Privacy
This site sets no cookies and makes no third-party requests. Everything below explains what that leaves, and what still has to be answered about the platform.
Who this covers, and who is responsible
This notice covers two different relationships, and they are not governed by the same thing. Keeping them apart is the whole structure of the page.
- If you are visiting this website
- Sweet decides what this site collects and why, so Sweet is responsible for it. That is the part of this page written in plain text, because it can be checked.
- If you are a borrower at a lending institution that uses Sweet
- Your relationship is with your lending institution. That institution decides what data is collected and what happens to it; Sweet processes that data on the institution's instructions, under the institution's contract. Requests about your loan or your data go to your institution, not to Sweet. Confirmthis describes the actual contractual position, and the exact language counsel wants for it.
- Legal entity
- Confirmthe exact legal entity name, jurisdiction of incorporation and registered address that these pages bind.
What this website does
Four things are true of the code that served you this page. Each names the file it can be checked in, because a privacy claim you cannot verify is just a nicer-sounding one.
-
This site sets no cookies.
No document.cookie write exists anywhere in src/. The measurement layer in src/layouts/Base.astro is explicitly cookieless.
-
Loading a page on this site makes no third-party requests. Every font, image, script and style comes from this domain.
Fonts are self-hosted in public/fonts/ (the Google Fonts import was removed); there is no analytics vendor tag, no pixel and no embed in the build. The one thing that can leave this domain is a form you deliberately submit. See below.
-
No analytics data is collected or transmitted unless and until Sweet configures an endpoint of its own.
The event layer in src/layouts/Base.astro sends nothing when PUBLIC_ANALYTICS_ENDPOINT is unset, and additionally requires an explicit consent signal before it sends anything even when it is set.
-
The site is static. Pages are pre-rendered files with no server-side session and no user account.
Astro static build, astro.config.mjs.
No account, no login, no profile, no advertising identifier, no cross-site tracking, and no data broker. Not as a policy position that could change quietly: there is nowhere in a static site for any of it to live.
What we collect when you contact us
One form on this site collects anything at all, and it only collects what you type into it. Nothing else on this site collects anything about you. As this page is built, that form is not live: no form backend is configured, so no form is rendered anywhere on the site and there is nothing to submit. This section describes what happens the moment it is switched on.
- Fields collected
- Your name · Work email · Institution · Institution type · Your role · Commercial portfolio size · What do you want to see? · Anything else (optional). Only the last one is optional.
- Purpose
- To answer you, and to prepare a demo that is about your institution rather than a generic one.
- Who receives it
-
Submissions post to Web3Forms
(
https://api.web3forms.com/submit), a third-party form backend, which delivers them to Sweet. It is the only third party this website sends anything to. ConfirmWeb3Forms' own data handling — where submissions are stored, for how long, under which jurisdiction, and whether a DPA is in place. It receives the name, work email, institution and role of every prospect who contacts Sweet. - Where it goes after that
- Confirmwhere an enquiry submitted on this site is delivered, which systems it lands in, and who can read it.
- How long it is kept
- Confirmhow long an enquiry submitted through this site is kept, and where.
- Server logs
- Confirmthe hosting provider's own request logs — what is captured (IP, user agent), how long it is kept, and who can read it. Static hosting still logs.
We do not sell enquiries, and we do not pass them to anyone who is not working on the answer. Confirmis any enquiry data synced to a CRM, a marketing tool or an outbound sequencer? If so, name it here and on the sub-processor list.
Measurement and cookies
There is a first-party measurement layer in this site's code and it is switched off. With no endpoint configured (the state this site ships in) it sends nothing, stores nothing and sets no cookie; it keeps the last few events in memory so the site's own behaviour can be debugged, and that memory dies with the tab. It is also gated behind an explicit consent signal, so configuring an endpoint alone does not start collection.
If that changes, this section changes with it, before the change ships. Confirmif Sweet turns the measurement layer on, name the endpoint, what is stored, for how long, and whether a consent banner is required in the jurisdictions Sweet sells into. Until then this paragraph describes something that is not happening.
Borrower and institution data in the platform
Everything in this section is about the product, not this website, and none of it can be verified from this site's code. It is written as questions rather than as answers.
- Where data is stored
- Confirmthe country or countries customer data is stored and processed in, and whether any processing happens outside them.
- Isolation between institutions
- Confirmengineering must state the tenancy model in ONE sentence, and that sentence becomes the only version anywhere on the site. Option A — each institution's data is held in a dedicated database instance, not pooled with other customers. Option B — data is held in a multi-tenant environment with per-institution logical segregation enforced at the data layer. Pick one, or write the true third thing.
- Retention during the contract
- Confirmretention during the contract, and the deletion or return window after termination.
- Deletion, and backups
- Confirmhow long deleted data persists in backups before it ages out.
- Is customer data used to train models?
- Confirmis customer or borrower data ever used to train or fine-tune a model? A yes/no with no qualifiers is the only answer a bank will accept.
The control set, the attestation and the sub-processor position live on the trust & security page.
Who else sees data
Confirmthe rest of the real list — model/AI providers, email delivery, error monitoring, support tooling, payroll-adjacent systems that touch customer data. An AI product with no AI vendor on its sub-processor list is the question a risk team will ask first.
The vendors this site's own copy already names, and what remains to be confirmed about each, are listed on the security page.
Your rights
What rights you have depends on where you are, and which of the two relationships above you are in. This section is deliberately not drafted here: a rights section that names the wrong regime, or promises a response window nobody has agreed to, is worse than an honest gap.
- Jurisdictions
- Confirmwhich privacy regimes apply — US state laws (which states), UK/EU GDPR, PIPEDA, others? This determines the whole section, and it is a commercial question about where Sweet sells as much as a legal one.
- How to make a request
- Confirmprivacy contact address — a monitored mailbox, not a personal one.
- Response commitment
- Confirmthe window Sweet commits to for responding to a privacy request, once counsel has set it.
- Data protection officer / representative
- Confirmis a data protection officer or EU/UK representative required for the markets Sweet sells into, and if so, who?
If you are a borrower, the fastest route is your lending institution. They hold the relationship and, in most cases, the legal obligation.
Children
This site is aimed at people doing their jobs at lending institutions. It is not directed at children and we do not knowingly collect anything from them.
Changes to this notice
The draft marker at the top of this page comes off when counsel has reviewed it, and that is the point at which this notice has an effective date. After that, material changes get a new date and the previous version stays available on request. Confirmthe change-notification approach counsel wants — dated versions here, email to customers, or contractual notice under the MSA.
- Privacy contact
- Confirmprivacy contact address — a monitored mailbox, not a personal one.
- Postal address for notices
- Confirmlegal notices address, and the postal address notices must be sent to.
- Page owner
- Confirmwho at Sweet owns these three pages after launch, by role — the person who has to answer a bank's third-party risk questionnaire.