This Privacy Policy explains how Shoola Labs ("Shoola Labs", "we", "us") collects, uses, shares and protects information in connection with BloomOS, our mortgage technology platform available at app.shoolalabs.com, and this website at shoolalabs.com (collectively, the "Services"). BloomOS is a product provided by Shoola Labs. The final registered legal entity name is pending confirmation and will be inserted here.
1. Company and product identification
BloomOS is software developed and operated by Shoola Labs. Customers are typically mortgage companies and mortgage teams ("Customers") whose authorized users access BloomOS. When a Customer uses BloomOS to process information about its own borrowers and contacts, Shoola Labs generally acts as a service provider to that Customer.
2. Information you provide
- Contact and inquiry information submitted through this website, such as name, company, email, phone number and message content.
- Content you choose to enter into BloomOS, including records, notes, documents and messages.
- Support requests and related correspondence.
3. Account information
When an account is created, we collect information needed to identify and authenticate the user, such as name, work email address, phone number, organization, role and permissions, and authentication metadata such as sign-in timestamps.
4. Product usage information
We collect information about how the Services are used, such as pages and features accessed, actions taken, device and browser information, IP address, and diagnostic and error logs. This information helps us operate, secure, troubleshoot and improve BloomOS.
5. Communications data
BloomOS includes calling, SMS, email and messaging functionality. Depending on how a Customer configures the Services, we may process call metadata and recordings where enabled, SMS content and metadata, email content and metadata, voicemail, internal team messages and customer messages, together with the activity history associated with those communications.
6. Connected email data
Users may connect a Google (Gmail) or Microsoft mailbox to BloomOS so that email can be sent, received, searched and managed inside the workspace. When a mailbox is connected, we process the email data and mailbox identifiers necessary to provide that functionality, along with the authorization tokens issued by the provider. Tokens are stored server-side and encrypted at rest. A connected mailbox is associated with the user who connected it.
7. Google user data disclosure
When you connect a Google account to BloomOS, BloomOS accesses only the minimum Google user data authorized by you through Google's consent screen, and uses it solely to provide the connected email functionality you requested. Depending on the scopes you approve, this may include:
- identifying the connected mailbox (for example, the email address of the account);
- reading and syncing email messages as authorized, so they can be displayed, searched and associated with records in BloomOS;
- sending email on your behalf as authorized from within BloomOS.
BloomOS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- Google user data is used only to provide or improve user-facing features of BloomOS that are prominent in the requested experience.
- We do not sell Google user data.
- We do not use Google user data for advertising purposes.
- We do not transfer Google user data to third parties except as necessary to provide or improve the requested functionality, to comply with applicable law, or as part of a merger, acquisition or sale of assets with notice to affected users.
- We do not allow humans to read Google user data unless we have your explicit consent for specific messages, it is necessary for security purposes or to comply with applicable law, or the data has been aggregated and de-identified.
- You can disconnect a connected Google account inside BloomOS at any time, and you may also revoke BloomOS's access from your Google Account permissions page. After disconnection, BloomOS stops accessing new Google data.
8. How we use information
We use information to:
- authenticate users and secure access to the Services;
- deliver and operate BloomOS features requested by the Customer and its users;
- provide customer support and respond to inquiries;
- maintain security, detect abuse, prevent fraud and troubleshoot issues;
- maintain audit trails and activity records;
- improve reliability, usability and product functionality;
- meet legal, tax and regulatory obligations.
9. Third-party providers
We use third-party service providers to deliver the Services — for example cloud hosting, database and storage infrastructure, telephony and messaging providers, email providers, analytics, error monitoring and payment processing. These providers process information on our behalf under contractual obligations, and only as needed to provide their services. We do not sell personal information.
10. Data retention
We retain information for as long as an account is active and as needed to provide the Services, and thereafter as required for legitimate business purposes, dispute resolution, security and legal or regulatory obligations. Customers may request deletion of their data, subject to legal retention requirements.
11. Account and provider disconnection
Users may disconnect a connected email or other provider account from within BloomOS at any time, and may revoke access directly with the provider. Disconnecting stops further access to that provider's data. Data already stored in the workspace is handled according to the Customer's retention configuration and this policy.
12. Your choices
You may update your account information, disconnect connected accounts, opt out of marketing emails, and request access to or deletion of personal information subject to applicable law. If you are an authorized user of a Customer organization, some requests may need to be directed to that organization's administrator. Contact us at privacy@shoolalabs.com.
14. Security
We use administrative, technical and organizational safeguards designed to protect information, including authenticated accounts, role and permission controls, organization-level access scoping, tenant separation, encrypted handling of provider credentials and audit trails. No method of transmission or storage is completely secure. See our Security page for more detail.
15. Children's privacy
The Services are intended for business use and are not directed to individuals under 18. We do not knowingly collect personal information from children.
16. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, by additional notice. Continued use of the Services after an update constitutes acceptance of the revised policy.
17. Contact us
Shoola Labs — BloomOS
Privacy inquiries: privacy@shoolalabs.com
General inquiries: support@shoolalabs.com
See also our Terms of Service.