Privacy
Effective June 3, 2026
1. Introduction and Scope
Maccabees Securities LLC (“Maccabees,” “we,” “our,” or “the Firm”) is a registered broker-dealer (CRD# 340041; SEC# 8-71469) and FINRA member firm headquartered in San Francisco, California. The Firm is engaged primarily in investment banking, including underwriting, corporate securities sales, private placements of securities, principal trading, and merger and acquisition (M&A) advisory services.
This Privacy Policy (“Policy”) describes how Maccabees collects, uses, shares, protects, and, where required, disposes of nonpublic personal information (“NPI”) and customer information in accordance with:
- Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer Information (17 C.F.R. Part 248), including the amendments adopted by the SEC on May 16, 2024, which became fully applicable to smaller broker-dealers on June 3, 2026;
- The Gramm-Leach-Bliley Act (15 U.S.C. §§ 6801–6809);
- SEC Regulation S-ID (Identity Theft Red Flags), where applicable; and
- Applicable FINRA rules, including FINRA Rules 3110 and 4370.
This Policy applies to all current, former, and prospective customers of Maccabees, as well as any individuals whose NPI the Firm receives in connection with its business activities, including counterparties in M&A transactions, investors in private placements, and other transaction participants.
2. About Our Business Model
Maccabees conducts four primary lines of business as reflected in its FINRA registration:
- Underwriting and Selling Group Participation — The Firm participates as underwriter or selling group member in offerings of corporate securities (other than mutual funds), including equity and debt capital markets transactions.
- Trading Securities for Own Account (Principal Trading) — The Firm engages in proprietary trading and may act as principal in certain transactions.
- Private Placements of Securities — The Firm arranges and facilitates exempt securities offerings under Regulation D, Rule 144A, and other applicable exemptions.
- Merger and Acquisition Advisory — The Firm provides M&A advisory services to corporate clients, which may involve receipt and use of material nonpublic information subject to strict confidentiality and information barrier protocols.
Important characteristics of our business: Maccabees does not hold or maintain customer funds or securities; does not introduce or refer customers to other broker-dealers; does not maintain customer brokerage accounts or retail investment accounts; and is not affiliated with any bank, savings institution, or credit union.
Because Maccabees is primarily an institutional and capital markets firm rather than a retail broker-dealer, the NPI we collect is generally limited in scope compared to a full-service retail firm. Nevertheless, we are fully committed to the highest standards of information privacy and security for all individuals whose information we handle.
3. Information We Collect
Depending on the nature of our relationship with you, we may collect the following categories of nonpublic personal information:
- Identifying Information: Full legal name, date of birth, Social Security number or taxpayer identification number (TIN), government-issued identification numbers, passport or driver’s license information, and country of citizenship.
- Financial Information: Net worth, annual income, investment experience, source of funds, bank account information, wire transfer details, and financial statements.
- Transaction Information: Securities transaction history, investment preferences, participation in specific offerings or placements, and transaction documentation.
- Contact Information: Business and personal addresses, telephone numbers, email addresses, and related communication data.
- AML/KYC Information: Information collected in connection with our anti-money laundering (AML) compliance program and know-your-customer (KYC) procedures, including beneficial ownership certifications and accredited investor verification.
- Professional and Business Information: Corporate affiliation, title, employer information, and professional background relevant to transaction due diligence.
- Sensitive Customer Information (as defined under amended Reg S-P): Including Social Security numbers, account credentials, financial account numbers, and government identification numbers.
We collect information directly from you (in connection with account opening, transaction onboarding, or service engagement); from publicly available sources, databases, and third-party data providers; through our electronic communications, website, and other digital channels; and from affiliated entities, third parties acting on your behalf, and regulators, where required or permitted by law.
4. How We Use Your Information
Maccabees uses the information we collect for the following purposes:
- Executing and administering transactions, including securities offerings, placements, and advisory engagements;
- Conducting AML, KYC, and other regulatory compliance obligations under FINRA rules, SEC regulations, and applicable federal and state law;
- Verifying your identity and accredited investor or qualified purchaser status where required for exempt offerings;
- Communicating with you regarding transactions, account activity, regulatory matters, and other business-related purposes;
- Maintaining books and records in accordance with SEC Rule 17a-3, Rule 17a-4, and applicable FINRA recordkeeping rules;
- Evaluating and managing our business risks, including credit and counterparty risk; and
- Complying with legal and regulatory obligations, court orders, and governmental investigations.
5. Sharing of Your Information
Permitted disclosures. We may share your NPI only as permitted or required by law, including with service providers and vendors who perform services on our behalf (subject to contractual confidentiality and data protection requirements); with regulators, self-regulatory organizations (including FINRA and the SEC), law enforcement, or governmental authorities when required by law, rule, regulation, subpoena, or court order; with other parties to a transaction (e.g., co-placement agents, underwriters, issuer counsel) to the extent necessary to complete the transaction and consistent with applicable law; as part of a merger, acquisition, or sale of all or substantially all of the Firm’s assets; and with your explicit written consent.
Information barriers. Given our M&A advisory business, the Firm maintains information barriers designed to prevent the improper flow of material nonpublic information between business units and to prevent misuse of such information in securities transactions. All personnel are required to comply with the Firm’s Information Barrier Policy.
We do not sell your information. Maccabees does not sell, rent, or trade your nonpublic personal information to any third party for marketing or other commercial purposes.
Opt-out rights. To the extent required by Regulation S-P, you have the right to opt out of certain disclosures of your NPI to nonaffiliated third parties. Because Maccabees generally does not share your NPI with nonaffiliated third parties for purposes beyond those described above, an opt-out mechanism may not be applicable in most circumstances. If a sharing arrangement arises that triggers opt-out rights, we will provide you with the required notice and opt-out opportunity prior to such sharing.
6. Safeguarding Customer Information (Amended Reg S-P)
In accordance with the SEC’s May 2024 amendments to Regulation S-P, effective for smaller broker-dealers as of June 3, 2026, Maccabees has adopted and maintains a comprehensive written information security program designed to protect the security, confidentiality, and integrity of customer information. The program includes:
- Written policies and procedures reasonably designed to protect customer information against unauthorized access, use, disclosure, or misappropriation; ensure secure disposal of customer information no longer needed for business or regulatory purposes; address privacy and security risks arising from remote work, mobile devices, and cloud-based systems; establish and enforce role-based access controls and least-privilege principles; require multifactor authentication (MFA) for all systems containing customer information; and undergo annual review to address evolving threats and regulatory requirements.
- Periodic risk assessments to identify systems, applications, and environments where customer information is stored, processed, or transmitted; evaluate vulnerabilities in email platforms, CRM systems, deal management tools, and cloud storage; identify internal and external threats to the confidentiality, integrity, and availability of customer information; and document risk mitigation strategies, updated at least annually or upon material business or technology change.
- Technical and administrative access controls, including role-based access limits on a need-to-know basis; mandatory MFA for all systems housing sensitive customer information; periodic access reviews; and immediate revocation upon termination or change in job responsibilities.
- Annual privacy and cybersecurity training for all personnel with access to customer information, including phishing awareness, secure data handling, and incident reporting; training upon hire and on material changes to this Policy; and specific training on material nonpublic information and information barrier protocols for M&A advisory personnel.
7. Incident Response Program
Pursuant to amended Regulation S-P, Maccabees has adopted a written Incident Response Program (IRP) designed to detect, respond to, and recover from unauthorized access to or use of customer information. The IRP includes a designated Incident Response Team with defined roles; monitoring and detection tools; assessment and escalation procedures aligned with the definition of “sensitive customer information” under amended Reg S-P; containment, eradication, and recovery protocols; and post-incident review.
Notification obligations. In the event of a breach or unauthorized access to or use of sensitive customer information, Maccabees will notify affected individuals as soon as practicable, but no later than 30 days after determining that a breach has occurred or is reasonably likely to have occurred. The notification will describe the nature of the incident in plain language, the categories of information involved, the steps the Firm is taking, and recommended protective measures. Maccabees will also notify relevant regulators (SEC, FINRA) as required and maintain records of all notifications, regulatory reports, and remediation actions.
Note: The 30-day notification period may be extended by up to 30 additional days only if the U.S. Attorney General determines in writing that immediate notification would pose a substantial risk to national security or public safety.
8. Disposal of Customer Information
In accordance with the Safeguards Rule under amended Regulation S-P, Maccabees maintains written procedures for the secure disposal of customer information, including shredding or otherwise rendering unreadable any paper documents containing NPI when no longer required; secure electronic deletion using industry-standard methods (e.g., NIST SP 800-88 Guidelines for Media Sanitization); and contractual requirements for service providers to securely dispose of customer information upon termination of their engagement.
Customer information will be retained for the periods required by applicable law and regulation, including SEC Rule 17a-4 (three-year minimum retention for most records, with the first two years in an accessible location), and disposed of only after all regulatory retention periods have been satisfied.
9. Service Provider Oversight
Maccabees recognizes that it retains responsibility for the protection of customer information even when handled by third-party service providers. Our oversight program includes initial due diligence (evaluating cybersecurity controls, SOC 2 Type II reports or equivalent certifications, incident response capabilities, and regulatory compliance posture); contractual requirements (confidentiality and data protection obligations at least as protective as this Policy; a requirement that the provider notify Maccabees as soon as possible, and no later than 72 hours, after becoming aware that a breach in security has occurred resulting in unauthorized access to a customer information system maintained by the provider, consistent with 17 C.F.R. § 248.30(a)(5); audit rights; and secure return or destruction upon termination); and ongoing monitoring (annual security questionnaires or attestations, review of updated SOC reports, monitoring of vendor-reported incidents, and re-evaluation upon material vendor changes).
10. Recordkeeping
Maccabees maintains records related to its privacy and information security program in accordance with applicable regulatory requirements, including written policies, procedures, and amendments; records of risk assessments and security reviews; documentation of incidents, breach notifications, and remediation actions; vendor due diligence records and service provider contracts; and training records and certifications. Records are retained for the periods required under SEC Rule 17a-4 and other applicable regulations, and are subject to examination by FINRA, the SEC, and applicable state securities regulators.
11. Your Rights Regarding Your Information
To the extent required or permitted by applicable law, you may have the following rights with respect to your NPI:
- Access: You may request confirmation of the categories of NPI we hold about you.
- Correction: You may request correction of inaccurate information we maintain about you.
- Opt-Out: You may have the right to opt out of certain third-party sharing of your NPI, as described in Section 5.
- Data Security Inquiries: You may contact the Firm’s CCO with questions about our data security practices.
To exercise any of these rights, or to ask questions about this Policy, please contact our Chief Compliance Officer using the information below.
12. Annual Privacy Notice
Regulation S-P requires that covered institutions provide customers with an initial privacy notice at the time of establishing a customer relationship and, in some circumstances, annual privacy notices thereafter. Maccabees will provide initial and any required annual privacy notices in compliance with applicable Regulation S-P requirements. Where Maccabees qualifies for the “no-change” annual notice exception (i.e., our privacy practices have not changed and we do not share NPI with nonaffiliated third parties in a manner requiring opt-out), we may deliver the annual notice through a means permitted under the revised rule, including electronic delivery.
13. Amendments to This Policy
Maccabees reserves the right to amend this Policy at any time in response to changes in applicable law, regulatory guidance, or business practice. Material amendments will be communicated to affected customers in the manner required by Regulation S-P and other applicable regulations. The current version of this Policy will be maintained in the Firm’s books and records and made available upon request.
14. Regulatory Compliance
This Policy has been reviewed and approved by the Firm’s Chief Compliance Officer and is designed to satisfy the requirements of Regulation S-P, 17 C.F.R. Part 248 (including the May 2024 amendments effective for smaller entities June 3, 2026); the Gramm-Leach-Bliley Act, 15 U.S.C. §§ 6801–6827; SEC Regulation S-ID, 17 C.F.R. Part 248, Subpart C (where applicable); FINRA Rule 3110 (Supervision); FINRA Rule 4370 (Business Continuity Plans and Emergency Contact Information); and SEC Rules 17a-3 and 17a-4 (Books and Records).
Contact & Questions
Questions, concerns, or requests regarding this Privacy Policy or the Firm’s privacy and data security practices should be directed to:
Attn: Chief Compliance OfficerMaccabees Securities LLC
365 Toni Stone Crossing, Suite 206
San Francisco, CA 94158
compliance@themaccabees.com
Telephone: (510) 214-6756
Customers experiencing a security incident or suspected unauthorized access to their information should contact the CCO immediately at the address and telephone number above.