Legal

Privacy Policy

What we collect, who touches it, and what we will never do with it. If something here is unclear, ask us — an answer you cannot understand is not a disclosure.

Effective [[EFFECTIVE DATE]]

Who we are, and whose data this is

MyDeskiso is a product of [[LEGAL ENTITY — e.g. Vcomputer26 LLC]] ("we", "us"). It is a business tool sold to independent sales organizations, brokers and funders — collectively, our customers. It is not a consumer product and it is not directed at the general public.

Two different kinds of data live here, and they are governed differently.

  • Account data — the names, email addresses and credentials of the people at a customer organization who sign in. We decide how this is handled, and this policy governs it directly.
  • Customer data — everything a customer enters or uploads about the merchants and funders they work with. The customer decides what to collect and why; we only process it on their instructions, to run the service. If you are a merchant who applied for funding and you want to know what is held about you, contact the organization you applied through. They can answer, correct and delete it; we will help them do so.

What we collect

We collect what the service needs to work, and nothing that exists only to profile you.

  • Account and sign-in: name, work email, a password stored only as an argon2id hash, an optional two-factor secret held encrypted, the role assigned to you by your organization, and session cookies that expire after eight hours.
  • Merchant and application data entered by our customers: business and contact details, addresses, phone numbers, revenue and business profile, the last four digits of an EIN or SSN, and a date of birth held encrypted. We do not store full Social Security or tax identification numbers.
  • Documents uploaded by customers or received by email on a deal — typically bank statements and signed agreements.
  • Communications tied to a deal: emails exchanged with funders and merchants through the platform, and internal team chat messages.
  • An audit record of actions taken in the platform — who did what, to which record, and when. This is a deliberate feature, not incidental logging.
  • Billing: we use Stripe for subscriptions. Card details are entered directly with Stripe and never reach our servers or our database.
  • On mobile: a push notification token identifying your device installation, if you allow notifications.

What we never do

We do not sell personal information, and we do not share it with data brokers or advertising networks. There is no advertising in this product, no cross-app or cross-site tracking, and no third-party analytics SDK embedded in the mobile app.

We do not pool one customer's records with another's. Every record belongs to exactly one organization and every query is scoped to it. There is no shared merchant pool, no cross-organization view, and no aggregated dataset built from customer deals.

We do not use customer data to train machine learning models.

Who processes data on our behalf

We use a small number of service providers, each for one job, and each bound to process data only on our instructions. Infrastructure is hosted in the United States.

  • Neon — the application database.
  • Vercel — application hosting and delivery.
  • Amazon Web Services (S3) — storage of uploaded deal documents, encrypted at rest.
  • Resend — sending transactional and deal email, and receiving replies routed back into a deal.
  • Stripe — subscription billing and payment processing.
  • Ably — real-time in-app updates. What we publish is a signal containing only opaque record identifiers, so that your browser knows to refetch. No message content, no names and no personal data are sent to Ably.
  • Google Firebase Cloud Messaging and Apple Push Notification service — delivery of mobile push notifications. See the section below for exactly what they receive.
  • Slack and GoHighLevel — only if your organization chooses to connect them, and only for the data that integration is configured to carry.

What a push notification actually contains

A push notification carries an event label such as "Funder replied", the business name on the deal it concerns, and an opaque identifier the app uses to open the right screen. The content of a message, a document, or any applicant detail is never included, and never reaches Apple or Google.

One consequence is worth stating plainly rather than burying: where a business is a sole proprietorship or trades under an owner's name, that business name is also a person's name. It will therefore appear on the lock screen of the device receiving the notification, and will pass through Apple's or Google's delivery infrastructure. Turning off notifications for the app in your device settings stops this entirely.

Device permissions on the mobile app

The mobile app asks for three things, each only when it is needed.

  • Camera — only when you choose to photograph a document. We do not access the camera in the background.
  • Notifications — optional, and revocable at any time in your device settings.
  • Face ID, Touch ID or your device passcode — used to unlock the app when you return to it. This check happens entirely on your device. No biometric data is transmitted to us, and none is stored on our servers. It is a lock on the app, not a way to sign in, and no long-lived credential is kept on the device.

How data is protected

Passwords are hashed with argon2id and are never recoverable in plain text. Particularly sensitive fields, along with the credentials for any integration you connect, are encrypted at rest with AES-256-GCM. Documents are stored encrypted and served through short-lived links rather than public URLs. Access within an organization is governed by roles that organization defines: a user can be restricted to only the deals assigned to them, and funder identities, full applicant details and commission figures are each gated separately.

We are not SOC 2 certified, and we will not imply otherwise. We are happy to walk any prospective customer through exactly how isolation, encryption, permissions and auditing work.

How long we keep it

We keep customer data for as long as the organization's account is active. When an account ends, the workspace becomes read-only for thirty days so the customer can export what they need, after which the data is deleted on request. Audit records may be retained longer where we are required to keep them, since their purpose is to evidence what happened.

Push notification tokens are deleted when you sign out, when you uninstall the app, or automatically once a device has stopped appearing.

Your choices and rights

If you have an account, you can view and correct your own profile in the app, and your organization's administrator can change or remove your access. Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to be free from discrimination for exercising them.

To make a request about account data, write to [[privacy@mydeskiso.com — must be a monitored mailbox]]. If your request concerns data an organization holds about a merchant, we will route it to that organization, because they decide what happens to it.

You can stop mobile notifications at any time in your device settings, and disconnect an integration such as Slack or GoHighLevel from your organization's settings.

Children

MyDeskiso is a business tool. It is not intended for anyone under 18, and we do not knowingly collect personal information from children.

Changes to this policy

If we change this policy in a way that matters, we will update the effective date above and notify account holders in the app or by email. Continuing to use the service after a change means the updated policy applies.

Contact

[[LEGAL ENTITY — e.g. Vcomputer26 LLC]]
[[POSTAL ADDRESS]]
[[privacy@mydeskiso.com — must be a monitored mailbox]]