LendFormaBack to LendForma

Privacy Policy

Effective August 14, 2026

LendForma is designed for sensitive financial information. This policy explains what we collect, why we use it, which service providers help operate LendForma, and the choices available to you.

Information you provide

When you create an account, statement or application package, you may provide identity and contact information, Social Security numbers, business details, ownership, assets, liabilities, income, expenses, source-and-use information, comments, signatures and supporting documents. A workspace manager may also provide your email address and role to invite you to a specific application.

Guest use

You can draft a statement without signing in. Guest statement changes are held in the browser session and are not saved to a LendForma account. We may store a small browser preference indicating whether you selected a fresh or demonstration form.

Account and payment information

If you sign in, authentication information is handled through Google or passwordless email. LendForma stores the account identifier needed to associate you with your private statements and case access. Stripe processes purchases and subscriptions; LendForma does not receive or store full payment-card numbers.

How we use information

  • Prepare statements and collaborative application packages.
  • Deliver and enforce case-specific invitations and permissions.
  • Store private supporting documents and provide authenticated downloads.
  • Record attributable case changes, reviews, document access and exports.
  • Authenticate accounts, process purchases, protect access, prevent abuse and respond to support or privacy requests.
  • Maintain and improve LendForma without intentionally placing financial field values in analytics or operational logs.

Service providers

LendForma currently relies on Vercel for application hosting and private object storage, Neon for managed PostgreSQL storage, Google and Auth.js for supported sign-in flows, Resend for magic-link email, and Stripe for payment processing. These providers process information on our behalf to perform those services. We do not sell your personal or financial information.

Automated review and sharing

Current submission-readiness reviews are deterministic and do not send package data to an external AI provider. Public app sharing sends only the website link. Case invitations grant the named signed-in participant permission to a specific application; workspace managers can revoke that access.

Security

LendForma uses HTTPS, authenticated case-scoped access, role checks, expiring invitation tokens stored only as hashes, private object storage, request validation, rate limiting, audit events and application-layer encryption for stored Social Security numbers. Sensitive document responses disable browser caching. No system can guarantee absolute security, so protect invitation links, downloaded packages and account access.

Retention and your choices

Account data and saved statements are retained while needed to provide LendForma, meet legal or security obligations and resolve disputes. Archived statements remain recoverable from your account. To request access, correction, export or deletion of account data, email hello@lendforma.com. Some limited records may be retained when required by law, fraud prevention, payment reconciliation or backup cycles.

Cookies and local storage

LendForma uses session cookies and related browser storage required for sign-in, security and guest preferences. We do not currently use advertising cookies.

Children and changes

LendForma is intended for adults and is not directed to children under 18. We may update this policy as the service changes. Material changes will be posted here with a revised effective date.

Contact

Questions or privacy requests can be sent to hello@lendforma.com.

Terms of ServiceLendFormaContact