Legal

Privacy Policy

Last updated: May 8, 2026

1. Who we are

Specter Systems ("we," "our," or "us") provides a commercial finance operating system that helps brokers, lenders, merchants, and finance teams manage funding applications, merchant files, supporting documents, underwriting workflows, lender submissions, CRM activity, communications, analytics, and third-party integrations.

2. Information we access

When you use Specter Systems or connect services to the platform, you authorize us to access and process the categories of data needed to deliver configured features.

This can include business and merchant funding applications, merchant files and supporting documents, bank statements, underwriting data, lender-submission materials, broker/lender/merchant workflow data, CRM routing records, user profiles, permissions, form submissions, including Jotform or other intake forms, and analytics or attribution data.

Where communications features or integrations are enabled, this can also include communications metadata and content, including email, SMS, call records, transcripts, action summaries, missing-information requests, message headers, labels, drafts, and related files or metadata.

For connected services such as Google Workspace, CRMs, communications providers, form tools, storage systems, analytics platforms, and lender portals, we process data according to your authorization, integration settings, applicable provider permissions, and our agreement with you. We do not request or store your Google password.

3. How we use your information

Application and file management: organizing merchant applications, supporting documents, bank statements, underwriting data, and lender-submission packages.

Workflow automation: routing CRM records, tracking missing information, generating operational summaries, preparing status updates, and coordinating broker, lender, merchant, and internal team activity.

Communications support: processing communications metadata or content where applicable to support email, SMS, calls, transcripts, summaries, follow-ups, and missing-information requests.

Document and data processing: extracting data, running OCR, classifying files, applying redaction or formatting rules, and writing standardized metadata for customer-designated systems.

Analytics and attribution: measuring pipeline activity, source attribution, operational performance, integration health, and product usage.

Audit, support, and security: logging processing events, troubleshooting issues, monitoring access, and protecting the Service.

We do not sell your data. We share it only with services you connect, integrations you enable or direct us to use, service providers that help us operate the Service, professional advisors, parties involved in a business transaction, or where required by law.

4. Data retention and deletion

Customer content may remain in Specter Systems, connected workspaces, CRMs, storage systems, form tools, communications platforms, lender portals, or other integrations depending on your configuration and retention settings.

We retain customer content, operational logs, backups, and security records for the periods needed to provide the Service, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and support business operations, unless a different retention period is stated in an applicable agreement.

You may revoke integration access through the relevant provider settings or request deletion by contacting us. Deletion requests may be limited by legal, security, backup, contractual, or operational requirements.

5. Security

All in-transit data is encrypted via TLS 1.2+.

Stored data is protected using encryption, access controls, monitoring, and other administrative, technical, and organizational safeguards appropriate to the nature of the Service.

Access keys and credentials are stored in managed secret systems where applicable and rotated based on operational risk and provider capabilities.

Least-privilege roles, authentication controls, and internal access procedures are used to limit Specter Systems personnel access to customer data.

No system can be guaranteed to be completely secure, and customers remain responsible for their own account access, user permissions, device security, and integration configurations.

6. Your choices

Integration access: review, limit, or revoke connected-service permissions through the relevant provider settings where available.

Data deletion: delete content in connected systems where you control it or request deletion by emailing privacy@spectersystems.io.

Marketing: where we send marketing communications, you can unsubscribe or opt out as described in those messages.

7. International data transfers

Specter Systems primarily operates from the United States. If you access the Service from outside the U.S., your information may be transferred to and processed in the U.S. and other countries where we or our service providers maintain facilities.

8. Children

Our service is intended for business users ages 18 and older. We do not knowingly collect information from children under 13.

9. Changes to this policy

We may update this Privacy Policy periodically. Material changes will be announced through reasonable notice, such as an in-app notice, email, or updated posting.

Continued use after the effective date constitutes acceptance.

10. Contact us

Questions or requests can be sent to privacy@spectersystems.io.

This Privacy Policy describes our data practices and is not legal, regulatory, lending, underwriting, credit, or compliance advice. Customers are responsible for their own lending, broker, underwriting, marketing, TCPA, GLBA, FCRA, ECOA, UDAAP, state licensing, privacy, data-security, and other legal or regulatory obligations.