Privacy Policy

Last Updated: March 15, 2026

Your privacy matters to us. This Privacy Policy explains how KorLoans collects, uses, and protects your personal information when you use our free loan tracking service.

1. Information We Collect

1.1 Account Information

When you create an account, we collect:

  • Email address (required for login and notifications)
  • Name (optional, for personalization)
  • Password (encrypted and stored securely)
  • Account role (lender or borrower)

1.2 Loan Tracking Data

To provide our service, we store the loan information you enter:

  • Loan amounts, interest rates, and terms
  • Payment records and dates
  • Disbursement records
  • Borrower information you add (names, phone numbers, email addresses)
  • Notes and custom fields you create

1.3 Usage Data

We collect limited analytics data to improve our service:

  • Page views, screen views, and feature usage (via PostHog Analytics)
  • Touch interactions and navigation patterns
  • Error logs for debugging
  • User identifiers linked to usage data (user ID, email, name) for product improvement

1.4 Technical Information

For security and service delivery:

  • IP address (for security and fraud prevention)
  • Browser type and version
  • Device information (mobile, desktop)
  • Session data (for authentication)

2. How We Use Your Information

We use the information we collect to:

  • Provide loan tracking functionality: Store and display your loan records, calculate balances, and track payments
  • Send email notifications: Payment reminders, portal invitations, and account updates (via Resend email service)
  • Improve the service: Analyze usage patterns to add features and fix bugs
  • Respond to support requests: Help you with questions and technical issues
  • Prevent fraud and abuse: Detect unauthorized access and malicious activity
  • Comply with legal obligations: Respond to valid legal requests

3. Data Storage and Security

We take data security seriously:

  • Secure servers: Your data is stored on secure servers with access controls and monitoring
  • Encryption in transit: All data transmitted between your device and our servers uses HTTPS encryption
  • Encrypted passwords: Passwords are hashed and salted using industry-standard algorithms
  • Regular backups: Automated backups protect against data loss
  • Limited access: Only authorized personnel can access production systems

However, no method of transmission over the Internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

4. Data Sharing

We DO NOT:

  • Sell your data to third parties
  • Share data with advertisers
  • Use your data for marketing to third parties
  • Share loan information with credit bureaus

We DO share with:

  • Email service provider (Resend): For sending notifications and invitations only
  • Analytics provider (PostHog): For product analytics and error tracking. PostHog receives user identifiers, screen views, and interaction data
  • Hosting provider: For secure data storage and service delivery
  • Users you invite: When you send a borrower portal invitation, that person can view their loan details only
  • Legal authorities: When required by law or to protect our rights

5. Your Rights

You have the following rights regarding your data:

  • Access: Request a copy of your personal data
  • Correction: Update or correct inaccurate information
  • Deletion: Delete your account and all associated data
  • Opt-out: Unsubscribe from email notifications (except essential account emails)
  • Data portability: Request a copy of your loan tracking data by contacting support

To exercise these rights, contact us at support@korloans.com

6. Cookies and Tracking

  • Session cookies: Required for login and authentication (essential for service)
  • PostHog Analytics: We use PostHog for product analytics to understand how our app is used and to improve the experience. PostHog collects screen views, touch interactions, and user identifiers (user ID, email, name). Data is sent to PostHog servers in the United States. PostHog does not use cookies on mobile.
  • No advertising cookies: We do not use tracking cookies for advertising purposes
  • No advertising analytics: We do not use Google Analytics or advertising-focused analytics services

7. Data Retention

  • Active accounts: Your data is retained as long as your account is active
  • Deleted accounts: Data is permanently deleted within 30 days after account deletion
  • Backup retention: Backups are retained for 90 days for disaster recovery purposes
  • Legal requirements: We may retain certain data longer if required by law

8. Children's Privacy

KorLoans is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

9. International Users

Your data may be processed and stored in servers located in various countries. By using KorLoans, you consent to the transfer of your information to these locations. We ensure appropriate safeguards are in place to protect your data in compliance with applicable privacy laws.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with a new "Last Updated" date. For material changes, we will notify you via email. Your continued use of KorLoans after changes are posted constitutes acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy or how we handle your data, please contact us at support@korloans.com