Legal
Privacy Policy
Last updated: August 12, 2026
1. Overview
This Privacy Policy describes how Lyte ("Lyte," "we," "us," or "our") collects, uses, discloses, and safeguards information when you use our websites, applications, APIs, and related services (collectively, the "Services"). The Services are designed for business finance professionals, including merchant cash advance (MCA) brokers, lenders, ISOs, and their teams, to manage leads, applications, lender outreach, and communications.
By accessing or using the Services, you agree to the practices described in this Privacy Policy and our Terms of Service. If you do not agree, do not use the Services.
2. Who we are
Lyte is operated by the entity identified on our website (the "Company"). For privacy questions, contact us using the details in the "Contact us" section below. The Company is the controller of personal information processed about account holders and visitors. Where you are a customer using the Services to process information about your own end users, applicants, contacts, or merchants, the Company acts as a processor or service provider on your behalf, and you are the controller of that information.
3. Information we collect
Information you provide
- Account details such as name, email, phone number, business name, role, and login credentials.
- Billing details such as payment method, billing address, tax ID, and transaction history. Card numbers and bank account credentials are processed by our payment processors and are not stored on our servers.
- Workspace content you upload or generate, including applications, bank statements, contracts, signatures, notes, templates, automations, and lender or merchant records.
- Communications you send through the Services, including SMS, email, and in-app messages, and any attachments.
- Support and feedback you submit, including survey responses and correspondence with us.
Information collected automatically
- Device and connection data such as IP address, browser, operating system, device identifiers, and language.
- Usage data such as pages viewed, features used, clickstream, referral URLs, and timestamps.
- Cookies, local storage, pixels, and similar technologies as described in the Cookies section.
- Log and diagnostic data, including error reports and performance metrics.
Information from third parties
- Identity, fraud, and verification signals from authentication, KYC, and anti-fraud providers.
- Lender APIs, CRMs, email/SMS providers, document storage, and analytics platforms you choose to connect.
- Publicly available business information used to enrich workspace records.
- Referrals, integrations, and authorized partners who share data with your permission.
4. How we use information
- Provide, operate, secure, and improve the Services.
- Create and manage accounts, workspaces, billing, and credits.
- Process payments, prevent fraud, and enforce credit and balance rules.
- Route, send, and receive SMS, email, and other communications you initiate.
- Power AI features such as bank statement analysis, message drafting, and automation suggestions.
- Provide customer support and respond to requests.
- Detect, investigate, and prevent abuse, security incidents, and policy violations.
- Comply with legal obligations, court orders, audits, tax, and accounting requirements.
- Develop new features and conduct product analytics in aggregated or de-identified form.
- Send service announcements, security alerts, and (with your permission where required) marketing.
5. Legal bases for processing
Where the GDPR, UK GDPR, or similar laws apply, we rely on the following legal bases: performance of a contract with you; our legitimate interests in operating, securing, and improving the Services; compliance with legal obligations; and your consent where required (for example, for certain marketing communications or cookies). You may withdraw consent at any time without affecting the lawfulness of prior processing.
7. We do not sell your data
Lyte does not sell personal information for money, and we do not rent, license, or otherwise make personal information available to data brokers, list brokers, lead aggregators, or any third party for the purpose of independent marketing to your contacts, applicants, merchants, or principals. We do not use your workspace content to enrich or build profiles for sale.
To the extent any sharing might be considered a "sale" or "sharing" for cross-context behavioral advertising under U.S. state laws, you may opt out using the controls described in the California section below. We honor Global Privacy Control (GPC) signals where required.
8. Communications, SMS & email
The Services let you send SMS, email, and other messages to recipients you choose. You are solely responsible for the content of those messages, the lawful basis for contacting recipients, and compliance with the TCPA, CAN-SPAM, CASL, telecom carrier rules (including 10DLC registration and brand/campaign requirements), state-level mini-TCPA laws, and any do-not-call obligations.
- We may scan messages and metadata to enforce carrier rules, prevent spam, fraud, and abuse, and provide deliverability analytics.
- We retain message logs for delivery, audit, billing, and legal compliance purposes.
- Recipients can reply STOP, UNSUBSCRIBE, or use equivalent opt-out mechanisms; you must honor those requests promptly.
9. Google user data & Limited Use
Lyte lets you connect a Google account so you can read, send, and manage that mailbox from inside Lyte. Connecting is entirely optional and is initiated by you; you can disconnect at any time. This section describes how we handle data obtained through Google APIs.
Permissions we request and why
- gmail.modify — to display your connected inbox inside Lyte, sync new messages and threads, link email conversations to the matching lead or application, send replies from your own address, and apply the read, starred, archive, spam, and trash changes you make in the Lyte interface back to Gmail.
- userinfo.email and openid — to identify which mailbox you connected and to display that address in your settings.
We request only the permissions needed to operate features that are visible to you in the Lyte interface. We do not use these permissions for any purpose you have not initiated.
What we store and for how long
- OAuth tokens for your connected mailbox. Refresh tokens are encrypted at rest and are never exposed to your browser or to other workspaces.
- Message and thread content synced from your mailbox — sender and recipient addresses, subject lines, snippets, message bodies, labels, timestamps, and threading headers — so that your inbox, conversation history, and reply threading work inside Lyte.
- Attachments are streamed from Gmail on request and are not retained on our servers except where you explicitly save a file to an application or workspace record.
- Synced Google data is scoped to your workspace and is accessible only to members of that workspace under the roles and permissions you configure.
You can disconnect a Google account at any time from Integrations in your dashboard, and you can revoke Lyte's access directly from your Google Account permissions page. On disconnection we stop syncing and delete the stored tokens and the synced message and thread content for that mailbox, subject to the limited backup and legal-retention periods described in the Data retention section.
Limited Use commitments
- We use Google user data only to provide and improve the user-facing features described above, which are prominent in the Lyte interface.
- We do not transfer Google user data to third parties except as necessary to provide or improve those user-facing features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to you.
- We do not use Google user data for advertising of any kind, including serving, targeting, retargeting, personalized, or interest-based advertising.
- We do not use Google user data — raw, aggregated, anonymized, or derived — to create, train, or improve foundational or generalized artificial intelligence or machine learning models, and we do not transfer it to any third party that would do so.
- Our sole AI model provider is OpenAI, accessed through the paid OpenAI Platform API. Content submitted through that API is not used by OpenAI to train or improve its models. We do not route Google user data to any other AI or machine learning provider.
- Where an AI feature processes a message from your connected mailbox, it does so only to produce the output you requested at that moment — for example, parsing a lender's emailed reply into structured offer terms — and the result is returned to your workspace and not retained by the model provider for any secondary purpose.
- We do not sell, rent, or license Google user data, and we do not use it to build or enrich profiles for sale or for marketing to your contacts.
- We do not allow humans to read Google user data, except with your affirmative agreement for specific messages (for example, when you ask our support team to investigate a message), where necessary for security purposes such as investigating abuse, to comply with applicable law, or for internal operations where the data has been aggregated and de-identified.
10. AI features and model training
The Services include AI-powered features that may process workspace content (for example, to analyze bank statements, draft messages, or summarize conversations). We use third-party model providers and may process content through them strictly to deliver the requested functionality.
- We do not use your workspace content to train foundation models for the benefit of unrelated third parties.
- We may use aggregated, de-identified, or anonymized signals to improve the Services and our internal models.
- AI output may be inaccurate or incomplete. You are responsible for reviewing AI output before relying on it for funding, underwriting, compliance, or customer-facing decisions.
11. Payments, billing & credits
Payments and subscriptions are processed by third-party processors (such as Stripe). We receive limited transaction metadata (such as last4, brand, status, and amounts) needed to operate billing, credits, and auto-recharge. We do not store full card numbers or bank credentials on our servers.
- Credits, prepaid balances, and usage-based fees are tracked in your account and may be debited automatically as you use paid features such as SMS, email, AI, or document processing.
- Auto-recharge, if enabled, will charge your saved payment method when your balance falls below a threshold you configure or that we set as a default.
- All fees are non-refundable except where required by law or expressly stated in the Terms of Service. Disputed charges must be raised in writing within the timeframes set out in the Terms of Service.
- We may share data with payment processors, fraud-prevention vendors, and tax authorities as needed to process transactions and meet legal obligations.
12. Lender, applicant & merchant data
When you submit applications, offers, stipulations, or other information to lenders or partners through the Services, you direct us to transmit that information on your behalf. Once received by a lender or partner, that party becomes an independent controller of the information and processes it under its own privacy practices and agreements with you and the applicant.
- You represent that you have a lawful basis and any required consents to submit applicant, principal, and merchant information.
- You will not upload information of consumers seeking personal credit, or information subject to laws (such as the FCRA, GLBA, or HIPAA) for which you do not have appropriate authorization and contractual coverage.
- We are not a consumer reporting agency; the Services are not intended to make eligibility determinations regulated by the FCRA.
14. Security
We implement administrative, technical, and physical safeguards designed to protect information, including encryption in transit, access controls, least-privilege principles, audit logging, and regular reviews of vendor security. No system is perfectly secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your credentials and the security of devices used to access the Services.
15. Data retention
We retain information for as long as needed to provide the Services, comply with legal obligations (including tax, accounting, fraud, and telecom record-keeping), resolve disputes, and enforce agreements. Retention periods vary based on the type of information and the purpose for which it is processed. After your account is closed, we may retain limited information in archival, backup, or compliance systems for the periods required by law or our legitimate interests.
16. Your rights & choices
- Access, correct, or delete account information through your dashboard or by contacting us.
- Export workspace content using available export tools or by request.
- Opt out of marketing emails using the unsubscribe link; transactional and security emails will continue.
- Manage cookies through your browser controls.
When the Company acts as a processor or service provider on your behalf (for example, with respect to your applicants, contacts, or merchants), we will route those individuals' requests to you as the controller, except where the law requires us to respond directly.
17. California (CCPA/CPRA) rights
California residents have the right to know, delete, correct, and obtain a copy of personal information; to opt out of the "sale" or "sharing" of personal information; and to limit the use of sensitive personal information. We do not sell personal information for money. To exercise rights, contact us using the details below. We will verify requests using information already on file. You may designate an authorized agent. We will not discriminate against you for exercising your rights.
18. EU/UK (GDPR) rights
If you are in the EEA, UK, or Switzerland, you have the right to access, correct, delete, restrict, or object to processing of your personal information, the right to data portability, and the right to lodge a complaint with your local data protection authority. To exercise these rights, contact us using the details below.
19. International transfers
We process information in the United States and other countries. When we transfer personal information from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as Standard Contractual Clauses, the UK International Data Transfer Addendum, or equivalent mechanisms.
20. Children's privacy
The Services are not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us so we can delete it.
21. Third-party services & links
The Services may link to or integrate with third-party platforms (lenders, CRMs, email and SMS providers, payment processors, AI providers, identity verification services, and analytics tools). Their data practices are governed by their own policies. We are not responsible for the content, privacy practices, or security of those third parties.
22. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated by posting an updated version with a new "Last updated" date and, where appropriate, by additional notice. Your continued use of the Services after the effective date constitutes acceptance of the updated policy.
23. Contact us
To exercise privacy rights or ask questions about this policy, contact us at privacy@lyte.app. You can also reach us through the support tools inside your dashboard.