Rising Tide Management LLP Effective 2 September 2026 Version 2026-09-02

Privacy Policy

This policy explains how Rising Tide Management LLP ("Rising Tide", "we", "us") collects, uses, shares, and protects personal information when you visit our websites at arisingtide.management and rtfrm.arisingtide.management, or use the Rising Tide Investor Portal at portal.arisingtide.management (the "Portal"), including when you sign in with Google or connect a Google Calendar. Use of the Portal is also governed by our Terms of Service.

1Information we collect

Information you give us

  • Contact and account details: your name, email address, company, company website, title, company stage, and the contents of messages you send us or forms you submit (for example, requesting information about a product or joining a waitlist).
  • Portal profile and content: profile information, fundraising details, investor and company records you create, documents you upload to a data room, and the outreach you draft or send through the Portal.
  • Eligibility and support records: accreditation self-certifications and any supporting documents you upload, and the details, screenshots, and contact information you include when reporting a problem.
  • Scheduling settings: the weekly availability windows, time zone, and notice periods you set for your booking links.
  • Booking details: if you book a meeting through a founder's scheduling link, the name, email address, and notes you enter. If someone books a meeting with you, we receive their details on your behalf.

Information we receive from Google

The Portal offers two optional Google integrations for users. Each asks for your permission on Google's consent screen, requests only the permissions listed below, and can be disconnected at any time. Separately, and outside any consent screen you will see, Rising Tide's own staff connect their Rising Tide Google Workspace accounts to our internal customer-relationship system; that is described under "Our own team's records" below, and the commitments in section 3 apply to it as well.

IntegrationGoogle permissionsWhat we receive and why
Sign in with Google openid, userinfo.email, userinfo.profile Your Google account email address, name, profile picture, and a Google account identifier, used solely to verify who you are and create your Portal session. Sign-in is handled by our authentication provider, Supabase; we do not receive or store Google API tokens through sign-in, and we never see your Google password. Sign-in is available only to accounts that already have Portal access or that complete our founder sign-up flow.
Google Calendar connection (founders, optional) openid, userinfo.email, calendar.freebusy, calendar.calendarlist.readonly, calendar.events The list of calendars you own (so your availability accounts for all of them) and your free/busy times, used only to compute available slots at the moment someone views your booking page. Your email address identifies the connected account. When a meeting is booked we create the event on your primary calendar with a Google Meet link, add the booker as an attendee, and later update or cancel that event if the booking changes. We do not import, store, or read the contents of your other calendar events.

To keep a calendar connection working we store a Google refresh token for your account, encrypted at rest. Free/busy information is queried live and is not retained after your availability has been computed. The events we create for confirmed bookings are also recorded in the Portal so both parties can see and manage them.

Information collected automatically

  • Portal security and audit records: sign-ins (including the method used), document and data-room access, and similar events, together with IP address and browser details (data-room visits record a salted hash of the IP address rather than the address itself), kept to secure the service and to meet our obligations to investors.
  • Website analytics and cookies: our marketing websites use Google Analytics, the LinkedIn Insight Tag, Apollo's website tracker, and Snitcher Radar to understand traffic and which companies visit. These tools set cookies and collect device, browser, and usage information. The Portal itself sets no analytics cookies; it uses only the cookies needed to operate the service (your sign-in session, data-room access, and short-lived sign-up and connection flow markers).
  • Our own team's records: Rising Tide staff connect their own Rising Tide Google Workspace accounts to our internal customer-relationship system (an internal Google integration with read-only access to our staff's mail and calendars). If you correspond or meet with our team, the emails you exchange with us (sender, recipients, subject, and message text) and the details of meetings with us (title, description, location, meeting link, time, and attendees) may be recorded against your record in that system. Messages our staff mark private are excluded before syncing. These records are retained for as long as the related customer record exists.

2How we use information

  • To provide, operate, and secure the websites and the Portal, including authenticating you and maintaining your session.
  • To run scheduling: compute your availability, create and manage booked meetings, and send calendar invitations and confirmation emails.
  • To respond to your enquiries, evaluate eligibility for our products, and communicate about products and services you have asked about.
  • To meet legal, regulatory, and contractual obligations, including investor-eligibility and record-keeping requirements.
  • To detect, investigate, and prevent fraud, abuse, and security incidents.
  • To understand how our websites are used and improve them.

We do not sell personal information, and we do not use it for third-party advertising.

3How we handle Google user data

Rising Tide's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

This applies to every Google integration we operate, including the internal Workspace sync of our own staff accounts. Information we receive from Google is used only to provide and improve the features described in this policy. We do not:

  • sell Google user data, or use it for advertising, retargeting, or credit decisions;
  • use Google user data to develop, improve, or train generalized artificial-intelligence or machine-learning models;
  • transfer Google user data to third parties except as needed to provide the feature (for example, sending a calendar invitation to the person you are meeting), for security purposes, to comply with law, or as part of a merger or acquisition with notice to you;
  • allow humans to read Google user data, except with your explicit permission, where necessary for security or to comply with law, or where the data has been aggregated and anonymized.

Revoking access. You can disconnect Google Calendar from the Scheduling page of the Portal, which deletes the stored refresh token and asks Google to revoke our access, or remove Rising Tide's access at any time from your Google Account permissions. Sign-in with Google can be replaced at any time by password or email-link sign-in; your Portal account and its email address exist independently of Google.

4AI features

Some Portal features, including the Marina introduction engine, use large language models provided by Anthropic to read the fundraising materials you choose to place in your data room, suggest investors, and draft outreach in your voice for you to review before it is sent. Inputs to these features are the materials you place in your data room, emails sent to Rising Tide's dedicated introduction mailbox, and problem-report text; content sent for processing is handled under Anthropic's commercial API terms, which do not permit use of that content to train their models. Google sign-in data, Google Calendar data, and mail or calendar records synced from our staff's Workspace accounts are never used as inputs to these features.

5How we share information

We share personal information only as described here:

  • Service providers that process data on our behalf under contract: Supabase (database, authentication, and file storage, hosted in the United States), Netlify (hosting), Resend (outbound and inbound email), Google (authentication, Calendar, and our internal Workspace integration), Anthropic (AI features), Apollo (contact and company enrichment for the Portal's investor directory, sales engagement, and the visitor tracker on our marketing websites), GitHub (problem reports are filed as issues for our engineers), and, on the marketing websites only, Google Analytics, LinkedIn, and Snitcher.
  • People you interact with: when you book a meeting, your details are shared with the founder you are meeting; when a founder shares a data room or scheduling link, the information they choose to include is visible to the recipients they authorize. Founder contact details are shared with other members of the Rising Tide founder network only when you opt in.
  • Professional advisers and authorities where required to comply with law, regulation, legal process, or to protect the rights, property, or safety of Rising Tide, our users, or others.
  • Business transfers in connection with a merger, acquisition, financing, or sale of assets, in which case we will notify you.

6Data retention

We keep personal information for as long as your account is active or as needed to provide the services, and afterwards for as long as required to meet legal, regulatory, accounting, and record-keeping obligations or to resolve disputes. Google refresh tokens are deleted when you disconnect or revoke access. Free/busy information is not retained. Booking records and the calendar events created for them are kept as part of your scheduling history. Emails and meetings synced into our internal customer-relationship system from our staff's accounts are retained for as long as the related customer record exists. Security and audit logs are retained for the period needed to investigate incidents and satisfy our obligations to investors.

7Security

We protect personal information with technical and organizational safeguards, including encryption in transit (TLS), encryption of stored Google refresh tokens at rest (AES-256-GCM), row-level access controls in our database, audit logging, and optional two-factor authentication for Portal accounts. No method of transmission or storage is completely secure; if you believe your account has been compromised, contact us immediately at the address below.

8Your rights and choices

Depending on where you live, you may have the right to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to withdraw consent. You can update your Portal profile and notification preferences in the Portal, revoke Google access as described in section 3, and unsubscribe from marketing emails using the link in any message. To exercise other rights, email us at the address below; we respond within 30 days. If you are in the European Economic Area or the United Kingdom, you may also lodge a complaint with your local data-protection authority.

9International transfers

Rising Tide operates from the United States, and our service providers may process information in the United States and other countries. Where required, we rely on appropriate safeguards, such as standard contractual clauses, for transfers of personal information.

10Children

Our websites and the Portal are intended for business use by adults and are not directed to anyone under 18. We do not knowingly collect personal information from children.

11Changes to this policy

We may update this policy from time to time. We will post the revised version here with a new effective date, and, for material changes affecting Portal users, require acknowledgement before continued access.

12Governing law

Rising Tide Management LLP is a United States business, and this policy and our handling of personal information are governed by the laws of the State of Delaware and applicable United States federal law, without prejudice to any rights you have under the data-protection laws of the place where you live.

Contact. Rising Tide Management LLP, Delaware, United States. inbound@arisingtide.management