Normfin

Privacy Policy

Normfin collects the minimum it needs to work, and nothing it does not.

What is collected

Normfin has no accounts, no login, and no database. The CRD checker at /check works by looking up a number you type against a static dataset built ahead of time from the SEC's own public investment adviser roster; the number you enter is never stored, only used to render the page you asked for. Anonymous usage analytics (pageviews and the checker's own submit event) run via Vercel Analytics, with no cross-site tracking cookies. Where product analytics is switched on, PostHog also records pageviews, interaction events and error reports; in the EU, EEA and UK nothing identifiable is captured until the cookie banner is answered, and declining switches it to a rotating hash with no cookie at all.

What is never done with it

Nothing here is sold, rented, or shared for advertising. No marketing lists, no third-party ad trackers, no profiling, no email capture. The only outside processors are Vercel (hosting and anonymous analytics) and, where product analytics is switched on, PostHog (usage analytics and error reporting), each holding the minimum their job needs.

The firm data shown by the checker

Firm names, cities, states and Form ADV figures shown on a /check result page are the SEC's own public disclosure, already available to anyone at sec.gov. Nothing about the visitor running the check is attached to that firm's record; there is no way, from this site, to know who looked up a given CRD number.