Privacy Policy
Normfin collects the minimum it needs to work, and nothing it does not.
Last updated: August 31, 2026
The data controller
Neige AI, Inc., a Delaware (USA) corporation, 2261 Market St STE 46015, San Francisco, CA 94114, United States, is the data controller for this site. Questions about this policy go to hello@normfin.com.
What is collected
Normfin has no accounts, no login, and no database. The CRD checker at /check works by looking up a number you type against a static dataset built ahead of time from the SEC’s own public investment adviser roster; the number you enter is never stored, only used to render the page you asked for. Anonymous usage analytics (pageviews and the checker’s own submit event) run via Vercel Analytics, with no cross-site tracking cookies. Where product analytics is switched on, PostHog also records pageviews, interaction events and error reports; in the EU, EEA and UK nothing identifiable is captured until the cookie banner is answered, and declining switches it to a rotating hash with no cookie at all.
What is never done with it
Nothing here is sold, rented, or shared for advertising. No marketing lists, no third-party ad trackers, no profiling, no email capture. The only outside processors are Vercel (hosting and anonymous analytics) and, where product analytics is switched on, PostHog (usage analytics and error reporting), each holding the minimum their job needs.
The firm data shown by the checker
Firm names, cities, states and Form ADV figures shown on a /check result page are the SEC’s own public disclosure, already available to anyone at sec.gov. Nothing about the visitor running the check is attached to that firm’s record; there is no way, from this site, to know who looked up a given CRD number.
Where it is processed
The services this site runs on (Vercel for hosting and analytics, PostHog for product analytics where switched on) are based in the United States, and that is where the data described on this page is transferred and processed, wherever you visit from. Each of them handles EU data under EU-approved safeguards: Data Privacy Framework certification or standard contractual clauses.
How long it is kept
Analytics data is retained only as long as it is needed to read usage trends; there is no other visitor record to keep.
Your rights
Ask, and anything this site holds about you is deleted. If you are in the European Union or the United Kingdom, you can also ask for a copy or a correction of it, and you have the right to complain to your local data-protection authority. Write to hello@normfin.com.