Privacy Policy
This Privacy Policy explains what information Jon Lynch Financial Group, LLC ("JLFG", "we") collects through the Vault platform, how we use it, who we share it with, and the rights you have. It applies to two distinct groups:
- Customers — the brokers, ISO shops, and funding advisors who license Vault;
- Merchants — the small businesses whose data flows through the platform when a Customer is working a deal on their behalf.
Where we describe data flows below, we mark which group we mean.
Contents
1. Information we collect
From Customers
- Account info: name, work email, company name, role, password hash, optional 2FA seed.
- Billing info: for paid tiers, processed by Stripe; we never see card numbers.
- Usage: pages viewed, features used, IP, browser, OS, timestamps. Aggregated to understand reliability and product fit.
- Support correspondence: messages you send to legal, support, or security mailboxes.
From Merchants (received via Customers)
- Business and owner identification (name, EIN, DBA, DL number, address, contact);
- Bank statements, voided checks, articles of incorporation, profit/loss statements;
- Soft-pull credit data when the Customer's funder integration requests it;
- Application content the merchant submits through a Customer-operated portal.
2. How we use it
We use the information above only for these purposes:
- Provide the Service — pipeline tracking, document handling, funder submission, commission calculation, communications;
- Security & integrity — fraud detection, abuse prevention, audit logging, incident response;
- Service reliability — uptime monitoring, error diagnostics, capacity planning;
- Account management — billing, support, onboarding;
- Legal compliance — when required by law, subpoena, or regulatory order.
We do not sell personal information. We do not use Customer Data or Merchant Data to train third-party AI models. We do not market to merchants. We do not share with data brokers.
3. When we share it
We share information only with:
- The funder you select when a Customer chooses to submit a deal — that's the whole point of the workflow;
- Service providers who run our infrastructure (hosting, monitoring, email, e-sign, OCR), each bound by data-processing agreements with security and confidentiality terms equivalent to ours;
- Auditors / advisors under confidentiality obligations;
- Law enforcement or regulators in response to a valid legal demand, with prompt notice to you where allowed;
- Successor entity if Vault is acquired or merged — same protections will apply.
4. Merchant data & consent
Merchant data is highly sensitive. The Customer is the controller of merchant data — they decide what to collect, who to share it with, and how long to retain it. We are the processor handling that data on the Customer's instructions.
Customers represent in their Terms of Service acceptance that they have obtained any required consent from each merchant before submitting that merchant's information to Vault. If you are a merchant whose information has been submitted and you wish to access, correct, or delete it, contact the broker who is working your deal first; if they are unresponsive, contact jonlynchfinancialgroup@gmail.com and we will route your request.
5. Cookies & tracking
Vault uses minimal cookies:
- Strictly necessary — session token, CSRF token, ToS-acceptance receipt;
- Functional — UI preferences (theme, last-viewed pipeline view);
- Analytics — privacy-respecting aggregate metrics via our self-hosted Umami install (no cross-site tracking, no third-party data sharing).
We do not use Google Analytics, Facebook Pixel, or any other ad-network tracker. We honor the Sec-GPC header.
6. Security
- TLS 1.2+ in transit, AES-256 at rest;
- Per-tenant database isolation;
- Row-level access control on all merchant records;
- Daily encrypted backups with weekly restore-tests;
- SOC 2 Type II posture (audit cadence: annual);
- Responsible-disclosure program at /security.txt.
7. Retention
We retain Customer Data for as long as your account is active, plus 30 days after termination during which you may export it. After that we delete or de-identify it, except where retention is required by law or to defend legal claims (typically up to 7 years for billing records). System logs are retained 90 days.
8. Your rights (CCPA / GDPR / state laws)
Depending on where you live, you may have the right to:
- Access the personal information we hold about you;
- Correct inaccurate information;
- Delete information (subject to legal retention requirements);
- Port your information in a machine-readable format;
- Object to or restrict certain processing;
- Opt out of "sale" or "sharing" of personal information — we do not sell or share for cross-context behavioral advertising, so this is moot for our service;
- Lodge a complaint with a supervisory authority.
To exercise these rights, email jonlynchfinancialgroup@gmail.com. We respond within 30 days. We do not discriminate against users who exercise their rights.
9. Children
Vault is a B2B product and is not directed to anyone under 18. We do not knowingly collect information from minors.
10. International transfers
Vault infrastructure is hosted in the United States. If you access the Service from outside the U.S., your information will be transferred to the U.S. Where required, we rely on the EU Standard Contractual Clauses or equivalent mechanism.
11. Changes
We will post material changes here with a new "Last revised" date and email account owners at least 14 days before the change takes effect.
12. Contact
Jon Lynch Financial Group, LLC
Attn: Vault Privacy
Privacy: jonlynchfinancialgroup@gmail.com
Security: jonlynchfinancialgroup@gmail.com
Legal: jonlynchfinancialgroup@gmail.com