Last updated August 13, 2026

Portal Privacy Policy

How the Bay Street merchant portal handles your bank-account data. This policy covers the portal specifically; our general privacy policy covers funding applications and the main website.

When you connect your business bank account, we receive a read-only copy of your transaction history and balances. If you choose manual access instead, you can upload bank statements containing the same kinds of information. We use that bank activity to show you what you still owe, whether your payments are tracking, and what your funding costs as a share of what comes in. Connected-bank data refreshes automatically; a manual statement remains current through its printed end date until you upload a newer one. Every figure in Positions is dated so you always know how current it is. We can never move money — the portal has no ability to debit, transfer, or pay from your account. You can disconnect at any time; the retention rules below explain when each copy is deleted.

From your connected bank account (via Plaid): transaction records (date, amount, description, pending status), account balances, and basic account metadata (such as account name and type) for the accounts you select. When you first connect we receive up to the previous 12 months of history, so your position history reflects your full funding period from day one. After that Plaid sends ongoing transaction updates — your balance and payment status are current as of the date shown in Positions, not live to the minute.

From bank statements you choose to upload: the original PDF and the account holder, statement period, balances, and posted transactions shown in it. We accept a statement as a position source only after its opening balance, transactions, and closing balance reconcile. Uploaded statements are a dated snapshot and do not refresh automatically.

We never receive your bank login credentials. You enter those directly with Plaid, our bank-connection provider. We also do not request account or routing numbers — the portal does not use the Plaid products that provide them.

Directly from you: your email address (for sign-in), funding-request amount and timing, messages to Bay Street, and files you choose to upload.

From our own records: the terms of the funding we placed for you — amount, payment schedule, balance — which is information Bay Street already holds.

How you use the portal: which pages you open, what you click, and a replay of your session, so we can find the places the portal is confusing or broken. These recordings are masked: we capture the page layout and where you clicked, not the words or numbers on the screen and not what you type. Your balances, transactions, account numbers and form entries are hidden from the recording before it leaves your browser. We record this against your business, not your name, and we do not use it to make funding decisions.

Solely to operate the portal and support your account: calculating your remaining balance and payment progress, detecting whether scheduled payments cleared, identifying other funding positions visible in your account so you can see your total obligations, handling requests for additional funding, and letting your Bay Street advisor help you. We do not sell your data, and we do not use it for advertising.

We share data only with service providers who help us run the portal, each bound by contract to protect it: Plaid (bank connection — Plaid’s End User Privacy Policy), Supabase (encrypted database and sign-in), Vercel (application hosting), Fireworks AI (automated extraction of bank statements and other documents you choose to upload), Salesforce (our customer-relationship system, where uploaded documents are copied for internal review), and Microsoft 365 (internal funding-request notifications, which may include those documents as attachments), and PostHog (masked product analytics and session replay, as described above). We also use email providers for sign-in codes. We may also disclose information where required by law. We do not sell or rent your data to anyone.

Bank connection: when you disconnect — or when your funding relationship ends and you are offboarded — your Plaid access is revoked immediately, so no further data can be retrieved. Any one-off or legacy report generated from your account is deleted at Plaid as well, not merely left unused.

Transactions and balances: deleted within 90 days of the end of your funding relationship, unless a specific record must be kept to meet a legal or audit obligation.

Contact details, messages, and funding-request details: deleted when your merchant record is removed.

Uploaded documents and bank statements: the encrypted portal copy remains until you remove it in Document Center or your merchant record is removed. Removing an accepted bank statement also removes the parsed bank facts that depended on it. Copies placed in Salesforce or included in an internal funding-request email are business records retained under Bay Street’s general privacy and regulatory retention requirements; removing the portal copy does not remove those records.

Note that records relating to your original funding application — the documents and information you submitted to obtain financing — are held separately by Bay Street under its general privacy policy and longer regulatory retention requirements. Documents submitted with a request for additional funding become part of those application records.

Disconnect at any time — contact your Bay Street advisor and we will revoke the connection, typically within 7 days and immediately on request where possible.

Turn off usage analytics by enabling “Do Not Track” in your browser settings. We honour that signal: with it on, we record no pages, no clicks and no session replay. Everything else in the portal works exactly the same.

Request deletion or a copy of your portal data by contacting your advisor or Bay Street directly. We action deletion requests within 30 days and confirm when complete. If a specific record must be retained for a legal obligation, we will tell you what and why, and delete everything else.

Your bank data is encrypted at rest — both by our database platform and, at the application layer, with AES-256-GCM, so the stored records are unreadable without a key held outside the database. All traffic is encrypted in transit with TLS 1.2 or higher. Access to the portal requires an emailed sign-in code, and you can only ever see your own business. Internal access is restricted by role and protected by multi-factor authentication.

Questions about this policy, or about the data we hold: contact your Bay Street advisor, or email privacy@baystreetlending.com.

← Back to the portal