and administrative messages [Contract / Legitimate Interests]
- Processing financial transactions, including payments and credit verifications [Contract / Legal Obligation]
- Research and analytics, including understanding and analyzing how you use the Services, improving the Services and our business, and developing other products and services [Legitimate Interests]
- Market Research, including understanding trends in the market for the Services and transacting therein [Legitimate Interests]
- Marketing, including marketing and advertising purposes (as permitted by applicable law), such as contacting you about our Services and providing you with promotional materials that may be useful, relevant, valuable, or otherwise of interest to you. We may also send you information about topics or content that may interest you or updates about new features of the Services. When marketing involves GLBA-protected information we provide the opt-out required by 12 CFR § 1016.7 [Contract / Legitimate Interests; consent where required]
- Legal compliance, including compliance with federal, state, and other laws and regulations; responding to lawful requests and legal process; protecting the rights, property, or safety of us or any other person; enforcing our Terms of Service; auditing our internal processes for compliance with legal and contractual requirements and internal policies; and protecting, investigating, and deterring against any fraudulent, harmful, unauthorized, or illegal activity, including cyberattacks and identity theft [Legal Obligation / Legitimate Interests]
- Other purposes, with your consent. There may be other uses of your Personal Information, for which we would ask for your consent to collect, use, or share your Personal Information [Consent]
Information Sharing and Disclosure
We collect your Personal Information in order to better run our Services; not to send it out to the world. Therefore, we will not share Personal Information you provide to us with unrelated third parties except for the following:
- Service providers. We may share Personal Information with non-affiliated third parties that help us provide the Services, such as vendors who assist with business and technology functions, our payment processing service, data analytics service providers, and email delivery, marketing and advertising, research, and customer service support. These providers are bound by contract to process Personal Information only on our instructions and to apply equivalent security controls.
- Affiliates. We may disclose Personal information among affiliated Vested entities in the ordinary course of business and for purposes of providing the Services.
- Professional advisors. We may disclose Personal Information to professional advisors, including lawyers, bankers, auditors, and insurers, as necessary for the provision of professional services they render to us.
- Legal compliance and protection. We may disclose Personal Information in the following scenarios: (i) if we are required to do so by law, regulation, or legal process, such as a court order or subpoena; (ii) to prosecute or defend legal claims; (iii) in response to requests by government agencies such as law enforcement authorities; (iv) when we believe disclosure is necessary or appropriate to protect against or respond to physical, financial, or other harm, injury, or loss to property; or (v) in connection with any legal investigation.
- Business transfers. In the event of a merger, acquisition, financial due diligence, reorganization, bankruptcy, receivership, purchase or sale of assets, or transition of service to another provider, we may transfer your Personal Information as part of such a transaction, as permitted by contract and/or law.
Note for Vermont residents: we will not share your nonpublic Personal Information with non-affiliated third parties without your consent, except as permitted by law.
Note for all Users: We do not and will not sell your Personal Information.
Your Information Rights
We provide you with various rights and options with respect to your Personal Information. Upon request, you may exercise certain rights as described below:
- Access your Personal Information, which includes the right to obtain confirmation from us regarding whether Personal Information concerning you is being processed, and where that is the case, access to the data and information related to how it is processed.
- Update or Correct your Personal Information by accessing your account or emailing us at support@vested.co.
- Delete your Personal Information by sending a request to support@vested.co with your name, email address, and phone number.
- Opt out of marketing communications by logging in and changing your account settings or by following the opt-out prompt in the email. You may continue to receive Service-related and other non-marketing emails.
- Do Not Track. Some Internet browsers may be configured to send “Do Not Track” signals to the online services that you visit. We currently do not respond to “Do Not Track” or similar signals. However, we do not knowingly track your activities across different websites or online services. Nevada residents: Under Nevada law (NRS 603A.340) you may submit a verified request that we not sell your “covered information.” Because Vested does not sell personal data, we nevertheless honor such requests at support@vested.co.
Retention
We retain Personal Information we receive in accordance with this Privacy Policy for the longer of the following: the duration of your use of the Services; or, as necessary to fulfill the purpose(s) for which it was collected, to provide the Services, resolve disputes, respond to a legal or regulatory inquiry, establish legal defenses, conduct audits, enforce our agreements, for legitimate business purposes, or as otherwise required to comply with existing contracts, laws, or regulations. Example schedule: transaction data – 7 yrs; marketing contact data – 3 yrs after last interaction.
For Residents of the EEA, UK, and Switzerland
In addition to the rights above, the EU General Data Protection Regulation (“GDPR”) and other applicable laws provide you with additional rights regarding your Personal Information, including:
- Transferring, including the right to data portability by easily transferring your Personal Information to a third party.
- Objecting to the processing of your Personal Information under certain circumstances, including with respect to direct marketing purposes or our reliance on our legitimate interests as the basis of the processing.
- Restricting us from continuing to process your Personal Information under certain circumstances, including a period during which we verify your Personal Information in response to your challenge to its accuracy.
- Withdrawing consent you may have given for processing your Personal information, which you can do at any time on a go-forward basis.
- Complaints concerning how your Personal Information is being processed, which you can submit to the data protection regulator in your jurisdiction. You can find your data protection regulator at this link: https://edpb.europa.eu/about-edpb/board/members_en.
- Deleting your Personal Information, with exceptions for certain circumstances.
For Residents of California
In addition to the rights above, the California Consumer Privacy Act (“CCPA”) and other applicable laws provide you with the additional rights below with respect to your Personal Information. However, these rights are not absolute, and in certain cases, we may decline your request, as permitted by law.
- Information. You have the right to request that we disclose to you Personal Information we have collected, used, or disclosed about you in the past 12 months. You may also request the categories of Personal Information we have collected about you, along with the purpose for doing so; the categories of sources of that data; and the categories of third parties with whom we shared it for a business purpose and our purposes for doing so.
- Deletion. You have the right to request the deletion of your Personal Information.
- Non-Discrimination. We will not discriminate against you for exercising any of your rights under the CCPA or applicable law.
- Opt out of sale. The CCPA uses a broad definition of “sale.” While we do not believe the definition applies to our use of Personal Information, to the extent “sale” may encompass internet-based advertising or other data uses described in the section entitled “Information Collected Automatically,” we will comply with all applicable law as to those activities. To opt out of receiving interest-based advertising, please contact us at support@vested.co.
Security
The security of your Personal Information is extremely important to us. We therefore take a number of organizational, technical, and physical measures designed to protect your Personal Information from loss, misuse, unauthorized access, alteration, disclosure, or destruction. Consistent with the NY SHIELD Act we maintain (a) administrative safeguards (policies, workforce training); (b) technical safeguards (encryption at rest/in transit, MFA, penetration testing); and (c) physical safeguards (access controls, secure hardware disposal). However, no safeguards are completely secure or error-free, so we cannot guarantee the security of your Personal Information.
Children
Our Services are not directed at, and we do not knowingly collect, maintain, or use Personal Information from, children under the age of 18. If you learn that your child under the age of 18 has provided us with Personal Information without your consent, you should contact us at support@vested.co so that we may delete such information. If we otherwise learn that any user of the Services is an individual under the age of 18, we will take appropriate steps to delete that individual's information.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time based on changes to applicable laws and regulations, changes in technology, or changes to our business. Material changes will be posted at least 30 days before they take effect and will be dated “Last Updated” at the top of this page; your continued relationship with Vested after that date constitutes acceptance of those changes.
Notwithstanding the foregoing, if a change is required by law or to address a security incident, we may make it effective immediately, in which case we will notify you as soon as practicable.
Questions and Contacting Us
If you have any questions or concerns about this Privacy Policy, would like to exercise any rights in relation to your Personal Information, or have any questions or privacy concerns, please contact us by email at support@vested.co, by phone at (347) 353-8592, or via physical mail at:
Vested, Inc.
1304 Chenille Cir
Weston, FL 33327
United States
Vested, Inc. is the data controller for the processing of your Personal Information.