Your firm’s client data
serves your firm’s clients.
Simbo does not sell personal or financial data, share it for third-party advertising, or combine client data across firms for commercial aggregation or benchmarking.
1. Who this policy covers
Simbo IP LLC ("Simbo," "we," or "us") provides financial software to asset managers and advisory firms. This policy describes our public website and our handling of information when providing the Simbo platform. A firm’s own privacy notice also governs its advisory relationship and the instructions it gives Simbo.
For firm-managed client records, the firm decides why and how those records are used, and Simbo processes them to provide the contracted software service. Simbo handles its own business inquiries, support communications, and website operations for those limited purposes.
For example: if The Invictus Collective uses Simbo, information about its clients belongs in that firm’s workspace. It is made available to Invictus’s authorized team and, where enabled, the individual clients entitled to see it. It is not made available to other Simbo customer firms.
2. Information we handle
The information in a firm’s deployment depends on the modules it enables and what the firm and its users provide. Categories may include:
- Identity and contact details
- Names, email addresses, phone numbers, mailing addresses, household and entity relationships, user identifiers, and account access information supplied by you or your firm.
- Financial records
- Assets, liabilities, accounts, ownership, dated valuations, income or other financial details entered or imported by your firm or an authorized user.
- Documents and communications
- Advisory agreements, uploaded files, reports, meeting requests, and communications or support information you choose to provide.
- Operational and security information
- Authentication and record-change events, permissions, and technical diagnostics needed to operate the service. Hosting systems may process IP addresses, requested paths, timestamps, and browser or device information when handling requests.
We receive information directly from users, from the firm managing their relationship, and from integrations that the firm authorizes. This public website does not connect to a firm’s private financial database.
3. How information is used
We use information to deliver the software functions requested by your firm: organizing financial records, presenting authorized views, managing documents and workflows, authenticating users, protecting access, resolving support requests, and maintaining the service. We may also preserve records or respond to valid legal obligations.
When you contact Simbo about the product, we use the information you voluntarily send to respond to that inquiry. We do not use firm-managed client financial records to advertise to individuals or build profiles for data brokers.
5. Retention and deletion
Firm-managed records are retained according to the firm’s documented retention schedule, service agreement, and applicable legal requirements. Earlier versions of compliance-managed records may be retained to support recordkeeping. Retention varies by record type and legal obligation; we do not promise that all financial records can be erased immediately.
For Simbo’s own inquiry, support, and operational information, retention is limited to what is necessary for the relevant purpose, resolving issues, security, and legal obligations. Deployment-specific retention periods and backup removal schedules must be set by the operator and can be requested through the privacy contact.
When deletion is appropriate, information is deleted or rendered inaccessible through the applicable process. Backups may retain a copy until the backup schedule expires; any legally retained records remain restricted to their permitted purpose. We explain any applicable retention exception and the expected completion timing when responding to a verified request.
Deleting an account, disabling access, and deleting regulated financial records are different actions. Account deletion removes the account and associated information that does not need to be retained; deactivation alone is not deletion. Uninstalling an app does not delete server-side records.
6. Access, correction, export, and your choices
You may request access to, correction of, export of, or deletion of your personal information, subject to applicable law and the firm’s recordkeeping obligations. You may also withdraw permission for optional processing. Withdrawal does not change processing already lawfully completed or information that must be retained.
For information managed by your advisory firm, contact that firm first so it can verify your request and identify the relevant records. You may also contact Simbo using the details below; we will coordinate with the responsible firm as appropriate. We may need to verify identity and authority before disclosing or changing information.
Depending on your jurisdiction, additional rights may apply, including restriction, objection, appeal of a decision, or a complaint to the relevant privacy authority. Requests will be handled within applicable legal timelines. We do not discriminate against people for exercising applicable privacy rights.
Manage your privacy choices7. Website, cookies, and planned mobile access
This public website serves its scripts, styles, and brand images from the same site. It sets no application cookies, uses no analytics or advertising scripts, and writes nothing to browser storage. The hosting provider may keep technical request logs for operations and security. Email links open your own email application; information is sent only when you choose to send an email.
Authenticated Simbo applications may use necessary session cookies and account preferences. Their enabled features and data processing must be described in the firm’s deployment notice. The public website’s cookie behavior does not describe every client application.
Simbo Mobile is in development. It connects to an approved firm’s Simbo Core client portal using an existing external-user account. Sign-in opens the firm’s authentication pages in the system browser, then the app uses session tokens to request the user’s authorized records. It does not create an independent Simbo advisory account.
The mobile app handles the identity, financial records, documents, preferences, and service requests needed for enabled portal features. A refresh credential is stored in the device’s protected credential storage; access tokens are held in app memory. Device biometrics or the device passcode can authorize unlocking that credential. Simbo does not receive your Face ID template, fingerprint template, or device passcode.
Local storage holds unlock-related preferences. Financial information is displayed in the app while you use it. Opening or sharing a document creates a temporary file, with the current implementation attempting to remove that file after sharing. A recipient or app you choose in the device’s share sheet receives the file you select under its own practices.
Signing out requests revocation of the mobile session and clears saved credentials; it does not delete your firm-managed account or financial records. The app’s Hide values preference conceals displayed amounts, and its email preferences control supported firm communications; neither deletes server-side information. Device permissions can be managed through device settings.
The reviewed mobile source includes no advertising or third-party analytics SDK in its direct dependency list. Its release build, dependency tree, backend integrations, and privacy disclosures must be checked before launch. This policy does not claim that an unreleased app collects no data or has received App Store approval.
8. Safeguards and security incidents
Core includes permission-controlled staff access, identity-scoped portal records, portal two-factor authentication, and version history for compliance-managed records. Operating safeguards also depend on the deployment’s hosting, transport security, storage configuration, monitoring, backup, and access procedures.
If an incident affects personal information, Simbo will coordinate with the responsible firm under the service arrangements and applicable law. The responsible parties must evaluate any required notifications and deliver them within the applicable legal deadlines. No transmission or storage system can guarantee absolute security.
These features support compliance processes. Simbo does not claim SEC approval or certification, and this policy does not replace a regulated firm’s required privacy notices or safeguards program.
9. Children, locations, and policy changes
Simbo is intended for asset management firms and their authorized users, and is not directed to children under 13. A firm may lawfully maintain records about minors as part of a household or account relationship; that does not authorize independent use of those records by Simbo. Contact us if you believe information was collected improperly.
Processing locations depend on the firm’s deployment and its service providers. Your firm or the privacy contact can explain the applicable hosting regions and any cross-border arrangements. Where required, appropriate legal transfer protections must be in place.
We will post changes here and update the effective date. Material changes will be communicated as required. A change to this policy does not by itself authorize a new use of information that requires consent.
10. Contact us about privacy
Operator: Simbo IP LLC.
For privacy questions, access requests, correction, export, consent withdrawal, or deletion, email info@simboip.com. Include your name, the firm associated with your account, and the type of request. Do not email passwords, full account numbers, or identity documents unless a secure verification method is arranged.
Account and product support ↗