Privacy
Effective for current ConditionRail workspaces.
Scope
ConditionRail is mortgage file infrastructure. This policy describes the categories of data we handle on behalf of lender, broker, and credit-union customers, how that data moves between systems, and what controls customers and borrowers retain.
1. Borrower documents
We process borrower-uploaded documents such as paystubs, W-2s, bank statements, tax returns, identification, gift letters, and homeowners insurance evidence. Documents are stored encrypted at rest and routed only to the lender workspace that requested them.
2. Mortgage file metadata
For each loan file we store condition lists, condition status, request timestamps, document classifications, exception reasons, and underwriter-readiness markers. This metadata never includes credit decisions issued by the lender.
3. Account and team data
For workspace users we store name, work email, workspace assignment, role within the workspace, and authentication events. We do not collect government identifiers for workspace users.
4. Communication logs
Reminders and status messages sent to borrowers (SMS, email) are logged with timestamps, delivery state, and the workspace user who triggered the action. Message bodies are retained for audit and dispute resolution.
5. LOS sync metadata
When a workspace is connected to a Loan Origination System, we record the systems connected, fields synced, sync timestamps, and the workspace user that authorized the connection. Credentials are stored in an encrypted secret store and never exposed to client code.
6. Consent and revocation
Borrowers consent to document handling at the point of upload and may revoke consent by contacting their lender. Lender administrators may revoke a borrower's portal access at any time; ConditionRail honors revocation on the next request.
7. Data retention
Default retention is seven (7) years from loan disposition, aligned with common mortgage recordkeeping practice. Customers may configure a shorter or longer retention window in their workspace settings, subject to applicable law and their own compliance program.
8. Self-hosted and customer-controlled deployment
ConditionRail is available in a customer-controlled deployment option where borrower documents and mortgage file metadata reside in storage and database resources owned by the customer. Customers retain full control of encryption keys, network boundaries, and export.
9. No use of borrower or customer data for model training
ConditionRail does not use borrower documents, mortgage file metadata, message contents, or any customer data to train, fine-tune, or evaluate machine learning models. This applies to first-party models and any third-party model providers integrated into the product.
AI may classify, match, draft, and flag. It may not approve, deny, waive, or communicate a credit decision.
Prepared by ConditionRail for lender review. Final credit, compliance, underwriting, and adverse-action decisions remain with authorized lending staff.
10. Subprocessors
We use a limited set of subprocessors for cloud hosting, transactional email, SMS delivery, and observability. A current list is available on request and is updated when subprocessors change.
11. Contact
Privacy questions and data subject requests: privacy@conditionrail.com.
12. Legal entity
ConditionRail, Inc, 123 E Tarpon Ave, Tarpon Springs, FL 34689. Privacy requests: privacy@conditionrail.com · Legal notices: legal@conditionrail.com.