This Privacy Policy applies to the FundLink Tech web application (the “Service”), including organization settings, View Emails, application intake, underwriting, funding, and related portals. By using the Service, you agree to this policy. Capitalized terms used for Google APIs follow the Google API Services User Data Policy.
1. Who we are
FundLink Tech operates a business funding platform used by our team, organization administrators, brokers, and merchants. The Service supports merchant cash advance / future-receivables applications: collecting business and owner information, bank statements and other documents, underwriting, offers, contracts, disbursements, and ACH collections.
Questions: hello@mg.fundlinktech.com. Support: hello@mg.fundlinktech.com.
2. Information we collect
Account and organization data
- Name, work email, role, and organization membership for users who sign in.
- Organization profile, settings, and audit of who connected shared services.
Merchant application data
- Business identity (legal name, DBA, EIN, addresses, industry, entity type).
- Owner identity (name, contact details, ownership percentage, identification documents, and other underwriting fields you submit).
- Financial documents such as bank statements, voided checks, licenses, applications, and related files.
- Bank account details you provide for funding or collections (including via Plaid or manual entry), and payment-processor records (for example GoACH or Actum) needed to move money.
Usage data
- Login sessions, IP address, device/browser information, and activity logs needed to secure the Service and troubleshoot issues.
3. Google account and Gmail data
Organization administrators may connect one shared Gmail inbox per organization from Organization Settings (“Organization Gmail (View Emails)”). Connecting uses Google OAuth. We request these scopes:
- https://mail.google.com/ — mailbox access so the Service can read inbound application emails and attachments through Google’s mail interface (including IMAP-style access used to ingest files).
- https://www.googleapis.com/auth/userinfo.email — the Google account email address, so we can show which inbox is connected and confirm the account.
We use that access only to:
- Display connected-inbox messages in View Emails for authorized users of that organization.
- Detect new merchant application emails and save attachments (for example PDFs and images) into the matching application file.
- Keep a local copy of message metadata needed to avoid duplicate processing (subject, sender, date, Google message id).
- Refresh OAuth tokens so the shared inbox stays connected until an admin disconnects it.
We store Google OAuth access and refresh tokens, the connected email address, organization id, and token expiry in our database so staff of that organization can use the shared inbox. Disconnecting Gmail in Organization Settings revokes the token with Google (when possible) and deletes the local token record.
Other organization admins who are allowed to manage that organization can see View Emails for the connected inbox. We do not sell Gmail contents. We do not use Gmail contents to create advertising profiles.
4. Google API Services User Data Policy (Limited Use)
Limited Use commitment. FundLink Tech’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, Gmail data obtained through Google OAuth is used only to provide or improve user-facing features that are prominent in the Service (View Emails and email-based application document intake). We do not:
- Use Gmail data for serving advertisements.
- Allow humans to read Gmail data unless you give us permission, it is necessary for security/legal compliance, or it is required to provide support after you request it — and then only by authorized personnel.
- Transfer Gmail data to third parties except as needed to operate those features (for example secure hosting/infrastructure) or as required by law, and not for independent use by those parties for their own purposes.
This section is intended to satisfy Google’s restricted-scope verification requirements for Gmail access.
5. How we use information
- Authenticate users and enforce organization access.
- Underwrite, offer, contract, fund, and collect merchant advances.
- Parse bank statements and documents you upload or that arrive by email.
- Communicate about applications, funding, and support.
- Maintain security, prevent fraud, and keep required business records.
- Improve the Service (without using Gmail data for ads).
6. How we share information
We share information only as needed to run the Service:
- Your organization. Users in the same organization with appropriate roles can see applications, documents, and the shared Gmail inbox.
- Payment and bank partners. GoACH, Actum, Plaid, and similar processors receive the data required to verify accounts or move funds — not your Google password, and not Gmail contents unless a document was already saved into an application file.
- Infrastructure vendors. Hosting, email delivery, and similar processors who are bound to handle data on our instructions.
- Legal. If required by law, regulation, or to protect rights and safety.
We do not sell personal information. We do not share Gmail data with data brokers or ad networks.
7. Storage, security, and retention
Application files, documents, and OAuth tokens are stored in our production systems (application database and private file storage). Access is limited to authenticated users of the relevant organization and to operators who need access to run the platform.
We retain application and funding records for as long as needed for underwriting, servicing, audits, and legal obligations. Synced email copies used for intake are kept while the organization uses View Emails and related processing. You may disconnect Gmail at any time; we then stop new mailbox access. Previously ingested documents that already belong to an application file remain part of that file unless deleted under your organization’s process.
8. Your choices
- Connect or disconnect the organization Gmail inbox in Organization Settings.
- Revoke FundLink Tech access at any time from your Google Account permissions page.
- Ask us to review or delete account-level data that is not required to be kept for legal or servicing reasons, using the contact below.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export personal information, or to object to certain processing. Send requests to hello@mg.fundlinktech.com. We may need to verify the request and may retain information where we have a legal or contractual duty to do so.
10. Children
The Service is for businesses and authorized staff. It is not directed to children under 13 (or 16 where applicable). We do not knowingly collect data from children.
11. Changes
We may update this policy. The “Effective” date at the top will change. Material changes to how we use Google user data will be reflected here before those changes take effect.
12. Contact
FundLink Tech
Privacy: hello@mg.fundlinktech.com
Support: hello@mg.fundlinktech.com
Related: Terms of Use.