Effective date: July 23, 2026 · McKnight MortgageOS — a McKnight Opportunity Group platform, operated by RJ Business Solutions, 1342 NM 333, Tijeras, NM 87059, USA
1. What We Collect
Account data: company name and contact email (signup), plus name/company/message if you use the contact form.
API request data: the JSON payloads you submit (e.g., borrower financial scenarios) and the computed results, stored in your account's request history so you can retrieve them.
Usage & metering data: endpoint, timestamps, response times, and unit counts per API key — used for billing, quotas, and abuse prevention.
We do not collect consumer credit reports, pull credit, or verify identities. Scenario data you send is processed as-is.
2. How We Use It
To provide and operate the Service (compute results, store your history, meter usage); to bill and enforce quotas; to respond to support and demo requests; to secure the Service; and to send service-related email. We do not sell personal information.
3. Consumer Data You Submit
If you submit information about consumers (e.g., borrower scenarios), you are responsible for having a lawful basis and any required consumer consents. Use the API's data-minimization pattern: submit only what the calculation needs. For structured API calls, do not submit SSNs, full account numbers, or government IDs — those endpoints do not require them.
Document uploads (Mortgage Document Intelligence): Documents you upload for OCR analysis (paystubs, W-2s, bank statements, tax forms) may inherently contain sensitive personal information. Before uploading, you must have the consumer's consent and, where practical, redact SSNs and full account numbers. Uploaded documents are stored encrypted at rest in private object storage, are accessible only to your account, are processed by machine-learning models solely to extract underwriting fields, and can be permanently deleted at any time via DELETE /api/v1/documents/:id. We do not use uploaded documents to train models.
4. Storage & Security
Data is stored on Cloudflare's global infrastructure (D1 database). API keys are stored as SHA-256 hashes — we cannot read your key after issuance. Transport is TLS-encrypted end to end. Access to production data is restricted to RJ Business Solutions operators.
5. Retention & Deletion
Request history and usage logs are retained while your account is active. You may request deletion of your account and associated request data at any time by emailing support@rjbusinesssolutions.org; we delete within 30 days except records we must keep for billing/legal compliance.
6. Sharing
We share data only with infrastructure providers necessary to run the Service (e.g., Cloudflare) under their standard data-protection terms, or when required by law. No advertising or data-broker sharing, ever.
7. Cookies & Analytics
The website uses no advertising cookies. Any analytics are aggregate and privacy-preserving.
8. Your Rights
Depending on your jurisdiction (e.g., California CCPA/CPRA), you may have rights to access, correct, delete, or port your personal information, and to non-discrimination for exercising them. Email us and we will honor verified requests.
9. Children
The Service is B2B and not directed to individuals under 18.
10. Changes & Contact
We will post any changes here with a new effective date. Contact: support@rjbusinesssolutions.org