Privacy Policy
Last updated: July 24, 2026
The short version
Lending firms use LendPacket to collect loan documents from their borrowers. The firm owns that data; we process it only to run the service. We don't sell data, we don't use your data for advertising, and we don't train AI models on your documents.
1. What we collect
- Account data (from lender users): name, work email, password hash, firm name, role, security settings.
- Loan file data (from firms and their borrowers): borrower names and contact details, document checklists, and the documents borrowers upload — which routinely contain sensitive financial information such as tax returns and bank statements. We collect these ON BEHALF OF the lending firm, which is responsible for having a lawful basis to request them.
- Billing data: plan, invoices, and payment status. Card numbers go directly to Stripe; we never see or store them.
- Usage and log data: actions taken in the product (kept in each firm's audit trail), error reports, and basic device information needed to run a secure web application.
- Prospect and support data: if you request our free checklist or contact us, we keep your name, email, and your request; emails you send to our support addresses are stored with your support ticket so we can answer you.
2. How we use it
To provide the service (storing and organizing documents, sending the emails firms configure, AI document review), to secure it (fraud and abuse prevention, audit trails), to bill for it, and to improve it using aggregate, de-identified usage patterns.
AI processing, specifically: when a borrower uploads a document, the full content of that document (the PDF or image itself — not just metadata) is transmitted to our AI subprocessor, Anthropic, so it can be read, classified, and checked; the checklist context needed to file it is sent along with it. File types the AI cannot read are classified from the filename only. AI-drafted reminders send names and outstanding-item lists; questions typed to the in-app assistant send the text you type. All Anthropic processing happens under commercial terms that prohibit training on this data, and review results (including a one-line description of each document) are stored with the document in your firm's workspace.
We also send product and trial emails to lender users about their own account — every marketing email includes a one-click unsubscribe.
3. What we never do
- Sell or rent personal data — anyone's, ever.
- Use borrower documents for advertising or model training.
- Email borrowers for our own purposes: borrowers only receive messages about their loan file, sent on the firm's behalf, in the firm's branding.
4. Who else touches the data (subprocessors)
Supabase (database, storage, authentication — on AWS, US region), Vercel (hosting, US region), Stripe (payments), Resend (email delivery, outbound and inbound support email — US region), Anthropic (AI processing), Sentry (error monitoring, US region). If you choose "Sign in with Google," Google processes that sign-in. Each processes data only to provide its function to us, under contract.
5. Security
Encryption in transit, and at rest via our infrastructure providers; firm-level data isolation enforced at the database layer; borrower access via unguessable, expiring, revocable links stored only as cryptographic fingerprints; role-based permissions and optional two-factor authentication; short-lived signed URLs for every document download; append-only audit trails; upload content screening (file-type verification and executable blocking). LendPacket staff can access a firm's workspace only through an audited, time-limited support mode that shows a visible banner while active. Full details on the Security page.
6. Security incidents
No system can promise it will never be breached, so here is the commitment instead: if we confirm a security incident affecting your firm's data or your borrowers' documents, we will notify affected firms without undue delay — describing what happened, what data was involved, and what we are doing about it — and we will support your firm's own notification obligations under applicable law. Incidents are tracked in our audit and monitoring systems from detection through resolution.
7. Retention and deletion
Firms control their own retention: documents are kept until deleted, and firms may enable an automatic purge policy (with warnings and a permanent deletion record). When an account is terminated, data remains exportable for at least 30 days and is then deleted from production systems on request or per our standard schedule. Backup copies are kept only as needed for disaster recovery and are deleted alongside production data when you ask us to delete.
8. Your rights
Lender users may access, correct, or delete their account data by contacting us. Borrowers: your documents are controlled by the lending firm that requested them — direct requests to that firm, and we will assist it in honoring them. Where privacy laws (e.g., CCPA/CPRA, GDPR) grant you rights directly against us as a processor/service provider, we honor them.
9. Cookies
We use cookies that are necessary to run the service: your sign-in session, security protections, and small preferences (like your board view). Advertising measurement: our public marketing pages use Google Ads and Meta (Facebook/Instagram) conversion tracking — cookies that tell us when a visit from one of our ads leads to a signup or a checklist download, plus a first-party cookie recording which ad campaign (if any) first brought you to our site. If a free trial later becomes a paid subscription, we may confirm that to the ad platform server-side using a one-way hashed email address, so the platform can measure which ads work. Ad personalization is disabled; we do not build advertising profiles, do not use cross-site tracking beyond this measurement, and do not sell personal information. Inside the application itself (and on borrower upload pages) there are no advertising cookies at all.
10. Children
LendPacket is a business tool and not directed at anyone under 18.
11. Changes and contact
LendPacket is operated by Maxivize LLC. Material changes will be announced in the app or by email. Questions or requests: hello@lendpacket.com.