How we protect your information
Last updated: September 4, 2026. See every published version.
What this page is
In plain terms: A description of how we actually handle your information, written so you can check it against what we do.
Manufactor Finance is a brand of JayBen, LLC. This page describes the controls we run on the information you give us, who can reach it, how long we keep it, and how to make us stop. It sits alongside our Privacy Policy, Terms of Use, and Disclosures. Where this page and the Privacy Policy describe the same practice, they are drawn from the same configuration, not written twice.
What we collect and what we don't
In plain terms: Contact details, what you tell us about your business, and how you used the form. No Social Security numbers, no bank logins, no payment card numbers.
We collect your name, company, email, phone number, state, the funding details you enter, and the record of your consent. We collect basic technical details about the submission: browser, language, timezone, referring page, and a one-way hash of your IP address rather than the address itself.
We do not collect Social Security numbers, bank credentials, or payment card numbers on this site. A funding partner may request underwriting documents later, directly from you, under their own agreement and their own security controls.
How we protect it
In plain terms: Encrypted at rest with keys we rotate, phone numbers stored only as a one-way hash plus the last 4 digits, files in private storage behind expiring links, optional scripts only after you consent, and a strict content security policy.
- Sensitive fields are encrypted at rest with managed keys that are versioned and rotated on a schedule.
- Phone numbers are held as a one-way hash plus the last 4 digits for display. The full number exists only in transit to the CRM or the funding partner you asked us to contact.
- Uploaded files live in private storage. They are reachable only through short-lived signed links, are re-encoded to strip embedded metadata, and are stored under random names.
- Analytics and advertising scripts load only after you consent, and never when your browser sends a Global Privacy Control signal.
- A content security policy limits what code the page is allowed to load, and violations are reported back to us.
Who can access it
In plain terms: Two named roles, sign-in through Google plus a second factor, sessions that expire, and an action log that cannot be edited.
Access is limited to 2 named roles: owner and operator. Operators work leads. Only the owner can change who has access, export consent evidence, or delete records. Sign-in is Google plus a second factor, sessions expire, and idle sessions end on their own.
Every administrative action and every sign-in, failure, and denied attempt is written to an append-only log. The log cannot be edited or deleted by anyone, including the owner.
How long we keep it
In plain terms: Fixed windows, published here, enforced by scheduled jobs and a legal hold when the law requires it.
| Record | How long |
|---|---|
| Consent records | 5 years |
| Lead and inquiry records with hashed identifiers on our systems | 5 years |
| Contact records, conversations, and any call recordings in our CRM platform | deleted 24 months after last activity, then permanently purged by the platform within 2 months |
| Cookie preference choices | 12 months |
| Any other operational data | no longer than needed for the purpose it was collected |
A legal hold pauses deletion when a dispute or legal matter requires it; held records are deleted when the hold ends.
This table is rendered from the same configuration the scheduled purge jobs read, so the published window and the enforced window cannot drift.
How consent is documented
In plain terms: We keep the page as you saw it, an image of the consent text with the box checked, the timing of your interactions, the version of the site and the language you saw, and a tamper-evident chain linking each record to the one before it.
When you submit a form we write a consent record: a copy of the page as it appeared to you with your typed answers masked, an image of the form area showing the consent text and the checked box, the timing of your interactions with the form, whether the consent text was on your screen when you checked the box, your browser and device details, a one-way hash of your IP address, the version of the site and consent language you saw, and a hash linking the record to the records before it.
Records are append-only. They cannot be edited after they are written, they are preserved monthly to write-once storage, and they are kept for 5 years. You can ask for a read-only copy of your own record at any time.
How to stop us
In plain terms: Use the stop page, reply STOP to a text, or email us. We stop and tell the partners who received your request within 10 business days.
Use Stop Contacting Me, reply STOP to any text message, or email hello@manufactorfinance.com. Tell us the number or email to stop, and we stop and tell the partners who received your request within 10 business days.
A stop request is recorded permanently so it survives any later import, and future submissions from that number or email are blocked rather than quietly accepted.
How to get your records
In plain terms: Ask, and we send what we hold about you, including your consent record.
Use the request form or email hello@manufactorfinance.com to access, correct, or delete what we hold, or to receive a copy of your consent record. We verify that the request comes from the person the records describe before we release anything.
Who else touches it
In plain terms: Named service providers under contract, AI providers under business terms that prohibit training on your data, and the funding partners you asked us to contact, who are independent companies.
- Hosting and database: our application host and managed database provider.
- CRM and messaging: HighLevel, which holds contact records, conversations, and call recordings.
- Email delivery: Resend.
- Measurement: Google Analytics and PostHog, loaded only with your consent.
- AI providers: only providers on an internal allowlist may receive personal information, and only under business terms that prohibit training on it.
- Funding partners: independent companies that receive your request when you ask to be contacted. They are controllers of their own copy and are governed by their own privacy practices.
If something goes wrong
In plain terms: We investigate, contain, and notify people and regulators when the law requires it. Responsible disclosure is welcome.
If we identify a security incident we investigate immediately, contain it, and notify affected people and regulators within the timeframes the law requires. If you believe you have found a vulnerability, email hello@manufactorfinance.com. We will not pursue legal action against good-faith research that avoids privacy violations, service disruption, and data destruction.
What we never do
In plain terms: No data brokers, no plaintext phone storage, no AI training on your information, no sharing beyond your request, no invented credentials, no fake urgency.
- We do not sell your information to data brokers or list buyers.
- We do not store your phone number in plaintext in this site's database.
- We do not allow any provider to train models on your personal information.
- We do not share your information beyond the request you made and the partners it was submitted for.
- We do not claim licenses, certifications, or credentials we do not hold, and we do not manufacture urgency to get a signature.
How we check ourselves
In plain terms: Quarterly self-run security tests, quarterly access and key reviews, a yearly policy review, and a public version history.
We run our own security test suite quarterly, review who has access and rotate keys quarterly, restore a backup to confirm it works quarterly, and review every policy on this site at least once a year. Each review is recorded, and every published change appears in the policy version history.
