Privacy Policy
How Rhofin collects, uses, shares, protects and retains personal information in connection with our website, preliminary enquiries, onboarding, underwriting, transaction administration, servicing and receivables-purchase activities.
- Introduction
- Who Is Responsible
- Information We Collect
- Shipment Planner Data
- Where We Obtain Information
- How We Use Your Information
- Consumer Reports and Credit Information
- How We Share Information
- SMS Communications
- Data Retention
- Cookies and Tracking Technologies
- Security Measures
- Your Privacy Rights
- Contact Us
Who we are and what this covers
Rhofin Inc. ("Rhofin," "we," "us," or "our") operates a technology and commercial-finance platform for eligible business customers, logistics providers and other transaction participants. This Privacy Policy explains how Rhofin collects, uses, shares, protects and retains personal information in connection with its website, preliminary enquiries, onboarding, underwriting, transaction administration, servicing and receivables-purchase activities.
This policy applies to individuals who interact with our website or platform, including business owners, officers, directors, beneficial owners, authorised users and guarantors of our business customers, as well as contacts at logistics providers, suppliers and account debtors. Our services are directed to businesses and the individuals who act for them, not to consumers acting in a personal, family or household capacity.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We collect and use personal information for the business and commercial purposes described in this policy.
Who is responsible for your information
Rhofin Inc., a Delaware corporation, is responsible for the personal information processed in connection with its website and platform. Rhofin acts as an independent controller of personal information it processes in its capacity as lender, purchaser, servicer, collateral agent and financing-program operator. We have designated a point of contact for data protection matters.
For any privacy enquiry, to exercise a right described in Section 12, or to raise a concern, contact us at compliance@rhofin.com. We may ask you to verify your identity before acting on a request.
What we collect
The categories of personal information we collect depend on how you interact with us. A website enquiry involves far less than onboarding as a customer. Depending on the relationship, we may collect:
We ask that you provide only the information we request, and that you do not send us special categories of information (such as health data) unless we specifically ask for it in connection with a transaction.
How we use planner scenarios
When you change the shipment planner, Rhofin records a stable scenario after you pause. A scenario may include hypothetical shipment values, costs and timing; HTS classification and origin and destination route codes; financing selections; calculated results; the planner-model and Important Information versions; an ephemeral browser-session identifier; and, if you are signed in, the email address associated with your Rhofin account.
We use planner scenarios only as first-party data to operate and test the planner, understand demand and improve the planner and Rhofin's products. We do not sell or share planner scenarios. We do not send planner financial values or signed-in email addresses to PostHog. We do not use planner scenarios for CRM enrichment, eligibility, underwriting, pricing, automated profiling or credit decisions.
We retain the link to a signed-in email address and the browser-session identifier for three years after a scenario is captured. We then remove both identifiers. We may retain the remaining de-identified scenario for longer for longitudinal product and demand analysis, and we will not attempt to re-identify it.
You may request access to, correction of or deletion of personal information in a planner scenario through the channels described in Your Privacy Rights and Contact Us.
Where the information comes from
We obtain personal information from the following sources:
- Applicants and customers, and the business owners, officers and guarantors who act for them;
- Logistics providers involved in a shipment;
- Suppliers and account debtors;
- Credit bureaus and commercial-data providers;
- Identity, fraud, sanctions and verification providers;
- Banks, payment providers and funding partners;
- Website-visitor identification providers;
- Public records and government sources; and
- Our website and platform, and your interactions with them.
How we use it
We use personal information for the following business and commercial purposes:
- Conducting preliminary eligibility reviews;
- Onboarding and business verification;
- Underwriting and making credit decisions;
- Fraud prevention and sanctions screening;
- Verifying shipments, invoices and proof of delivery;
- Originating and administering commercial loans;
- Purchasing and administering receivables;
- Perfecting and enforcing security interests;
- Managing cargo release;
- Servicing, payment processing and collections;
- Resolving complaints and disputes;
- Complying with laws, audits, litigation and regulatory requests; and
- Protecting the platform and preventing unauthorised access.
No sale; no advertising. We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We do not use your personal information to make decisions producing legal or similarly significant effects about you by solely automated means without human involvement.
Credit reports and your authorisation
To assess eligibility and make credit decisions, Rhofin may obtain personal and commercial credit reports and other consumer reports about a business and the individuals associated with it, including owners, officers and guarantors, from credit bureaus and other consumer-reporting agencies.
This Privacy Policy is not your authorisation to obtain a consumer report about you. Where an individual's consumer report may be obtained, a separate, affirmative authorisation is requested from that individual during onboarding, before the report is obtained. Where required by applicable law, if we take adverse action based in whole or in part on information in a consumer report, we will provide the notices that law requires.
Who we share information with
We share personal information with the following categories of recipients where relevant to a transaction or to operating our platform:
- Current or future partner banks;
- Special-purpose vehicles and other funding or purchasing entities;
- Current and prospective financing sources assessing a transaction or portfolio;
- Servicers, agents, collateral agents and collection providers;
- Logistics providers involved in the transaction;
- Credit bureaus;
- Identity, sanctions, fraud and verification providers;
- Payment and banking-service providers;
- Cloud, communications, analytics and security vendors;
- Website-visitor identification and sales-engagement vendors; and
- Insurers, auditors, legal advisers, regulators and government authorities.
Rhofin shares information with these parties only where relevant to evaluating, originating, funding, acquiring, administering, servicing or enforcing a transaction, operating the platform, protecting against fraud or complying with applicable law.
We require our service providers to process personal information only for the purposes for which we engage them. We may also disclose personal information as required by law, regulation, subpoena, court order or governmental authority, or to protect the rights, property or safety of Rhofin, our customers or others. If Rhofin is involved in a merger, acquisition, financing or sale of assets, personal information may be transferred as part of that transaction.
We process personal information primarily in the United States. Where information is transferred from another country, we take steps to provide appropriate protection consistent with applicable law.
Our text-message programme
Where you have voluntarily provided a mobile phone number and given explicit consent, we may send you SMS (text) messages relating to your use of the Rhofin platform. This section sets out what we send, how to opt in and out, and how we handle your number.
Consent is always explicit. The only places Rhofin collects mobile phone numbers for SMS are our public Contact Us page (with an explicit, unchecked-by-default SMS consent checkbox next to the phone field) and the authenticated portal at app.rhofin.com. We never opt you in by default.
How long we keep information
We retain personal information for as long as necessary to fulfil the purposes described in this policy, to administer and service transactions, and to comply with our legal, regulatory, tax, audit and recordkeeping obligations, after which it is deleted or anonymised. Because we originate and administer financing and purchase receivables, we generally retain financing, receivables-purchase, shipment, cargo-release, verification, credit-decision, consent, adverse-action, sanctions-screening and audit records for at least seven years after the later of transaction completion or termination of the relevant relationship, unless a longer period is required by law, litigation hold or contract.
Website enquiry and general contact records are retained for a shorter period sufficient to respond and maintain business continuity. You may request deletion of your personal information (see Section 12), subject to any overriding legal or legitimate business need to retain it.
How we use cookies
Our website and authenticated portal use cookies and similar technologies to operate correctly, keep the services secure, and understand how visitors move through them. Strictly necessary cookies are required for the services to function. Our configured analytics tools begin on first visit without a separate cookie prompt and use a persistent pseudonymous browser identifier across Rhofin subdomains. You can block or delete these cookies through your browser settings.
We use PostHog as our product-analytics provider. It records page and route visits, selected actions, and privacy-masked session replays so we can understand journeys from the public website into the portal and improve those journeys. After portal authentication, the journey may be associated with an internal profile and organisation identifier and limited account categories such as portal and role; we do not send PostHog names, email addresses, phone numbers, organisation names, financial values or free-text form content. Public-site inputs and the displayed enquiry email are masked. In the portal, all visible text, input values and element attributes are masked; URL query strings, fragments and access tokens are removed, and network request or response headers and bodies are not recorded. A successful portal logout resets the analytics identity. Rhofin configures the PostHog project not to retain IP addresses and does not use this information for advertising.
We also use a business-visitor identification service, lemlist, on our public website. It records the pages you visit on our website, together with technical information such as your browser details and the IP address your visit comes from, and uses that information to identify the business a visit is likely to have come from; for visits from the United States it may also identify an individual business contact and their job role. We use this only to understand which businesses are interested in our services and to prioritise our own business-to-business outreach. The script itself does not store anything on your device or read your existing cookies, and it does not run in the authenticated Rhofin portal. If you would prefer not to be identified in this way, you can block the script in your browser or write to us at compliance@rhofin.com.
We do not use cookies or tracking technologies to build advertising profiles or to share your browsing behaviour with third-party advertisers. You can control cookies through your browser settings; disabling certain cookies may affect how the website works.
How we protect information
We implement technical and organisational measures designed to protect personal information against loss, misuse, and unauthorised access, alteration or disclosure. Our measures include:
- Encryption of data in transit using industry-standard TLS protocols;
- Encryption of data at rest on our servers and cloud infrastructure;
- Access controls limiting data access to authorised personnel on a need-to-know basis;
- Regular review of our information-security policies and procedures;
- Use of reputable, security-accredited cloud infrastructure and service providers; and
- Contractual obligations on our service providers to maintain appropriate security.
Where a security incident affecting personal information occurs, we will notify affected individuals and authorities as and when required by applicable law.
No method of transmission over the internet or method of electronic storage is completely secure. While we use commercially reasonable measures to protect personal information, we cannot guarantee its absolute security.
Your choices and rights
Depending on where you live and the nature of the information, you may have rights to request access to, a copy of, correction of, or deletion of certain personal information we hold about you, and to appeal a decision on your request. To make a request, email us at compliance@rhofin.com. We will respond within the timeframe required by applicable law and may need to verify your identity first.
Some US state privacy laws contain exemptions for personal information collected in a business-to-business context, and for financial information and activities governed by the federal Gramm-Leach-Bliley Act (GLBA) and the Fair Credit Reporting Act (FCRA). Where such an exemption applies, a particular right may be limited or unavailable, and information handled under GLBA and FCRA is governed by those frameworks and their own notices.
If you believe we have not handled your personal information consistently with this policy or applicable law, you may contact your state attorney general or applicable regulator. If you are located outside the United States, you may have rights under the laws of your jurisdiction and may contact us to exercise them. We encourage you to contact us first so we can address your concern directly.
Get in touch about your information
For any privacy-related enquiry, to exercise a right, or if you have a concern about how we handle personal information, please reach out to us directly.