Privacy notice.

What we collect about the people we work with, where it comes from, who receives it, how long we keep it, and how to reach a person about it. Our separate policy on how we use AI is at How We Use AI; where the two overlap, that document is the more precise one and it governs.

1. Who we are and what this covers

Bambu Capital Management, LLC, a Delaware limited liability company ("Bambu Capital", "we"), is a private equity firm with offices in Boston, Massachusetts and Boca Raton, Florida. This notice covers this website, our investor data room and portal, and the internal systems we run to manage relationships with investors, companies and the people at them. It does not cover software our counterparties choose to run.

Effective date: 8 September 2026. Version 1.0.

2. What we collect, and where it comes from

From you directly. Your name, firm, email address, the kind of inquiry you select, and your message when you use the investor inquiry form (if delivery fails, a copy may appear in our hosting provider's logs). Your role and contact details when you sign a confidentiality agreement or join our data room, and a phone number if you enrol in SMS sign-in codes. Questions you ask the data room assistant, and its answers, are recorded with your email address, organisation and role, and are readable by our team.

From our own correspondence. Our partners connect their own Microsoft 365 mailboxes to our systems. Each partner chooses whether Inbox and Sent are read, how far back the first read looks (90 days by default), and the scope: mail whose senders or recipients include an address or web domain on one of our investor or deal records, or all mail with anyone outside bambu-capital.com. Each partner also chooses the depth: the sender, To and Cc addresses and the date; the subject line as well; the opening of the message (up to 1,000 characters, 300 by default); or the full text, up to 20,000 characters. The system records whether a message carried attachments, never the attachments, their names or blind-copy recipients. Messages that look like sign-in codes, password resets or wire instructions are never kept, and threads whose every participant is at bambu-capital.com are not captured. Switching capture off stops further reading but keeps what was captured until the partner deletes it or the retention window expires. Matched correspondence, including any stored text, is visible to everyone at our firm with CRM access.

With a separate consent, the same connection reads the partner's calendar and keeps each meeting's time, subject, organiser name and address, attendee addresses, whether it was online and the partner's own response, never notes, locations or join links. With a further write grant, Bambu OS can place invitations into that partner's calendar on the partner's instruction.

Two further steps are each switched on by the partner. One writes the people they correspond with at a firm's own web domain directly onto that firm's record as contacts, without review (name and email address, plus a title and phone number when a rule-based reading of the person's own signature finds them, which needs full-text depth); anyone at our firm can remove such a contact. The other proposes frequent correspondents as network contacts, or adds them directly when the partner so chooses, using a firm or phone number the person stated in their own sign-off.

From meetings we record. Some meetings are recorded and transcribed by Fellow, a third-party notetaker. Participants are told at the time: the notetaker announces itself when it joins. Transcripts and notes may be brought into our records and may be sent to an AI provider as our AI policy describes.

From our partners' professional networks. Our partners upload their own LinkedIn connections (name, firm, title, profile address, the email address where LinkedIn includes it, and when they connected) and their address books (the LinkedIn contacts file and Apple Contacts: names, email addresses, phone numbers, firms and titles). Address-book entries are matched to people already in our records by name and fill in missing email addresses and phone numbers.

From a licensed business-data provider. For people on our active relationship records, we may look up professional contact details from a licensed provider of business contact data: work and personal email addresses, a phone number, current title and firm, the person's location, a LinkedIn profile address and the firm's web domain. We send the provider a person's LinkedIn profile address, or an email address we already hold, or their name and firm. When we ask the provider to identify a person from a name and firm, its list of candidates stays on the record for one day so a repeat request costs nothing, and a member of our team picks one candidate or none. Each month we ask the provider which of the people we hold have changed jobs or have opted out; a change becomes a proposal, an opt-out is applied at once. For batch lookups we check results against the provider's published opt-out list, refreshed monthly, before anything is queued or accepted, and when that list later names a person we remove the email addresses, phone number and location we took from the provider. Results are proposals in a review queue; nothing reaches a person's record until a member of our team accepts it, but the proposal itself, holding the provider's email addresses, phone number and location, stays in our database in every state, including declined, until a purge removes it. Each accepted value is recorded with the provider's record identifier; that identifier lets us remove the email addresses, phone number and location, while titles, firms and profile addresses taken from the provider are retained as professional information. We will name the provider where the law requires it, or once the provider has agreed to be named, which we have asked for. Provider data is never used to evaluate anyone for employment, credit, insurance or housing; the provider's terms require this, and our software keeps provider-sourced titles and firms out of our executive-role searches.

From the open web. Public information about firms. For one feature, finding a single contact's public LinkedIn profile address, a button first checks our own records and, where a vendor key exists, queries the business-data provider by that person's email address; failing those, it sends the person's name, the firm name on their record and that firm's web domain (or the domain of their email address when the record has no website) to our AI provider, which runs up to three searches on a search engine. Only a profile address the search actually returned is offered, the email address is never sent to the AI provider, and the address is kept only when a team member saves the record. This lookup keeps only a public profile address, which is not tracked by provider identifier, so the opt-out check above does not apply to it.

People we have not met. For an investor firm we are approaching that has no contact on our records, we may ask the provider for the people who lead investment allocation there. They are proposals until a member of our team accepts them, they carry the same provider identifier and opt-out handling as everyone else, and whether we write to them is a decision a person makes. We also buy facts about firms themselves (size, founding year, industry, location); that is information about a company, not a person.

From this website. Our public pages set no cookies of their own and load no advertising or tracking scripts. Our typefaces are served by Google Fonts, so Google receives the font request from your browser. Our hosting provider, Cloudflare, records requests to the site (address, browser, pages requested) in its logs and aggregate traffic figures, which we use to keep the site running. We do not track visitors across other sites and do not change our behaviour in response to browser Do Not Track or Global Privacy Control signals. Signing in to the data room or Bambu OS sets one session cookie (bambu_sess, sent to every bambu-capital.com subdomain, up to seven days; twelve hours for Bambu OS sign-ins) used only to keep you signed in; the session record holds your IP address and browser. Connecting a mailbox sets a short-lived second cookie for that step only.

3. What we use it for

We do not sell personal information, and we do not share it for anyone else's advertising.

4. Who receives it

Our systems run on Cloudflare. Our email and calendars run on Microsoft 365; a partner's outbound mail from Bambu OS goes through that partner's own Microsoft 365 mailbox. Copies of some of our records are committed to a private GitHub repository as backups. Resend delivers our inquiry form, data room notifications, agreement records, outreach and support mail; a copy of every data room email is kept in our outbox record. Twilio Verify receives a phone number to send SMS sign-in codes where a data room user enrols one. Fellow holds the recordings and transcripts of meetings we record with it; its sub-processors are listed in our AI policy.

Some of what we hold is sent to AI providers for the purposes and under the limits in our AI policy, which names each provider and what it receives. In the data room, your question and the document passages used to answer it go to the AI provider named there. When a team member asks for a briefing on a record, up to twelve of the most recent messages captured on it from their own mailbox go to our AI provider (subject, the stored opening of up to 1,000 characters, direction, date, and a display name or stand-in label), together with the record's own facts and its message, reply and meeting statistics; never email addresses, recipient lists or attachments. A separate book-level briefing sends record names, owners and stages only.

Purchased contact details are used only inside our team's tools. They are not shown in the data room, not given to another investor or counterparty, and not exported to anyone else; our software withholds them from every outside-facing view, except that a profile address saved to a record travels with our record backups.

We share information with our lawyers, accountants and auditors when our work requires it, and with authorities when the law requires it.

5. How long we keep it

Relationship records, including data room records, are kept for as long as our firm exists, or until we delete them on request. Captured messages and meetings are removed during the mailbox's regular sync once older than the window each partner sets, between 30 days and three years, one year by default; a switched-off mailbox is swept only when reconnected, or when the partner uses the erase control, which also removes the derived items the sweep does not touch (relationship scores, cached briefings, activity entries and contacts added to records). Purchased email addresses, phone numbers and locations are kept while our licence with the provider is live; when the licence ends, or when the provider's opt-out list names the person, we remove them by the provider's record identifier; titles, firms and profile addresses taken from the provider are retained as professional information. In the data room, sign-in, agreement, assistant and email logs are retained after an account is deleted, as compliance records.

6. Your choices and rights

You may ask what we hold about you, where it came from, or ask us to correct or delete it. Write to ir@bambu-capital.com; a person, not a form, will answer. We may ask you to verify your identity, and we will reply within 45 days. If your state's law gives you rights over personal information held by businesses, we will honour them as the law provides. If you are in the European Union or the United Kingdom, you have the rights your law provides, including access, correction, erasure and objection; write to the same address. If you do not want to hear from us about our funds, say so and we will stop.

7. Security

Access to our systems is limited to our team, to investors and their advisers granted access to the data room, to external reviewers granted read-only access to a document index, to people at companies we are evaluating or have invested in who are granted a portal for their own company, and to fundraising agents we engage; our own monitoring robot accounts also sign in to check the systems are up. We maintain administrative, technical and physical safeguards appropriate to the information we hold, including encryption in transit and at rest with our providers. In the data room, sign-ins are recorded with the time, IP address and browser; your agreement acceptance record shows the IP address it was accepted from; document opens and downloads are logged; and PDF and Office documents you view or download are stamped with your name, email address and the time.

8. People under 18

Our services are for professional investors and companies. We do not knowingly collect information about anyone under 18.

9. Changes

When this notice changes materially we will update the date above and note what changed here.

Changes: version 1.0 (8 September 2026), first publication.

Questions About This Notice

A person will answer.

Ask what we hold, where it came from, or ask us to delete it. Requests are handled by a person, not a form.

Contact us →