LadderpayPrivacy Policy

LadderPay Privacy Policy

LadderPay, a dba of Wurthy Services, LLC

v1.1 — Revised September 14, 2026

Part A — Consumer Financial Privacy Notice (GLBA)

A-1. Why are we providing this notice?

Financial companies choose how they share your personal information. Federal law gives consumers the right to limit some but not all sharing, and requires us to tell you how we collect, share, and protect your personal information. LadderPay is the servicing platform for the retail installment contract (“RIC”) you entered into with your service provider (the “Merchant”). This notice describes the practices of LadderPay, a dba of Wurthy Services, LLC.

A-2. What information do we collect?

The types of personal information we collect and share depend on the product or service you have with us. This information can include:

  • Identity and contact information: name, address, email, phone number, date of birth, and government identification information provided at application;
  • Financial information: bank account and routing numbers, income information, and account balances provided directly or through our bank-connection provider (Plaid);
  • Bank-transaction information may include transaction amounts and dates, descriptions, categories, and related account information when provided directly or through an authorized bank connection.
  • Credit information: credit scores and credit report information obtained from consumer reporting agencies (a soft inquiry that does not affect your credit score);
  • Transaction and account information: payment history, payment amounts and dates, contract terms, account status, and communications with us;
  • Device and usage information when you use our website or borrower portal (see Part B).

A-3. How do we use your information?

  • To process your application, including verifying your identity and obtaining credit information with your authorization;
  • To service your contract: processing payments, sending statements and receipts, providing payoff quotes, and administering autopay;
  • To communicate with you about your account, including payment reminders and, if you opt in, text messages (see the Text Message Terms & Consent);
  • To comply with law, including recordkeeping, disclosures, and responses to lawful requests;
  • To prevent fraud and protect the security of our platform.
  • To prepare and validate deidentified datasets from permitted contract, payment, bank-transaction and related financial records for commercial financial research, analytics and artificial-intelligence development, as described in A-7. We obtain any additional authorization required before beginning this use.

A-4. With whom do we share your information?

We share personal information only as follows:

  • With your Merchant — the seller-creditor on your contract — for purposes of originating and administering your contract (e.g., account status, payment progress);
  • With service providers who perform functions on our behalf under contract, including payment processing (Moov), bank connection (Plaid), credit reporting agencies (TransUnion), identity/business verification, e-signature, communications (email/SMS), and customer support tooling. Service providers may use your information only to perform services for us;
  • Vendors that help us prepare or test deidentified datasets may access selected source information only under a lawful processing arrangement with confidentiality, security and use restrictions. Independent dataset buyers and AI developers receive only qualifying deidentified outputs under A-7.
  • With a licensed collection agency if your account becomes significantly past due, as described in your contract;
  • For legal and safety reasons, including to comply with law, respond to legal process, enforce our agreements, or protect rights, property, or safety;
  • In a business transfer, such as a merger, acquisition, financing, or sale of assets, subject to this notice’s protections.

We do not sell your personal information. A-7 describes paid licensing of qualifying deidentified information. We do not share your personal information with nonaffiliated third parties for their own marketing purposes.

A-5. How do we protect your information?

We use administrative, technical, and physical safeguards designed to protect your personal information, including encryption in transit, access controls, and audit logging.

A-6. Your choices

  • Federal law gives you the right to limit certain disclosures of nonpublic personal financial information to nonaffiliated third parties when no exception applies. We provide any required notice and opportunity to exercise that right before such a disclosure. If a disclosure relies on your consent or direction, you may revoke it for future disclosures. A-7 explains choices for any optional Data Authorization; withdrawing that authorization does not cancel your contract or payment obligations.
  • You may opt out of text messages at any time by replying STOP (see Text Message Terms);
  • You may opt out of marketing emails via the unsubscribe link in any marketing message. We will still send you account and servicing communications.

A-7. Commercial use of deidentified financial data

We may use permitted retail installment contract, payment, bank-transaction and related financial records, including historical records already held and records lawfully collected in the future, to prepare and test deidentified datasets. We do so only where the required rights and permissions allow the selected records and use. If new consent is required, we obtain it before the new processing begins. Updating this notice alone does not supply that consent.

Deidentified data must meet applicable legal requirements and must not reasonably identify, be associated with, or permit inferences about a particular individual or household. It must also protect merchant identity as required by the applicable commercial terms. Qualifying outputs may preserve individual rows or relationships over time and may include statistics, features, labels and synthetic examples. Removing names or replacing account identifiers alone is not sufficient.

We may retain, combine, adapt, use, sell, license and permit further licensing of qualifying outputs for lawful commercial, analytical, research, statistical, educational and development purposes. These include financial and business research, benchmarking, product development, and development of artificial-intelligence and machine-learning models, including foundation models: training, fine-tuning, evaluation, retrieval, improvement and commercialization of models, products and services. Recipients may include affiliates, data intermediaries, distributors, AI developers, researchers and other commercial customers. Model commercialization may include distribution of model weights, provided protected information is not reconstructed or disclosed and all applicable restrictions are satisfied.

We may receive payment for these uses. You do not receive a fee, royalty, revenue share or other compensation unless required by law or expressly agreed in writing. No separate approval is requested for each buyer or transaction within the valid authorization.

We commit to maintaining qualifying data in deidentified form, taking reasonable measures against identification, and contractually requiring recipients to preserve those protections, avoid reidentification, and bind permitted downstream recipients to equivalent restrictions. Testing of deidentification is limited to what applicable law permits. We do not publicly release datasets without the enforceable recipient protections required for the release.

If you provide an optional Data Authorization, you may withdraw it by contacting privacy@ladderpay.ai. Upon receipt, we stop adding affected records and initiating new Program preparation, and halt unfinished preparation without undue delay, except processing needed to implement withdrawal or comply with law. Subject to applicable law, source permissions and any express written agreement, qualifying outputs lawfully completed and validated before receipt may continue to be used, combined with other authorized outputs and newly licensed without a time limit, including after account closure. Permitted uses of trained models may also continue. These provisions do not override mandatory withdrawal, deletion or remediation requirements and do not promise universal recall or model unlearning. Ordinary contract servicing and required record retention continue under their separate authority.

Part B — Website & Online Privacy Policy

B-1. Scope

This Part B applies to ladderpay.ai, the LadderPay borrower and merchant portals, and our online communications. It supplements Part A. Where state privacy law applies to information not covered by GLBA, this Part B governs.

B-2. Information we collect online

  • Information you provide: application fields, account settings, support requests, and communications;
  • Automatic information: IP address, device and browser type, pages viewed, and interactions, collected via cookies and similar technologies;
  • Analytics: we use analytics services (currently PostHog) to understand site usage.

B-3. State privacy rights

Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to opt out of certain processing. The rights available depend on the information, activity and applicable law, including any financial-information exemption. GLBA coverage does not automatically exempt every category of information or every activity from state privacy law. Where we process information only on a Merchant's behalf, we support the Merchant's response to your request. Where we determine independent purposes, we handle the applicable request directly. Contact privacy@ladderpay.ai; we will direct your request to the appropriate process, verify your request as required and respond within the time required by applicable law. You will not be discriminated against for exercising your rights. If we deny your request, you may appeal by emailing privacy@ladderpay.ai with “Privacy Appeal” in the subject line; we will review and respond within the time required by your state's law.

B-4. Children

Our services are for adults. We do not knowingly collect personal information from anyone under 18. Contracts require the buyer to be at least the age of majority in their state.

B-5. Retention

We retain personal information for as long as needed to service your contract, comply with legal obligations (including record-retention rules applicable to consumer credit), resolve disputes, and enforce agreements. Qualifying deidentified outputs may be retained and licensed as described in A-7. Source personal information does not become eligible for indefinite retention merely because it was used to prepare an output.

B-6. Changes to this policy

We will post any changes on this page with an updated effective date, and for material changes affecting your contract or financial information we will notify you directly (email or portal notice). We do not treat posting a revised notice or a change of brand as permission for a materially expanded historical-data use. We obtain any required new consent or other valid authorization before that use begins and provide revised financial privacy notices and choices where required.

B-7. Contact us

LadderPay, a dba of Wurthy Services, LLC — 2021 Fillmore St #1224, San Francisco, CA 94115 — privacy@ladderpay.ai — (415) 234-3881.

Prior brand notice: LadderPay was formerly operated under the Wurthy brand. This notice describes the stated practices of Wurthy Services, LLC for the covered services from its applicable effective date. A brand change does not itself transfer records, amend another entity's obligations, or expand permission for previously collected information. Historical records remain subject to applicable rights, restrictions and any valid subsequent authorization.