Lorica is a personal debt management and payment automation web application developed by Automate 100, LLC ("we," "us," or "Lorica"). Lorica helps users analyze debt, create payoff plans (e.g., Avalanche method with user overrides), accumulate funds for creditor payments, and automate scheduled ACH debits from their checking account to support accelerated debt payoff according to their selected strategy.
This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our service. It includes integrations with third parties such as Plaid (for read-only financial account linking), Stripe (for subscription billing), Legend Bank / Infinant (for individual DDA Dedicated Accounts via a direct sponsor bank relationship), Spinwheel (for user-directed creditor payments), and FirstPromoter (for affiliate/partner referral attribution and commission tracking). [PENDING CONTRACT EXECUTION with Legend Bank]
We do not sell your personal information for targeted advertising or similar purposes. By using Lorica, you acknowledge receipt of this Privacy Policy and our data practices described herein. Contractual consent to our terms is governed separately by the Lorica Terms of Service.
If applicable under the Gramm-Leach-Bliley Act (GLBA) and Regulation P, we provide a separate GLBA Privacy Notice detailing our practices for nonpublic personal information (NPI), including initial and annual delivery as required. This Privacy Policy supplements, but does not replace, any such GLBA notice. The GLBA Privacy Notice will be delivered electronically at account opening and annually thereafter. You may request a paper copy at no charge by contacting us at privacy@trylorica.com.
We collect only the information necessary to provide our service:
Account and Login Information: Email address and basic profile details you provide during sign-up. Lorica uses passwordless authentication (one-time email codes and passkeys); we do not collect or store account passwords. If you enable SMS verification, we also collect the mobile number you provide (see the SMS / Text Messaging section).
Financial Data via Plaid (with your explicit consent during linking): Read-only access to account balances, transaction history, masked account/routing numbers, and creditor/payee details. We do not collect, store, or have access to your full bank login credentials, passwords, or sensitive authentication tokens.
Payment and Subscription Data: Billing information processed securely by Stripe (e.g., credit/debit card details or ACH for subscriptions — we do not store full card numbers or sensitive payment info ourselves).
Affiliate / Partner Attribution Data: If you subscribe through a partner or affiliate referral (for example, by applying a partner’s coupon or referral code at checkout), we associate your subscription with the referring partner so that partner commissions can be calculated and paid. The data involved is your subscription identifier (Stripe customer ID), the associated invoice and commission metadata, and your email address, which is shared with our attribution provider, FirstPromoter. We do not share your bank account data, debt details, or identity-verification data with FirstPromoter. See Section 4.
Dedicated Account Data (if enrolled): If you choose to open a Dedicated Account, an individual DDA account is opened in your name at Legend Bank, Member FDIC, via Infinant (Legend Bank’s fintech core provider). [PENDING CONTRACT EXECUTION] Identity verification is performed via Plaid’s IAV product; results are passed to Infinant for bank-side CIP validation. Legend Bank retains ultimate responsibility for KYC/CIP and BSA/AML screening. We do not receive or store raw CIP data (e.g., SSN in identifiable form). We maintain operational logs of user consents, authorizations, and timestamps in our backend (Xano) solely to facilitate and support the service, consistent with our limited role and applicable recordkeeping obligations.
Usage and Device Data: IP address, browser type, device information, pages visited, and analytics collected via Xano (our backend platform) and our frontend application.
Other: Any information you voluntarily provide (e.g., debt details, payoff preferences, or responses to suggestions for third-party services). Some of the information we process, including financial account data and debt details, may constitute sensitive personal information under applicable state privacy laws. We use and disclose such information only to provide the services you have requested and as otherwise permitted by law. We do not use sensitive personal information to infer characteristics about you beyond what is necessary for the service.
Lorica uses minimal tracking technologies. We do not use advertising pixels, session replay tools, cross-site trackers, or third-party behavioral analytics. The following technologies are used solely to operate and improve the service:
Session and Authentication Cookies: Lorica sets session cookies required for login, authentication state, and security. These are first-party, session-scoped, and essential to the functioning of the service. You cannot opt out of these without losing access to your account.
Backend Operational Logs (Xano): Our backend platform captures server-side request logs including IP address, browser type, and page/endpoint accessed. These logs are used for debugging, security monitoring, and abuse prevention. They are not shared for advertising purposes and are retained for up to 90 days.
Frontend Analytics: Our frontend application may capture usage analytics (e.g., page views, feature interactions) to help us improve the product. No personally identifiable information is sent to third-party advertising networks.
Affiliate / Partner Attribution: Our partner and affiliate attribution (via FirstPromoter) is based on coupon or referral codes applied at checkout. It is used solely to attribute a subscription to the referring partner for commission purposes and does not place advertising pixels or perform cross-context behavioral advertising or cross-site identity resolution.
No Advertising Pixels or Cross-Site Tracking: Lorica does not use Facebook Pixel, Google Ads tags, or similar third-party advertising trackers. We do not participate in cross-context behavioral advertising or cross-site identity resolution.
Most browsers allow you to control cookies through browser settings. Disabling essential session cookies will prevent you from logging in to your account. Disabling analytics cookies will not affect your core service functionality.
We use your information to:
Provide debt analysis, personalized payoff recommendations (e.g., Avalanche prioritization with user overrides), budgeting tools, and fund accumulation tracking.
Facilitate optional automated ACH debits from your linked checking account (only after your explicit authorization and setup; draws never exceed available balance and never advance funds).
Process Stripe subscriptions for service access.
Enable user-directed creditor payments via Spinwheel (we do not communicate directly with creditors or reorder payments without your approval).
Attribute qualifying subscriptions to the partner or affiliate who referred you, for the purpose of calculating and paying partner commissions (via FirstPromoter). Attribution is based on the coupon or referral code applied at checkout.
Suggest (opt-in) referrals to non-profit debt counseling, debt management plan providers, or licensed debt settlement organizations if your situation warrants (Phase 2 only — not active at launch). We do not receive compensation that influences our recommendations. Any referral arrangement will be disclosed to you before it is activated.
Improve the service, debug issues, and ensure security.
Comply with legal obligations (e.g., responding to subpoenas, BSA/AML recordkeeping where applicable).
We process your personal information only for the purposes described in this Policy and do not use it for unrelated purposes without your consent. We do not use automated decision-making or profiling in a way that produces legal or similarly significant effects on you without your prior notice and, where required, consent.
We share information only as necessary and do not sell it for targeted advertising:
Service Providers: Plaid (account linking and KYC/IAV — see plaid.com/legal), Stripe (subscription payments — see stripe.com/privacy), Xano (backend infrastructure), our frontend application host, Legend Bank / Infinant (Dedicated Account setup, KYC/CIP validation, and AML compliance — see Legend Bank privacy policy [LINK TO BE ADDED UPON CONTRACT EXECUTION]), Spinwheel (creditor payment portal), FirstPromoter (affiliate/partner referral attribution and commission tracking — see firstpromoter.com privacy policy), ZeptoMail (transactional email delivery), and Twilio (SMS one-time passcodes). These providers are bound by strict contracts.
Partner / Affiliate Attribution (FirstPromoter): When you subscribe through a partner or affiliate referral, we share a limited set of data with FirstPromoter, our attribution provider, solely to attribute the subscription to the referring partner and calculate their commission: your subscription identifier (Stripe customer ID), the associated invoice and commission metadata, and your email address. We do not share your bank account information, transaction history, debt details, or identity-verification data with FirstPromoter. Attribution is coupon/referral-code based and is not used for advertising. FirstPromoter acts as our processor under a data processing agreement. This inbound partner-attribution activity is separate and distinct from the optional outbound debt-counseling referrals described immediately below.
As Required by Law: To comply with legal processes, protect rights/safety, or prevent fraud.
Affiliate Referrals to Debt-Counseling Providers (optional, Phase 2 only): If you consent to a suggestion, we may share limited contact/financial overview data with recommended third-party organizations (e.g., licensed non-profit DMP providers). Data shared with your consent is limited to your name, email, and a summary of your debt situation. You may withdraw this consent at any time by contacting privacy@trylorica.com. Not active at Phase 1 launch.
We do not ‘sell’ or ‘share’ personal information as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA), including for cross-context behavioral advertising.
For Plaid-linked data, Plaid may share with financial institutions or service providers as described in their policy; you can manage connections via Plaid Portal (my.plaid.com). Legend Bank controls privacy for any Dedicated Account — review their privacy policy (link to be provided upon contract execution). [PENDING CONTRACT EXECUTION]
If you provide your mobile phone number and opt in, we send you one-time passcodes (OTPs) and account-related text messages to verify your identity and secure your account (for example, at login or when authorizing sensitive actions). These messages are transactional; we do not send marketing texts. We deliver these messages through our SMS provider, Twilio.
We do not sell or share your mobile phone number, or your SMS opt-in or consent, with any third party or affiliate for their own marketing purposes. Message frequency varies based on your account and login activity. Message and data rates may apply. You can opt out at any time by replying STOP to any message; reply HELP for help or contact us at support@trylorica.com. Opting out of texts may limit SMS-based verification; other login and verification methods remain available.
We use industry-standard measures: HTTPS/TLS 1.3 in transit, AES-256 encryption at rest (via Xano), strict access controls, and multi-factor authentication (MFA). We regularly review and update safeguards in accordance with our Information Security Policy. No Lorica personnel have signatory authority, view-only access (beyond user-authorized support), or control over debits/credits outside your pre-authorized schedule.
In the event of a security breach involving your personal information, we will notify you and applicable regulators as required by law. We maintain an incident response plan and will provide notice within the timeframes required by applicable law (including within 30 days to the FTC where required under the GLBA Safeguards Rule).
We retain personal information only as long as necessary to provide the service, fulfill the purposes described in this Policy, comply with legal obligations, resolve disputes, and enforce our agreements.
Operational logs, consent records, and authorization timestamps (e.g., ACH setup, creditor directives) are retained for up to 5 years after account closure or last transaction, consistent with Bank Secrecy Act recordkeeping requirements (where applicable) and other regulations.
Plaid-linked financial data is not stored long-term beyond active use for features like income detection or suitability checks; historical transaction data is managed per Plaid’s policies.
After account termination or upon valid deletion request, we delete or anonymize personal information except as required by law (e.g., compliance records). Retention periods may vary based on applicable laws, including U.S. state privacy requirements.
| Data Category | Retention Period | Notes |
| Account / profile data | Duration of account + 5 years | Retained to support legal obligations and dispute resolution |
| Operational logs, consent records, ACH authorizations | 5 years after account closure or last transaction | BSA recordkeeping requirement where applicable; Reg E / NACHA authorization retention |
| Plaid-linked financial data | Not stored beyond active service use | Historical transaction data managed per Plaid policies; access tokens revoked on disconnection |
| Subscription / billing records (Stripe) | 7 years | Tax and accounting record retention requirements |
| Affiliate / partner attribution data (FirstPromoter) | Duration of partner relationship + as required for commission and tax records | Stripe customer ID, email, invoice/commission metadata held by attribution provider under DPA |
| Support communications | 3 years after resolution | Customer service and dispute history |
| Backend server / access logs (Xano) | 90 days | Security monitoring and abuse prevention |
| Compliance / legal records (SARs, OFAC, law enforcement) | 5 years from filing or relevant action | BSA mandatory retention |
| Anonymized / aggregated analytics | Indefinite | No personal information retained post-anonymization |
You may:
Access, correct, or delete your data (contact us at privacy@trylorica.com).
Revoke consents (e.g., unlink Plaid accounts via dashboard/Plaid Portal, toggle creditors, cancel automation — immediate stop of future actions with notifications to you and, where applicable, Spinwheel/Legend Bank).
Opt out of non-essential processing or affiliate suggestions.
Depending on your location, you may have additional rights under U.S. state privacy laws (including but not limited to California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Indiana, and others). These may include rights to know categories/sources of personal data collected and shared; opt out of targeted advertising, profiling, or sale/sharing of personal data (we do not sell or share for targeted advertising under these definitions); limit use of sensitive information; appeal decisions; and non-discrimination for exercising rights.
We honor Global Privacy Control (GPC) or universal opt-out signals where required. Submit requests to privacy@trylorica.com; we verify identity as needed and respond within statutory timelines (e.g., 45 days, extendable where permitted). You may designate an authorized agent to submit requests on your behalf. Authorized agent requests must be submitted to privacy@trylorica.com with written proof of authorization or a power of attorney. We may verify the consumer’s identity directly in addition to verifying the agent’s authority.
Our service is not directed to children under 13 (or 16 in some jurisdictions) and we do not knowingly collect data from them. If we become aware that we have collected personal information from a child under 13 without verifiable parental consent, we will delete that information as promptly as practicable. If you believe we may have inadvertently collected information from a minor, please contact us at privacy@trylorica.com.
We will notify you of material changes via email or in-app notice at least twenty-one (21) days before the effective date and will post the updated policy with a new effective date. If you continue using Lorica after the effective date of a material change, your continued use indicates you have reviewed the updated Policy. If you do not agree with any changes, you may close your account before the effective date. Contractual acceptance of updated terms is governed by the Lorica Terms of Service.
For privacy-related questions, requests, or concerns, please contact us:
| Field | Detail |
| Legal Name | Automate 100, LLC d/b/a Lorica |
| Mailing Address | 401 Broadway, Suite 100, Tacoma, WA 98402 |
| Privacy Email | privacy@trylorica.com |
| Response Timeframe | 45 days (extendable where permitted by law) |
| GLBA Privacy Notice | Delivered at account opening and annually; paper copy available on request |
If you believe your privacy rights have not been addressed to your satisfaction, you may also contact your state’s Attorney General or applicable privacy regulator. California residents may contact the California Privacy Protection Agency (cppa.ca.gov). Virginia residents may contact the Virginia Attorney General’s Consumer Protection Section.
By using Lorica, you acknowledge receipt of this Privacy Policy and our data practices as described herein. Contractual consent to Lorica’s terms of service is governed separately by the Lorica Terms of Service. You may withdraw consent to non-essential data processing at any time by contacting privacy@trylorica.com or using in-app controls.
| Version | Date | Summary | Approved By |
| 2.0 | March 2026 | Initial published draft. Synctera referenced as BaaS partner throughout. | William Eskridge, Founder |
| 2.2 | April 22, 2026 | BaaS partner updated: Synctera replaced with Legend Bank, Member FDIC / Infinant throughout. Dedicated Account corrected to individual DDA model via Infinant with Plaid IAV. Address corrected. Service providers list updated. Revocation language updated. Affiliate referral note updated to Phase 2 only. Perkins Coie engagement noted. [PENDING CONTRACT EXECUTION] on Legend Bank fields. | William Eskridge, Founder |
| 2.3 | July 2026 | Added FirstPromoter as an affiliate/partner attribution processor (Sections 1, 2, 2a, 3, 4, and retention schedule) and disclosed the referred-subscription data flow shared with it (Stripe customer ID, email, invoice/commission metadata). Clarified that inbound partner attribution is coupon/referral-code based and distinct from the Phase-2 outbound debt-counseling referrals (relabeled for clarity). Frontend vendor references generalized pending confirmation of the current host. | William Eskridge, Founder |
Prepared by: Automate 100, LLC · Version 2.3 · July 2026 · PRELIMINARY — PENDING COUNSEL REVIEW