Legal

Information Security Policy

Organization: AdSnap, LLC (operating as Coattail)  ·  Owner: Jonathan Allen, Founder & CEO  ·  Effective: June 2026  ·  Review Cadence: Annually

1. Purpose and Scope

This policy governs how Coattail protects production systems, user data, and third-party credentials. It applies to all infrastructure, code, and personnel (including contractors) involved in operating the Coattail mobile application and its backend services.

2. Access Control

The principle of least privilege is enforced at every layer:

3. Data Classification and Handling

Classification Description Examples Controls
Highly Sensitive Data whose exposure could cause financial or identity harm Plaid and SnapTrade credentials, portfolio holdings, brokerage account IDs, order records Service-role-only table; no client RLS; AES-256 at rest; TLS 1.2+ in transit
Sensitive Personal identifying information Email address, display name, profile photo, push notification token RLS-protected; stored in Supabase (encrypted at rest); never logged
Internal Operational and diagnostic data Usage analytics, crash reports, app logs Anonymized where possible; retained per vendor policy (Amplitude, Sentry)
Public Publicly available government and regulatory data Congressional STOCK Act trades, SEC filings, FDA decisions Sourced from public APIs; no special restriction; not PII

Supabase enforces AES-256 encryption at rest and TLS 1.2+ for all data in transit. No sensitive data is stored in client-side storage (AsyncStorage holds only non-sensitive UI preferences).

4. Credential and Secret Management

5. Vulnerability and Patch Management

6. Incident Response

In the event of a suspected breach or unauthorized access:

  1. Contain — Immediately rotate affected credentials via the relevant secret store dashboard.
  2. Assess — Determine scope of exposure using Supabase logs and Sentry crash reports.
  3. Notify — If user data is confirmed exposed, notify affected users within 72 hours via in-app message and email.
  4. Remediate — Patch the vulnerability before restoring affected services.
  5. Document — Record the incident, timeline, and remediation steps.
Security contact for external reporting: [email protected]

7. Third-Party Vendor Security

All third-party vendors handling user data are evaluated for SOC 2 compliance or equivalent before integration:

Vendor Purpose Compliance
Supabase Database, authentication, storage, and Edge Functions SOC 2 Type II
Plaid Brokerage connectivity (read-only investments product) SOC 2 Type II, PCI DSS
SnapTrade Brokerage connectivity, portfolio data, and order transmission Reviewed through vendor security and contractual documentation
Railway Background job runner for daily data ingestion SOC 2 Type II
Sentry Crash reporting and error monitoring SOC 2 Type II
Expo (EAS) App build infrastructure and push notification delivery SOC 2 Type II

8. Data Retention and Deletion Policy

Effective: June 2026  ·  Reviewed: Annually

8.1 What We Retain and For How Long

Data Type Retention Period
Account credentials (Supabase Auth) Active until account deletion
Brokerage connection credentials (Plaid and SnapTrade) Active until user disconnects brokerage or deletes account
Synced portfolio holdings Active until user disconnects the linked account or deletes account
Morning brief history 90 days rolling
Trade feed and investor data Indefinite (public disclosure data — not PII)
Push notification tokens Active until account deletion or token rotation
Analytics events (Amplitude) Per Amplitude's data retention policy (24 months)

8.2 User-Initiated Deletion

Users may request full account deletion at any time by contacting [email protected] or via the in-app Settings screen. Upon verified request, we will:

  1. Revoke or delete all active Plaid and SnapTrade connections as part of the deletion workflow
  2. Delete account-scoped holdings, brief history, profile data, and authentication identity, subject to limited records retained for security, audit, dispute, or legal obligations
  3. Confirm deletion in writing to the requesting email address

8.3 Brokerage Disconnection

When a user disconnects a brokerage account, Coattail revokes or deletes the applicable provider connection and removes current synced account and holdings data from active use. Limited order, security, audit, or legal records may be retained where reasonably necessary.

9. Policy Review


Last reviewed: June 2026  ·  Next review due: December 2026