Privacy Policy

Last updated: July 18, 2026

DoneThat LLC (“DoneThat,” “we,” “us,” or “our”) operates the DoneThat website, platform, and related services available through donethat.io.

This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you visit our website, create an account, submit an intake form, request a match, book or participate in an engagement, apply to become an expert, sign an agreement, join a waitlist, or otherwise interact with DoneThat.

By using DoneThat, you acknowledge the practices described in this Privacy Policy.

1. Information we collect

A. Information you provide directly

We may collect information that you provide when you:

  • create or update an account
  • submit an intake or matching form
  • join a waitlist
  • request or accept an expert match
  • book or participate in a session, sprint, project, or ongoing advisory engagement
  • apply to become or participate as an expert
  • sign an agreement
  • submit a review, testimonial, referral, or case-study approval
  • contact customer support
  • communicate with DoneThat or another user
  • subscribe to emails or other communications

The information you provide may include:

  • name
  • email address
  • telephone number
  • account credentials
  • business name
  • job title or role
  • business location
  • industry
  • business stage
  • ownership history
  • approximate revenue range
  • number of locations or employees
  • acquisition or launch date
  • availability
  • scheduling preferences
  • the decision, question, or operating issue for which you are seeking support
  • information about your business objectives, operations, finances, employees, customers, vendors, or plans
  • documents and materials you choose to provide
  • feedback, reviews, testimonials, support requests, and other communications

Documents or materials you provide may include financial summaries, operating reports, leases, vendor proposals, business plans, pricing information, schedules, organizational information, or other records relevant to an engagement.

Please do not submit information that you do not have the right to share. You should avoid submitting Social Security numbers, complete bank-account numbers, health information, personal employee records, customer payment information, or other highly sensitive information unless it is specifically requested, legally permitted, and genuinely necessary.

B. Expert information

If you apply to become or participate as an expert, we may collect:

  • professional and employment history
  • business ownership and operating experience
  • education and qualifications
  • areas of expertise
  • industries and situations in which you have experience
  • professional references
  • profile photographs
  • biography and profile information
  • rates
  • availability
  • scheduling preferences
  • tax and payout information
  • signed agreements
  • communications regarding customers and engagements
  • performance, reliability, and customer-feedback information

We may verify information using references, interviews, publicly available sources, or other reasonable methods.

C. Payment and payout information

Payments and expert payouts are processed by third-party payment providers, including Stripe.

These providers may collect payment-card details, bank-account information, identity-verification information, tax information, billing information, and other information needed to process payments or payouts.

DoneThat may receive transaction information such as:

  • customer name
  • billing contact details
  • payment status
  • transaction amount
  • transaction date
  • payment-method type
  • limited payment-method details
  • payout status
  • refunds
  • disputes
  • chargebacks

DoneThat generally does not receive or store complete payment-card numbers.

Payment providers process information under their own terms and privacy policies.

D. Electronic-signature and agreement information

DoneThat uses DocuSign or similar services to manage and execute certain agreements.

When you receive, review, or sign an agreement, DoneThat and the electronic-signature provider may process:

  • name
  • email address
  • signature
  • initials
  • date and time of signing
  • document contents
  • document status
  • IP address
  • device and browser information
  • authentication and audit-trail information

Electronic-signature providers may process this information under their own terms and privacy policies.

E. Communications and engagement information

We may collect communications between:

  • you and DoneThat
  • customers and experts
  • users and customer support
  • users participating in an engagement

This may include emails, messages, intake responses, scheduling communications, recaps, feedback, complaints, refund requests, and engagement-related documents.

DoneThat does not record or transcribe the substance of a session unless all participants are informed and the required consent has been obtained.

F. Information collected automatically

When you visit or use DoneThat, we and our service providers may automatically collect information such as:

  • IP address
  • browser type
  • device type
  • operating system
  • device identifiers
  • referring website
  • referral or campaign source
  • pages viewed
  • links clicked
  • dates and times of visits
  • approximate location derived from IP address
  • session duration
  • website interactions
  • error and performance information
  • cookie and similar-technology identifiers

G. Advertising and referral information

DoneThat may advertise through third-party services, including Reddit.

Advertising platforms may provide DoneThat with aggregated or campaign-level information such as:

  • advertising impressions
  • clicks
  • campaign names
  • referral sources
  • general campaign performance
  • visits attributable to an advertisement

DoneThat does not currently use the Reddit Pixel, Reddit Conversions API, uploaded Reddit advertising audiences, or similar Reddit tracking technologies on the DoneThat website.

If DoneThat later implements an advertising pixel, conversion API, custom audience, or similar tracking technology, this Privacy Policy will be updated as appropriate.

H. Information from other sources

We may receive information from:

  • customers
  • experts
  • referrals
  • personal or professional contacts
  • alumni networks
  • business organizations
  • publicly available business sources
  • social media
  • public licensing, opening, expansion, or acquisition announcements
  • other people who believe DoneThat may be relevant to you

For example, someone may refer you or your business to DoneThat and provide your name, contact information, business affiliation, and a brief explanation of why DoneThat may be useful.

We may also use publicly available information to identify businesses that may benefit from DoneThat. We will not treat publicly available information as confirmation that a business has a particular private problem.

2. How we use information

We may use information to:

  • operate, maintain, and improve DoneThat
  • create and manage accounts
  • respond to inquiries
  • understand a customer’s question or business situation
  • assess whether DoneThat is appropriate for a customer
  • recommend an expert or engagement format
  • evaluate and vet experts
  • create and display expert profiles
  • confirm expert availability
  • facilitate introductions and matching
  • process intake forms
  • share relevant information with a proposed or selected expert
  • prepare for and administer engagements
  • facilitate scheduling and communications
  • process payments, refunds, fees, and payouts
  • manage agreements and electronic signatures
  • provide customer support
  • investigate complaints
  • resolve payment, quality, attendance, or engagement disputes
  • monitor expert reliability, responsiveness, and quality
  • enforce our Terms of Service and other agreements
  • prevent fraud, misuse, circumvention, and security incidents
  • send confirmations, reminders, recaps, follow-up links, and administrative messages
  • request reviews, testimonials, referrals, or feedback
  • publish approved expert profiles, testimonials, and case studies
  • improve matching, engagement formats, pricing, and customer experience
  • measure website, referral, and advertising performance
  • understand which acquisition sources lead to inquiries or bookings
  • conduct analytics and business research
  • comply with legal, tax, accounting, and regulatory obligations
  • establish, exercise, or defend legal claims
  • protect DoneThat, our users, and others
  • create aggregated or de-identified information that does not reasonably identify an individual or business

We may send promotional or marketing communications where permitted. You may opt out of marketing emails by using the unsubscribe link in the email or contacting us.

You may still receive transactional or administrative messages after opting out of marketing communications.

3. How we disclose information

A. Between customers and experts

When a customer requests a match or books an engagement, we may provide a proposed or selected expert with information reasonably necessary to:

  • evaluate the requested engagement
  • assess fit
  • prepare for the conversation
  • deliver the engagement
  • provide a recap or follow-up
  • recommend an appropriate next step

This may include intake responses, contact information, business information, the customer’s question, and materials submitted for review.

Customers may receive information about an expert’s:

  • identity
  • experience
  • professional history
  • qualifications
  • rates
  • availability
  • areas of expertise
  • engagement offerings
  • approved testimonials or reviews

Users should use information received through DoneThat only for the applicable introduction or engagement and should not disclose it unnecessarily.

B. Service providers

We may disclose information to third-party providers that perform services for DoneThat, including providers supporting:

  • website hosting
  • cloud infrastructure
  • databases and storage
  • authentication
  • payment processing
  • expert payouts
  • electronic signatures
  • agreement management
  • email delivery
  • scheduling
  • video communication
  • analytics
  • advertising
  • customer support
  • fraud prevention
  • security
  • error monitoring
  • legal services
  • accounting
  • tax services
  • insurance
  • other business operations

Examples include Stripe for payments and payouts and DocuSign for electronic signatures and agreement management.

These providers may process information on our behalf or under their own terms and privacy policies.

C. Legal, compliance, and safety disclosures

We may disclose information when we reasonably believe disclosure is necessary to:

  • comply with applicable law
  • comply with a subpoena, court order, governmental demand, or other legal process
  • enforce our Terms of Service or another agreement
  • investigate suspected fraud, abuse, misconduct, or unlawful activity
  • prevent or respond to a security incident
  • protect the rights, property, or safety of DoneThat, our users, or others
  • establish, exercise, or defend legal claims

Where legally permitted and appropriate, we may attempt to notify an affected user before disclosing information in response to legal process.

D. Business transactions

If DoneThat is involved in a financing, merger, acquisition, reorganization, bankruptcy, sale of assets, due-diligence process, or similar transaction, information may be disclosed to potential or actual investors, buyers, advisors, lenders, or other participants.

Any recipient would be expected to handle information consistently with applicable law and any confidentiality obligations.

E. With your direction or consent

We may disclose information when you request, authorize, or consent to the disclosure.

Examples include:

  • approving an introduction
  • requesting that materials be shared with an expert
  • authorizing a referral
  • approving a testimonial
  • participating in a case study
  • permitting use of a name, quotation, logo, or business story
  • requesting direct contact with another user

4. Confidential business information

DoneThat is designed to facilitate private business conversations.

Experts agree through their applicable agreements and the Terms of Service to treat nonpublic customer information confidentially and use it only for the relevant engagement.

However:

  • DoneThat is not a law firm
  • DoneThat is not an accounting firm
  • DoneThat is not a medical provider
  • DoneThat is not a fiduciary
  • communications through DoneThat do not automatically create a legally privileged relationship
  • DoneThat cannot guarantee that another user will never misuse information

Customers remain responsible for deciding what information to disclose.

Do not submit:

  • trade secrets that are unnecessary for the engagement
  • information subject to another person’s confidentiality rights without authorization
  • regulated personal information
  • personal employee records
  • sensitive customer information
  • confidential legal communications
  • data you do not have permission to share

5. Cookies and similar technologies

DoneThat and its service providers may use cookies, local storage, and similar technologies to:

  • operate the website
  • maintain login sessions
  • remember preferences
  • understand website use
  • measure traffic and referrals
  • troubleshoot errors
  • improve performance
  • protect against fraud and abuse

DoneThat may also receive basic referral and campaign information when a user visits through an advertisement or promotional link.

DoneThat does not currently use the Reddit Pixel or Reddit Conversions API.

You may be able to control cookies through your browser settings. Disabling certain cookies may interfere with website functionality.

6. Aggregated and de-identified information

We may aggregate or de-identify information so that it does not reasonably identify a particular individual or business.

We may use and disclose aggregated or de-identified information for:

  • analytics
  • research
  • product development
  • marketplace improvement
  • trend analysis
  • business planning
  • marketing
  • reporting

We will not intentionally re-identify information that has been properly de-identified except where necessary to test or improve the de-identification process or as permitted by law.

7. Data retention

We retain information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to:

  • provide the platform
  • maintain accounts
  • administer engagements
  • process payments and payouts
  • preserve transaction and agreement records
  • comply with tax, accounting, legal, and regulatory obligations
  • resolve disputes
  • enforce agreements
  • detect fraud or abuse
  • maintain security
  • establish or defend legal claims

Retention periods may vary based on:

  • the type of information
  • whether an account remains active
  • whether an engagement is ongoing
  • payment-provider requirements
  • tax and accounting requirements
  • contractual obligations
  • legal requirements
  • fraud-prevention and security needs

When information is no longer reasonably necessary, we may delete, anonymize, or de-identify it.

Information may remain temporarily in backups or archival systems before being overwritten or deleted.

8. Data security

We use reasonable administrative, technical, and organizational measures designed to protect information against:

  • unauthorized access
  • unauthorized disclosure
  • loss
  • misuse
  • alteration
  • destruction

These measures may include access controls, reputable service providers, authentication controls, limited internal access, encrypted transmission where supported, monitoring, and operational safeguards.

No website, storage system, database, or method of transmitting information is completely secure. We cannot guarantee absolute security.

You are responsible for:

  • maintaining the confidentiality of your login information
  • using a secure password
  • protecting access to your email and devices
  • notifying us promptly of suspected unauthorized access

9. Your choices and privacy rights

Depending on where you live and applicable law, you may have the right to request that we:

  • confirm whether we maintain personal information about you
  • provide access to certain personal information
  • correct inaccurate information
  • delete certain information
  • provide a portable copy of certain information
  • restrict or object to certain processing
  • explain certain uses or disclosures

You may also:

  • update certain account information
  • unsubscribe from marketing emails
  • request account closure
  • control certain cookies through your browser
  • withdraw consent where processing depends on consent

To submit a request, email mo@donethat.io.

We may need to verify your identity before processing a request.

We may deny or limit a request where permitted by law, including where information must be retained to:

  • complete a transaction
  • comply with legal or tax obligations
  • preserve payment or agreement records
  • detect fraud or security incidents
  • resolve disputes
  • enforce agreements
  • protect the rights of others

10. Marketing communications

You may opt out of promotional emails by:

  • clicking the unsubscribe link included in the email
  • or contacting mo@donethat.io

Opting out of marketing emails will not prevent DoneThat from sending transactional messages such as:

  • booking confirmations
  • payment notices
  • scheduling communications
  • agreement notices
  • security alerts
  • service updates
  • engagement follow-ups
  • other communications necessary to provide the platform

11. Children

DoneThat is intended for business users who are at least 18 years old.

We do not knowingly collect personal information from children under 18.

If you believe a child has provided information to DoneThat, contact us at mo@donethat.io.

12. International users

DoneThat is operated from the United States.

If you access DoneThat from outside the United States, your information may be transferred to, stored in, and processed in the United States or other countries where our providers operate.

Those countries may have privacy and data-protection laws that differ from the laws of your location.

13. Third-party websites and services

DoneThat may contain links to third-party websites or services.

We do not control and are not responsible for the privacy, security, content, or practices of third parties.

You should review the privacy policies of any third-party service before providing information.

14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time.

When we make changes, we will update the “Last updated” date.

If a change is material, we may provide additional notice through:

  • the website
  • email
  • your account
  • another reasonable method

Your continued use of DoneThat after an updated Privacy Policy becomes effective signifies acknowledgment of the revised policy.

15. Contact us

Questions, requests, or concerns regarding this Privacy Policy may be sent to:

DoneThat LLC
New York, New York
mo@donethat.io

Questions? Contact mo@donethat.io

Talk to someone who's DoneThat.

Find Your Expert →

Full refund if your first session is not useful.