Privacy Notice
This notice explains what personal information Beacon collects about you, why, and the choices you have. It covers our website, our communications, and your use of the Beacon product. It is written to be read — plain where it can be, precise where it must be.
On this page
1 · Who we are
Beacon is operated by Startup Academy LLC, a company registered in the State of California, United States, trading as Beacon Revenue®. For the personal information described in this notice, Startup Academy LLC is the data controller.
You can reach us about privacy at privacy@beaconrevenue.io, or by post at 548 Market St PMB 419537, San Francisco, California 94104, United States.
2 · Who this notice covers
This notice applies to the personal information we handle as a controller — that is, information about you as a person: visitors to our website, people who contact us or receive our communications, and the individual users of a Beacon workspace.
It is separate from the business data a customer connects to Beacon — for example, records from their billing or CRM systems. Where those records contain personal information, Beacon processes them on the customer's instructions, as a processor, under our Data Processing Agreement — the customer, not Beacon, decides how that data is used. If you're an individual whose data reached Beacon because a company you deal with connected their systems, please contact that company; we act on their behalf. Section 5 explains this split.
3 · What we collect
Information you give us
- Contact & enquiry details — your name, work email, company, and anything you write to us in a form, email, or a booked call.
- Account details — the identity you sign up with (handled by our authentication provider, Clerk) and your workspace settings.
- Billing details — for paid plans, the billing contact and, where needed, billing address and tax ID for your invoices. Card payments are processed by Stripe; we do not store full card numbers.
Information we collect automatically
- Product usage — how you use Beacon (pages viewed, features used, actions taken), to run and improve the service.
- Technical & device data — IP address, browser and device type, and similar diagnostics, including through cookies (Section 8).
We do not ask for special-category data (such as health, race, or political views), and ask that you don't send it to us.
4 · How and why we use it
We use personal information to:
- Provide and run Beacon — create your account, deliver the service, and support you. Legal basis: performance of a contract.
- Communicate with you — answer enquiries, send service messages, and (where you've asked or where permitted) share relevant updates. Legal basis: legitimate interests, or consent where required.
- Keep Beacon secure — detect, prevent and investigate abuse, fraud and security incidents. Legal basis: legitimate interests and legal obligations.
- Improve the product — understand usage and fix problems, using aggregated or de-identified data wherever possible. Legal basis: legitimate interests.
- Meet legal and accounting obligations — billing records, tax, and lawful requests. Legal basis: legal obligation.
Where we rely on legitimate interests, we've weighed them against your rights; you can object at any time (Section 12). Where we rely on consent, you can withdraw it at any time.
5 · Data you bring into Beacon
Beacon reads from the systems a customer connects — billing, and optionally CRM and others — to produce that company's revenue intelligence. Some of those records may contain personal information (for example, a customer contact's name and email).
For this data, the customer is the controller and Beacon is the processor. We only act on the customer's documented instructions, under the Data Processing Agreement. We keep the derived shape we need — and the invoice lines needed to reproduce each sealed figure — and link back to the source; the customer's own systems stay the system of record, and we never write to them. We never sell it, never use it to build a profile of any individual, and — importantly — Beacon's AI never invents or recomputes a figure; every number is produced by a fixed, reproducible calculation the customer can trace to the source.
If you are an individual and want to know how a particular company uses Beacon with your data, contact that company directly.
6 · Google user data
If you connect a Google account to Beacon — today, that means Google Calendar — this section explains exactly what we do with it. It sits alongside the rest of this notice; where the two differ for Google data, this section governs.
What we access
Beacon asks Google for read-only access to calendar events. That covers the events on every calendar you can already see in Google Calendar — your own calendar, and calendars other people have shared with you — and nothing you can’t see.
Beacon reads events only. It never creates, changes or deletes an event, and it does not read your calendar settings or who your calendars are shared with. We ask for the narrowest permission that makes the feature work. We do not request access to Gmail, Google Drive, Contacts, Chat or Meet.
How you grant it — and how you take it back
You authorise Beacon in Google's own consent screen. We never see or hold your Google password, and we never complete that step on your behalf. You can revoke Beacon's access at any time from your Google account permissions page, or by disconnecting the source inside Beacon. Revoking stops all further access immediately.
How we use it
Calendar data is used for one purpose: to put your own company's intelligence next to the meetings it relates to — for example, a short briefing ahead of a customer or board meeting.
We do not use Google user data for advertising. We do not sell it. We do not use it to develop, train or improve generalised artificial-intelligence or machine-learning models. Where Beacon's AI reads calendar data, it does so to produce output for you, in your workspace, at that moment.
How we store it
We store the minimum the feature needs, inside your own workspace. For each meeting, that is:
- its title
- its start and end time
- the number of people invited
We do not store event descriptions, attachments, or the names and email addresses of the people invited. What we store sits under the same hosting (Section 10) and retention rules (Section 11) as everything else. Access tokens are held encrypted and used only to make the calls the feature requires. Disconnecting the source deletes the calendar data we derived from it.
How we share it
We do not transfer Google user data to others except to the infrastructure providers named in Section 9 that host or transmit it on our behalf, and then only as necessary to provide the feature you asked for — or where the law requires it, or where you have given explicit consent. No one at Beacon reads your calendar data except where you specifically ask us to for support, where it is necessary for security, or where the law requires it.
Beacon's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
7 · The benchmark network
Beacon offers anonymised peer benchmarks — so a company can see how its growth and retention compare to similar companies. This runs on a strict, opt-in basis, and it's worth being exact about what it does and doesn't involve.
- Only aggregated statistics ever leave a workspace — pre-computed figures per metric and peer group. Raw records never leave. Your customers, your individual prices, and your company's identity are never shared or made identifiable.
- Nothing publishes until a group is large enough to protect it — a peer figure is only ever shown once at least seven companies are in a group, so no single one can be picked out.
- Contributing and receiving go together — on paid plans a company can contribute its anonymised data and receive the benchmarks back, or do neither, and can leave the network at any time.
- On the Free plan, contributing anonymised aggregates is a condition of the plan — it's what makes Free free — and this is stated plainly, as an explicit consent step, at sign-up. On paid plans it's a reciprocal choice: contribute and you receive the full benchmark intelligence; opt out and benchmarks stay off.
- It's off until switched on, and contributed figures are pooled separately from your own workspace data — they follow the same hosting described in Section 10, not a separate region.
Because these figures are aggregated and non-identifying, they are not "personal data" about you. The point of this section is to be transparent about how the network works. The exact consent language shown at sign-up is covered in our benchmark consent terms.
8 · Cookies & analytics
Short section, because there isn't much to tell. We run no advertising cookies and no cross-site tracking, and we do not sell or share what we measure. The site works exactly the same whether you accept analytics or decline them.
Essential — always on
One entry in your browser's local storage, beacon-consent, records the choice you made in the cookie banner and when you made it. It is written only once you answer the banner, and it is the thing that stops us asking again. Nothing else is stored to run the site.
Analytics — only if you say yes
If you allow analytics, we load PostHog (PostHog Inc.), hosted in the European Union and served through beaconrevenue.io rather than a third-party domain. It records which pages you view, what you click, your approximate location from your IP address, and your device and browser type. It does not record what you type into forms, and we do not use it to build advertising profiles.
Nothing analytics-related loads before you consent — not the script, not a cookie, not a request. You can change your mind at any time: open your cookie preferences and choose again.
Other companies your browser talks to on this site
- Google Fonts — our typefaces are served by Google's font service, so your browser requests them from Google, which sees your IP address. No cookie is set for this.
- HubSpot — if you join the waitlist, the form posts your details directly to HubSpot, our CRM. We deliberately use HubSpot's form API rather than their embedded script, so no HubSpot cookie is set on this site. If you follow a booking link you leave our site for HubSpot Meetings, where their own cookie notice applies.
- Vercel — our host. It processes the server logs any web host keeps to serve and secure the site.
Section 9 lists who we share information with, and section 10 explains where it is held.
9 · Who we share with
We don't sell your personal information. We share it only with the service providers who help us run Beacon, under contracts that require them to protect it and use it only for us:
- Airtable and Notion — the secure data layer where your workspace lives.
- Anthropic (Claude) — the AI that powers Beacon's reasoning and drafting features.
- Clerk — sign-in and account security.
- Stripe — payment processing for paid plans.
- Vercel and Railway — hosting for the app and its services.
- Resend — transactional email (alerts, reports, service messages).
- Sentry — error monitoring, to keep the product reliable.
- Mintlify — our documentation.
- HubSpot — our customer and marketing communications.
- PostHog — product-usage analytics, so we can see which parts of Beacon are used (EU-hosted).
We also share information with professional advisers and authorities where we're legally required to or to protect our rights, and with a successor in the event of a merger, acquisition or reorganisation (subject to this notice). The complete, current subprocessor list — with each provider's role and hosting region — is maintained in our Data Processing Agreement.
10 · Where your data is held
We would rather you read this and know exactly where your information sits, so here is the list, service by service.
Run inside the EU: our application servers and our operational database (Netherlands); error monitoring (Frankfurt, Germany); the email we send you (Ireland); product-usage analytics (EU).
Run in the United States: the analytics data store that holds your workspace's tables (Airtable); sign-in and account security (Clerk); the AI reasoning layer (Anthropic); the website and app front end (Vercel); our internal workspace, and the permanent record of your sealed settings and figures (Notion).
We do not offer EU-only hosting, and we are not going to tell you we are EU-resident, because we are not. We chose the EU everywhere we could. Where we could not — the AI layer is the one that cannot move — we have named it above rather than leaving it for you to find.
Because we're US-based and use the providers above, personal information is processed in the United States. Where we transfer personal information from the EU, UK or Switzerland to the US, we rely on the European Commission's Standard Contractual Clauses (and the UK and Swiss equivalents) and, where a provider is certified under the EU–US Data Privacy Framework, that framework.
11 · How long we keep it
We keep personal information only as long as we need it, then delete or anonymise it. In practice, retention is set per type of data and per purpose, and where more than one rule could apply, the strictest governs. A few specifics:
- Account & workspace data — kept while your workspace is active. A free workspace that goes idle is automatically paused after 60 days, and inactive data is cleaned up on a defined schedule.
- Enquiries & marketing — until you unsubscribe or ask us to stop, and a reasonable period after.
- Billing & legal records — for the period required by law (typically several years for tax).
- On erasure — when you ask us to delete your personal information, we do. Where that information sat inside a sealed, reproducible financial record, we remove the personal details but keep a de-identified aggregate, so the historical record still reconciles without identifying you.
- Anonymised benchmark aggregates — retained in non-identifying form; because they can't be traced to you, they aren't deleted when an account closes.
12 · Your rights
Depending on where you live, you have rights over your personal information. For people in the EU/UK, these include the right to access your data, correct it, delete it, restrict or object to processing, request portability, and withdraw consent. You can also complain to your data protection authority.
For California residents, the CCPA/CPRA gives you the right to know what we collect, to delete it, to correct it, and to opt out of "sale" or "sharing" of personal information — we do not sell your personal information. We won't discriminate against you for exercising these rights.
To exercise any of these, email privacy@beaconrevenue.io. We'll verify your request and respond within the time the law allows.
13 · Security
We protect personal information with technical and organisational measures appropriate to the risk. A few things are structural to how Beacon is built: we never ask for or store your login to another system — you connect each system in its own login screen and can revoke access there at any time, and the scoped access that connection gives us is held encrypted on Beacon's own backend, each connection under its own key; Beacon is read-first and writes back only with a person's approval; and access to data is scoped by role, with sensitive data an explicit, separate grant. Everything travels over HTTPS. We hold no security certifications yet — no SOC 2, no ISO 27001 — and we say so on our Security statement rather than leave you to discover it. Our full posture is described there.
14 · Children
Beacon is a business product and is not directed to children. We don't knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we'll delete it.
15 · Changes & contact
We may update this notice as Beacon evolves or the law changes. We'll post the new version here with an updated date, and for material changes we'll give you reasonable notice. For any question about this notice or your data, contact privacy@beaconrevenue.io.