Who this applies to
Our customers are organizations, such as funders, brokers and accounting firms, that create an Underly account (“Customer”). Users are the people a Customer adds to its organization.
For bank statements and other merchant data uploaded to Underly, the Customer is the data controller. LendPipe processes that data on the Customer's instructions.
Information we collect
- Account data: your name, email address, password if you set one (stored hashed), the organization you belong to and your role in it.
- Billing data: your plan and billing history. Card details are collected and held by Dodo Payments; we never see or store card numbers.
- Customer content: the statements you upload and what Underly reads from them, such as transactions, balances, account details and business names, plus the labels, notes and offers you add.
- Usage data: pages visited, browser type, IP address and the time of each visit.
How we use information
- To provide and operate Underly
- To read statements and produce analyses for your organization
- To send sign-in codes and emails about the service
- To bill paid plans and apply plan limits
- To monitor performance, fix problems and prevent abuse
- To comply with legal obligations
Customer content
Statements and merchant data uploaded to Underly belong to the Customer. We do not look at that content for any purpose other than running Underly for you, including support you ask for.
Each organization's content is stored separately and is visible only to members of that organization.
AI and model training
Underly uses Google Cloud's Vertex AI to read statements. LendPipe does not use statements, figures or any other Customer content to train, fine-tune or improve AI models, and our agreement with Google prohibits it from using that content to train its models.
Service providers
We do not sell personal information. These providers process information on our behalf to run Underly:
| Provider | What it does | What it handles |
|---|---|---|
| Supabase | Database | Account data and analyses |
| Amazon Web Services | File storage and the Underly API | Uploaded statements and analyses |
| Google Cloud (Vertex AI) | Reading statements | Statement pages and text |
| Inngest | Running statement processing | Data passed between processing steps |
| Resend | Sending email | Email addresses and email content |
| Dodo Payments | Payments and billing | Billing details and card payments |
| PostHog | Product analytics | Usage data, and the name and email of signed-in users |
| Cloudflare | Bot checks at sign-up and sign-in | IP address and browser signals |
| Vercel | Hosting underly.app | Usage data and IP addresses |
We may also share information when required by law or court order, to protect the rights and safety of LendPipe or others, or in connection with a merger, acquisition or sale of assets, with appropriate confidentiality protections.
Cookies and analytics
Underly uses a cookie to keep you signed in. We use PostHog to understand how Underly is used. On the public pages of underly.app it records page views, clicks and session replays. Inside the app it records only which pages are opened and who is signed in; it never records the screen or the content of your statements. PostHog keeps an identifier in a cookie and in your browser's local storage.
Underly does not use advertising cookies or third-party tracking cookies.
Data retention
Uploaded statements and analyses are kept until you delete them. Deleting an analysis removes its statements, its figures and its stored files. Copies can remain in database backups and in our processing provider's run history for a limited time before they expire.
Account and organization data is kept while the account is active and for a reasonable period afterwards to meet legal and operational obligations. To delete an account and everything in it, email us.
Security
Every connection to Underly uses TLS, and stored statements and figures are encrypted at rest. No system is perfectly secure. If you believe your account has been compromised, email us immediately.
Your rights
You may ask to access, correct or delete your personal account information by emailing us. Requests about merchant data in uploaded statements should go to the Customer that uploaded them, as the Customer is the data controller for that information.
California residents may have additional rights under the CCPA, including the right to know what information we have collected and the right to request deletion.
Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify Customers by email or a notice in Underly before the changes take effect. Continued use after notice means you accept the updated policy.
Contact
Questions about this page, or a request about your data? Email hello@lendpipe.ai.