Platform Privacy Notice
Version 1.0 draft · August 23, 2026
The practices described here are current and accurate as at the date above. The wording of this notice is under legal review and may be refined — that review is about how it is expressed, not about whether it applies. Where the notice says a mechanism is not yet built, it says so explicitly (§9) rather than leaving it to be assumed.
This notice covers the Apsis Line platform — the software a lender licenses to take a borrower through a mortgage application. For how this public website handles information, see the separate Privacy Policy. They are different surfaces and they are governed separately.
1. Who is responsible for your information
Your lender is the data controller. Under the Gramm-Leach-Bliley Act (GLBA) and Regulation P, the financial institution you are applying with holds the customer relationship and decides how your information is used. Apsis Line is that lender’s service provider — we handle borrower data only to deliver the application experience on the lender’s behalf, under its contract.
The practical consequence, stated plainly because it decides where to send a question: your rights are exercised through your lender, not through us. Your lender’s own privacy notice governs your relationship. If you contact us directly we will route your request to the lender and tell you we have done so — we will not act unilaterally on a record the lender may be legally required to keep.
2. What the platform handles
| Category | Examples |
|---|---|
| Identity and contact | Name, address, phone, email, date of birth, Social Security number |
| Financial | Income, employment, assets, debts, account details |
| Property and loan | Property address and value, loan purpose, balances, rates, status |
| Application activity | Progress through the application, documents uploaded, consents given |
| Demographic information | Collected only where law requires it, under the Home Mortgage Disclosure Act (HMDA). Section 7 is a self-identification, and the platform records who actually entered each response so a co-applicant’s answer is never reported as that person’s own self-report. |
| Technical | Error and health signals, scrubbed of personal information before storage |
3. Why it is handled
To deliver the application: collecting what the loan requires, verifying it with the services your lender uses, and passing the file to the lender’s loan origination system, which is the system of record. We do not sell borrower information, and we do not use it for advertising.
Purpose limitation is contractual. Any use of borrower-derived data beyond delivering the loan experience exists only where the lender’s contract expressly grants it. Absent that grant, nothing learned from one lender’s deployment reaches another.
4. What is excluded by construction
Some protections are enforced by how the software is built rather than by policy, which is the distinction worth caring about:
- Each lender runs as its own isolated deployment — its own application, database, and credentials. No lender’s data shares a runtime, a database, or a key space with another’s.
- Your Social Security number never rests in durable local storage in the browser, and is scrubbed from the operational mirror.
- Vendor credentials never reach your browser. Every third-party call is made server-side.
- Product analytics carry no borrower personal information. Your internet protocol (IP) address is discarded at ingestion, identification is cookieless, and session replay is switched off at the project level.
- Raw amounts, free text, identity and protected characteristics are excluded from any product-improvement dataset by construction — not redacted afterwards.
5. Who else sees it
Your lender, always — it is the controller and the file is theirs. Your lender’s loan origination system, which holds the official record. Service providers the loan requires — credit, verification, appraisal, flood, and disclosure services — each reached with the lender’s own credentials and receiving only what that service needs. And the infrastructure providers that host the software: application hosting, the database, and product analytics, each bound by contract and none permitted to use borrower data for their own purposes.
We disclose information where the law requires it. We do not sell it.
6. The one thing that leaves a lender’s deployment
Named here rather than buried, because a notice that omitted it would be incomplete. A de-identified, tenant-anonymous set of structural aggregates — things like which journey type was used, which phase was reached, a bucketed count of debts, a device class — may be used to improve the product across deployments.
It carries no borrower personal information and no identification of which lender it came from. The exportable shapes are an explicit list a lender can inspect, the export is off unless a lender’s contract turns it on, and every record stamps the basis it was retained under.
7. How long it is kept
Retention of your loan file is your lender’s decision and obligation — mortgage records carry retention requirements under the Equal Credit Opportunity Act (ECOA), HMDA and the Truth in Lending Act and Real Estate Settlement Procedures Act Integrated Disclosure (TRID) rule, and those attach to the lender’s system of record, not to us. Within a lender’s deployment we hold data for as long as that lender’s contract directs, and on termination we return or destroy it on the timetable that contract sets.
Product-analytics events are de-identified and are retained on the analytics provider’s plan schedule. That window is currently longer than this use actually needs, and reducing it is an open item — we would rather say so than imply a shorter one.
8. Your rights, and the honest route to them
Depending on where you live you may have rights to access, correct, delete, or port your information, and to limit certain uses. Exercise them with your lender — as controller, it decides and it holds the official record. We support the lender in fulfilling those requests within its deployment.
Where a record is subject to a legal retention obligation, a deletion request may be refused or deferred in part. If that happens you should be told which records and why — a silent partial deletion is not an acceptable answer, and we will not produce one.
9. Current status — stated because it is true today
Apsis Line has no signed lender and no borrower data in production. This notice describes how the platform is built to handle your information when a lender operates it. Some of the automated mechanisms that support these commitments — a scheduled retention purge and an automated data-subject export and erasure routine — are designed and not yet built, and they must ship before any product-improvement collection is enabled. Collection for that purpose is currently off.
We publish that rather than describe a capability that is not operating yet.
10. Security
How the platform protects information — isolation, encryption, the audit trail, and what is deliberately not yet built — is on the Security page. If we confirm a security incident affecting a lender’s data, that lender receives written notice within two business days of confirmation; notification to consumers and regulators is the lender’s, as controller.
11. Children
The platform is for adults applying for a mortgage. It is not directed to children and we do not knowingly collect information from them.
12. Changes
We may update this notice; the version and date above reflect the current text. Material changes affecting licensed lenders are communicated through their named contact.
13. Contact
If you are a borrower, contact your lender first — it holds your file and your rights run through it. For questions about this notice or about how the platform is built: robert@apsisline.com, or see Support.