Trust · Privacy

Privacy Policy

Last updated · September 2026Applies to thegonch.com and the TheGonch platform
Not yet counsel-reviewed. This policy is written in plain language by TheGonch and has not been reviewed by legal counsel. It describes current practice accurately as of the date above. A firm’s use of the platform is governed by its written agreement with TheGonch, which takes precedence where the two differ.

TheGonch is a platform used by financial advisory firms to run their practices. This policy explains what data we hold, why, where it lives and who can act on it. It is deliberately short. Where something is not yet in place, it says so.

1. Two kinds of data

We handle two categories of information and treat them differently.

Website enquiry data
Information you give us when you request a walkthrough or contact us through thegonch.com. TheGonch decides how this is used.
Firm and advisor platform data
Everything a firm and its advisors enter into the platform: people, activity, opportunities, goals, production. The firm decides how this is used; TheGonch processes it to provide the service.

2. Website enquiry data

When you request a walkthrough or a technical review, we collect the details you provide: name, work email, firm, role, advisor count and anything you write in the message. We use it to respond to you and to run the conversation about a deployment. We do not add you to marketing lists, and we do not share enquiry data with third parties other than the sub-processors needed to store and send email.

3. Firm and advisor platform data

Platform data is entered by a firm’s advisors, managers and administrators in the course of their work. It includes information about the firm’s clients and prospects. TheGonch processes this data solely to provide the platform to the firm: storing it, displaying it to users the firm has authorised, and deriving the views and summaries the product offers.

Who within a firm can see what is determined by the firm’s organizational structure and roles, and is enforced in the database. TheGonch staff do not access platform data except to operate, support or secure the service, and privileged account and team actions performed through the platform’s audited administration routes are logged.

4. Ownership and control

Operating data belongs to the firm. TheGonch does not sell it, use it for advertising, or use it to build products for other firms. The firm may instruct us to export or delete its data, subject to the process in section 8.

5. Sub-processors

TheGonch uses a small number of infrastructure providers to host and operate the platform. The current list, what each does, and what is known about where each processes data is maintained on the Sub-processors page. That page is the authoritative list and is updated when providers change.

6. Analytics and tracking

Neither thegonch.com nor the platform uses advertising analytics, advertising pixels or cross-site tracking. We do not run third-party behavioural analytics on platform data. Infrastructure providers generate ordinary server logs (such as request logs) as part of operating the service.

7. Data location

The primary database is hosted in the United States (AWS us-east-1, Northern Virginia). This statement covers the database. Other sub-processors may process data in other regions; where a provider’s processing location has not yet been confirmed, the Sub-processors page says so rather than assuming it matches the database.

8. Retention, deletion and export

Platform data is retained for as long as the firm uses the platform. On request from a firm’s authorised administrator, TheGonch will export the firm’s data or delete it. Both are currently handled by TheGonch on request rather than as self-serve features, and deletion from provider backups follows the providers’ own retention schedules.

A documented, firm-configurable retention policy does not yet exist. Enquiry data is kept for as long as the conversation it relates to is active and is deleted on request.

9. Security status

Current controls, the architecture, and the list of items not yet in place (including SOC 2, ISO 27001, independent penetration testing and single sign-on) are documented on the Security page. We would rather a firm read that list before deploying than discover it afterwards.

10. Changes and contact

When this policy changes, the date at the top changes with it and firms with an active deployment are told directly. Questions about this policy or about a firm’s data can be raised through the contact page.