Hyperloop ("we," "us") provides an accounts-receivable / cash-application
platform (app.hyperloopai.io) that helps businesses match incoming customer
payments to their invoices. This policy explains what we collect, how we use and
share it, and your choices.
Hyperloop is a B2B service used by businesses ("customers"). This policy covers
data we process about our customers, their authorized users, and the financial
data our customers connect to the service.
for users of the platform.
customers sync from their ERP/accounting systems.
bank account through Plaid, we receive **incoming transaction data and account
metadata** (account name, type, and last-four "mask") for the purpose of
matching payments to invoices. We request read-only access and only the
Transactions product; we do not initiate payments or move funds.
We use the information solely to provide the service: detecting incoming cash,
matching payments to open invoices (cash application), collections workflows,
reporting, and support. We do not sell personal or financial data, and we do
not use it for advertising.
We use Plaid Inc. to securely connect to your financial institution. When you
link an account, you interact with Plaid's flow and authorize the connection;
your banking credentials are handled by Plaid and are **never seen or stored by
Hyperloop**. Plaid's handling of your data is governed by Plaid's own privacy
policy (https://plaid.com/legal/#end-user-privacy-policy). We store only an
encrypted access token and the transaction/account data needed for cash
application.
We share data only with sub-processors that help us operate the service, under
appropriate contractual protections, limited to what each requires:
We may also disclose information to comply with law or protect our rights. We do
not sell your data.
If you connect a Google (Gmail) account to send accounts-receivable reminder emails, Hyperloop requests the single send-only scope https://www.googleapis.com/auth/gmail.send (plus openid and email to identify the connected account). Hyperloop's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements:
You connect and disconnect the Gmail integration at will, and you can revoke Hyperloop's access at any time from your Google Account permissions page.
We use technical and organizational measures appropriate to the risk, including encryption of data in transit and at rest, role-based and least-privilege access controls, per-customer data isolation, and access logging. No method of transmission or storage is completely secure, but we work to protect your information and review our measures over time.
We retain data only as long as needed to provide the service and meet legal/
recordkeeping obligations. Raw bank-transaction payloads are automatically purged
after 90 days; connections and associated bank data are deleted when you unlink
an account or on request/offboarding.
removes the connection and stops data collection.
data by contacting [email protected]. We honor applicable privacy-law
rights (e.g., CCPA/CPRA) and respond within the timeframe required by law.
By connecting a financial account, you consent to the collection, processing, and
storage of the associated data as described here and authorize the connection via
Plaid.
We may update this policy; we will revise the "Last updated" date and, for
material changes, provide additional notice.
Questions or requests: [email protected], HyperloopAI, Inc.,
131 Continental Dr, Suite 305, Newark, DE 19713.