Legal

Privacy Policy

Effective Date
March 2026
Last Updated
July 2026
Version
2.4 (preliminary)
Review Status
Pending Counsel Review
Issued By
Automate 100, LLC d/b/a Lorica
Privacy Contact
v2.4 changes (July 2026): Added an SMS / Text Messaging section (4a) and disclosed Twilio (SMS) and ZeptoMail (email) as processors; updated Account & Login Information to reflect passwordless authentication (email one-time codes and passkeys; no stored passwords). PRELIMINARY — pending counsel review.
Contents
  1. 1. Introduction
  2. 2. Information We Collect
  3. 2a. Cookies and Tracking Technologies
  4. 3. How We Use Your Information
  5. 4. Sharing Your Information
  6. 4a. SMS / Text Messaging (Mobile Messaging)
  7. 5. Data Security
  8. 6. Data Retention
  9. Retention schedule by data category
  10. 7. Your Rights
  11. 8. Children’s Privacy
  12. 9. Changes to This Policy
  13. 10. Contact Us
  14. Acceptance
  15. Version History

1. Introduction

Lorica is a personal debt management and payment automation web application developed by Automate 100, LLC ("we," "us," or "Lorica"). Lorica helps users analyze debt, create payoff plans (e.g., Avalanche method with user overrides), accumulate funds for creditor payments, and automate scheduled ACH debits from their checking account to support accelerated debt payoff according to their selected strategy.

This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our service. It includes integrations with third parties such as Plaid (for read-only financial account linking), Stripe (for subscription billing), Legend Bank / Infinant (for individual DDA Dedicated Accounts via a direct sponsor bank relationship), Spinwheel (for user-directed creditor payments), and FirstPromoter (for affiliate/partner referral attribution and commission tracking). [PENDING CONTRACT EXECUTION with Legend Bank]

We do not sell your personal information for targeted advertising or similar purposes. By using Lorica, you acknowledge receipt of this Privacy Policy and our data practices described herein. Contractual consent to our terms is governed separately by the Lorica Terms of Service.

If applicable under the Gramm-Leach-Bliley Act (GLBA) and Regulation P, we provide a separate GLBA Privacy Notice detailing our practices for nonpublic personal information (NPI), including initial and annual delivery as required. This Privacy Policy supplements, but does not replace, any such GLBA notice. The GLBA Privacy Notice will be delivered electronically at account opening and annually thereafter. You may request a paper copy at no charge by contacting us at privacy@trylorica.com.

2. Information We Collect

We collect only the information necessary to provide our service:

2a. Cookies and Tracking Technologies

Lorica uses minimal tracking technologies. We do not use advertising pixels, session replay tools, cross-site trackers, or third-party behavioral analytics. The following technologies are used solely to operate and improve the service:

Most browsers allow you to control cookies through browser settings. Disabling essential session cookies will prevent you from logging in to your account. Disabling analytics cookies will not affect your core service functionality.

3. How We Use Your Information

We use your information to:

We process your personal information only for the purposes described in this Policy and do not use it for unrelated purposes without your consent. We do not use automated decision-making or profiling in a way that produces legal or similarly significant effects on you without your prior notice and, where required, consent.

4. Sharing Your Information

We share information only as necessary and do not sell it for targeted advertising:

We do not ‘sell’ or ‘share’ personal information as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA), including for cross-context behavioral advertising.

For Plaid-linked data, Plaid may share with financial institutions or service providers as described in their policy; you can manage connections via Plaid Portal (my.plaid.com). Legend Bank controls privacy for any Dedicated Account — review their privacy policy (link to be provided upon contract execution). [PENDING CONTRACT EXECUTION]

4a. SMS / Text Messaging (Mobile Messaging)

If you provide your mobile phone number and opt in, we send you one-time passcodes (OTPs) and account-related text messages to verify your identity and secure your account (for example, at login or when authorizing sensitive actions). These messages are transactional; we do not send marketing texts. We deliver these messages through our SMS provider, Twilio.

We do not sell or share your mobile phone number, or your SMS opt-in or consent, with any third party or affiliate for their own marketing purposes. Message frequency varies based on your account and login activity. Message and data rates may apply. You can opt out at any time by replying STOP to any message; reply HELP for help or contact us at support@trylorica.com. Opting out of texts may limit SMS-based verification; other login and verification methods remain available.

5. Data Security

We use industry-standard measures: HTTPS/TLS 1.3 in transit, AES-256 encryption at rest (via Xano), strict access controls, and multi-factor authentication (MFA). We regularly review and update safeguards in accordance with our Information Security Policy. No Lorica personnel have signatory authority, view-only access (beyond user-authorized support), or control over debits/credits outside your pre-authorized schedule.

In the event of a security breach involving your personal information, we will notify you and applicable regulators as required by law. We maintain an incident response plan and will provide notice within the timeframes required by applicable law (including within 30 days to the FTC where required under the GLBA Safeguards Rule).

6. Data Retention

We retain personal information only as long as necessary to provide the service, fulfill the purposes described in this Policy, comply with legal obligations, resolve disputes, and enforce our agreements.

Retention schedule by data category

Data CategoryRetention PeriodNotes
Account / profile dataDuration of account + 5 yearsRetained to support legal obligations and dispute resolution
Operational logs, consent records, ACH authorizations5 years after account closure or last transactionBSA recordkeeping requirement where applicable; Reg E / NACHA authorization retention
Plaid-linked financial dataNot stored beyond active service useHistorical transaction data managed per Plaid policies; access tokens revoked on disconnection
Subscription / billing records (Stripe)7 yearsTax and accounting record retention requirements
Affiliate / partner attribution data (FirstPromoter)Duration of partner relationship + as required for commission and tax recordsStripe customer ID, email, invoice/commission metadata held by attribution provider under DPA
Support communications3 years after resolutionCustomer service and dispute history
Backend server / access logs (Xano)90 daysSecurity monitoring and abuse prevention
Compliance / legal records (SARs, OFAC, law enforcement)5 years from filing or relevant actionBSA mandatory retention
Anonymized / aggregated analyticsIndefiniteNo personal information retained post-anonymization

7. Your Rights

You may:

Depending on your location, you may have additional rights under U.S. state privacy laws (including but not limited to California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Indiana, and others). These may include rights to know categories/sources of personal data collected and shared; opt out of targeted advertising, profiling, or sale/sharing of personal data (we do not sell or share for targeted advertising under these definitions); limit use of sensitive information; appeal decisions; and non-discrimination for exercising rights.

We honor Global Privacy Control (GPC) or universal opt-out signals where required. Submit requests to privacy@trylorica.com; we verify identity as needed and respond within statutory timelines (e.g., 45 days, extendable where permitted). You may designate an authorized agent to submit requests on your behalf. Authorized agent requests must be submitted to privacy@trylorica.com with written proof of authorization or a power of attorney. We may verify the consumer’s identity directly in addition to verifying the agent’s authority.

8. Children’s Privacy

Our service is not directed to children under 13 (or 16 in some jurisdictions) and we do not knowingly collect data from them. If we become aware that we have collected personal information from a child under 13 without verifiable parental consent, we will delete that information as promptly as practicable. If you believe we may have inadvertently collected information from a minor, please contact us at privacy@trylorica.com.

9. Changes to This Policy

We will notify you of material changes via email or in-app notice at least twenty-one (21) days before the effective date and will post the updated policy with a new effective date. If you continue using Lorica after the effective date of a material change, your continued use indicates you have reviewed the updated Policy. If you do not agree with any changes, you may close your account before the effective date. Contractual acceptance of updated terms is governed by the Lorica Terms of Service.

10. Contact Us

For privacy-related questions, requests, or concerns, please contact us:

FieldDetail
Legal NameAutomate 100, LLC d/b/a Lorica
Mailing Address401 Broadway, Suite 100, Tacoma, WA 98402
Privacy Emailprivacy@trylorica.com
Response Timeframe45 days (extendable where permitted by law)
GLBA Privacy NoticeDelivered at account opening and annually; paper copy available on request

If you believe your privacy rights have not been addressed to your satisfaction, you may also contact your state’s Attorney General or applicable privacy regulator. California residents may contact the California Privacy Protection Agency (cppa.ca.gov). Virginia residents may contact the Virginia Attorney General’s Consumer Protection Section.

Acceptance

By using Lorica, you acknowledge receipt of this Privacy Policy and our data practices as described herein. Contractual consent to Lorica’s terms of service is governed separately by the Lorica Terms of Service. You may withdraw consent to non-essential data processing at any time by contacting privacy@trylorica.com or using in-app controls.

Version History

VersionDateSummaryApproved By
2.0March 2026Initial published draft. Synctera referenced as BaaS partner throughout.William Eskridge, Founder
2.2April 22, 2026BaaS partner updated: Synctera replaced with Legend Bank, Member FDIC / Infinant throughout. Dedicated Account corrected to individual DDA model via Infinant with Plaid IAV. Address corrected. Service providers list updated. Revocation language updated. Affiliate referral note updated to Phase 2 only. Perkins Coie engagement noted. [PENDING CONTRACT EXECUTION] on Legend Bank fields.William Eskridge, Founder
2.3July 2026Added FirstPromoter as an affiliate/partner attribution processor (Sections 1, 2, 2a, 3, 4, and retention schedule) and disclosed the referred-subscription data flow shared with it (Stripe customer ID, email, invoice/commission metadata). Clarified that inbound partner attribution is coupon/referral-code based and distinct from the Phase-2 outbound debt-counseling referrals (relabeled for clarity). Frontend vendor references generalized pending confirmation of the current host.William Eskridge, Founder
COUNSEL REVIEW REQUIRED BEFORE PUBLICATION. This Policy was prepared by Automate 100, LLC for internal planning purposes only. It must be reviewed and approved by qualified privacy counsel before publication or presentation to any consumer. All bracketed fields must be completed prior to launch. This Policy should be reviewed in conjunction with Lorica’s GLBA Privacy Notice, RegE Disclosure, AML/BSA Program, and Terms of Service.

Prepared by: Automate 100, LLC · Version 2.3 · July 2026 · PRELIMINARY — PENDING COUNSEL REVIEW