← Back to Shallot

Privacy Policy

Last updated: 2026-09-05

What we collect

When you join the waitlist, we collect your name, email address, an automatically derived source or referrer value (so we can see which community sent you), and the timestamp of your submission. That is the complete list — we do not ask for anything else on this site, and we do not collect any payment information, credit card details, or billing information anywhere on this site.

We also collect aggregate, anonymous analytics via Vercel Analytics and Vercel Speed Insights: page views, scroll depth, and time on page. These figures are aggregate measurements, not tied to a named individual, and this site sets no advertising or cross-site tracking cookies.

How we use it

We use your waitlist information to contact you about early access to Shallot and to send the newsletter you signed up for. Email addresses may be exported from our database and imported into a third-party newsletter platform (currently Substack) so we can send that newsletter — this is a manual export today, not an automated, real-time integration.

Who we share it with

We rely on a small number of sub-processors to run Shallot, and your information may pass through their infrastructure:

  • Vercel — hosting, deployment, and analytics
  • Neon — our database provider
  • Clerk — authentication for account holders
  • Plaid — bank account connections (see Bank connections below)
  • Substack — newsletter delivery

We do not sell your information, and we do not share it with anyone outside of the sub-processors listed above.

How long we keep it

We keep waitlist entries until you ask us to remove your information or until the waitlist closes, whichever comes first.

Bank connections

Shallot uses Plaid Inc. to connect to financial institutions. When you link a bank, you enter your sign-in credentials into Plaid's own interface. Shallot never sees, receives, or stores those bank sign-in credentials.

Plaid provides Shallot with account details, balances, transactions, and loan terms for the accounts you select. Plaid's handling of that data is governed by Plaid's privacy policy.

Shallot stores the access credential Plaid issues in encrypted form and uses it only to retrieve your own data.

You can disconnect a bank at any time from Settings. Disconnecting stops future data retrieval from Plaid. Accounts and transactions already imported stay in your own Shallot data until you delete them yourself.

Your rights

You can ask us to access, correct, or delete your information at any time by emailing privacy@shallot.money.

Contact

[LEGAL ENTITY NAME PENDING] operates Shallot. Questions about this policy can be sent to privacy@shallot.money.