Frankly Advisors Privacy Policy
Last updated: July 16, 2026
1. Introduction
Modern X Inc., an Ontario corporation operating as "Frankly Advisors" ("Frankly," "we," "us," or "our"), operates a private business deal origination platform at franklyadvisors.com and related application surfaces (collectively, the "Platform"). Frankly is the controller of the personal information described in this policy. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you visit our websites, register a buyer account, join the paid Frankly Network, sign a non-disclosure agreement, access a data room, or otherwise interact with our services.
This policy applies to all users of the Platform: business owners ("Sellers"), prospective acquirers ("Buyers"), including paid Frankly Network members ("Members"), and M&A advisors, brokers, and intermediaries ("Advisors").
We are a Canadian organization and operate in accordance with Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA"), Quebec's Law 25 where it applies (Section 14), and applicable provincial privacy laws. Where you reside in a U.S. state with a comprehensive privacy law, the additional rights in Section 13 apply to you to the extent that law applies to us.
Voluntary-compliance note. We describe rights under several U.S. state privacy laws even though the revenue and volume thresholds of most of those laws may not apply to us today. Where a law does not legally apply to us, our description of the corresponding rights is a statement of the practices we endeavor to honor as a matter of policy, not a representation that the statute governs our processing. We honor the core access, correction, deletion, and advertising opt-out rights described here regardless.
2. Information We Collect
2.0 Notice at collection (summary)
At or before the point we collect it, we collect the categories of personal information listed below, for the purposes in Section 3, retained for the periods in Section 9. We do not sell your personal information for money. Our advertising technology may "share" limited identifiers for measurement as described in Section 4.4, which you can opt out of (Section 13). Sensitive information (government ID, financial documents, credentials) is used only to provide the services you request and for security and legal compliance.
2.1 Information you provide directly
- Contact and account information. Name, email address, phone number, company name, login credentials, and communication preferences.
- Buyer acquisition criteria ("Buybox"). Industries, locations, price range, and related preferences you save to receive matches.
- Buyer intake information. Acquisition criteria, investment capacity, financing status, and timeline submitted through intake forms.
- Identity verification documents (Members). An image of a government-issued photo ID that you upload during member activation, plus the file's technical metadata (type, size), your submission timestamps, the review outcome, and any rejection reason. Handling details are in Section 6.
- Accreditation attestation (Members). Your self-attested responses to qualification statements presented during activation.
- Proof-of-funds documents. Bank, brokerage, or lender documents you upload for listings that require proof of funds, plus review outcome and timestamps. Handling details are in Section 6.
- NDA signature records. When you sign a non-disclosure agreement on the Platform, we capture and retain the signed document (PDF and HTML snapshot), the template version, your typed signature, the signing timestamp, your IP address, and your browser user agent, as legally required evidence of execution.
- Payment information. Payments are processed by Stripe, Inc. We receive and store subscription status, plan, billing interval, billing period dates, and Stripe customer and subscription identifiers. We do not receive or store your full card number. Stripe's handling of your payment data is governed by Stripe's privacy policy.
- Communications. Messages, emails, form submissions, and other correspondence with us or with brokers through the Platform.
- Phone number and SMS consent. Your mobile number and consent preferences, when you provide them through our forms or opt-in mechanisms.
- Advisor-contributed client data. Advisors may submit information about their clients; Advisors represent they have obtained appropriate consent.
2.2 Information collected automatically
- Device and usage data. Browser type, operating system, device identifiers, IP address, pages visited, time on page, click patterns, and navigation paths.
- First-party funnel and analytics events. We assign your browser an opaque random visitor identifier (the
fk_visitor_idcookie and local storage key) and record product events such as browsing opportunities, viewing a teaser, starting registration, creating a buybox, requesting or signing an NDA, opening a data room, starting or completing checkout, and cancelling a subscription. Each event may store campaign parameters (utm_*,fbclid,gclid), the referring site (host only), and the landing page path. After you register, your earlier anonymous events from the same browser session identifier are linked to your account so we can measure where the sign-up journey succeeds or fails. - Listing and page view analytics. Anonymous view counts and traffic source classification for listings and pages.
- Data room access logs. Every successful data room access (and certain denied attempts) is logged with the email used, timestamp, IP address, and browser user agent. These logs are a core confidentiality and audit control and may be shared with the responsible broker.
- Email delivery data. Our transactional email provider (Resend) reports delivery events such as bounces and spam complaints so we can stop sending to addresses that do not want or cannot receive mail. We do not currently embed open-tracking pixels in buyer notification emails.
- General location. Approximate geographic location derived from IP address.
2.3 Information from third parties
- Business data enrichment. We use services (including AIArk and Hunter.io) and public sources to verify and supplement business contact and company information.
- Verification signals. When you sign an NDA we may run automated screening on the details you provided (for example, checking whether your email domain matches your stated company and whether public web results corroborate your name and company) to score the submission for broker review.
- Advertising platforms. Meta and Google provide us aggregate campaign performance data tied to their identifiers (see Section 4).
3. How We Use Information
We use personal information to:
- Provide the services. Operate accounts, match buyer criteria against listings platform-wide, deliver match notifications and digests, provide data room access, and facilitate confidential introductions.
- Verify member identity. Review government ID submissions to activate member verification and display the Verified Network Member badge.
- Assess deal qualification. Review proof-of-funds submissions where a listing requires them.
- Execute and evidence agreements. Generate, store, and evidence NDA signatures and per-listing access records.
- Bill and manage subscriptions. Process payments through Stripe, manage renewals, handle payment failures and grace periods, and administer refunds.
- Communicate. Send transactional messages (match tipoffs, NDA confirmations, data room access links, billing notices, verification outcomes) and, with consent where required, marketing messages.
- Measure and improve. Analyze funnel drop-off, feature usage, and traffic sources; improve matching and platform functionality.
- Advertise. Measure and optimize advertising campaigns (Section 4).
- Protect the platform. Detect and prevent fraud, unauthorized access, scraping, seller-identification attempts, and circumvention; enforce our terms and NDAs, including using access logs as evidence.
- Comply with law. Meet legal, tax, audit, and regulatory obligations.
3A. Automated Decision-Making and Artificial Intelligence
We use artificial-intelligence tools to classify, summarize, and draft content (match summaries, email drafts, inquiry classification, listing enrichment) and to score how well a buyer's criteria fit a listing. These outputs are decision support. We do not make decisions that produce legal or similarly significant effects about you solely by automated means; a member of our team reviews any such output before it is acted on. Where a U.S. state law or Law 25 gives you a right to information about, or to opt out of, certain profiling, you may exercise it as described in Sections 13 and 14. AI processing is performed by the providers listed in Section 5 under contract; API inputs are not used to train their models per their applicable API policies.
4. Cookies, Analytics, and Advertising Technology
4.1 Essential cookies
Authentication, security, and session cookies necessary for the Platform to function. These cannot be disabled.
4.2 First-party analytics (fk_visitor_id)
We set a first-party cookie and local storage value named fk_visitor_id containing a random identifier. It is not your email or name. It lets us count unique visitors, connect steps of the same visit across our marketing site and application (both on franklyadvisors.com domains), and measure where prospective buyers drop out of the sign-up journey. Access to this analytics data is restricted to administrators.
4.3 Google services
We use Google Analytics (usage measurement) and Google Maps Platform (address autocomplete and geographic matching). Google may collect your IP address and device information. You can opt out of Google Analytics with Google's browser add-on. Google's privacy policy governs its processing.
4.4 Meta Pixel and Conversions API
We use the Meta (Facebook) Pixel and Meta's Conversions API to measure and optimize our advertising:
- The Pixel sets Meta cookies (such as
_fbpand_fbc) in your browser and reports page views and conversion events (for example, viewing an opportunity, submitting a registration form, or completing a checkout) to Meta. - Our servers may also send the same conversion events to Meta's Conversions API, together with matching identifiers that can include your email address, phone number, and name (which are hashed before matching), your IP address, and the Meta cookie values, so Meta can attribute conversions to ads and improve delivery. Duplicate events are reconciled using a shared event identifier.
- Meta processes this data under its own terms as an independent or joint controller for its advertising services.
This is "sharing" for advertising; you can opt out. Our use of the Meta Pixel and Conversions API constitutes "sharing" for cross-context behavioral advertising under the CCPA and comparable state laws. You may opt out (Section 13.2) by: (a) emailing privacy@franklyadvisors.com with "Do Not Sell or Share" in the subject; (b) using the "Do Not Sell or Share My Personal Information" link we post; or (c) sending a recognized opt-out preference signal such as Global Privacy Control (GPC), which we honor for the browser that sends it. For Canadian visitors, we rely on implied consent for advertising cookies as permitted under PIPEDA and OPC guidance, subject to the same opt-out. You can also limit Meta's use of your data through your Facebook ad preferences, industry opt-outs (such as youradchoices.com), or browser tracking protections. When you first visit, we show a brief, dismissible cookie notice that links to these controls; it does not block the site.
4.5 Managing cookies
Most browsers let you refuse or delete cookies. Essential features may not work without them. Where a consent banner or preference center is offered, your selections there control the non-essential categories.
4.6 Cookie categories
| Category | Examples | Purpose | Can you disable? |
|---|---|---|---|
| Essential | auth/session/security cookies | Sign-in, security, core function | No (required) |
| First-party analytics | fk_visitor_id | Visitor counting, funnel measurement | Yes (browser controls) |
| Third-party analytics | Google Analytics | Usage measurement | Yes (Google opt-out) |
| Advertising | Meta _fbp/_fbc (Pixel + CAPI) | Ad measurement/optimization | Yes (opt-out in §4.4/§13.2) |
5. Third-Party Service Providers
We share personal information with service providers that process it on our behalf under contractual confidentiality and data protection obligations:
| Provider | Purpose | Data involved |
|---|---|---|
| Stripe | Payment processing, subscriptions, billing portal | Name, email, payment card (held by Stripe, not us), subscription state |
| Supabase | Database, authentication, file storage, backend functions | Account data, application data, uploaded documents (encrypted at rest and in transit) |
| Resend | Transactional email delivery | Email address, message content, delivery/bounce/complaint events |
| Twilio | SMS and voice (where you opt in) | Phone number, message content |
| Analytics, Maps | Device/usage data, IP, location inputs | |
| Meta | Advertising measurement (Pixel + Conversions API) | Event data, cookies, hashed contact identifiers (Section 4.4) |
| OpenAI | AI-assisted classification, drafting, summarization | Content submitted for processing; API inputs are not used to train OpenAI models per its API policy |
| Vercel | Website hosting and delivery | IP address, device information |
| AIArk, Hunter.io, Foursquare | Business data enrichment and location verification | Business contact and location data |
| Serper | Web-presence check during NDA verification scoring | Name and company as submitted on the NDA form |
We do not permit service providers to use your personal information for their own marketing.
6. Identity and Financial Document Handling
6.1 Government ID documents
- Stored in a private, encrypted storage bucket that is not publicly accessible.
- Uploaded only through secure, single-use signed upload channels.
- Viewable only by authorized Frankly administrators for verification review, through access links that expire within seconds of issuance.
- Never shared with sellers, brokers, other members, or advertising platforms.
- Never used for any purpose other than verification review, fraud prevention, and legal compliance.
- Purged on the schedule in Section 9, and earlier upon your verified deletion request, subject to legal retention needs.
6.2 Proof-of-funds documents
- Stored with the same private, encrypted storage protections.
- Reviewed by the broker responsible for the listing that requires them, for the sole purpose of qualifying deal access.
- An approved proof of funds is valid across listings for six (6) months from upload, after which a fresh document is required.
- Never shared with sellers or used for marketing.
6.3 No biometric processing
Verification review is performed by human reviewers. We do not create biometric templates, run facial recognition, or extract biometric identifiers from your ID document.
7. Confidential Deal Information and Cross-Broker Sharing
The Platform operates a matching network in which buyer criteria are evaluated against all active listings regardless of contributing brokerage. When a match occurs:
- Teaser-level, non-identifying information (industry, region, summarized financial range) may be shared between the managing advisors to evaluate fit.
- Full confidential information, including seller identity and financial statements, is shared only after execution of a non-disclosure agreement through the Platform.
- When you pursue a specific opportunity, your name, contact details, verification status (the fact of the badge, never your ID document), NDA status, proof-of-funds status (approved/pending/expired, and the document itself where the deal requires broker review), and relevant communications are shared with the broker responsible for that listing, typically Hedgestone Business Advisors or a participating partner brokerage, to progress the transaction.
- Data contributed by advisors is not made available to competing advisors for prospecting or solicitation.
8. Other Disclosures
We may also disclose personal information:
- With your consent or at your direction.
- Legal requirements. To comply with law, court order, subpoena, or governmental request, or to establish or defend legal claims, including enforcing NDAs and non-circumvention obligations (access logs and signature records may be produced as evidence).
- Safety and integrity. To protect the rights, property, or safety of Frankly, our users, sellers, or the public, including fraud prevention.
- Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this policy's commitments.
We do not sell personal information for money. We will never share, sell, or provide your mobile phone number or SMS opt-in data to third parties or affiliates for marketing or promotional purposes.
9. Data Retention
| Category | Retention |
|---|---|
| Account information | Life of the account; identifiable profile removed within 30 days of deletion request or termination |
| Inquiry and intake data | Up to 3 years after last interaction |
| NDA signature records (signed PDF, snapshot, execution evidence) | 7 years from signature or longer where a live dispute requires |
| Data room access and denial logs | 7 years (audit and enforcement record) |
| Transaction, matching, and attribution records | Duration of relationship plus 7 years |
| Subscription and billing records | 7 years (tax and audit) |
| Government ID — superseded or rejected | Purged within 90 days |
| Government ID — active/approved | Purged within 30 days after account deletion, absent a legal hold |
| Proof-of-funds documents | Purged 12 months after upload (6 months after the validity window lapses); earlier upon verified deletion request |
| Funnel and analytics events | Identifiable form up to 24 months, then aggregated/anonymized |
| Anonymized, aggregated data | Indefinitely |
9.1 De-identified data
Where we retain or use de-identified or aggregated data, we maintain it in a form that cannot reasonably be linked back to you, do not attempt to re-identify it except to test our de-identification, and require the same of any recipient.
10. Security
Confidentiality is the core of our business. Safeguards include: encryption in transit (TLS) and at rest; row-level access controls in our database; private storage buckets for identity and financial documents with short-lived signed access links; role-restricted administrative access; access and denial logging on confidential deal rooms; confidentiality obligations for all team members and partners; collection limited to what is necessary for the purposes in Section 3; and periodic review of security practices. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
10.1 Third-party links
The Platform may link to third-party sites and services we do not control. Their privacy practices are governed by their own policies, not this one.
11. Breach Notification
If a breach of security safeguards involving your personal information creates a real risk of significant harm, we will notify you and the Office of the Privacy Commissioner of Canada as soon as feasible, in accordance with PIPEDA (and the Commission d'accès à l'information du Québec where Law 25 applies), and will comply with any additional notification obligations under applicable U.S. state breach notification laws for affected residents.
12. Your Rights under PIPEDA (all users)
You may: request access to your personal information; request correction; withdraw consent to collection, use, or disclosure (subject to legal or contractual restrictions; some withdrawals will end our ability to provide services); and complain to the Office of the Privacy Commissioner of Canada (www.priv.gc.ca). Contact privacy@franklyadvisors.com. We respond within 30 days and will not discriminate against you for exercising rights.
13. U.S. State Privacy Rights
The following applies to residents of U.S. states with comprehensive consumer privacy laws, to the extent those laws apply to Frankly, and otherwise as a matter of the voluntary-compliance policy stated in Section 1.
13.1 Rights common to covered states
Subject to legal exceptions, you may: (a) confirm whether we process your personal information and access it; (b) correct inaccuracies; (c) delete personal information you provided or we obtained about you; (d) obtain a portable copy; and (e) opt out of targeted advertising. We do not sell personal information for money, and we do not use personal information for profiling in furtherance of decisions with legal or similarly significant effects.
How to exercise: email privacy@franklyadvisors.com with the subject "Privacy Rights Request," or use any in-product privacy controls we offer. We will verify your identity using your account email and respond within 45 days (extendable once by 45 days where permitted, with notice). If we deny a request, you may appeal by replying to our decision; we will respond to appeals within the period your state's law requires, and will tell you how to contact your state Attorney General if you disagree with the outcome.
Authorized agents: where your state permits, an authorized agent may submit an opt-out request on your behalf with proof of authorization.
Opt-out preference signals: we honor a recognized universal opt-out signal (such as Global Privacy Control) received from your browser as a request to opt out of targeted advertising and "sharing" for that browser, where your state's law requires it.
13.2 California (CCPA/CPRA)
In the last 12 months we have collected the categories of personal information described in Section 2: identifiers (name, email, phone, IP, fk_visitor_id); customer records (billing records; government ID for member verification; financial documents for proof of funds); commercial information (subscriptions, deal activity); internet activity (usage, funnel events); geolocation (approximate, from IP); professional information (company, acquisition criteria); sensitive personal information (government ID number as displayed on your uploaded document; account log-in credentials); and inferences (match scoring).
- Sources: you; your devices; service providers; enrichment providers; advertising platforms.
- Purposes: as described in Section 3.
- Disclosure for business purposes: to the service providers in Section 5 and the deal parties in Section 7.
- Sale and "sharing": we do not sell personal information for money. Our use of the Meta Pixel and Conversions API may constitute "sharing" for cross-context behavioral advertising under the CCPA. California residents may opt out of sharing by emailing privacy@franklyadvisors.com with "Do Not Sell or Share" in the subject, via GPC, or via the "Do Not Sell or Share My Personal Information" link we post.
- Sensitive personal information: we use it only to provide the services you request (verification, security), which does not require a "Limit the Use of My Sensitive Personal Information" link under current regulations.
- No knowledge of sales of minors' data: we do not knowingly collect or sell information of consumers under 16.
- Non-discrimination and financial incentives: we do not offer financial incentives in exchange for personal information.
- Shine the Light: we do not disclose personal information to third parties for their own direct marketing.
13.3 Colorado, Virginia, Connecticut
Residents of Colorado, Virginia, and Connecticut have the rights in Section 13.1, including the right to opt out of targeted advertising and the right to appeal. Virginia and Connecticut require consent before processing "sensitive data" (which can include government ID data and precise geolocation): we obtain your consent when you choose to upload an ID document as part of member activation, and we do not collect precise geolocation. Colorado recognizes universal opt-out mechanisms as described above.
13.4 Utah
Utah residents may access and delete personal information, obtain a copy, and opt out of targeted advertising. Utah provides notice-and-opt-out (rather than consent) for sensitive data: this policy is that notice, and you may opt out by not uploading optional documents and by contacting us.
13.5 Other states
Residents of other states with comprehensive privacy laws (including Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, and others as they take effect) receive the rights in Section 13.1 to the extent their law applies to us. We apply the strictest common denominator of those frameworks in practice.
14. Quebec (Law 25)
Where Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25, applies to your personal information: our Privacy Officer (Section 18) is the person in charge of the protection of personal information; we obtain consent for the collection, use, and disclosure of your personal information as required, and separately for sensitive information; you have rights of access, correction, withdrawal of consent, portability, and (where applicable) de-indexing; and we assess privacy impacts and safeguards before transferring personal information outside Quebec, including to service providers in Canada and the United States (Section 15). You may complain to the Commission d'accès à l'information du Québec.
15. International Data Transfers
Your information may be transferred to, stored, and processed in countries other than your own, including Canada and the United States, where our service providers operate. These jurisdictions may have different data protection laws. We use contractual and technical safeguards to protect transferred information in accordance with this policy.
16. Scope; No EEA/UK Targeting
Our services are directed to buyers and sellers of businesses in Canada and the United States. We do not target or offer the Platform to individuals in the European Economic Area or the United Kingdom, and this policy is not written to the GDPR or UK GDPR. If you access the Platform from those regions, you do so on your own initiative and are responsible for local-law compliance.
17. Children
Our services are directed to adults engaged in business transactions. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, contact us and we will delete it.
18. Changes to This Policy
We may update this policy. Material changes will be posted with a new "Last updated" date, and, for registered users, notified by email where the change materially affects previously collected information. Continued use after the effective date constitutes acceptance to the extent permitted by law; where law requires fresh consent (for example, new purposes for sensitive data), we will ask for it.
19. Contact Us
Modern X Inc. (o/a Frankly Advisors)
Privacy Officer
2967 Dundas St. W. #1491
Toronto, ON M6P 1Z2, Canada
Privacy: privacy@franklyadvisors.com
Legal notices: legal@franklyadvisors.com
Our Privacy Officer is responsible for compliance with this policy, PIPEDA, and Law 25 where it applies. You may also complain to the Office of the Privacy Commissioner of Canada at www.priv.gc.ca, to the Commission d'accès à l'information du Québec, or, for U.S. state rights, to your state Attorney General as described in Section 13.