We Can Lend You Money

Privacy policy

Last updated: May 2, 2026.

Draft: this is a structural skeleton. Final copy is reviewed by counsel before launch. [GEMINI] drafts the full policy text per legal/privacy-policy.md; Claude reviews; counsel finalizes.

1. What we collect

  • Account data: name, email, password (hashed), role (founder/backer).
  • KYC data (founders only): government ID image, date of birth, address. Encrypted at rest. Provided by Persona.
  • Liveness video (founders only): the 30-second selfie. Encrypted at rest. Face embeddings deleted at T+30 days unless flagged for fraud investigation.
  • Pledge data (backers): pledge amount, reward tier, shipping address (encrypted). Stripe handles card data — we never see full card numbers.
  • Behavior: IP, user-agent, page views (for security + drift detection).

2. How we use it

  • Run the platform — identity verification, payment processing, shipping for rewards, customer support.
  • Detect fraud — the drift detector flags unusual patterns (one IP funding too much, rapid-fire pledges).
  • Communicate — campaign updates, milestone reminders, MatchMaker digest if you opt in.

We do not sell personal data. We do not share with advertisers.

3. AI agents

We use AI agents (PitchCoach, CompliantWriter, VideoVerifier, etc.) to review submissions. Bias-control rule: no agent infers age, race, gender, or any protected trait. Decisions are auditable. Every campaign approval/rejection has a human-readable, policy-citable reason. See agents/README.md in our codebase for the full agent specs.

4. Sharing

  • Stripe — payment processing. Stripe's privacy policy applies.
  • Persona — KYC. Persona's privacy policy applies.
  • Cloudflare R2 — encrypted file storage.
  • Postal SMTP (self-hosted) — email delivery.

5. Retention

  • KYC data: retained for 7 years per AML/KYC rules, then deleted.
  • Liveness face embeddings: deleted at T+30 days unless fraud-flagged.
  • Inactive accounts: deleted after 24 months of inactivity, 30-day notice.

6. Your rights (CCPA + GDPR-aligned)

  • Access — request a copy of your data.
  • Correction — fix inaccuracies.
  • Deletion — we delete unless legally required to retain.
  • Portability — JSON export available on request.

Email info@wecanlendyoumoney.com with subject "Data request".

7. Children

Not for users under 18. We don't knowingly collect data from minors.

8. Changes

Material changes are posted here with a 30-day notice. Last updated at the top of this page.

Backer Concierge
AI assistant · Type 'human' for a person