Privacy
How SweetTech handles information — for visitors to this website, and for the data our lending-institution customers entrust to the platform.
Effective 2026-09-02 · Last updated 2026-09-02
Who we are, and who this covers
This policy is published by SweetTech (“Sweet”, “we”), 1495 Canyon Boulevard, Suite 101, Boulder, CO 80302, US. It covers the websites SweetTech operates — sweettech.ai and sweetag.ai, including the status pages at /status/ on each: two names for the same company and the same platform. It also covers two different relationships, and your rights run differently in each:
- Visitors and business contacts
- If you visit this website or contact us about the product, Sweet decides what is collected and why, and is responsible to you for it. The sections below on what this website collects and how we use it describe what that is.
- Borrowers at institutions that use Sweet
- If you are applying for or holding a loan with a lending institution that runs on Sweet, your relationship — and your data relationship — is with that institution. The institution decides what is collected and how it is used; Sweet processes that data as the institution's service provider, only on its documented instructions and under contract with it. Requests about your loan or your data go to your institution, and we support institutions in answering them.
What this website collects
Little, by design. This is a static informational site: it has no accounts, no logins, no advertising and no cross-site identifiers. It uses one analytics service, Google Analytics, to measure how the site is used — which pages are visited, in what order, from which referrer, on what kind of device — and that is the only analytics or tracking script it loads. Videos on this site load from YouTube only when you choose to play them.
- Analytics cookies, from Google Analytics
- Google Analytics sets first-party cookies (
_ga,_ga_*) to tell a returning browser from a new one and to group page views into a visit. Google processes the resulting usage data on our behalf under its terms; Google states that Google Analytics 4 does not log or store IP addresses. We use it to understand how the site is used, not for advertising. If your browser sends a Global Privacy Control or Do Not Track signal, Google Analytics is switched off for your visit: no analytics cookie is set and no usage data is sent. - Security cookies, from our CDN
- The site is delivered through Cloudflare, which may set security cookies (such as
cf_clearance) when its automated-traffic checks run for a visitor. They distinguish a verified browser from a bot, are not readable by this site's code, and — Cloudflare states — are used for security, not cross-site tracking. - Server logs
- Cloudflare, as our hosting and delivery provider, keeps standard edge logs (IP address, request URL, user agent, timestamp) for security and operations under its own policies.
- If you contact us
- When you reach out — through the contact form when one is offered on this site, or by email — we collect what you provide: typically your name, work email, institution, role, and your message. Form submissions are delivered to us by Web3Forms, a form delivery service.
- If you subscribe to status updates
- Your email address, or the Slack or Teams destination you provide, delivered through Atlassian Statuspage (see Who else processes data).
- Do Not Track and GPC
- We honour both. When your browser sends a Do Not Track or Global Privacy Control signal, Google Analytics is switched off for your visit using Google's own opt-out setting: no analytics cookie is set and no usage data is sent to Google. Cloudflare's security cookies and edge logs are unaffected, because they are security measures rather than tracking.
How we use information you give us
We use enquiry information to respond to you, to prepare demos and proposals relevant to your institution, and to maintain ordinary business records of the conversation. We do not sell it, share it for advertising, or pass it to anyone other than service providers who process it for us under contract. We keep enquiry information for as long as the conversation and our ordinary business records require.
Platform data: what Sweet processes for institutions
Sweet is a loan origination and servicing platform licensed by lending institutions. In providing it, Sweet processes borrower and institution data as a service provider, solely to deliver the service under each institution's agreement and instructions. Lending institutions are regulated financial institutions, and Sweet handles this data consistent with the confidentiality and safeguarding obligations that apply to their service providers, including under the Gramm–Leach–Bliley Act. Depending on what each institution enables, that data can include:
- Identity and contact data
- Names, addresses, dates of birth, government identifiers, and contact details of applicants, borrowers, and related parties.
- Application and financial data
- Loan applications, financial statements, collateral and property information, and the documents submitted with them.
- Data from connected sources
- Where an institution enables an integration, data flows from that provider under the institution's instructions — for example bank account and transaction data through financial data connections, or credit reports from the bureaus the institution orders from. Credit reports are ordered by the institution, held for that institution alone, and are never combined across customers or resold.
- Documents and signatures
- Generated loan documents, uploaded files, and electronic signature and vaulting records.
- Communications
- Notifications the institution sends borrowers through the platform, by email and SMS.
Sweet does not sell this data and does not use it for advertising. Where the platform's AI-assisted features process it — reading submitted documents, checking files for completeness, raising flags for review — they do so as part of the service, and the platform is built so that credit decisions are made by people at the lending institution: Sweet's AI does not approve, decline, or price a loan.
Where data lives, and how it is protected
- Location
- Customer data is stored and processed in the United States, on Amazon Web Services in us-east-1 (N. Virginia) — the sole cloud region for the production platform.
- Isolation
- Each institution's loan, borrower, and document data is held in a dedicated database and a dedicated document store for that institution — it is not pooled with other customers' records.
- Encryption
- TLS 1.2 minimum in transit on all public endpoints — older protocols are refused. AES-256 encryption at rest across the database and document storage, with keys managed in AWS KMS, including institution-specific keys for personally identifiable information.
- Access
- Institution users authenticate through the institution's own single sign-on (SAML/OIDC) where configured; Sweet's internal access is role-based and limited to what operating the service requires.
The control framework and attestations behind this are set out on the security page.
Security incidents
If a confirmed security incident affects an institution's data, Sweet notifies that institution without undue delay, as its agreement and applicable law require, and supports the institution in meeting its own notification obligations to borrowers and regulators.
Who else processes data, and why
Sweet does not sell data — enquiries or platform data — to anyone. We disclose it only to service providers under contract with us — including the principal providers below (list current as of 2026-09-02) — at an institution's direction, or where the law requires it. Providers that help Sweet run the platform and this website act under contract; those handling platform data act on our instructions, and our website CDN (Cloudflare) additionally keeps edge logs under its own policies, as described above:
- Amazon Web Services
- Cloud hosting for the production platform (us-east-1, United States).
- Cockroach Labs
- Managed database service, itself running on AWS us-east-1.
- Cloudflare
- Delivery, DNS, and security for this website.
- Novu
- Notification orchestration for platform email and SMS.
- Twilio
- SMS delivery for platform notifications.
- SendGrid
- Email delivery for platform notifications.
- Sentry
- Application error monitoring, used to keep the service reliable.
- Atlassian Statuspage
- Service-status notifications: if you subscribe to updates on our status page, your email address or the webhook destination you provide is processed there to deliver them.
- Nutrient
- Document viewing and processing components in the platform.
- Google (Google Analytics)
- Usage analytics for this website: page views, referrer and device information, processed under Google's terms. Switched off when your browser sends a Global Privacy Control or Do Not Track signal.
Separately, integrations an institution chooses to enable — financial data connections, credit bureaus, electronic signature and vaulting providers, CRM systems — receive data because that institution directed it, under that institution's own agreements with those providers. Institutions are notified of sub-processor changes as their agreements provide.
Retention
Platform data is retained for the duration of the institution's agreement and as the institution instructs; lending records carry their own regulatory retention periods, which the institution controls. When an agreement ends, data is returned or deleted in accordance with the contract, and residual copies in backups are handled in accordance with that contract. Website enquiries are kept only as long as described above.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, and to object to or restrict some processing.
- If you are a borrower
- The fastest and usually the legally correct route is your lending institution: it holds the relationship and the obligation, and Sweet supports it in fulfilling verified requests.
- If you contacted us directly
- Email privacy@sweettech.ai. We will verify the request — for example against the email address of record — and respond within the time the applicable law allows.
- Security concerns
- Email security@sweettech.ai.
Children
This site is aimed at people doing their jobs at lending institutions. It is not directed at children and we do not knowingly collect anything from them.
Changes to this policy
Material changes get a new effective date at the top of this page, and the previous version stays available on request. Material changes apply going forward — not to information collected before the change, unless you agree.
- Privacy contact
- privacy@sweettech.ai
- Postal address
- SweetTech, 1495 Canyon Boulevard, Suite 101, Boulder, CO 80302, US