Opening notice
This Privacy Policy (“Policy”) describes how LendTrack Pro (“LendTrack”, “we” or the “Platform”) collects, uses, stores, discloses and protects information relating to the people who use or interact with our services.
LendTrack Pro is a B2B SaaS technology platform intended primarily for lenders, finance businesses, cooperatives and other operators that manage their own credit portfolios.
This Policy should be read together with our Terms and Conditions and, where applicable, with our Data Processing Addendum or Agreement (“DPA”).
1.Scope
This Policy may apply to information relating to:
- 1.Lenders that contract LendTrack;
- 2.account owners and administrators;
- 3.employees and Authorized Users of Lenders;
- 4.Borrowers whose data is managed through the Platform;
- 5.loan applicants or Leads;
- 6.people who use the Borrower Portal;
- 7.people who interact through WhatsApp, SMS, email or other enabled channels;
- 8.visitors to our website;
- 9.users of our web or mobile applications;
- 10.users and integrators of our API;
- 11.people who request support; and
- 12.other individuals whose information is legitimately processed through LendTrack.
How we handle information depends fundamentally on who collected the data and for what purpose.
2.Privacy roles
This distinction is fundamental to understanding this Policy.
2.1Data managed by a Lender
When a Lender uses LendTrack to enter, store, query or manage information relating to its own Clients, Borrowers, guarantors, references or other people:
the Lender acts, as a general rule, as data Controller and LendTrack acts as data Processor on the Lender's behalf.
This means the Lender primarily determines:
- what information it collects;
- from whom;
- why;
- how long it must retain it;
- who may access it;
- what queries it runs;
- what communications it sends; and
- what decisions it makes using that information.
LendTrack provides the infrastructure and processes that information in order to deliver the services requested.
Where a person wishes to exercise a right relating specifically to information entered by a Lender, they should normally address their request to that Lender first.
LendTrack may reasonably cooperate with the Lender in handling valid requests.
2.2LendTrack's own data
LendTrack may act as Controller in respect of information we process for our own legitimate purposes, including:
- account creation and administration;
- authentication;
- security;
- contracting;
- invoicing;
- support;
- fraud prevention;
- subscription management;
- legal compliance;
- communications relating to our service;
- protection of our infrastructure; and
- LendTrack's business operation.
2.3Lead marketplace
Where a person submits a loan application directly through LendTrack's public marketplace, LendTrack may act as Controller in respect of the processing necessary to:
- receive the application;
- hold it temporarily in the marketplace;
- manage its assignment;
- prevent abuse;
- disclose it to a participating Lender; and
- manage its expiry.
Once the information is validly disclosed to a Lender that claims the application, that Lender may become an independent Controller in respect of its subsequent processing.
3.Information we may process
Depending on the functionality used, LendTrack may process the following categories.
3.1Identification
We may process:
- first name;
- surnames;
- national ID (cédula);
- passport or other identifier;
- date of birth;
- nationality where applicable;
- photographs;
- identity documents; and
- other information necessary for identification or verification.
3.2Contact information
Including:
- phone;
- WhatsApp;
- email;
- address;
- locality; and
- any other contact information provided.
3.3Employment and financial information
A Lender may record:
- employer;
- occupation;
- income;
- economic activity;
- place of work;
- employment references; and
- other information relating to credit assessment or administration.
3.4References and third-party data
Lenders may enter information about:
- family members;
- personal references;
- commercial references;
- guarantors;
- co-debtors; or
- other people connected with an operation.
The Lender is responsible for holding a valid legal basis to enter that information and for providing the applicable notices.
3.5Credit information
The Platform may process:
- loans;
- applications;
- principal;
- interest;
- late charges;
- penalties;
- installments;
- dates;
- balances;
- payment history;
- refinancings;
- restructurings;
- payment behavior;
- delinquency indicators;
- scoring;
- risk analysis; and
- other information relating to the managed portfolio.
3.6Documents
The following may be stored:
- contracts;
- promissory notes;
- identification documents;
- receipts;
- invoices;
- vouchers;
- employment documents;
- authorizations;
- bureau documents;
- files uploaded by users; and
- other documents relating to the functionality used.
3.7Financial and banking information
Where certain functionality requires it, we may process:
- banking information;
- withdrawal account;
- account holder;
- financial institution;
- payment-related data;
- transaction identifiers;
- payout statuses;
- refunds;
- chargebacks;
- available money;
- held money; and
- other information necessary to administer those operations.
LendTrack endeavors not to store sensitive card information where that information must be handled directly by the relevant payment processor.
3.8Tax information
Tax functionality may process:
- RNC;
- e-NCF;
- receipt type;
- billing data;
- information contained in e-CF documents;
- certificates or related references;
- submission statuses;
- responses from tax systems; and
- other data required for DGII-related functionality.
3.9Technical information
We may collect automatically:
- IP address;
- user-agent;
- browser;
- operating system;
- device type;
- technical identifiers;
- timestamps;
- sessions;
- authentication events;
- security activity;
- errors;
- logs;
- API events;
- webhook events; and
- other reasonably necessary telemetry.
3.10Audit records
We may retain records relating to:
- user;
- tenant;
- action;
- date and time;
- IP address;
- previous values;
- subsequent values;
- privileged operations;
- administrative access;
- authorizations; and
- relevant security events.
3.11Consents
Where functionality requires consent, we may retain evidence such as:
- identity;
- type of consent;
- version of the text accepted;
- date and time;
- IP;
- user-agent;
- the user who recorded the authorization; and
- the related document or PDF.
4.How we obtain information
We may obtain information:
- 1.directly from the user;
- 2.from the Lender;
- 3.from Authorized Users;
- 4.from the Borrower;
- 5.from the Applicant;
- 6.through the Borrower Portal;
- 7.through APIs;
- 8.through authorized integrations;
- 9.through payment gateways;
- 10.through identity services;
- 11.through bureau providers;
- 12.through the DGII;
- 13.through WhatsApp, SMS or email;
- 14.automatically through use of the Platform; and
- 15.from other sources legitimately used by the Lender or LendTrack.
5.What we use the information for
Depending on the context and on our role, we may process information in order to:
- provide the Platform;
- administer Clients and loans;
- record payments;
- calculate balances;
- generate amortization schedules;
- generate documents;
- manage collections;
- produce reports;
- carry out analysis;
- manage expenses;
- run OCR;
- enable communications;
- process payments;
- administer withdrawals;
- run automations;
- maintain auditing;
- provide APIs;
- deliver webhooks;
- provide support;
- authenticate users;
- protect accounts;
- prevent fraud;
- investigate incidents;
- comply with legal obligations;
- administer subscriptions;
- calculate platform charges;
- maintain tax and accounting records;
- provide artificial intelligence functionality;
- manage loan applications;
- administer the marketplace;
- run authorized bureau queries;
- provide electronic invoicing functionality; and
- improve the reliability and security of the Platform.
Where LendTrack acts as Processor, these operations are carried out primarily to deliver the services requested by the Lender.
6.Artificial intelligence
LendTrack may offer functionality based on artificial intelligence, including LT-Brain, risk analysis, document analysis, OCR and other tools.
6.1Information sent to AI systems
Depending on the function used, the following may be processed:
- user instructions;
- questions;
- tenant information;
- Client-related information;
- documents;
- fragments retrieved from documents;
- context needed to answer;
- results from internal tools; and
- previous conversations where memory is enabled.
A tenant's entire information set is not necessarily sent to an external provider for every request.
6.2Logical isolation
AI tools are designed to operate within the authorized context of the relevant tenant.
The Platform's global administrative access must not be used as a mechanism to let the assistant query other tenants indiscriminately.
6.3RAG and documents
Where retrieval-augmented generation (RAG) is used, fragments of the Lender's documents may be used as context to generate answers.
Retrieved content must be treated by the system as reference information and not as authorized instructions to modify security rules.
6.4Memory
Certain features may retain:
- preferences;
- persistent instructions;
- working rules;
- summaries; and
- conversation context.
Mechanisms may be provided to manage or delete that memory.
6.5Provider
LendTrack uses or may use OpenAI for certain artificial intelligence functionality.
Information sent is subject to the contractual conditions and configurations applicable to the service used by LendTrack.
Until that configuration has been confirmed, LendTrack must not publicly state that Zero Data Retention exists or that no data can be used for training.
6.6Human decisions
AI outputs are support tools.
LendTrack does not intend its AI tools to automatically replace the Lender's human judgment in credit decisions.
7.Credit bureau
LendTrack may facilitate integrations with providers such as Equifax or TransUnion.
A query must be run only where the Lender holds the corresponding authorization and legal basis.
We may retain evidence of the consent associated with the query.
LendTrack does not authorize the Lender to query credit information merely because the functionality technically exists.
The Lender is answerable for the lawfulness of each query.
8.Identity verification
We may process identification data using validation tools or available external services.
These tools may take information provided by the Lender or Client and compare it against authorized sources or external providers.
The results are not an absolute guarantee of identity.
9.Lead marketplace
A person may voluntarily provide information through /solicitar or an equivalent interface so that their information may be considered by participating Lenders.
9.1Information
The application may include:
- identity;
- contact details;
- amount requested;
- financial information;
- purpose;
- employment information; and
- other data requested in the form in force.
9.2Pool
The application may be held temporarily in a pool accessible to eligible Lenders.
9.3Claim
A Lender may claim an application.
When that happens, the necessary information may be disclosed to that Lender.
9.4Release
An assignment may expire or be released for inactivity.
The application may subsequently be claimed by another Lender.
As a result, different Lenders may receive information from the same application at different times, in line with how the marketplace works and with the notice given to the Applicant.
9.5Subsequent responsibility
After legitimately receiving the information, each Lender is responsible for its independent processing under applicable law.
9.6No guarantee
LendTrack does not guarantee that an application will:
- be claimed;
- be approved;
- receive an offer; or
- result in a loan.
9.7Expiry
Unconverted Leads may be deleted or anonymized in accordance with the retention period in force.
10.Borrower Portal
Borrowers may access certain functionality through links, tokens, credentials or other mechanisms provided by the Platform.
Data may be displayed relating to:
- the loan;
- balance;
- installments;
- payments;
- documents; and
- other authorized information.
The Lender is responsible for correctly maintaining the data it uses to identify and contact the Borrower.
Users must keep their access links and credentials private.
11.WhatsApp, SMS, email and push
LendTrack may facilitate communications through external providers.
This may involve disclosing:
- phone;
- email;
- name;
- identifiers;
- necessary information about the loan; and
- the message content
to the relevant provider.
The Lender is responsible for obtaining the consents required to send those communications and for honoring valid opt-out requests.
The Lender must consider the risk of disclosure where a phone number or email is incorrect, shared or has been reassigned.
12.Payments
Where a Lender connects its own Stripe, PayPal, dLocal, Azul or other gateway account, certain information necessary to complete the transaction may be disclosed to that provider.
In the ordinary payment flow between Lender and Borrower, the processing credentials belong to the Lender.
Payment providers may act as independent Controllers in respect of certain processing carried out under their own legal obligations.
13.Balances and withdrawals
Where balance, autopay or withdrawal functionality is enabled, we may process:
- account holder;
- banking institution;
- bank details;
- available amount;
- held amount;
- withdrawal requests;
- processing statuses;
- failures;
- reversals;
- payout identifiers; and
- verification documentation.
Sensitive banking information may be protected by additional security mechanisms where these are enabled.
The necessary data may be disclosed to dLocal, financial institutions or other providers needed to execute the operation.
14.Electronic invoicing
Where a Lender uses e-CF functionality, tax information may be transmitted to the Dirección General de Impuestos Internos (DGII) and to the technology providers required.
The Lender determines and is responsible for the tax information of its own operations.
15.Files and antivirus
Uploaded files may undergo automated security checks.
LendTrack may use services such as VirusTotal.
Depending on the implementation used, this may involve sharing:
- the file hash;
- metadata; or
- the file itself
with the security provider.
The Lender must not upload documents where it lacks authorization to subject them to the processing necessary to deliver the service.
16.Analytics
We may use tools such as Google Analytics to understand:
- site usage;
- navigation;
- performance;
- device;
- sessions;
- pages visited; and
- related metrics.
Where applicable law requires consent for certain technologies, we will endeavor to apply the corresponding mechanisms.
17.Cookies and similar technologies
LendTrack may use cookies or equivalent storage for:
Necessary cookies
Necessary for:
- authentication;
- sessions;
- security;
- essential preferences; and
- operation of the Platform.
Analytics
Technologies may be used to understand site usage and improve how it works.
External providers
Certain integrations may use their own technologies.
Where legally required, we may provide consent or configuration mechanisms.
18.API and webhooks
Lenders can integrate external systems through API keys and webhooks.
Where a Lender configures an external integration, the information requested through that integration may leave the systems controlled by LendTrack and reach the system designated by the Lender.
The Lender is responsible for:
- protecting its API keys;
- configuring appropriate scopes;
- securing its endpoints;
- protecting the data received; and
- complying with applicable law in respect of the systems it connects.
19.LendTrack administrative access
This section is an important disclosure.
Authorized LendTrack personnel may, where reasonably necessary, access a tenant and the information it contains.
This may occur in order to:
- provide support;
- investigate errors;
- correct inconsistencies;
- carry out migrations;
- investigate fraud;
- respond to incidents;
- protect security;
- recover information;
- comply with legal obligations; or
- carry out other legitimate administrative operations necessary to maintain the Platform.
In certain circumstances, authorized personnel may perform actions within the tenant as the Lender's technical representative.
Where technically applicable, those actions may be recorded in the audit systems.
Administrative access is intended for legitimate operational purposes and does not authorize personnel to use Personal Data for personal purposes.
20.Audit records
LendTrack maintains, or may maintain, append-only records intended to provide traceability.
These records may contain Personal Data and may be deliberately resistant to modification or deletion.
This characteristic is necessary for:
- security;
- investigation;
- accountability;
- integrity;
- compliance;
- fraud prevention; and
- legal defense.
21.Billing ledger
Records relating to LendTrack charges may use an immutable ledger.
A historical transaction may be retained even where there is a subsequent:
- refund;
- credit;
- correction; or
- reversal.
In those cases, the correction may be recorded as a new offsetting entry rather than by altering the original movement.
22.How long we retain information
We do not necessarily retain every category for the same period.
Retention depends on:
- purpose;
- the contractual relationship;
- tax obligations;
- security;
- auditing;
- fraud prevention;
- legal defense;
- applicable law; and
- valid instructions from the Controller.
22.1Active account
The data necessary to deliver the service may be retained while the account remains active.
22.2After termination
It may then be deleted or anonymized in accordance with our procedures, subject to the exceptions below.
22.3Information that may be retained longer
We may retain information where necessary for:
- tax obligations;
- e-CF;
- auditing;
- the ledger;
- fraud prevention;
- investigations;
- litigation;
- claims;
- regulatory obligations; or
- legal compliance.
22.4Backups
Residual copies may remain temporarily in backups until their normal rotation cycle completes.
22.5Test accounts
Tenants expressly created as temporary or test accounts may be deleted automatically after they expire.
Users are responsible for exporting beforehand any information they need to keep.
23.Data deletion
LendTrack does not promise instant, universal and irreversible deletion of every record immediately upon receiving a request.
A valid request is assessed taking into account:
- our role in respect of the data;
- the Lender's instructions;
- legal obligations;
- tax records;
- auditing;
- the ledger;
- security;
- backups; and
- third-party rights.
Where appropriate, information may be:
- deleted;
- anonymized;
- restricted; or
- retained under a legitimate exception.
24.Export
Lenders may have export tools available in formats such as CSV, Excel or PDF.
We recommend keeping independent copies of documentation they are under a legal, tax or business obligation to retain.
25.Security
LendTrack implements reasonable technical and organizational measures intended to protect information.
Depending on the functionality and configuration, these may include:
- authentication;
- role-based controls;
- passkeys;
- MFA;
- step-up authentication;
- rate limiting;
- webhook validation;
- session management;
- access revocation;
- auditing;
- file scanning;
- API controls;
- encryption of certain categories of information; and
- technical monitoring.
However, no system connected to the Internet can guarantee absolute security.
26.Encryption
Certain categories of information may use additional application-level encryption, potentially including:
- address;
- references;
- banking information; and
- other selected PII.
The availability of those controls may depend on the technical configuration in force.
Accordingly, this Policy does not state that absolutely all information stored by LendTrack is encrypted by a single application-level mechanism.
27.Multi-tenant architecture
LendTrack uses multi-tenant infrastructure.
Separation between Lenders is implemented through application, authentication and authorization controls.
This means different Lenders may use shared infrastructure.
We do not claim that each tenant necessarily has:
- a separate physical server;
- a separate physical database; or
- independent cryptographic isolation.
Lenders are not authorized to access information belonging to other tenants.
28.Security incidents
Where LendTrack determines that a security incident affecting Personal Data has occurred, it will take reasonable steps to:
- investigate;
- contain;
- mitigate;
- document; and
- make the legally required notifications.
Where we act as Processor, we may notify the incident to the Lender acting as Controller in accordance with the applicable DPA and law.
29.Providers and subprocessors
To deliver LendTrack we may use external providers.
These may include:
| Provider | General purpose |
|---|---|
| Supabase | Database, PostgreSQL and Realtime |
| AWS S3 | Document storage |
| Cloudinary | Images |
| Upstash Redis | Cache and rate limiting |
| Better Auth | Authentication |
| OAuth and analytics | |
| PayPal | Payments |
| Stripe | Payments connected by Lenders |
| dLocal | Payments and payouts |
| Azul | Payments |
| Twilio | WhatsApp and SMS |
| EmailJS | |
| Pusher | Realtime and presence |
| OpenAI | Artificial intelligence |
| VirusTotal | File security |
| Equifax | Credit information |
| TransUnion | Credit information |
| DGII | Electronic invoicing |
| PDF.co | Document processing |
| Vercel | Hosting and execution |
Actual use depends on the functionality enabled.
LendTrack may add, replace or remove providers as the Platform evolves.
30.International transfers
Some providers may operate infrastructure or process information outside the Dominican Republic.
Use of LendTrack may therefore involve international transfers of, or access to, information.
Where appropriate, LendTrack will adopt reasonable contractual, technical or organizational measures intended to protect that processing in line with the applicable obligations.
The Lender, as Controller in respect of its Clients, must equally ensure that its use of international providers through LendTrack is compatible with its own legal obligations.
31.Individual rights
Depending on applicable law and the circumstances, a person may have rights relating to their Personal Data, including rights of:
- access;
- rectification;
- updating;
- objection;
- erasure where applicable;
- being informed of certain processing; and
- other rights recognized by applicable law.
Rights are subject to the exceptions and requirements established by law.
32.Requests relating to a Lender's data
If your information was collected by a finance business, lender or business that uses LendTrack, that organization will normally be the Controller.
In that case, we recommend addressing the request directly to that entity.
LendTrack may cooperate with the Lender in responding, in line with our obligations as Processor.
We will not unilaterally modify credit information managed by a Lender merely because a person asks us to, where we have no legal authority to determine the substantive accuracy of that information.
33.Requests relating directly to LendTrack
We may request information reasonably necessary to verify the requester's identity before providing, modifying or deleting information.
34.Minors
LendTrack Pro is primarily a business platform and is not directed at minors contracting our services directly.
Lenders are responsible for determining whether they may legitimately process information relating to minors within their operations and for obtaining the necessary authorizations.
LendTrack may restrict certain functionality relating to minors where necessary.
35.Incorrect data
Where a Lender enters incorrect information about a Borrower, primary responsibility for correcting the record lies with the Lender that controls that data.
LendTrack may provide tools to make corrections and to keep traceability of changes.
36.Changes of Lender or tenant
A Client's information will not be arbitrarily transferred from one Lender to another.
Transfers, migrations, marketplace operations or others involving a change of Controller must be carried out through authorized functionality and on a valid legal basis.
37.Anonymized and aggregated data
LendTrack may generate statistical, aggregated or duly anonymized information that does not reasonably identify a person, in order to:
- analyze performance;
- improve infrastructure;
- detect trends;
- plan capacity;
- develop functionality;
- measure security; and
- produce statistics.
Where information is effectively anonymized such that it ceases to be Personal Data under applicable law, it may be handled separately from identifiable data.
LendTrack will not use this provision as authorization to commercialize identifiable credit files of a Lender's Clients.
38.No sale of Personal Data
LendTrack does not sell Borrower files or the Personal Data of a Lender's Clients as a standalone commercial product.
Disclosure of information to:
- subprocessors;
- payment processors;
- infrastructure providers;
- Lenders through the marketplace;
- bureaus;
- authorities; or
- other necessary recipients
takes place only where a corresponding purpose and basis exists, and does not in itself constitute a sale of data.
39.Legal requirements
We may retain or disclose information where we believe in good faith that it is reasonably necessary to:
- comply with a law;
- respond to a court order;
- respond to a competent authority;
- protect rights;
- investigate fraud;
- protect security;
- prevent harm; or
- exercise or defend legal claims.
Where legally possible and appropriate, we may inform the affected Lender.
40.Corporate changes
In the event of:
- merger;
- acquisition;
- reorganization;
- investment;
- sale of assets;
- succession; or
- transfer of LendTrack's operation,
information may form part of the assets transferred, subject to the applicable privacy obligations.
41.Changes to this Policy
We may modify this Policy to reflect:
- legal changes;
- new functionality;
- new providers;
- security modifications;
- business changes; or
- changes in our processing practices.
Where a change is material, we will endeavor to communicate it through:
- email;
- in-Platform notice;
- dashboard;
- website; or
- another reasonable means.
The Policy displays its last-updated date.
42.Versioning and evidence
LendTrack may keep historical versions of this Policy and record which version was in force or was presented to a user at a given time.
Where specific consent must be obtained, we may record:
- version;
- user;
- tenant;
- date;
- time;
- IP;
- user-agent; and
- other appropriate technical evidence.
43.Relationship with the Terms and the DPA
This Policy explains our privacy practices and does not replace our Terms and Conditions.
Where LendTrack processes Personal Data on a Lender's behalf, the processing may additionally be governed by the LendTrack Pro DPA.
On matters specifically relating to Controller-Processor obligations, the DPA prevails in the event of a contradiction with the general provisions of this Policy.
44.Governing law
This Policy is construed in accordance with applicable law, including, where relevant, the Dominican Republic's Personal Data protection regulations.
Nothing in this Policy is intended to remove rights a person holds under mandatory rules.
45.Contact
For privacy-related enquiries:
- Platform
- LendTrack Pro
- Support
- soporte@lendtrackpro.com
- Website
- lendtrackpro.com
Annex A — Summary matrix of roles
- The Lender's account
- LendTrack: Controller.
- Purpose: administering the contractual relationship, authentication, billing, security and support.
- Borrower data entered by the Lender
- Lender: Controller.
- LendTrack: Processor.
- Personal references entered by the Lender
- Lender: Controller.
- LendTrack: Processor.
- Marketplace before a Lead is assigned
- LendTrack: Controller in respect of the marketplace's operation, subject to the final legal configuration of the service.
- Lead delivered to a Lender
- Receiving Lender: Controller in respect of its subsequent processing.
- Payment processors
- The role depends on the operation and on the provider's terms. Some providers may act as independent Controllers in respect of their own obligations.
- LendTrack's internal security and fraud-prevention data
- LendTrack: Controller.
Annex B — Information pending before publication
This Policy must be completed before it can be considered final:
- 1.Registered name of the operating entity.
- 2.RNC.
- 3.Address.
- 4.Privacy email.
- 5.Legal email.
- 6.Retention period after an account is cancelled.
- 7.Retention period for unconverted Leads.
- 8.Contractual configuration with OpenAI regarding training and retention.
- 9.Final DPA.
- 10.Review of the actual Google Analytics/cookie configuration before publishing the corresponding section.
- 11.Confirmation of exactly what the VirusTotal integration sends in production — hash, file or both.
- 12.Confirmation of the bureau providers actually enabled in production.
- 13.Confirmation of the e-CF providers used in production.
Until these items are completed, LendTrack must not make public statements more specific than the technical practices actually verified.
End of the Privacy Policy