Privacy Policy
This Privacy Policy explains how CashflowReviewer ("we", "us") collects, uses, and protects information in connection with the CashflowReviewer service (the "Service"). The Service is a business-to-business tool: our customers are businesses that upload bank-statement data to underwrite commercial deals. By using the Service you agree to this Policy.
1. Information we collect
- Account information — name, email address, firm name, team membership, and login events.
- Customer Data — bank statements, CSVs, forwarded business or application emails, applications, attachments, applicant, broker, owner, business-contact and deal information your business submits for analysis, and the classifications, notes, extracted fields, matches, and results generated from them.
- Business-research data — when you choose Business & risk lookup, the business name, location, known website, and industry hint you confirm, plus the resulting public-source citations, derived business profile, industry estimate, and possible public-court matches. Raw statement transactions and account data are not submitted to this lookup.
- Usage and security data — IP address, approximate location, browser type, timestamps, and credit-usage records, used for security, abuse prevention, metering, and support.
- Legal-acceptance evidence — verified account email and identifier, organization and role, server timestamp, IP address, approximate network-derived location, browser time zone, browser/device information, request identifier, affirmative acceptance actions, and the version, cryptographic hash, and exact snapshot of the Terms and Privacy Policy accepted.
- Local storage — the app caches your own deals in your browser for speed; the cache is wiped on sign-out and when a different account signs in on the same browser.
2. How we use information
- To provide the Service: receive organization-addressed forwarded emails, preserve their originals and attachments in the organization archive, extract application and business fields, identify statement attachments, propose a saved-deal match or new Calc for human confirmation, parse and classify imported statements, compute metrics, store deals for your team, and meter credits.
- At your request, to research a business’s public identity, industry, web footprint, and carefully matched public-court signals, retain the cited result with the deal, and let your authorized team review it later.
- To secure the Service: authentication, tenant isolation (your data is scoped to your account), fraud and abuse detection.
- To administer and prove the agreement: require first-use and updated-terms acceptance, retain an immutable acceptance record, resolve disputes, and comply with legal obligations.
- To support you and to send service communications (e.g., credit balance, account notices).
- To train, test, evaluate, develop, and improve CashflowReviewer using Customer Data, derived information, product outcomes, corrections, feedback, and usage patterns as described below.
3. Product improvement, training, and evaluation
CashflowReviewer is designed to improve as the Service is used. We may retain and use Customer Data and related results to train, test, evaluate, develop, and improve CashflowReviewer, including its statement parsers, transaction classifiers, funder and recurring-obligation detection, scoring and pricing logic, AI-assisted features, reconciliation controls, support tooling, and other product models and workflows.
Training and evaluation materials may include raw or redacted statement text and images; transaction descriptions, dates, amounts and balances; account, institution and layout information; extracted fields; classifications, corrections and rules; deal, pricing and offer outcomes; parser, reconciliation and confidence results; AI inputs and outputs; support and error records; and usage signals. We may combine information and learnings across customers to evaluate the Service and build product-wide improvements.
Where reasonably practicable for the improvement purpose, we minimize, redact, aggregate, or remove direct account, business, organization, and user identifiers before use. Access is restricted to authorized personnel and service providers who need the information for the disclosed purpose. De-identification is a safeguard, not a promise that every retained training or evaluation item is anonymous. Another customer does not receive direct access to your identifiable statements, deals, files, account rules, or pricing records, although generalized patterns learned from many customers may affect shared product behavior.
For statement-layout learning, the Service may also create a privacy-reduced format descriptor containing the detected financial-institution name, generic statement section or column headings, coarse column positions and types, page and parsed-row counts, reconciliation status, and a one-way layout fingerprint. A format descriptor does not contain raw PDF text, transaction descriptions, dollar amounts, balances, account numbers, filenames, merchant or business names, user email addresses, or organization identity. The server filters every descriptor before it can enter the system-wide format queue.
Training and evaluation copies may be retained for as long as reasonably necessary to improve and protect the Service, subject to applicable law. Deleting an operational deal or account does not necessarily remove information already incorporated into a restricted training or evaluation dataset, aggregated or de-identified information, a format descriptor, evaluation result, parser rule, or trained model parameter. We will honor deletion or objection rights where applicable law requires.
4. What we do NOT do
- We do not sell Customer Data or personal information.
- We do not give one customer direct access to another customer's identifiable deals, statements, files, account-level rules, or pricing records. Account rules you create govern only your account, although corrections, outcomes, derived information, and generalized patterns may be used for the product-improvement purposes in Section 3.
- We do not make your submitted deal available to another customer as that customer's underwriting file. This does not prevent shared product features from reflecting generalized improvements learned across customers as described in Section 3.
5. Third-party processors
We use infrastructure and service providers to run, secure, support, and improve the Service. They process data for us under their applicable service terms and for the functions described below:
- Netlify — hosting, authentication, serverless compute, and the organization-scoped platform data and file archive.
- Supabase — an independent private disaster-recovery destination when enabled. Backup objects are compressed and encrypted by CashflowReviewer before transfer; Supabase does not receive the separate application encryption key.
- Google Drive API — optional customer-authorized file mirroring. When your organization connects Drive, CashflowReviewer creates a unique organization folder and may copy uploaded and generated files there. Drive is not required and is not the authoritative application database. Legal-acceptance evidence is also queued for a restricted administrative archive in the software owner's Google Drive account when that owner-controlled connection is configured; the platform's immutable server record remains authoritative if the mirror is delayed or unavailable.
- Resend — optional native email receiving. When an organization owner or manager enables Email intake and forwards an application to the organization-specific address, Resend receives the message and attachments and sends CashflowReviewer a signed delivery notice. The full message and attachments are then retrieved for organization-scoped archiving and review.
- Anthropic — optional AI processing through the organization’s configured API account, used (a) to map an unrecognized CSV column layout (only the header row and a few truncated sample rows are sent), (b) for optional AI review features where offered, (c) for a user-initiated public-web business lookup using only the business identity fields the user confirms, and (d) when native Email intake is enabled, to extract application, business, applicant, broker and attachment-type fields from the forwarded message and supported attachments. Email-intake results remain scoped to the submitting organization and require human review before a statement is imported into a Calc. API data is not used by Anthropic to train models per its commercial API terms.
- Public websites and records surfaced through the lookup provider — the optional Business & risk lookup may retrieve public business-registry, licensing, company-website, industry, news, directory, or court-record pages. CashflowReviewer stores the resulting citations and research output with the authorized organization’s deal; it does not send bank transactions or account data to those public sources.
- Stripe — payment processing, once online checkout is enabled. We never store full card numbers.
6. Third-party data inside statements
Statements you upload typically describe a third-party business (e.g., a merchant applying to you for funding). For that data, your business is the party responsible for having a lawful basis to process it, and we process it only as your service provider to deliver the analysis you requested (see the Terms of Service, Section 4).
7. Retention and deletion
- By default, operational account and deal data are retained while your account is active so your team can re-open past deals. Organization owners can configure file-retention periods in Team settings. Separate product-improvement copies and derived materials are governed by Section 3 rather than those operational file-retention settings.
- You can delete individual deals in the app and export an organization manifest from Team settings.
- An organization owner can request organization deletion in the app. The request has a seven-day recovery window and may be canceled during that period. After the window, organization-scoped operational platform records and files are removed automatically, subject to a legal hold; records required for billing, fraud prevention, security, or law; and product-improvement copies or derived materials retained under Section 3. A connected organization Drive folder is moved to that Drive account's trash where supported.
- Legal-acceptance records, document snapshots, billing records, and related security evidence may be retained after account closure for the period reasonably necessary to establish, exercise, or defend legal claims, enforce agreements, prevent fraud, and meet legal obligations. They are not used for underwriting or marketing.
8. Security
CashflowReviewer uses layered technical and organizational safeguards. The Service runs on Netlify infrastructure; Netlify states that its Blobs storage encrypts data at rest and in transit. CashflowReviewer also uses TLS for network transport, server-verified identity, server-enforced tenant authorization, restricted server-side analysis, file validation, rate and abuse controls, integrity checks and recovery history, and an independently encrypted disaster-recovery copy when that backup is enabled. Optional processors such as Anthropic, Google Drive, Resend, Stripe, and Supabase receive only the information needed for their disclosed functions. Access to production systems is restricted. No method of transmission, storage, or processing is 100% secure, but we use commercially reasonable safeguards and review the Service's security on an ongoing basis.
9. Your choices and rights
- You can access and update account information in the app, export organization metadata, and delete individual deals or request organization deletion.
- Depending on your jurisdiction, you may have rights to access, correct, delete, or port personal information — contact us and we will honor applicable rights.
- The Service is not directed to children and we do not knowingly collect children's data.
10. Changes
We may update this Policy prospectively. When the current legal version changes, every organization owner, manager, and member must affirmatively accept the updated Terms and Privacy Policy before continuing to use authenticated features.
11. Contact
Privacy questions or requests: ml7779@gmail.com.