Privacy Policy

Alooma Operations Command Center · Last updated June 3, 2026

Who this is for

The Alooma Operations Command Center (“the system”) is an internal tool built for Alooma Holdings to manage its own treasury and vendor payments. It is not a consumer product. The only users are Alooma Holdings staff. This policy explains what data the system handles and how it is protected.

What we collect

The system stores Alooma Holdings' own business records: bank account details (institution, nickname, last four digits, balances and transactions), vendor and invoice information, and related operational notes. When a bank account is connected through Plaid, the system receives real-time balances and transaction history for that account on a read-only basis.

How we use it

Data is used solely to operate the dashboard: showing cash position across accounts, organizing and approving vendor invoices, and producing internal financial and tax reporting for Alooma Holdings. We do not use the data for advertising, and we do not build profiles for any third party.

Bank data via Plaid

Bank connections are powered by Plaid. The system requests only Plaid's Balance and Transactions products, read-only. It does not initiate payments or transfers and does not retrieve full account or routing numbers. Plaid access tokens are stored securely on our servers and are never exposed to the browser. Plaid's own handling of data is governed by the Plaid End User Privacy Policy. Consent to connect an account is captured through Plaid's flow at the time of connection.

We do not sell or share your data

We never sell, rent, license, or monetize the data the system holds. It is not shared with third parties except the infrastructure providers required to run the service (listed below), each bound by their own contractual and security obligations.

How we protect it

All data is encrypted in transit (TLS 1.2 or better) and at rest. Access is restricted to authorized Alooma Holdings staff through authenticated login and role-based permissions enforced at the database level. Administrative access to the underlying systems is limited to named individuals and protected by multi-factor authentication. Every change is recorded in an append-only audit log. The service runs on Vercel and Supabase, both SOC 2 Type II certified providers.

Retention and deletion

Financial records are retained while operationally and legally required (typically up to seven years for tax and lender documentation) and then eligible for deletion. A connected bank account can be disconnected at any time, which immediately stops further data collection, and the associated data can be deleted on request.

Contact

Questions about this policy or a data request can be directed to Jake Stein at jstein@aloomaholdings.com, or to the system's technical and security contact, Josue Llanas, at josue@vancom.io.