Legal ยท ERFG-PRIV-004
Privacy Policy โ Bank Balance Dashboard
What financial information the Bank Balance Dashboard collects, why we collect it, who can see it, how long we keep it, and how a connection can be withdrawn. This policy applies to everyone who uses the system and to every bank account connected to it.
Effective August 4, 2026 · Last updated August 4, 2026
This policy governs the Bank Balance Dashboard and the bank accounts connected to it through Plaid. It does not govern ERFG’s text message appointment reminder programs — those are covered by our general privacy policy.
- Document
- ERFG-PRIV-004 — Privacy Policy (Bank Balance Dashboard)
- Version
- 1.1
- Originally issued
- 4 August 2026 (v1.0)
- Review cycle
- Annual, or on material change
- Published at
- theerfg.com/privacy/bank-balance-dashboard
01Who We Are and What This Covers
The Engine Room Financial Group (“ERFG,” “we”) operates the Bank Balance Dashboard — a private, internal reporting system that shows the current bank balances of ERFG and of the entities ERFG manages, together with the recent transaction activity behind each balance.
This policy covers the information handled by that system. The system is not a public or consumer-facing product: there is no sign-up, it is not offered to the public or to third parties, and access is limited to a small number of named ERFG officers with a business need to see the company’s cash position.
Because the system is internal and has no external users, it is not offered under public terms of service; access to it is governed by ERFG’s Access Control Policy (ERFG-ACP-002).
02Information We Collect
We connect to bank accounts through Plaid Inc., which acts as our service provider for retrieving bank data. Through Plaid we receive, for each connected account:
- Account identification
- Financial institution name, account name and type, and a masked account number (last four digits)
- Balances
- Current (ledger) balance and available balance, and the time the figure was retrieved
- Transactions
- Date, amount, direction, description or merchant name, and pending/posted status
- Statements
- Where enabled, a copy of the institution’s account statement, used for independent tie-out
We also record ordinary application information about our own users: the identity of the officer who signed in, and log entries showing when data was retrieved and whether the job succeeded.
What we never receive or store. We do not receive or store bank login credentials. Authentication happens inside Plaid Link, directly between the account holder and the financial institution — those credentials are never visible to ERFG. We also do not collect full account or routing numbers beyond the masked identifier used to label an account, and we do not collect Social Security numbers or other government identifiers through this system.
03Why We Collect It, and Consent
We use this information for one purpose: to report cash position to authorized ERFG officers. Specifically:
- to calculate and display each account’s current balance;
- to show the recent transaction activity that supports a balance;
- to send a daily balance brief to authorized officers;
- to tie balances out against bank-issued statements so that reported figures are accurate;
- to detect when a bank connection has gone stale, so a figure is never presented as current when it is not.
Every connection is made with the account holder’s authorization. A bank account is connected only by a person authorized to act for the account holder, who reviews and accepts the disclosure presented in Plaid Link at the time of connection — including Plaid’s own end user privacy policy — before any data is retrieved. ERFG additionally records the internal written authorization for each entity’s accounts before connecting them. Consent covers the collection, processing and storage described in this policy, and can be withdrawn as set out in Section 07.
We do not use this information for marketing, advertising, profiling, credit decisioning, or automated decision-making, and we do not sell it or share it for anyone else’s commercial purposes.
04Who Can See It
- Authorized ERFG officers only. Access is granted by named individual on a need-to-know basis, requires single sign-on with multi-factor authentication, and is reviewed quarterly. There is no public route into the application.
- Plaid Inc., as our service provider for retrieving bank data. Plaid’s handling of end user information is governed by its own end user privacy policy, available at plaid.com/legal.
- Infrastructure providers that host the application, its database, and our email — acting on our instructions, under contract, and with no right to use the data for their own purposes.
- Professional advisers, auditors or regulators, where disclosure is required by law, by a valid legal process, or for a legitimate audit of the entities concerned.
We do not disclose this information to anyone else.
05How We Protect It
- All data is encrypted in transit using TLS 1.2 or better, and at rest using AES-256.
- API credentials and access tokens are held only in an encrypted secret store, never in source code and never in logs.
- Access requires multi-factor authentication; the application is private with no anonymous access.
- The system is read-only. It cannot move, initiate or reconcile funds — there is no payment capability to misuse.
- Full detail is in our Information Security Policy (ERFG-ISP-001) and Access Control Policy (ERFG-ACP-002).
06How Long We Keep It
We keep information only as long as it serves the purpose above. In summary: balance snapshots and transaction records are kept on a rolling 24-month window; access tokens and account metadata are deleted within 30 days of a connection being removed; application logs are kept 90 days. The complete schedule, the disposal methods used, and our legal hold process are set out in our Data Retention and Disposal Policy (ERFG-DRP-003), which is reviewed annually.
07Withdrawing a Connection, and Your Choices
An account holder or managed entity may at any time:
- Disconnect an account — we remove the connection at Plaid, which immediately ends all further retrieval of that account’s data;
- Request deletion of data already collected — we delete it within 30 days, except any part we must keep for a specific legal, regulatory or accounting obligation, which we will identify to you;
- Ask what we hold — we will provide a description of the categories held for the accounts concerned;
- Ask us to correct anything inaccurate in the account information we hold.
Send any of these requests to privacy@TheERFG.com. Requests are received at that monitored address and handled by ERFG’s Information Security Owner. We acknowledge requests promptly and confirm completion in writing.
08Children’s Information
The system is an internal business tool for company bank accounts. It is not directed to children and we do not knowingly collect information from anyone under 18.
09Changes to This Policy
If we change this policy we update the version and effective date above and publish the revised version at theerfg.com/privacy/bank-balance-dashboard. Material changes affecting how connected account data is used will be communicated to the account holders concerned.
10Contact
The Engine Room Financial Group
Attn: Information Security Owner
Registered / mailing address: 456A Central Ave Suite 115, Cedarhurst, NY
11516
Operating address: 181 S Franklin Ave, Valley Stream, NY 11581
privacy@TheERFG.com ·
(516) 878-0015
Questions about privacy, security or a deletion request should go to that address.
The Engine Room Financial Group
Registered / mailing address: 456A Central Ave Suite 115, Cedarhurst, NY 11516
Operating address: 181 S Franklin Ave, Valley Stream, NY 11581