Privacy Policy
Last updated: May 2026
Legacy Business Acquisition Center ("LBAC," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, and protect information when you use our platform at legacybac.com. By using our platform, you agree to the practices described in this policy.
1. Information We Collect
We collect information you provide directly, information collected automatically, and information from third parties.
Account Information
When you create an account, we collect your name, email address, password (hashed), phone number, company or business name, role (buyer, seller, broker, or consultant), and profile information you choose to provide.
Listing Data
Sellers and brokers provide business listing information including business descriptions, financial figures, location, industry, and supporting documents. This information is stored and, where marked public, displayed to other users.
Usage Data
We automatically collect log data when you use the platform, including IP address, browser type, pages visited, features used, timestamps, and referring URLs. We also collect device and connection information.
Payment Information
Subscription payments are processed by Stripe. We do not store your full credit card number, CVV, or bank account credentials. Stripe provides us with a payment token and limited card metadata (last four digits, card type, expiration date). Stripe's privacy policy governs their handling of your payment data.
Communications
We retain messages exchanged through our platform messaging system, inquiry threads, and deal room communications as part of deal records.
2. How We Use Information
We use the information we collect to:
- Operate and improve the LBAC platform and its features
- Create and manage your account and subscription
- Facilitate connections between buyers, sellers, brokers, and consultants
- Process subscription payments and send billing communications
- Send transactional emails (inquiry notifications, deal room updates, NDA confirmations)
- Provide customer support and respond to inquiries
- Detect fraud, abuse, and security threats
- Comply with legal obligations
- Send platform updates and marketing communications (you may opt out at any time)
- Conduct analytics to understand platform usage and improve user experience
3. Information Sharing
We share your information only as described below. We do not sell your personal information to third parties.
With Other Users as Part of Deal Flow
When you initiate or receive an inquiry, execute an NDA, or join a deal room, certain profile and contact information is shared with the counterparty and any designated advisors. Public listing information is visible to all registered users.
With Service Providers
We share data with trusted third-party vendors who assist us in operating the platform, including cloud hosting providers (AWS), payment processors (Stripe), email delivery services (Brevo/Sendinblue), and analytics tools. These providers are contractually obligated to protect your data and may only use it as directed by us.
For Legal Compliance
We may disclose information when required by law, subpoena, court order, or government request, or when we believe disclosure is necessary to protect the rights, property, or safety of LBAC, our users, or the public.
Business Transfers
If LBAC is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify affected users of any such change in ownership or control.
4. Data Retention
We retain your account data for as long as your account is active or as needed to provide services. Deal room records, NDA records, and transaction communications may be retained for up to seven (7) years following the close or termination of a deal for legal and compliance purposes.
When you delete your account, we will delete or anonymize your personal data within 90 days, except where retention is required by law or for legitimate business interests such as fraud prevention and dispute resolution.
5. Security
We implement commercially reasonable technical and organizational security measures to protect your information, including:
- HTTPS/TLS encryption for all data in transit
- Encrypted data storage at rest
- Access controls limiting data access to authorized personnel
- Regular security assessments and monitoring
No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential.
7. Your Rights
You have the following rights regarding your personal information:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete personal data.
- Deletion: Request deletion of your personal data, subject to legal retention requirements.
- Portability: Request your data in a structured, machine-readable format.
- Opt-out of marketing: Unsubscribe from marketing emails at any time via the link in any email or through account settings.
- Withdraw consent: Where processing is based on consent, withdraw that consent at any time.
To exercise any of these rights, contact us at privacy@legacybac.com. We will respond to verified requests within 30 days.
8. California Privacy Rights (CCPA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) grant you additional rights regarding your personal information, including the right to know what categories of personal information we collect, the right to delete your personal information, and the right to opt out of the sale of your personal information.
LBAC does not sell personal information as defined by the CCPA. To submit a CCPA request, contact us at privacy@legacybac.com with the subject line "CCPA Request." We will not discriminate against you for exercising your CCPA rights.
9. Children's Privacy
LBAC is intended solely for users who are 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If we become aware that we have inadvertently collected personal information from a minor, we will take steps to delete that information promptly.
If you believe we may have collected information from someone under 18, please contact us immediately at privacy@legacybac.com.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and notify registered users by email. We encourage you to review this policy periodically.
Your continued use of the platform after any changes take effect constitutes your acceptance of the revised policy.
11. Contact
For privacy-related questions, data requests, or concerns about this policy, please contact:
Privacy Team — Legacy Business Acquisition Center
Email: privacy@legacybac.com