Privacy Policy
Effective August 20, 2026. Last updated August 20, 2026.
This policy explains what Sunbloom Capital LLC (“Sunbloom Capital”, “we”, “us”), a privately held California limited liability company, does with personal information: the information of the loan officers who subscribe to our platform, and the borrower information those officers make available to us so the platform can do its job.
This website sets no cookies. It loads no analytics, no advertising tags, no third-party fonts and no tracking pixels of any kind. Nothing you do on these pages is recorded beyond the ordinary server request log described below.
1. Two different roles
We handle personal information in two capacities, and the difference matters for your rights:
- Subscriber information — we are the controller. When a loan officer signs up, we decide what we collect about them and why. This policy governs it.
- Borrower information — we are a service provider. The borrower records the platform reads and writes belong to the subscribing officer and their lender. We process them only on that officer's instructions, only to run the platform for them, and for no purpose of our own. A borrower's request to see, correct or delete their information is answered by the officer and the lender who hold the relationship; we help them do it.
2. What we collect
From subscribers
- Name, business email, business phone, company, NMLS identifier, and the states in which the officer is licensed.
- Account settings: assistant configuration, message templates, schedules, approved audiences, and corrections the officer makes to drafts.
- Billing status from Stripe: plan, subscription state, invoice history, and the card brand, last four digits and expiry. We never receive or store a full card number.
- Support correspondence.
From the connected CRM, on the subscriber's behalf
- Contact details of the officer's leads and clients: name, phone number, email, mailing or property address.
- Loan-related detail already on the record: property value, loan balance, purpose, occupancy, credit-score band, pipeline stage, campaign, tags and notes.
- The text-message conversation between the officer and that contact, including messages the platform drafts and sends.
- Do-not-contact and opt-out status.
We do not ask a borrower for a Social Security number, government identification number or full financial account number, and the platform is built to refuse to do so by text.
Automatically
- Server request logs from our hosting provider: IP address, timestamp, request path, response code and error detail. These exist to run and secure the service.
- Operational counters — how many messages were drafted, sent, delivered or blocked — used to run allowances and diagnose faults.
3. Why we use it
- To provide the platform: read a conversation, draft a reply, send it, schedule a follow-up, escalate to a human.
- To enforce the platform's own guards: opt-outs, quiet hours in the borrower's time zone, state licensing limits and send caps.
- To bill subscriptions and manage accounts.
- To provide support, investigate faults and secure the service against abuse.
- To meet legal, tax and record-keeping obligations.
4. What we do not do
- We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months.
- We do not use borrower content to train general-purpose AI models, and our AI provider is contractually prohibited from doing so with content we send it.
- We do not use one subscriber's data to change another subscriber's assistant. Corrections an officer makes are stored in that officer's own account. Anything we keep to improve the platform generally is aggregated and de-identified — counts and rates, not conversations.
- We do not advertise to borrowers, build advertising profiles, or make credit decisions.
5. Who processes it
We keep the list short on purpose. These are the service providers that may process personal information for us, all in the United States:
| Provider | What it does | What it sees |
|---|---|---|
| Cloudflare, Inc. | Hosting, edge compute, key-value storage, this website, and email routing for our published addresses | All platform data, at rest and in transit |
| Anthropic, PBC | AI model that drafts message text | The conversation and record detail needed to draft a reply |
| Stripe, Inc. | Subscription payments | Subscriber billing details and card data, which it holds, not us |
| Google LLC | The mailbox that receives our account and support email | Subscriber name, email address and the content of messages sent to us |
The subscriber's own CRM is not our provider — it is the officer's system, connected by the officer, and it remains the system of record for borrower data. Text messages are sent through the messaging carrier attached to that CRM account.
We may also disclose information where the law requires it, to protect our rights or someone's safety, or to a successor in a merger or sale of the business. If that happens, this policy travels with the data.
6. How long we keep it
The platform holds working state, not a second copy of the CRM. Most of it expires on its own:
| What | Kept for |
|---|---|
| Opt-out and do-not-contact records | Indefinitely. Deleting one would let us contact that person again, so we do not delete them. |
| Delivery checks on a just-sent message | 2 hours |
| Follow-up schedule state for an active conversation | Up to 60 days after the last activity |
| Send and delivery logs, conversation outcome markers | Up to 180 days |
| Closed-file and funded markers | Up to 3 years, for record-keeping |
| Server request logs | Up to 30 days |
| Subscriber account and configuration | For the life of the account, then deleted within 60 days of closure |
| Invoices and payment records | As long as tax and accounting law requires, typically 7 years |
Deleting a contact in the CRM removes it at source; the platform's working state for that contact then expires on the schedule above.
7. Security
- All traffic is encrypted in transit with TLS. Stored data is encrypted at rest by our hosting provider.
- CRM API credentials are encrypted with a separate key and are never displayed back, logged, or included in any export.
- Administrative access is limited to the people who need it and is protected by multi-factor authentication.
- The platform treats the content of an inbound message as data, never as an instruction — a message cannot tell the assistant to change its rules, reveal a credential, or contact anyone else.
No system is perfectly secure. If a breach affects your information we will notify you, and any regulator we are required to notify, without undue delay.
8. Borrowers: your choices
If you have received a text from a loan officer using this platform:
- Reply STOP — or “unsubscribe”, “remove me”, “take me off your list”, and similar wording. The platform marks you do-not-contact immediately and stops all outbound texting to your number. No further action is needed and there is nothing to confirm.
- To see, correct or delete the information held about you, contact the loan officer or the lender you were speaking to — they hold the relationship and the record. You may also write to us at privacy@sunbloomcapital.com and we will route the request to them and assist.
9. California residents
Under the California Consumer Privacy Act, as amended, California residents have the right to know what personal information is collected and how it is used, to request correction or deletion, to opt out of sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of these rights.
We do not sell personal information and we do not share it for cross-context behavioural advertising. We do not use or disclose sensitive personal information for any purpose beyond providing the service, so there is nothing to limit. We do not use personal information to profile people in a way that produces legal or similarly significant effects.
The categories we collect are identifiers, customer records, commercial information, internet activity limited to server logs, geolocation limited to the state and time zone on a record, and professional information about subscribers. Each is collected for the purposes in section 3, from the sources in section 2, and disclosed only to the providers in section 5.
To make a request, write to privacy@sunbloomcapital.com. We will verify you against information we already hold and respond within 45 days, extending once by a further 45 days where necessary and telling you if we do. An authorised agent may act for you with written permission. If a request concerns borrower information, we act on the instructions of the officer or lender who controls it, and we will tell you who that is.
10. Other US states
Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana — have comparable rights to access, correct, delete and port their information, and to opt out of targeted advertising, sale and certain profiling. We do not engage in any of those three activities. Use the same address above; where a state provides an appeal, we will explain how in our response.
11. Children
The platform is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. If we learn we have, we delete it.
12. Where data is processed
We operate in the United States and our providers process data in the United States. The platform is not offered outside the United States.
13. Changes to this policy
We may update this policy. The current version always lives at this URL with its effective date at the top. If a change materially affects how we handle subscriber information, we will email the address on the account before it takes effect.
14. Contact
Sunbloom Capital LLC
23841 Pebble Beach Place
Laguna Niguel, CA 92677
Privacy: privacy@sunbloomcapital.com
Support: support@sunbloomcapital.com
Phone: (949) 463-2009