Privacy Policy

Last updated: May 20, 2026

LayaVantage Systems Corp., a Colorado corporation doing business as FranVantage ("FranVantage," "Company," "we," "us," or "our"), operates the FranVantage platform at franvantage.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

For privacy-related inquiries: privacy@franvantage.com

1. Information We Collect

1.1 Account Information

When you create an account, we collect your name, email address, phone number (if you choose to provide it), and authentication credentials. We may also collect profile details such as company name and franchise sector of interest. Accounts are managed through Supabase Auth, a third-party authentication service.

1.2 Uploaded Documents

When you upload a Franchise Disclosure Document (FDD) for analysis, we store the document in encrypted cloud storage (AWS S3). Documents are processed by our AI analysis pipeline and retained during your active access period.

1.3 Usage Data

We automatically collect information about how you interact with the Service, including pages visited, features used, analysis views, timestamps, browser type, device information, IP address, and referring URLs. This data is used to improve service quality and diagnose technical issues.

1.4 Payment Information

Payment processing is handled entirely by Stripe. We do not store your credit card number, CVV, or full billing details on our servers. Stripe may share with us your name, billing address, last four digits of your card, and transaction history for record-keeping purposes.

2. How We Use Your Information

  • Analysis Processing — Your uploaded FDDs are processed through our AI pipeline (Amazon Bedrock with Anthropic Claude models) to generate analysis, summaries, and financial models.
  • Service Improvement — Aggregated, anonymized usage data helps us improve the quality and reliability of our analysis.
  • Account Management — To manage your account, process credits, and communicate service-related information.
  • Security — To detect, prevent, and address technical issues, fraud, or abuse.
  • Legal Compliance — To comply with applicable legal obligations.

We do not use your uploaded documents or analysis outputs to train AI models. Your FDD content is processed for analysis purposes only and is not incorporated into any machine learning training dataset.

3. SMS/Text Messaging

Opt-In and Consent

FranVantage offers optional SMS/text message notifications to account holders. SMS is off by default and requires your explicit opt-in. You may enable SMS notifications by:

  • Navigating to Account Settings at app.franvantage.com/account
  • Adding your phone number in the Account Information section
  • Enabling the "SMS Notifications" toggle

By enabling SMS notifications, you consent to receive transactional text messages from FranVantage at the phone number you provide. You may withdraw consent at any time (see "Opt-Out" below).

Types of Messages

We send only transactional, service-related messages. We never send marketing, promotional, or advertising messages via SMS. Message types include:

  • Document analysis completion alerts
  • Document upload confirmations (admin accounts)
  • Pipeline failure or stall notifications (admin accounts)

Message Frequency

Message frequency varies based on your usage of the platform. Most users receive fewer than 5 messages per month. You will never receive more than one message per event.

Message and Data Rates

Message and data rates may apply. FranVantage does not charge for SMS messages, but your mobile carrier may charge standard messaging fees. Consult your carrier's pricing plan for details.

Opt-Out

You may opt out of SMS notifications at any time by any of the following methods:

After opting out, you may opt back in at any time by re-enabling the toggle in Account Settings or by replying START to our number.

Help

For help with SMS notifications, reply HELP to any message, or contact us at support@franvantage.com.

Phone Number Privacy

Your phone number is collected solely for the purpose of sending the notifications described above. We do not:

  • Share your phone number with any third party for marketing purposes
  • Sell, rent, or lease your phone number to anyone
  • Use your phone number for any purpose other than delivering the notifications you opted into

Your phone number is transmitted to our SMS delivery provider (Twilio) solely for message delivery. Twilio's privacy practices are governed by their own privacy policy.

Supported Carriers

SMS notifications are available to US mobile phone numbers on all major carriers. Carriers are not liable for delayed or undelivered messages.

4. Third-Party Services

We use the following third-party services to operate the platform:

  • Amazon Web Services (AWS) — S3 for document storage, Bedrock for AI processing, Lambda for document extraction. Data is processed and stored in the US-East-1 region.
  • Stripe — Payment processing. Subject to Stripe's Privacy Policy.
  • Supabase — Authentication and database services. Data is stored in the US-East-1 region on SOC 2 Type II compliant infrastructure.
  • Vercel — Frontend hosting and content delivery.
  • Twilio — SMS message delivery for account holders who opt into text notifications.

Under the current API and enterprise terms of our AI service providers, document content submitted via their APIs is not used to train their models and is not retained beyond what is necessary to complete the processing request.

5. Cookies and Analytics

We use only essential cookies required for authentication and session management:

  • Authentication Session Cookie — Maintains your login session. Essential for the Service to function. Set by our authentication provider (Supabase). Expires when you sign out or after session timeout.

We use the following analytics services to understand how visitors interact with our website and platform:

  • Google Analytics — Collects anonymized usage data such as pages visited, time on page, and referral source. This data is used solely to improve our website and is not combined with personally identifiable information. You can opt out by installing the Google Analytics Opt-out Browser Add-on.
  • Microsoft Clarity — Provides aggregated insights into how visitors use our site, including session activity and interaction patterns, to help us identify usability issues. Clarity data is governed by Microsoft's privacy practices.

We do not use advertising cookies or participate in cross-site behavioral tracking.

6. How Documents Are Processed

When you upload an FDD, the document is transmitted to third-party AI services for optical character recognition (OCR), text extraction, embedding, and analysis. These third-party providers include AI model providers (such as Amazon Bedrock, Anthropic Claude, and Mistral) and cloud infrastructure services.

Under the current API and enterprise terms of our AI service providers, document content submitted via their APIs is not used to train their models and is not retained beyond what is necessary to complete the processing request. We rely on these provider terms for this protection — we do not have individually negotiated data processing agreements with each provider at this time.

We are transparent about this because your FDDs contain sensitive information and you deserve to know exactly how they are handled.

7. Data Sharing and Disclosure

We do not sell, rent, or distribute your personal information or document content to third parties for their marketing or commercial purposes.

We share data only in the following circumstances:

  • Service providers: With third-party AI, infrastructure, and payment providers necessary to operate the platform. These providers receive only the data needed to perform their specific function.
  • Legal requirements: When required by law, regulation, subpoena, court order, or legal process.
  • Safety and rights: When we believe disclosure is necessary to protect our rights, your safety, or the safety of others, or to investigate fraud or security issues.
  • Business transfers: In connection with a merger, acquisition, reorganization, or sale of assets, your data may be transferred as part of that transaction. We will notify you of any such change and any choices you may have regarding your data.

8. Data Security

We implement industry-standard security measures to protect your information:

  • Encryption in Transit — All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher.
  • Encryption at Rest — Uploaded documents and analysis data are encrypted at rest using AES-256 encryption in AWS S3.
  • SOC 2 Compliant Infrastructure — Our infrastructure providers (AWS, Supabase) maintain SOC 2 Type II compliance. FranVantage itself has not obtained independent SOC 2 certification at this time.
  • Access Controls — Your documents are accessible only to you and authorized system administrators for support purposes.

9. Data Breach Notification

In the event of a data breach that affects your personal information or uploaded documents, we will notify affected users without unreasonable delay and in accordance with applicable law. Where required, we will also notify relevant regulatory authorities. Notification will include a description of the breach, the types of data involved, and steps we are taking in response.

10. Data Retention

  • FDD Documents — Retained in encrypted storage during your active access period (90 days from analysis completion, or longer if renewed). Deleted upon account deletion.
  • Analysis Results — Retained for the same period as the associated document.
  • Account Data — Retained for the life of your account. Upon account deletion, personal data is removed from our primary systems within 30 days and backup copies are purged within 90 days. Anonymized usage data may be retained indefinitely.
  • Payment Records — Transaction records are retained for 7 years to comply with tax and accounting obligations.

11. Your Rights

Regardless of your location, we provide the following rights to all users:

  • Access — Request a copy of the personal data we hold about you.
  • Correct — Update or correct inaccurate personal data via your Settings page.
  • Delete — Request deletion of your account and associated data through the Settings page. This will permanently remove your uploaded documents, analysis results, and personal information.
  • Export — Request a machine-readable export of your personal data.
  • Opt out — Opt out of non-essential communications, including SMS notifications.

To exercise these rights, visit your Settings page or contact us at privacy@franvantage.com. We will respond to requests within 30 days.

12. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

  • Right to Know: You may request the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collection, and the categories of third parties with whom we share it.
  • Right to Delete: You may request that we delete your personal information, subject to certain exceptions.
  • Right to Opt Out of Sale/Sharing: We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising purposes.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

Categories of personal information we collect: Identifiers (name, email, phone number, IP address), commercial information (purchase history), internet activity (usage data, interactions), and professional information (uploaded FDD content).

To exercise your California privacy rights, contact us at privacy@franvantage.com.

13. International Users

FranVantage is operated from the United States and is primarily intended for users located in the United States. If you access our services from outside the United States, please be aware that your data will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction.

By using FranVantage, you consent to the transfer of your information to the United States. We do not currently target users in the European Economic Area (EEA) or the United Kingdom. If this changes, we will update this policy with appropriate legal bases for processing, data transfer mechanisms, and additional rights.

14. Children's Privacy

The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from anyone under 18 years of age. If we become aware that we have collected personal data from a minor, we will take steps to delete that information promptly.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a prominent notice on the Service. The "Last updated" date at the top of this page indicates when the policy was last revised. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.

16. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at privacy@franvantage.com.