Privacy Policy
Your data, handled with care
Effective July 16, 2026
1. Who we are
LogicLinks ("LogicLinks," "we," "us," or "our") is a software-as-a-service platform that provides customer relationship management, scheduling, communication, and document collection tools for mortgage professionals. This Privacy Policy explains how we collect, use, store, share, and protect information when you use our service at logiclinks.io and any related applications (the "Service").
2. Information we collect
Account information
When you create an account, we collect your name, email address, phone number, role, employer, NMLS identifier where applicable, and authentication credentials.
Borrower and lead data
When you use the Service to manage your pipeline, we store the borrower, lead, and contact information you enter or import, including names, contact details, financial information, loan details, employment, assets, properties, and documents.
Data from connected Google or Microsoft accounts
If you connect a Google or Microsoft account to power the inbox, calendar, chat, video conferencing, or contacts features, we access only the data covered by the scopes you grant during consent. This may include email messages, calendar events, contacts, chat threads, and meeting links. We do not access anything outside the granted scopes.
Usage information
We collect basic operational data such as IP address, browser type, pages visited, and timestamps to operate the Service, detect abuse, and troubleshoot issues.
3. How we use your data
- Provide, maintain, and improve the Service.
- Display your inbox, calendar, contacts, and other connected data inside the Service so you can act on it.
- Send transactional emails and SMS messages that you have configured the Service to send.
- Authenticate users and prevent fraud.
- Comply with applicable laws and regulations.
4. Google API Services User Data (Limited Use)
LogicLinks's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google user data to provide or improve user-facing features that are prominent in the Service's user interface.
- We do not transfer Google user data to third parties except as necessary to provide or improve user-facing features, comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.
- We do not use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
- We do not use Google user data to develop, improve, or train generalized AI and/or machine learning models. Any AI features in the Service that touch Google user data operate on a per-user basis and use the data only to provide the user-facing feature in real time.
- We do not allow humans to read Google user data unless we have the user's affirmative agreement for specific messages, it is necessary for security purposes, to comply with applicable law, or our use is limited to internal operations and the data has been aggregated and anonymized.
5. Microsoft Graph data
When you connect a Microsoft 365 account, we access mail, calendar, and contacts data via the Microsoft Graph API only to provide the user-facing features you have enabled. We apply the same Limited Use principles described above to Microsoft data.
6. How we share data
We do not sell your data. The third parties we rely on to deliver the Service are listed on our sub-processors page, including what data each one processes and where. We share information only:
- With sub-processors that operate parts of the Service (for example, cloud hosting, email delivery, SMS delivery, and error monitoring), each bound by data-processing agreements.
- With other users of your organization in accordance with the roles and permissions you configure.
- When required by law or legal process.
- In connection with a merger, acquisition, or asset sale, with notice to affected users.
7. Data retention
We retain your account and pipeline data for as long as your account is active. Concrete retention windows:
- Leads, contacts, and pipeline records: retained until you (or your org admin) delete them, or until the organization is closed.
- Connected mailbox metadata (Gmail / Microsoft): cached message bodies, threads, and labels are purged from our cache within 30 days of you disconnecting the mailbox. OAuth tokens are revoked at the provider and cleared from our database immediately on disconnect.
- Database backups: point-in-time backup snapshots roll off after 7 days. Data deleted from active storage is unrecoverable after that window.
- Audit logs: retained for 13 months for compliance + incident investigation.
- Closed accounts: all account data is deleted within 30 days of account closure (delayed only as required to resolve disputes, enforce agreements, or comply with legal obligations).
8. Security
Data is encrypted in transit (TLS 1.2+) and at rest. Access to production systems is restricted to authorized personnel and logged. We follow industry-standard practices to protect against unauthorized access, loss, and misuse.
9. Your rights
Depending on your jurisdiction (GDPR, CCPA/CPRA, and similar laws), you may have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — request that inaccurate or incomplete data be corrected.
- Deletion — request that we delete your personal data, subject to legal retention obligations.
- Portability — receive an export of your data in a machine-readable format.
- Objection + Restriction — object to or restrict certain processing.
- Withdrawal of consent — including disconnecting linked Gmail / Microsoft 365 accounts at any time, which revokes our access at the provider and clears our cached data per the retention schedule in Section 7.
To exercise any of these rights, email info@logiclinks.io with the subject line "Privacy Rights Request" and the specific right you'd like to exercise. We will verify your identity (typically via the email address on your account) and respond within 30 days. If we need more time we will tell you why and when we will respond.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect personal information from them.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and update the effective date above. Material changes will be communicated by email to account administrators.
12. AI features and shared improvement corpus
LogicLinks includes AI features (document extraction, loan-file analysis, guideline chat, and email drafting) that process borrower loan documents you upload to the Service. These features run through Amazon Bedrock with zero-retention configured, meaning your documents are NOT stored by the AI provider and are NOT used to train any generalized foundation model.
Shared improvement corpus (effective 2026-08-15). When a loan officer at your organization corrects an AI document extraction (for example, marks it as the wrong document type or edits an extracted value), we may use that correction to improve extraction accuracy across the LogicLinks platform. Before any correction leaves your tenant, it goes through a two-pass de-identification pipeline (deterministic regex scrub for known PII patterns such as SSNs, phone numbers, exact dollar amounts, email addresses, and street addresses, followed by an AI verification pass), then is hand-reviewed by a LogicLinks administrator before entering the shared corpus. Only the de-identified structural pattern (e.g. "on this employer's paystub layout, the YTD gross field is in the second column") is retained. Raw borrower documents and unscrubbed extractions NEVER leave your tenant.
Opt-out. Your organization administrator can opt out of contributing corrections to the shared corpus at any time at /settings/account/ai. Opting out is forward-looking; corrections captured before opt-out remain governed by the terms in effect at capture time. Opting out does not remove your organization from benefiting from platform-wide extractor improvements shipped in future releases. Corrections captured before 2026-08-15 are grandfathered and are never eligible for the shared corpus, regardless of opt-out status.
Fair-lending review. We periodically audit the shared corpus for patterns that could introduce bias against protected classes in the downstream extractor prompts. If a review identifies a problematic pattern, the affected examples are retired from the corpus and the extractor prompt is corrected.
13. Contact
Questions about this policy? Email us at info@logiclinks.io.