Current-practice summary
This policy is grounded in the current repository and public trust routes checked for this page. It distinguishes data the app intentionally asks for from data that may be created by normal hosting and browser requests. It does not claim that every production edge log, deployment platform record, browser extension, network operator, search engine, or linked third party is controlled by 401kROBS.com.
Categories collected by the site versus hosting infrastructure
Site-requested information: the provider-match flow asks for selected option values. Public pages and tools may process form or control values in the browser to display local results. The current public site does not publish accounts, user profiles, comments, newsletter signup, checkout, or file-upload intake.
Hosting and infrastructure records: a visitor’s browser necessarily requests pages, scripts, styles, metadata, fonts generated through Next.js, Open Graph images, and API responses. Hosting infrastructure may process technical request details such as IP address, user agent, referrer, URL path, timestamp, status code, and performance or security logs. 401kROBS.com cannot honestly describe Vercel’s complete platform retention or use from this repository; readers should review Vercel’s own privacy notice for Vercel-controlled practices.[9]
Provider-match inputs are transient answer options
The provider-match API validates and scores answer options only. The observed input categories are:
- Account type, used only for eligibility cautions and validation.
- Business funding goal.
- Rollover amount range, not an exact balance.
- Expected employee administration range.
- Setup timing preference.
- Service priority.
- Additional financing preference.
- Specialist-support preference.
Current source and public methodology state that the flow does not request contact details, store a lead, send an email, call a CRM, or transmit answers to providers.[1][2] The route returns ranked providers and methodology to the browser. The repository does not show a database write, provider webhook, analytics event, email call, or CRM client in that route.
The match flow should not be used to submit sensitive or private facts. It does not ask for name, email, phone number, mailing address, account number, Social Security number, business name, franchise brand, exact retirement balance, plan document, tax return, bank statement, payroll record, login credential, or marketing consent or provider outreach consent, provider follow-up request, lead source field, CRM identifier, file upload, payment detail, newsletter signup, account password, or free-text private fact.
Cookies, localStorage, and sessionStorage
Searches of the current application source found no first-party analytics script, cookie banner, document.cookie write, cookies() route usage, localStorage persistence, or sessionStorage persistence supporting this privacy page. Several focused tool reviews also accepted no saved scenario, no query persistence, and no local/session storage behavior for selected routes.
This statement is limited to the checked repository state. Browsers, browser extensions, hosting infrastructure, linked websites, and future site changes can have separate storage behavior. The current site should not be described as anonymous, log-free, cookie-proof, or storage-proof beyond what the app source supports.
Analytics, advertising, and external embeds
The current package dependencies are Next.js, React, lucide-react, Radix/shadcn-related UI packages, Tailwind tooling, and TypeScript/ESLint tooling. The checked package does not include Google Analytics, Vercel Analytics, Speed Insights, Meta Pixel, advertising SDKs, tag managers, or payment libraries. Source searches did not find adsbygoogle, DoubleClick, googletag, Google display-ad script, iframe embeds, or a dedicated sponsored-content route.[6]
401kROBS.com currently has no affiliate relationships and does not earn commissions from provider links. A clicked provider link may take the reader to a third party that has its own logs, cookies, tracking, forms, and privacy terms. This site policy does not control those third-party practices.
Third-party links, fonts, images, and server behavior
The site links to IRS, DOL, FTC, provider, professional, and other external pages. Opening an external link leaves 401kROBS.com and may disclose request information to that destination. Current source uses route-local Open Graph image handlers and schema scripts. The root layout imports Geist fonts through next/font/google; Next.js documentation describes next/font as built-in font optimization, and the repository does not show a hand-written Google Fonts link tag.[10]
The app’s observable server behavior is standard Next.js route rendering, static metadata generation, sitemap/robots output, Open Graph image routes, and the provider-match POST route. No custom Express/Fastify server, authentication middleware, payment route, comment route, or public upload route was observed.
Sensitive-data prohibition
Do not submit, paste, encode in URLs, or attempt to route Social Security numbers, retirement-account numbers, tax returns, plan documents, trust agreements, valuation reports, bank statements, payroll files, employee census data, purchase agreements, franchise disclosure documents, litigation records, medical information, login credentials, or confidential provider contracts through ordinary site interactions.[4]
If a question requires those materials, use the relevant provider, plan administrator, ERISA attorney, CPA, valuation professional, lender, payroll provider, government agency, or another secure channel established for that relationship.
Retention, deletion, and security limits
The app source does not show a first-party database write for ordinary pages or for provider-match answers. That supports a narrow current-practice statement: provider-match answers are used to return an immediate response, not stored as a site lead in observed source. It does not prove that hosting logs, CDN records, browser caches, search-engine caches, backups, or third-party destination logs do not exist.
FTC guidance recommends collecting only needed information, retaining it only while there is a legitimate business need, protecting it, and disposing of it securely.[7] 401kROBS.com should not promise a deletion deadline, encryption standard, incident notice process, security certification, or log-retention period that is not implemented and visible from current systems.
Children, international visitors, and state-law boundaries
401kROBS.com is about ROBS business-financing education for adults evaluating retirement-plan and small-business decisions. It is not directed to children, and the current site does not ask for a child’s information. COPPA-specific obligations are cited only to explain why child-directed data collection would require separate treatment; this site does not create that workflow.[8]
The site can be visited from different states or countries, and privacy rights can depend on location, status, data category, and applicable law. This policy does not promise California, Colorado, Connecticut, Virginia, Utah, EU, UK, Canadian, or other statutory coverage, verification, response timing, appeal rights, authorized-agent processing, or regulator-specific disclosures beyond the current no-intake status and observed app behavior.
Privacy rights, requests, and no public intake
Current public routes state that 401kROBS.com has no public privacy-request channel, deletion-request channel, data-subject request workflow, accessibility-report channel, named support inbox, ticket queue, secure portal, or response service level.[3] Opening the Contact page, a policy page, a provider page, a tool, an external source, or a provider link does not submit a privacy request.
If 401kROBS.com later publishes a real privacy intake method, only that future method should be treated as a request channel. A future channel would need separate instructions for identity verification, scope, sensitive-data handling, timing, and response boundaries.
Policy changes and effective date
This Privacy Policy is effective 2026-08-17. Future changes should update the route text, metadata, schema date, sitemap last-modified date, route-local Open Graph representation, footer/header integrations, and focused tests when the observable data practice changes.
A policy update is not proof that past data was collected, deleted, sold, shared, retained, secured, transferred, or reviewed in any way not stated in the version then published.
Sources and verification destinations
Internal sources establish only current observable site behavior and no-intake status. External sources are primary privacy or platform sources used for limited guidance claims, not as a blanket compliance certification.
[1]Provider Match page and POST-only API route
Human-readable Provider Match page for the current match flow. The underlying /api/provider-match route is POST-only: current route code accepts answer options, returns calculated results, and states that it does not request contact details, store a lead, or transmit answers to providers.
[2]Provider match methodology
Current public methodology names the match inputs, says contact details are not collected, and states that leads are not stored or sent to providers.
[3]Contact status
Current no-public-intake route states there is no privacy-request, accessibility-report, deletion-request, data-subject request, or named support inbox on the site.
[4]Request a Correction
Current no-intake route warns against sending Social Security numbers, account records, tax returns, plan documents, payroll files, bank records, contracts, medical details, or credentials through ordinary site interactions.
[6]Advertising Policy
Current advertising policy records no active affiliate relationship and no observed Google display-ad script, adsbygoogle placement, DoubleClick reference, or dedicated sponsored-content route in the checked repository state.
[7]FTC: Protecting Personal Information
Primary FTC business guidance for collecting only needed information, keeping it only as long as there is a legitimate business need, protecting it, and disposing of it securely.
[8]FTC: Children's Online Privacy Protection Rule
Primary FTC rule source for child-directed online-service obligations and parental-consent concepts; cited only to explain that this site is not directed to children.
[9]Vercel Privacy Notice
Vercel’s own privacy notice for its platform practices. This site policy can describe only the repository-observed app behavior, not Vercel’s complete infrastructure handling.
[10]Next.js next/font documentation
Next.js documentation for built-in font optimization. The repository uses next/font/google in the root layout rather than a visible Google Fonts link tag.