Legal

Privacy Policy

Last updated: August 12, 2026

1. Overview

This Privacy Policy describes how Lyte ("Lyte," "we," "us," or "our") collects, uses, discloses, and safeguards information when you use our websites, applications, APIs, and related services (collectively, the "Services"). The Services are designed for business finance professionals, including merchant cash advance (MCA) brokers, lenders, ISOs, and their teams, to manage leads, applications, lender outreach, and communications.

By accessing or using the Services, you agree to the practices described in this Privacy Policy and our Terms of Service. If you do not agree, do not use the Services.

The Services are intended for business use only. They are not consumer-facing financial products. Lyte is not a lender, broker, credit reporting agency, debt collector, or financial advisor.

2. Who we are

Lyte is operated by the entity identified on our website (the "Company"). For privacy questions, contact us using the details in the "Contact us" section below. The Company is the controller of personal information processed about account holders and visitors. Where you are a customer using the Services to process information about your own end users, applicants, contacts, or merchants, the Company acts as a processor or service provider on your behalf, and you are the controller of that information.

3. Information we collect

Information you provide

  • Account details such as name, email, phone number, business name, role, and login credentials.
  • Billing details such as payment method, billing address, tax ID, and transaction history. Card numbers and bank account credentials are processed by our payment processors and are not stored on our servers.
  • Workspace content you upload or generate, including applications, bank statements, contracts, signatures, notes, templates, automations, and lender or merchant records.
  • Communications you send through the Services, including SMS, email, and in-app messages, and any attachments.
  • Support and feedback you submit, including survey responses and correspondence with us.

Information collected automatically

  • Device and connection data such as IP address, browser, operating system, device identifiers, and language.
  • Usage data such as pages viewed, features used, clickstream, referral URLs, and timestamps.
  • Cookies, local storage, pixels, and similar technologies as described in the Cookies section.
  • Log and diagnostic data, including error reports and performance metrics.

Information from third parties

  • Identity, fraud, and verification signals from authentication, KYC, and anti-fraud providers.
  • Lender APIs, CRMs, email/SMS providers, document storage, and analytics platforms you choose to connect.
  • Publicly available business information used to enrich workspace records.
  • Referrals, integrations, and authorized partners who share data with your permission.
You are responsible for ensuring you have all necessary rights, notices, and consents to upload, share, or process information about third parties (including merchants, applicants, principals, or contacts) through the Services.

4. How we use information

  • Provide, operate, secure, and improve the Services.
  • Create and manage accounts, workspaces, billing, and credits.
  • Process payments, prevent fraud, and enforce credit and balance rules.
  • Route, send, and receive SMS, email, and other communications you initiate.
  • Power AI features such as bank statement analysis, message drafting, and automation suggestions.
  • Provide customer support and respond to requests.
  • Detect, investigate, and prevent abuse, security incidents, and policy violations.
  • Comply with legal obligations, court orders, audits, tax, and accounting requirements.
  • Develop new features and conduct product analytics in aggregated or de-identified form.
  • Send service announcements, security alerts, and (with your permission where required) marketing.

6. How we share information

  • With service providers and processors who help us run the Services (hosting, storage, databases, analytics, error monitoring, email, SMS, AI inference, identity verification, customer support, and payment processing).
  • With integrations and lenders you choose to connect or send applications to, only as directed by you.
  • With other users in your workspace based on roles and permissions you configure.
  • With professional advisors (lawyers, accountants, auditors, insurers).
  • With authorities or other parties when required by law, subpoena, court order, or to protect rights, safety, property, and the integrity of the Services.
  • In connection with a corporate transaction such as a merger, acquisition, financing, reorganization, or sale of assets, subject to customary confidentiality protections.

7. We do not sell your data

Lyte does not sell personal information for money, and we do not rent, license, or otherwise make personal information available to data brokers, list brokers, lead aggregators, or any third party for the purpose of independent marketing to your contacts, applicants, merchants, or principals. We do not use your workspace content to enrich or build profiles for sale.

To the extent any sharing might be considered a "sale" or "sharing" for cross-context behavioral advertising under U.S. state laws, you may opt out using the controls described in the California section below. We honor Global Privacy Control (GPC) signals where required.

8. Communications, SMS & email

The Services let you send SMS, email, and other messages to recipients you choose. You are solely responsible for the content of those messages, the lawful basis for contacting recipients, and compliance with the TCPA, CAN-SPAM, CASL, telecom carrier rules (including 10DLC registration and brand/campaign requirements), state-level mini-TCPA laws, and any do-not-call obligations.

  • We may scan messages and metadata to enforce carrier rules, prevent spam, fraud, and abuse, and provide deliverability analytics.
  • We retain message logs for delivery, audit, billing, and legal compliance purposes.
  • Recipients can reply STOP, UNSUBSCRIBE, or use equivalent opt-out mechanisms; you must honor those requests promptly.

9. Google user data & Limited Use

Lyte lets you connect a Google account so you can read, send, and manage that mailbox from inside Lyte. Connecting is entirely optional and is initiated by you; you can disconnect at any time. This section describes how we handle data obtained through Google APIs.

Lyte's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Permissions we request and why

  • gmail.modify — to display your connected inbox inside Lyte, sync new messages and threads, link email conversations to the matching lead or application, send replies from your own address, and apply the read, starred, archive, spam, and trash changes you make in the Lyte interface back to Gmail.
  • userinfo.email and openid — to identify which mailbox you connected and to display that address in your settings.

We request only the permissions needed to operate features that are visible to you in the Lyte interface. We do not use these permissions for any purpose you have not initiated.

What we store and for how long

  • OAuth tokens for your connected mailbox. Refresh tokens are encrypted at rest and are never exposed to your browser or to other workspaces.
  • Message and thread content synced from your mailbox — sender and recipient addresses, subject lines, snippets, message bodies, labels, timestamps, and threading headers — so that your inbox, conversation history, and reply threading work inside Lyte.
  • Attachments are streamed from Gmail on request and are not retained on our servers except where you explicitly save a file to an application or workspace record.
  • Synced Google data is scoped to your workspace and is accessible only to members of that workspace under the roles and permissions you configure.

You can disconnect a Google account at any time from Integrations in your dashboard, and you can revoke Lyte's access directly from your Google Account permissions page. On disconnection we stop syncing and delete the stored tokens and the synced message and thread content for that mailbox, subject to the limited backup and legal-retention periods described in the Data retention section.

Limited Use commitments

  • We use Google user data only to provide and improve the user-facing features described above, which are prominent in the Lyte interface.
  • We do not transfer Google user data to third parties except as necessary to provide or improve those user-facing features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to you.
  • We do not use Google user data for advertising of any kind, including serving, targeting, retargeting, personalized, or interest-based advertising.
  • We do not use Google user data — raw, aggregated, anonymized, or derived — to create, train, or improve foundational or generalized artificial intelligence or machine learning models, and we do not transfer it to any third party that would do so.
  • Our sole AI model provider is OpenAI, accessed through the paid OpenAI Platform API. Content submitted through that API is not used by OpenAI to train or improve its models. We do not route Google user data to any other AI or machine learning provider.
  • Where an AI feature processes a message from your connected mailbox, it does so only to produce the output you requested at that moment — for example, parsing a lender's emailed reply into structured offer terms — and the result is returned to your workspace and not retained by the model provider for any secondary purpose.
  • We do not sell, rent, or license Google user data, and we do not use it to build or enrich profiles for sale or for marketing to your contacts.
  • We do not allow humans to read Google user data, except with your affirmative agreement for specific messages (for example, when you ask our support team to investigate a message), where necessary for security purposes such as investigating abuse, to comply with applicable law, or for internal operations where the data has been aggregated and de-identified.

10. AI features and model training

The Services include AI-powered features that may process workspace content (for example, to analyze bank statements, draft messages, or summarize conversations). We use third-party model providers and may process content through them strictly to deliver the requested functionality.

  • We do not use your workspace content to train foundation models for the benefit of unrelated third parties.
  • We may use aggregated, de-identified, or anonymized signals to improve the Services and our internal models.
  • AI output may be inaccurate or incomplete. You are responsible for reviewing AI output before relying on it for funding, underwriting, compliance, or customer-facing decisions.

11. Payments, billing & credits

Payments and subscriptions are processed by third-party processors (such as Stripe). We receive limited transaction metadata (such as last4, brand, status, and amounts) needed to operate billing, credits, and auto-recharge. We do not store full card numbers or bank credentials on our servers.

  • Credits, prepaid balances, and usage-based fees are tracked in your account and may be debited automatically as you use paid features such as SMS, email, AI, or document processing.
  • Auto-recharge, if enabled, will charge your saved payment method when your balance falls below a threshold you configure or that we set as a default.
  • All fees are non-refundable except where required by law or expressly stated in the Terms of Service. Disputed charges must be raised in writing within the timeframes set out in the Terms of Service.
  • We may share data with payment processors, fraud-prevention vendors, and tax authorities as needed to process transactions and meet legal obligations.

12. Lender, applicant & merchant data

When you submit applications, offers, stipulations, or other information to lenders or partners through the Services, you direct us to transmit that information on your behalf. Once received by a lender or partner, that party becomes an independent controller of the information and processes it under its own privacy practices and agreements with you and the applicant.

  • You represent that you have a lawful basis and any required consents to submit applicant, principal, and merchant information.
  • You will not upload information of consumers seeking personal credit, or information subject to laws (such as the FCRA, GLBA, or HIPAA) for which you do not have appropriate authorization and contractual coverage.
  • We are not a consumer reporting agency; the Services are not intended to make eligibility determinations regulated by the FCRA.

13. Cookies & tracking

We use cookies, local storage, and similar technologies to keep you signed in, remember preferences, measure usage, and secure the Services. You can control cookies through your browser settings. Disabling certain cookies may break functionality.

14. Security

We implement administrative, technical, and physical safeguards designed to protect information, including encryption in transit, access controls, least-privilege principles, audit logging, and regular reviews of vendor security. No system is perfectly secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your credentials and the security of devices used to access the Services.

15. Data retention

We retain information for as long as needed to provide the Services, comply with legal obligations (including tax, accounting, fraud, and telecom record-keeping), resolve disputes, and enforce agreements. Retention periods vary based on the type of information and the purpose for which it is processed. After your account is closed, we may retain limited information in archival, backup, or compliance systems for the periods required by law or our legitimate interests.

16. Your rights & choices

  • Access, correct, or delete account information through your dashboard or by contacting us.
  • Export workspace content using available export tools or by request.
  • Opt out of marketing emails using the unsubscribe link; transactional and security emails will continue.
  • Manage cookies through your browser controls.

When the Company acts as a processor or service provider on your behalf (for example, with respect to your applicants, contacts, or merchants), we will route those individuals' requests to you as the controller, except where the law requires us to respond directly.

17. California (CCPA/CPRA) rights

California residents have the right to know, delete, correct, and obtain a copy of personal information; to opt out of the "sale" or "sharing" of personal information; and to limit the use of sensitive personal information. We do not sell personal information for money. To exercise rights, contact us using the details below. We will verify requests using information already on file. You may designate an authorized agent. We will not discriminate against you for exercising your rights.

18. EU/UK (GDPR) rights

If you are in the EEA, UK, or Switzerland, you have the right to access, correct, delete, restrict, or object to processing of your personal information, the right to data portability, and the right to lodge a complaint with your local data protection authority. To exercise these rights, contact us using the details below.

19. International transfers

We process information in the United States and other countries. When we transfer personal information from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as Standard Contractual Clauses, the UK International Data Transfer Addendum, or equivalent mechanisms.

20. Children's privacy

The Services are not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us so we can delete it.

21. Third-party services & links

The Services may link to or integrate with third-party platforms (lenders, CRMs, email and SMS providers, payment processors, AI providers, identity verification services, and analytics tools). Their data practices are governed by their own policies. We are not responsible for the content, privacy practices, or security of those third parties.

22. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated by posting an updated version with a new "Last updated" date and, where appropriate, by additional notice. Your continued use of the Services after the effective date constitutes acceptance of the updated policy.

23. Contact us

To exercise privacy rights or ask questions about this policy, contact us at privacy@lyte.app. You can also reach us through the support tools inside your dashboard.