Privacy Policy
Your data, handled with care
Effective August 23, 2026
1. Who we are
LogicLinks LLC ("LogicLinks," "we," "us," or "our") is a software-as-a-service platform that provides customer relationship management, scheduling, communication, document collection, e-signature, and AI-assisted loan-file tools for licensed mortgage professionals. This Privacy Policy explains how we collect, use, store, share, and protect information when you use our service at logiclinks.io and any related applications (the "Service").
When our mortgage-professional customer (the "Customer" or "Loan Officer") uses the Service to manage information about a borrower, prospect, or referral partner, LogicLinks acts as a service provider or processor to the Customer under applicable US state privacy laws and under the Gramm-Leach-Bliley Act (GLBA). The Customer, not LogicLinks, is the party that has the direct relationship with the borrower.
2. Personal information we collect
The categories below track the categories used in the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA) so you can see, in one place, what we collect, where we get it, why we collect it, and who we share it with.
(a) Identifiers and account information
Name, email address, phone number, employer, job role, NMLS identifier, workspace subdomain, and authentication credentials (hashed password, MFA secret in encrypted form, recovery codes). Sources: you (when you create or update the account); your organization administrator (for invited users). Purposes: create and secure your account, provide the Service, authenticate you, meet legal obligations.
(b) Borrower, lead, and pipeline data
Borrower and prospect names, contact details, employment history, income, assets, liabilities, property information, loan program interest, milestones, tasks, notes, uploaded documents (paystubs, tax returns, bank statements, loan estimates, appraisals, etc.), and communication history. Sources: your loan officers (typed or uploaded), your borrowers (via secure upload links or connected credit / AUS / PPE integrations as those roll out), and integrated third-party services you connect (consumer reporting agencies, AUS, wholesale lenders). Purposes: provide the Service on the Customer's behalf; no other use. This category includes sensitive personal information described in Section 2(f).
(c) Data from connected Google or Microsoft 365 accounts
If you connect a Google or Microsoft account to power inbox, calendar, chat, video conferencing, or contacts features, we access only the data covered by the OAuth scopes you grant during consent. This may include email messages, calendar events, contacts, chat threads, and meeting links. Sources: you, via OAuth consent to Google or Microsoft. Purposes: provide the specific user-facing features you enabled. We do not access anything outside the granted scopes. See Sections 4 and 5.
(d) Communications you send through the Service
Content, recipients, timestamps, and delivery status for SMS, email, and voice communications you send to borrowers or partners via our Twilio and SendGrid integrations, plus associated consent and opt-out records. Sources: you and, for delivery events, our communications providers. Purposes: deliver the communication, maintain compliance records (TCPA / CAN-SPAM / state opt-out registries), and provide reporting.
(e) Internet, device, and usage information
IP address, browser and device type, operating system, pages visited within the Service, referring URLs, timestamps, error logs, and coarse geolocation derived from IP address (city / region only). Sources: automatically collected from your browser or client. Purposes: operate the Service, detect and prevent abuse, troubleshoot, secure our infrastructure.
(f) Sensitive personal information
Because the Service supports mortgage origination, borrower files often contain information that state privacy laws classify as Sensitive Personal Information ("SPI") or a special category of data, including: Social Security numbers and other government-issued identifiers, financial account numbers, credit report data, account credentials (for the LogicLinks account itself), and, incidentally, information that may reveal race, ethnicity, national origin, or veteran status (for example, on a URLA demographic addendum or a VA COE).
We use SPI only to provide the Service, secure our infrastructure, comply with law, and, at the Customer's direction, transmit it to integrated third parties (such as a wholesale lender or AUS). We do not use, share, or disclose SPI to infer characteristics about any individual, for targeted advertising, or for any other purpose beyond those a consumer would reasonably expect for a mortgage-operations platform, and we do not sell it. California residents may limit our use of SPI in the ways described in Section 14; because our uses of SPI are already limited to those permitted without an explicit "limit" request under CPRA regulations, there is no additional processing to restrict.
Retention of each category
Retention windows for each category are described in Section 10 (Data retention).
3. How we use your data
- Provide, maintain, secure, and improve the Service.
- Display your inbox, calendar, contacts, borrower pipeline, and other connected data inside the Service so you can act on it.
- Send transactional emails, SMS, and voice communications that you have configured the Service to send to your contacts on your behalf.
- Authenticate users and prevent fraud and abuse.
- Bill for the Service, collect payment, and prevent payment fraud (via our payment processor, Stripe).
- Investigate and respond to security incidents and to requests from law-enforcement or regulators.
- Comply with applicable laws and regulations.
4. Google API Services User Data (Limited Use)
LogicLinks's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google user data to provide or improve user-facing features that are prominent in the Service's user interface.
- We do not transfer Google user data to third parties except as necessary to provide or improve user-facing features, comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.
- We do not use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
- We do not use Google user data to develop, improve, or train generalized AI and/or machine learning models. Any AI features in the Service that touch Google user data operate on a per-user basis and use the data only to provide the user-facing feature in real time.
- We do not allow humans to read Google user data unless we have the user's affirmative agreement for specific messages, it is necessary for security purposes, to comply with applicable law, or our use is limited to internal operations and the data has been aggregated and anonymized.
5. Microsoft Graph data
When you connect a Microsoft 365 account, we access mail, calendar, and contacts data via the Microsoft Graph API only to provide the user-facing features you have enabled. We apply the same Limited Use principles described above to Microsoft data.
6. How we share your data
We do not sell your personal information. We do not sell personal information for monetary or other valuable consideration, as that term is defined by the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA) and comparable state privacy laws, and we have not done so in the twelve (12) months preceding the effective date above.
Sharing for cross-context behavioral advertising (marketing site only). Our public marketing site at logiclinks.io uses Google Analytics 4 and the Meta (Facebook) Pixel to measure how visitors reach us and to help us reach similar audiences with our own ads. These are strictly opt-in and do not fire unless a visitor accepts them on the cookie banner. Under CCPA/CPRA and comparable laws, that Pixel activity is considered "sharing" personal information for cross-context behavioral advertising. It applies only to marketing-site visitors and never to information inside a customer's workspace. Borrower information, loan-file data, and any content stored inside an authenticated LogicLinks workspace is NEVER shared with Google Analytics, Meta, or any other advertising platform. See Sections 7 and 14 for how to opt out or change your choice at any time.
We are not a data broker. LogicLinks does not collect personal information for the purpose of selling it to third parties. We are not registered as a data broker in any state that maintains a data-broker registry, and we are not required to be, because we operate as a service provider to our mortgage-professional customers.
The third parties we rely on to deliver the Service are listed on our sub-processors page, including what data each one processes and where. We share information only:
- With sub-processors that operate parts of the Service (for example, cloud hosting on AWS, email delivery via SendGrid, SMS and voice delivery via Twilio, subscription billing via Stripe, and error monitoring), each bound by data-processing agreements that restrict their use of personal information to providing the contracted service.
- With integrated third-party services that you or your organization administrator connect (for example, a consumer reporting agency, an automated underwriting system, or a wholesale lender), only at your direction and only to the extent necessary to complete the action you initiated.
- With other users of your organization in accordance with the roles and permissions your organization administrator configures.
- When required by law or valid legal process, or to protect our rights, property, or safety, or that of our users or the public. Where we are legally permitted, we give the affected Customer reasonable prior notice.
- In connection with a merger, acquisition, financing, or sale of all or substantially all of our assets, with notice to affected users.
We will provide reasonable notice before adding a new sub-processor that processes Customer Data on our behalf so you can object or terminate if a specific sub-processor is not acceptable to you.
7. Cookies and tracking technologies
We use two categories of cookies and equivalent browser storage (localStorage, sessionStorage): (a) strictly necessary cookies that operate everywhere on the Service, and (b) optional analytics and advertising cookies that operate only on our public marketing site and only if you accept them on the cookie banner.
Strictly necessary (all pages)
- Authentication and session cookies — keep you signed in, protect against cross-site request forgery, and enforce multi-factor authentication.
- User-preference storage — remembers UI preferences such as light / dark theme, collapsed sidebar state, and last-viewed tab.
- Security telemetry — short-lived tokens used for rate-limiting and abuse detection.
- Consent state — remembers whether you accepted or declined the analytics banner so we do not ask again on every visit.
Optional — marketing site only, opt-in
The following load only on our public marketing site (logiclinks.io) and only if you click Accept on the cookie banner. They do NOT load anywhere inside an authenticated customer workspace.
- Google Analytics 4 — measures aggregate marketing-site traffic (pages viewed, referral source, browser, coarse geography). IP address is anonymized before Google receives it. Data is retained per our GA4 configuration.
- Meta (Facebook) Pixel — measures marketing-site actions such as signup starts and lets us build audiences for our own ads on Facebook and Instagram. As described in Section 6, activity from the Pixel is considered "sharing" for cross-context behavioral advertising under CCPA/CPRA and comparable state laws.
Change your choice. Click Cookie preferences on any marketing page (also linked in the footer as "Do Not Sell or Share My Personal Information") to reopen the banner and change your selection at any time. Declining immediately stops future loading of the analytics and advertising scripts on this browser.
Do Not Track and Global Privacy Control (GPC). Because these scripts run only on the marketing site and only with your affirmative Accept click, a Do Not Track (DNT) or Global Privacy Control (GPC) signal has the same effect as declining the banner: no analytics or advertising scripts fire.
8. Automated decision-making
LogicLinks does not use personal information to make solely automated decisions that produce legal or similarly significant effects about any consumer (for example, we do not automatically approve, deny, price, or condition a mortgage loan).
The Service includes AI features (document extraction, loan-file analysis, guideline chat, and email drafting) that surface suggestions and reference material to a licensed loan officer. Those outputs are informational only and are reviewed and acted on by the loan officer, not automatically applied. Where a state privacy law gives consumers the right to opt out of profiling for decisions with significant effects, that right does not apply to these features because they do not perform that kind of profiling. See Section 9 for more on the AI features.
9. AI features and shared improvement corpus
LogicLinks includes AI features (document extraction, loan-file analysis, guideline chat, and email drafting) that process borrower loan documents you upload to the Service. These features run through Amazon Bedrock with zero-retention configured, meaning your documents are NOT stored by the AI provider and are NOT used to train any generalized foundation model. LogicLinks does not use Customer Data, borrower communications, or AI feature inputs or outputs to train, fine-tune, or improve any foundation model, our own machine-learning models, or any third-party model. The only exception is the opt-in shared improvement corpus described below.
Shared improvement corpus (effective 2026-08-15). When a loan officer at your organization corrects an AI document extraction (for example, marks it as the wrong document type or edits an extracted value), we may use that correction to improve extraction accuracy across the LogicLinks platform. Before any correction leaves your tenant, it goes through a two-pass de-identification pipeline (deterministic regex scrub for known PII patterns such as SSNs, phone numbers, exact dollar amounts, email addresses, and street addresses, followed by an AI verification pass), then is hand-reviewed by a LogicLinks administrator before entering the shared corpus. Only the de-identified structural pattern (e.g. "on this employer's paystub layout, the YTD gross field is in the second column") is retained. Raw borrower documents and unscrubbed extractions NEVER leave your tenant.
Opt-out. Your organization administrator can opt out of contributing corrections to the shared corpus at any time at /settings/account/ai. Opting out is forward-looking; corrections captured before opt-out remain governed by the terms in effect at capture time. Opting out does not remove your organization from benefiting from platform-wide extractor improvements shipped in future releases. Corrections captured before 2026-08-15 are grandfathered and are never eligible for the shared corpus, regardless of opt-out status.
Fair-lending review. We periodically audit the shared corpus for patterns that could introduce bias against protected classes in the downstream extractor prompts. If a review identifies a problematic pattern, the affected examples are retired from the corpus and the extractor prompt is corrected.
10. Data retention
We retain your account and pipeline data for as long as your account is active. Concrete retention windows:
- Leads, contacts, and pipeline records: retained until you (or your org admin) delete them, or until the organization is closed.
- Connected mailbox metadata (Gmail / Microsoft): cached message bodies, threads, and labels are purged from our cache within 30 days of you disconnecting the mailbox. OAuth tokens are revoked at the provider and cleared from our database immediately on disconnect.
- Database backups: point-in-time backup snapshots roll off after 7 days. Data deleted from active storage is unrecoverable after that window.
- Audit logs: retained for 13 months for compliance + incident investigation.
- Closed accounts: all account data is deleted within 30 days of account closure (delayed only as required to resolve disputes, enforce agreements, or comply with legal obligations such as quarterly MCR / NMLS reporting, CFPB advertising record-keeping, and FCRA-related retention requirements).
11. Data residency
Customer Data is stored and processed in the United States, currently in Amazon Web Services (AWS) US-East-1 (Northern Virginia). We may move data among AWS US regions for reliability, backups, or disaster recovery, but we do not store Customer Data outside the United States without prior written consent from the Customer.
12. Security
We use commercially reasonable administrative, physical, and technical safeguards to protect Customer Data from unauthorized access, loss, or misuse. Current safeguards include encryption in transit (TLS 1.2 or later), encryption at rest for stored borrower documents and PII fields (AES-256), least-privilege access controls for our personnel, audited administrative actions, regular vulnerability scanning of our infrastructure, and periodic review of our security controls. These safeguards are designed to satisfy the reasonable-security standards under the GLBA Safeguards Rule (as amended May 2024), the New York SHIELD Act, Massachusetts 201 CMR 17.00, and comparable state data-security laws.
Security incident notification. If we become aware of a security incident that materially affects the confidentiality, integrity, or availability of Customer Data, we will notify the affected Customer without undue delay and no later than seventy-two (72) hours after we confirm the incident where the underlying event triggers a notification obligation under applicable law (including the GLBA Safeguards Rule as amended in May 2024 and applicable state data-breach notification laws). Our notice will describe what we know about the incident and the remediation steps we are taking. We will cooperate reasonably as the Customer meets any downstream notification obligations to its borrowers or regulators.
No system is completely secure. You are responsible for maintaining the security of your account credentials, enabling multi-factor authentication, and promptly notifying us if you suspect unauthorized access to your account.
13. GLBA privacy notice
The Gramm-Leach-Bliley Act (GLBA) governs how "financial institutions" handle Nonpublic Personal Information (NPI) about consumers who obtain financial products or services for personal, family, or household purposes.
LogicLinks is not itself a financial institution. Our mortgage-professional Customers are financial institutions under GLBA. When a Customer uses the Service to store or process NPI about its borrowers, LogicLinks acts as a service provider to that Customer under 15 U.S.C. § 6802(b)(2) and applicable Regulation P provisions. We use NPI only to provide the Service to the Customer, do not disclose NPI to third parties for their own independent marketing use, and require our sub-processors to do the same under written agreements.
Our Customers are responsible for delivering initial and annual GLBA privacy notices to their borrowers, obtaining required consents, and honoring borrower opt-out rights. Nothing in this Privacy Policy is intended to be, or should be treated as, the GLBA privacy notice that a Customer provides to its own borrowers.
14. Your privacy rights
Depending on where you live, you may have rights under one or more of the following laws:
- United States (state). The California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), the Colorado Privacy Act (CPA), the Virginia Consumer Data Protection Act (VCDPA), and equivalent comprehensive privacy laws in Connecticut, Utah, Texas, Oregon, Montana, Tennessee, Indiana, Iowa, Delaware, New Hampshire, New Jersey, Kentucky, Minnesota, Rhode Island, Maryland, and other states as new laws take effect.
- Non-US. The Service is directed to users in the United States. To the extent an applicable non-US privacy law (for example, a visitor from an EEA member state or the UK using our marketing website) grants rights, we will honor them where legally required.
Subject to verification and applicable exceptions, you may have the right to:
- Know / Access — request confirmation of whether we process personal information about you, the categories and specific pieces we process, our sources, our purposes, and the categories of third parties we share with.
- Correction — request that inaccurate or incomplete personal information be corrected.
- Deletion — request that we delete your personal information, subject to exceptions permitted by law (e.g., completing a transaction, security, legal record-keeping).
- Portability — receive a copy of your personal information in a portable, machine-readable format.
- Opt-out of sale or sharing / targeted advertising — direct us not to sell your personal information or share it for cross-context behavioral advertising. We do not sell personal information. We do share limited marketing-site activity for cross-context behavioral advertising through the Meta Pixel and Google Analytics (marketing site only, opt-in). You may opt out at any time by clicking Cookie preferences on any marketing page, by using the "Do Not Sell or Share My Personal Information" link in our footer, or by sending a Global Privacy Control signal from your browser.
- Limit use of sensitive personal information — under CPRA, direct us to limit our use of SPI to purposes that do not require an opt-in. As described in Section 2(f), our uses are already limited to those purposes.
- Opt-out of profiling — where applicable, opt out of profiling that produces legal or similarly significant effects. As described in Section 8, we do not perform that kind of profiling.
- Withdrawal of consent — including disconnecting linked Gmail / Microsoft 365 accounts at any time, which revokes our access at the provider and clears our cached data per the retention schedule in Section 10.
- Appeal — if we decline a rights request in a state that provides an appeal right (Colorado, Virginia, Connecticut, Texas, Oregon, and others), you may appeal by replying to our response with the word "Appeal".
How to exercise these rights. Email info@logiclinks.io with the subject line "Privacy Rights Request" and the specific right you would like to exercise, or write to us at the address in Section 19. If you have an account, you may also exercise these rights from your account settings. We will verify your identity (typically via the email address on your account) and respond within 45 days, with a one-time 45-day extension where reasonably necessary and permitted by law. If we need the extension we will tell you why. An authorized agent may submit a request on your behalf with written proof of authorization.
Borrower requests. If you are a borrower and your loan officer uses LogicLinks to manage your file, please direct rights requests to the loan officer or their organization in the first instance, because they are the party that determined how and why to collect your information. We will help our Customers respond to those requests.
Non-discrimination. We will not deny goods or services, charge different prices, provide a different level or quality of service, or retaliate against you for exercising a privacy right.
15. Children
The Service is a business tool for licensed mortgage professionals. It is not directed to, marketed to, or intended for use by minors, and we do not knowingly collect personal information from anyone under the age of eighteen (18). Consistent with the Children's Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from children under the age of thirteen (13). If you become aware that a minor has provided us with personal information, contact us and we will delete it.
16. International visitors and complaints
The Service is offered from the United States and is intended for use by licensed US mortgage professionals. If you access the Service or our marketing website from outside the United States, you understand that your information is transferred to and processed in the United States, which may have different data-protection standards than your home jurisdiction.
If you are a resident of the European Economic Area, the United Kingdom, or another jurisdiction that provides a right to lodge a complaint with a data-protection supervisory authority, you may do so with your local authority. We ask that you also contact us first so we have the opportunity to address your concern.
17. Third-party links and integrations
The Service and our marketing website contain links to, and integrations with, third-party sites and services (for example, wholesale-lender portals, integrated pricing engines, credit-bureau services, and social platforms). Those third parties operate under their own privacy policies and terms, and this Privacy Policy does not apply to their practices. We encourage you to review the privacy policy of any third-party site or service before providing personal information to it.
18. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and update the effective date above. If we make a material change, we will provide reasonable notice to Customer account administrators (for example, by email) before the change takes effect. Your continued use of the Service after the effective date of a change constitutes acceptance of the updated policy.
19. Contact
Questions about this policy, or a privacy rights request? Email us at info@logiclinks.io or write to us at the address below.
LogicLinks LLC
Attn: Privacy
2111 N Tejon Street
Colorado Springs, CO 80907