Legal
Privacy Policy
Last updated: July 11, 2026
This Privacy Policy explains how LoanConsole handles information in connection with the public website, the LoanConsole application, and related services.
LoanConsole provides business software to private lenders. Customers enter information about their own organizations, loans, borrowers, investors, properties, payments, documents, and servicing activity.
For customer-entered borrower, investor, and similar records, the customer generally determines why and how the information is used, and LoanConsole processes it to provide the Service. For account, billing, website, and support information collected for LoanConsole’s own operations, LoanConsole determines the relevant purposes described below.
1. Information we handle
Account and organization information
We may handle names, work email addresses, organization names, roles, phone numbers, job titles, business contact information, authentication status, and account preferences.
Customer content
Customers may enter or upload loan terms, borrower and investor names and contact information, property details, financial figures, payment records, fees, reserves, statements, payoff records, notes, documents, and imported spreadsheets. Because free-text and uploaded documents can contain information chosen by a customer, customers should submit only information they are authorized to process.
Authentication and security information
We handle password hashes, session and refresh-token information, email-verification and password-reset activity, MFA status, protected TOTP secrets, hashed recovery codes, login attempts, security logs, and IP-derived rate-limiting information.
Billing information
Subscription checkout and card entry are handled by Stripe. LoanConsole does not store full card numbers. We retain subscription status and provider identifiers needed to administer billing.
Communications and support
We may handle emails, support requests, transactional-message records, document-delivery metadata, invitation activity, and information you choose to include when contacting us.
Technical and website information
We may collect device and browser information, IP address, request and error logs, page and referral information on public marketing pages, and diagnostic information needed to operate and protect the Service.
2. How information is collected
We receive information:
-
directly from account holders and invited users;
-
from customers who enter or import borrower, investor, loan, and servicing records;
-
from borrower or investor portal users who authenticate to a customer-provisioned account;
-
automatically from browsers, devices, servers, and security systems;
-
from operational providers such as Stripe, Resend, and hosting or monitoring services.
We do not purchase borrower or investor information from data brokers.
3. How we use information
We use information to:
-
create and administer accounts and workspaces;
-
provide loan-servicing calculations, records, documents, portals, exports, and related product functions;
-
authenticate users, prevent abuse, investigate security events, and enforce access controls;
-
process subscriptions and administer billing;
-
deliver transactional email, invitations, password resets, and customer-directed documents;
-
provide support and respond to questions;
-
monitor reliability, diagnose errors, and improve the Service;
-
comply with law and protect the rights, security, and integrity of LoanConsole, our customers, and others.
We do not use customer loan-book content for advertising.
4. Customer content and third-party requests
Customers are responsible for the information they submit and for providing legally required notices or obtaining legally required permissions.
If you are a borrower, investor, guarantor, or other person whose information was entered by a LoanConsole customer, contact that lender first regarding access, correction, or deletion. LoanConsole will assist the customer with valid requests where reasonably required.
5. How information is disclosed
We disclose information only as needed to operate the Service, follow customer instructions, comply with law, address security or fraud, enforce agreements, or complete a corporate transaction subject to appropriate protections.
Current operating providers include:
-
Stripe — subscription checkout and billing
-
Neon — managed PostgreSQL database hosting
-
Render — backend and API hosting
-
Vercel — website and frontend hosting
-
Cloudflare — DNS, network delivery, TLS, and inbound email routing
-
Resend — transactional email and customer-directed document delivery
-
Sentry — error monitoring and diagnostics when enabled
-
Vercel Analytics — aggregate analytics on public marketing routes
LoanConsole does not intentionally send authenticated app or portal financial page activity to marketing analytics.
6. Browser storage, cookies, and analytics
LoanConsole uses browser storage and similar technologies as needed for authentication, security, preferences, and product operation. Third-party hosted services, such as Stripe checkout, may use their own necessary technologies.
Public marketing pages use limited analytics to understand aggregate page use. LoanConsole does not use advertising pixels or cross-site behavioral advertising on authenticated financial surfaces.
7. Sale, targeted advertising, and profiling
LoanConsole does not sell personal information.
LoanConsole does not share personal information for cross-context behavioral advertising and does not use personal information to profile individuals for decisions about lending, housing, employment, insurance, education, health care, or similar legal effects.
If those practices change, this policy and any required choice mechanisms will be updated before the change applies.
8. Data location and retention
Production data is hosted in the United States.
We retain information for as long as reasonably needed to provide the Service, preserve issued records and audit integrity, maintain security, support exports and backups, administer billing, resolve disputes, prevent fraud, and meet legal obligations.
Deletion from active systems may not immediately remove information from backups, security logs, billing records, or records that must be retained for legal or operational reasons.
9. Security
LoanConsole uses administrative, technical, and organizational safeguards designed for the information it handles. These include encrypted transport, password hashing, protected authentication secrets, role-based access, workspace isolation, database-level tenant controls, audit history, managed infrastructure, and access revocation.
No system can be guaranteed completely secure. Account holders are responsible for protecting credentials, recovery codes, devices, and team access. For more detail, see the Security page.
10. Privacy choices and requests
Depending on location and applicable law, individuals may have rights to request access, correction, deletion, or a portable copy of personal information and to appeal certain request decisions.
Requests may be sent to support@loanconsole.app. We may need to verify identity and authority before acting.
Where LoanConsole processes information for a customer, we may direct the request to that customer or assist the customer in responding. LoanConsole will not discriminate against an individual for exercising an applicable privacy right.
11. Children
The Service is intended for business use and is not directed to children under 18. LoanConsole does not knowingly solicit personal information directly from children.
12. Changes and contact
We may update this policy as the Service, providers, or legal requirements change. Material updates will be communicated where appropriate.
Privacy questions and requests: support@loanconsole.app
Security reports: security@loanconsole.app