Privacy Policy
Effective Date: March 1, 2026
Last Updated: August 11, 2026
This Privacy Policy explains how Silverstone Business Brokerage collects, uses, stores, shares, and protects information connected with the Website, user accounts, subscriptions, listings, broker profiles, seller information, investor information, messages, appointment requests, payment status, compliance requests, and related marketplace services.
Information We Collect
We may collect information that users provide directly, including name, email address, phone number, account role, authentication identifiers and verification status, profile details, company information, broker information, seller listing information, investor information, business descriptions, asking prices, locations, industries, photos, logos, documents, valuation requests, support requests, appointment requests, messages, inquiries, and communications submitted through the Website.
We may also collect operational information, including login activity, terms acceptance records, privacy/cookie consent records, IP address, browser and device information, session data, security logs, form submissions, upload activity, subscription status, Stripe or payment processor customer/subscription identifiers, invoice/payment status, and other technical information needed to operate and secure the Website.
Identity, Verification, Authentication, and Account Security Providers
We may use Auth0 Universal Login, Clerk, Microsoft, passkey providers, authenticator applications, email-verification services, fraud-prevention services, or other third-party identity and security providers. Depending on the provider and settings, those services may process email address, external user ID, password or passkey authentication, device or security-key responses, biometric confirmation performed locally by the user’s device, authenticator-app codes, recovery information, verification status, IP address, device information, browser information, login time, security signals, and session information. Silverstone generally receives identity claims, verification status, authentication-assurance information, and an external provider identifier rather than the password or passkey secret entered on the provider-hosted page.
Silverstone may store the Auth0, Clerk, or other provider user ID together with the Silverstone role, subscription status, listing permissions, company/team membership, profile information, verification status, authentication provider, last login time, and security audit information. Every protected route is authorized against the role and permissions stored in the Silverstone database; browser visibility of a button or link does not itself grant permission.
Billing and Payment Information
Payments may be processed by third-party payment processors such as Stripe, Clerk billing services, or another authorized hosted processor. When hosted checkout is used, payment card information is submitted directly to the processor and is not intended to pass through or be stored by the Silverstone application. We do not intentionally store full credit card numbers, card security codes, or equivalent raw payment credentials. We may store limited payment-related records such as subscription plan, paid status, renewal information, transaction identifiers, customer identifiers, subscription identifiers, invoice status, fraud-prevention status, and payment history needed for account administration, audit, dispute handling, fraud prevention, and customer support.
Payment processors maintain their own security and compliance programs. No payment, authentication, internet, email, hosting, or database system can be guaranteed completely secure. Users should not send card numbers or security codes through listings, messages, feedback, email, support forms, or document uploads.
How We Use Information
We use information to operate the marketplace, create and manage accounts, display listings and profiles, process subscriptions, route inquiries and messages, schedule appointments, provide support, send confirmations and notices, maintain security, prevent fraud and abuse, enforce Terms of Service, verify compliance, improve Website functionality, troubleshoot errors, perform analytics, preserve records, and comply with legal obligations.
Listings, Profiles, Feedback, and User-Submitted Content
Information users choose to post in business listings, broker profiles, investor profiles, seller listings, logos, photos, descriptions, and related marketplace fields may be visible to other users or public visitors depending on Website functionality. Feedback submissions are recorded for Admin review and emailed to Silverstone support together with sender identity, role, submission time, page, IP address, and browser/device information used for security, audit, and response purposes. Users are responsible for ensuring they have authority to submit all business, broker, seller, investor, photo, logo, listing, financial, confidential, personal, feedback, or recommendation information.
Local Image Upload Validation and Storage
Logos, headshots, listing photographs, and other public-facing images are processed locally by the Website. Silverstone may decode the actual file contents, enforce file-size and pixel limits, correct orientation, strip embedded metadata, resize the image, convert it to PNG or JPEG, assign a random server filename, and store it outside the public application directory. Silverstone does not use an external image-content review service for this process. Users remain responsible for every image submitted and may report unlawful or prohibited content to Support.
Silverstone may remove content, suspend accounts, preserve audit evidence, or respond to reports when unlawful, infringing, malicious, or otherwise prohibited material is discovered. Technical file validation is not a review or endorsement of image subject matter.
Messages, Feedback, Newsletters, Blogs, and Communications
The Website may process and retain messages, broker inquiries, seller inquiries, investor contacts, appointment requests, acknowledgement emails, support requests, feedback notes and recommendations, valuation requests, newsletter delivery records, unsubscribe preferences, and related communications for delivery, customer support, Admin review, audit, abuse prevention, dispute handling, compliance, and security purposes.
When automated translation is enabled, text from messages, feedback, support requests, appointment notes, inquiries, valuation requests, or other communication fields may be transmitted to a third-party translation service provider to detect the source language and produce a requested or operational translation. Silverstone may retain translated text in a local cache to reduce repeat translation requests. Machine translation can contain errors and is provided for communication convenience only; users should independently verify important legal, financial, licensing, tax, accounting, contract, or transaction language.
Members who join may receive periodic Silverstone Group newsletters, blog updates, business-trend summaries, forecasts, selling tips, closing information, membership updates, and related marketplace communications at the account email address. Monthly newsletter emails include a method to unsubscribe from future monthly newsletters. We may retain the unsubscribe status and date so the preference can be honored. Transactional, security, account, billing, support, and legally required messages may still be sent where appropriate.
Public City Pages, Crawlable Links, and Referral Information
The Website may publish state and city homepages, search landing pages, directories, blogs, and standard crawlable links that visitors, search engines, and automated systems can access and index. When a visitor follows a link, the destination may receive ordinary referral information such as the referring page, browser information, and IP-related network information. Standard followed links do not mean that Silverstone verifies, endorses, sponsors, or guarantees the destination, and no search-engine ranking or referral result is promised.
Cookies and Similar Technologies
We may use cookies, session cookies, local storage, analytics tools, security tools, and similar technologies to keep users logged in, remember preferences, operate forms, record consent, improve performance, understand Website usage, prevent fraud, and secure accounts. Users may control cookies through browser settings, but disabling cookies may prevent some Website features from working correctly.
Data Sharing
We do not sell personal information. We may share information with service providers that help operate the Website, including hosting providers, email providers, payment processors, analytics providers, security providers, customer support tools, professional advisors, and other vendors that need information to provide services. We may also disclose information when required by law, subpoena, court order, regulator request, law enforcement request, legal claim, fraud prevention need, security incident, business transfer, or enforcement of our Terms of Service.
Security
We use administrative, technical, and organizational safeguards designed to protect information, including HTTPS, secure and HTTP-only cookies, SameSite cookie controls, CSRF protection, rate limiting, session expiration, session invalidation, server-side role authorization, security logging, hosted payment checkout, secret storage outside the public website directory, and, when configured, Auth0 Universal Login, passkeys, email verification, and multi-factor authentication. Privileged roles may be required to use a passkey or authenticator-app MFA. Recovery codes may be created when MFA is activated.
However, no internet-based platform, identity provider, passkey system, authentication system, email system, payment system, hosting environment, browser, device, network, or database can be guaranteed completely secure, available, or immune from attack. Users are responsible for protecting devices, email accounts, authentication factors, recovery codes, and sessions; promptly reporting suspected compromise; and signing out of shared devices.
Financial Intelligence Documents and Reports
When a member uses a Financial Intelligence tool, we may process and retain the uploaded filename, privately stored document, extracted text or metrics, automated report, acceptance record, report date, User ID, and related audit information. These tools are informational only and are not audits, appraisals, valuations, verification, legal advice, tax advice, accounting advice, investment advice, or financing advice. Users must have lawful authority to upload documents and are solely responsible for verifying information, obtaining professional advice, and determining how any output is used. Members may delete completed reports through the Dashboard; backup copies may remain for a limited period until routine backup rotation.
No Security Guarantee and No Liability Created by this Policy
This Privacy Policy describes practices and does not create a warranty, guarantee, fiduciary duty, professional duty, or promise of absolute security. Use of the Website and all information, tools, listings, communications, reports, links, authentication providers, payment processors, and other services remains subject to the disclaimers, releases, assumption-of-risk provisions, arbitration requirements, damages limitations, and limitation-of-liability provisions in the Terms of Service, to the maximum extent permitted by applicable law. Nothing in this Privacy Policy excludes a legal right or liability that applicable law does not permit to be excluded.
Retention
We may retain account records, listing records, billing status, payment identifiers, messages, logs, consent records, security records, compliance records, and other operational information as long as reasonably needed to provide services, comply with legal obligations, resolve disputes, enforce agreements, prevent fraud, maintain backups, and operate the Website.
User Choices and Requests
Users may request account assistance, correction of certain information, deletion where legally and technically available, or a privacy/compliance review by contacting the Website through the contact methods provided on the Website. Some records may be retained where needed for security, legal compliance, billing records, dispute resolution, fraud prevention, or legitimate business purposes.
Children
The Website is intended for adults and commercial users. It is not intended for children under 18, and users under 18 may not use the Website.
United States Processing
Information may be processed, transferred, and stored in the United States or other jurisdictions where the Website, Website Parties, or service providers operate. By using the Website, users consent to such processing and transfer.
Changes
We may update this Privacy Policy at any time. Continued use of the Website after changes are posted constitutes acceptance of the updated policy.