Skip to main content
401kROBSCheck eligibility
Privacy Policy

Privacy Policy for current 401kROBS.com data practices

Direct answer: 401kROBS.com currently publishes educational pages, calculators, directories, trust pages, and a provider-match API. The observed app does not publish accounts, comments, newsletter signup, checkout, file upload, public contact forms, or a public privacy-request intake. The provider-match endpoint receives selected answer options to calculate immediate results; current source says it does not request contact details, store a lead, or transmit answers to providers.[1][2][3]

Published and reviewed by Dennis Shirshikov. Effective and last updated 2026-08-17.

Site data: selected provider-match options and ordinary technical request data are the current data categories this policy can identify from code.

No sensitive intake: do not paste or route Social Security numbers, retirement-account records, tax returns, plan documents, payroll files, bank records, contracts, medical details, or credentials through ordinary site interactions.

No legal promise: this policy describes observed current practices; it is not a privacy-law compliance opinion, data-processing agreement, security certification, or response-service promise.

Current-practice summary

This policy is grounded in the current repository and public trust routes checked for this page. It distinguishes data the app intentionally asks for from data that may be created by normal hosting and browser requests. It does not claim that every production edge log, deployment platform record, browser extension, network operator, search engine, or linked third party is controlled by 401kROBS.com.

Ordinary page visits

The Next.js app serves public pages, trust pages, tools, provider pages, metadata, JSON-LD, and route-local Open Graph image routes. The repository does not define accounts, logins, checkout, comments, newsletter signup, or a sitewide user database.

Provider-match answers

The only App Router API route currently observed is /api/provider-match. It accepts a POST JSON object with answers, validates allowed option values, calculates immediate provider rankings, and returns results, methodology, an eligibility note, and privacy copy.

No contact intake

Current Contact and Request a Correction routes state there is no public general, editorial, correction, provider, commercial, privacy, accessibility, deletion, or data-subject request channel.

Browser-only tools

Repository source includes many calculators and worksheets. Focused tool reviews and source patterns show tool pages use browser state and native form interactions rather than accounts or saved scenarios, subject to each route's current implementation.

Categories collected by the site versus hosting infrastructure

Site-requested information: the provider-match flow asks for selected option values. Public pages and tools may process form or control values in the browser to display local results. The current public site does not publish accounts, user profiles, comments, newsletter signup, checkout, or file-upload intake.

Hosting and infrastructure records: a visitor’s browser necessarily requests pages, scripts, styles, metadata, fonts generated through Next.js, Open Graph images, and API responses. Hosting infrastructure may process technical request details such as IP address, user agent, referrer, URL path, timestamp, status code, and performance or security logs. 401kROBS.com cannot honestly describe Vercel’s complete platform retention or use from this repository; readers should review Vercel’s own privacy notice for Vercel-controlled practices.[9]

Provider-match inputs are transient answer options

The provider-match API validates and scores answer options only. The observed input categories are:

  • Account type, used only for eligibility cautions and validation.
  • Business funding goal.
  • Rollover amount range, not an exact balance.
  • Expected employee administration range.
  • Setup timing preference.
  • Service priority.
  • Additional financing preference.
  • Specialist-support preference.

Current source and public methodology state that the flow does not request contact details, store a lead, send an email, call a CRM, or transmit answers to providers.[1][2] The route returns ranked providers and methodology to the browser. The repository does not show a database write, provider webhook, analytics event, email call, or CRM client in that route.

The match flow should not be used to submit sensitive or private facts. It does not ask for name, email, phone number, mailing address, account number, Social Security number, business name, franchise brand, exact retirement balance, plan document, tax return, bank statement, payroll record, login credential, or marketing consent or provider outreach consent, provider follow-up request, lead source field, CRM identifier, file upload, payment detail, newsletter signup, account password, or free-text private fact.

Cookies, localStorage, and sessionStorage

Searches of the current application source found no first-party analytics script, cookie banner, document.cookie write, cookies() route usage, localStorage persistence, or sessionStorage persistence supporting this privacy page. Several focused tool reviews also accepted no saved scenario, no query persistence, and no local/session storage behavior for selected routes.

This statement is limited to the checked repository state. Browsers, browser extensions, hosting infrastructure, linked websites, and future site changes can have separate storage behavior. The current site should not be described as anonymous, log-free, cookie-proof, or storage-proof beyond what the app source supports.

Analytics, advertising, and external embeds

The current package dependencies are Next.js, React, lucide-react, Radix/shadcn-related UI packages, Tailwind tooling, and TypeScript/ESLint tooling. The checked package does not include Google Analytics, Vercel Analytics, Speed Insights, Meta Pixel, advertising SDKs, tag managers, or payment libraries. Source searches did not find adsbygoogle, DoubleClick, googletag, Google display-ad script, iframe embeds, or a dedicated sponsored-content route.[6]

401kROBS.com currently has no affiliate relationships and does not earn commissions from provider links. A clicked provider link may take the reader to a third party that has its own logs, cookies, tracking, forms, and privacy terms. This site policy does not control those third-party practices.

Sensitive-data prohibition

Do not submit, paste, encode in URLs, or attempt to route Social Security numbers, retirement-account numbers, tax returns, plan documents, trust agreements, valuation reports, bank statements, payroll files, employee census data, purchase agreements, franchise disclosure documents, litigation records, medical information, login credentials, or confidential provider contracts through ordinary site interactions.[4]

If a question requires those materials, use the relevant provider, plan administrator, ERISA attorney, CPA, valuation professional, lender, payroll provider, government agency, or another secure channel established for that relationship.

Retention, deletion, and security limits

The app source does not show a first-party database write for ordinary pages or for provider-match answers. That supports a narrow current-practice statement: provider-match answers are used to return an immediate response, not stored as a site lead in observed source. It does not prove that hosting logs, CDN records, browser caches, search-engine caches, backups, or third-party destination logs do not exist.

FTC guidance recommends collecting only needed information, retaining it only while there is a legitimate business need, protecting it, and disposing of it securely.[7] 401kROBS.com should not promise a deletion deadline, encryption standard, incident notice process, security certification, or log-retention period that is not implemented and visible from current systems.

Children, international visitors, and state-law boundaries

401kROBS.com is about ROBS business-financing education for adults evaluating retirement-plan and small-business decisions. It is not directed to children, and the current site does not ask for a child’s information. COPPA-specific obligations are cited only to explain why child-directed data collection would require separate treatment; this site does not create that workflow.[8]

The site can be visited from different states or countries, and privacy rights can depend on location, status, data category, and applicable law. This policy does not promise California, Colorado, Connecticut, Virginia, Utah, EU, UK, Canadian, or other statutory coverage, verification, response timing, appeal rights, authorized-agent processing, or regulator-specific disclosures beyond the current no-intake status and observed app behavior.

Privacy rights, requests, and no public intake

Current public routes state that 401kROBS.com has no public privacy-request channel, deletion-request channel, data-subject request workflow, accessibility-report channel, named support inbox, ticket queue, secure portal, or response service level.[3] Opening the Contact page, a policy page, a provider page, a tool, an external source, or a provider link does not submit a privacy request.

If 401kROBS.com later publishes a real privacy intake method, only that future method should be treated as a request channel. A future channel would need separate instructions for identity verification, scope, sensitive-data handling, timing, and response boundaries.

Policy changes and effective date

This Privacy Policy is effective 2026-08-17. Future changes should update the route text, metadata, schema date, sitemap last-modified date, route-local Open Graph representation, footer/header integrations, and focused tests when the observable data practice changes.

A policy update is not proof that past data was collected, deleted, sold, shared, retained, secured, transferred, or reviewed in any way not stated in the version then published.

Sources and verification destinations

Internal sources establish only current observable site behavior and no-intake status. External sources are primary privacy or platform sources used for limited guidance claims, not as a blanket compliance certification.

[1]Provider Match page and POST-only API route

Human-readable Provider Match page for the current match flow. The underlying /api/provider-match route is POST-only: current route code accepts answer options, returns calculated results, and states that it does not request contact details, store a lead, or transmit answers to providers.

[2]Provider match methodology

Current public methodology names the match inputs, says contact details are not collected, and states that leads are not stored or sent to providers.

[3]Contact status

Current no-public-intake route states there is no privacy-request, accessibility-report, deletion-request, data-subject request, or named support inbox on the site.

[4]Request a Correction

Current no-intake route warns against sending Social Security numbers, account records, tax returns, plan documents, payroll files, bank records, contracts, medical details, or credentials through ordinary site interactions.

[6]Advertising Policy

Current advertising policy records no active affiliate relationship and no observed Google display-ad script, adsbygoogle placement, DoubleClick reference, or dedicated sponsored-content route in the checked repository state.

[7]FTC: Protecting Personal Information

Primary FTC business guidance for collecting only needed information, keeping it only as long as there is a legitimate business need, protecting it, and disposing of it securely.

[9]Vercel Privacy Notice

Vercel’s own privacy notice for its platform practices. This site policy can describe only the repository-observed app behavior, not Vercel’s complete infrastructure handling.

[10]Next.js next/font documentation

Next.js documentation for built-in font optimization. The repository uses next/font/google in the root layout rather than a visible Google Fonts link tag.

Use this policy as a current-state map

The safe rule is simple: do not send private records through ordinary site interactions, and do not treat policy links as request channels.

Check no-intake status