Privacy policy
Last meaningful update: May 17, 2026. This is a plain-English summary of how Settled handles your information today. The formal policy is being finalized with counsel; if anything here surprises you, email chris@settled.work and we'll explain it or fix it.
What we collect
To verify you and move money on your behalf, we collect: your phone number (used for sign-in and notifications), your legal first and last name, your business name and EIN if you're a paying GC, your residential or business address, your date of birth, the last four digits of your SSN (for sender-side KYC), and a bank link via Plaid (we receive a processor token — never your bank login).
When you sign a lien waiver in the app, we additionally store your typed name, your company name, an image of your drawn signature, your IP address, the user-agent string of the device you signed on, and the timestamp.
Who we share it with
We share the minimum required to operate the rails:
- Dwolla — for ACH disbursement and KYC. They are a U.S.-regulated money-services business and move funds through their partner banks.
- Plaid — for bank account verification.
- Clerk — for phone OTP authentication.
- Twilio + Resend — for SMS and email delivery.
- Your construction lender — when you or your GC opts to send a signed release packet to the bank of record. This is what makes the waiver useful; we tell you which bank each time.
We do not sell your data. We do not share it with advertisers. We do not use it to train models.
What counterparties see
People you transact with see your name and phone number (so they can recognize who's paying or invoicing them). They never see your bank account name, your bank account mask, the institution that holds your account, your address, your DOB, or your SSN. The same protection runs the other way — you see counterparties' names, never their banking details.
How long we keep it
Account records and signed waivers are retained for at least seven years to satisfy state lien-record retention rules. You can delete optional fields (e.g. email, notification preferences) at any time. Core KYC and audit-trail records can't be deleted while you have active payments or open signed releases — regulators require us to keep them.
Your rights
Email chris@settled.work to: see what we have on you, correct it, delete optional parts of it, or close your account. We respond within seven business days.