
PRIVACY POLICY
OVERVIEW
This Privacy Policy (“Policy”) constitutes a legally binding, comprehensive disclosure governing the data collection, technical processing, systemic retention, cross-platform sharing, and information security practices of Reyes Commercial Capital LLC (“Reyes Commercial Capital,” “we,” “us,” or “our”). This Policy applies to all Personal Information and Sensitive Personal Information ingested, processed, or retained via our website (www.reyescommercialcapital.com), digital portals, API integrations, application submission workflows, electronic communications (including SMS, email, and telephonic channels), and downstream underwriting or financial evaluation systems.
This document describes your operational choices and transactional rights regarding the management of your data. Reyes Commercial Capital executes its processing activities in strict adherence to applicable federal, state, and industry-specific statutes, including but not limited to the Gramm-Leach-Bliley Act (GLBA), the Fair Credit Reporting Act (FCRA), the Bank Secrecy Act (BSA), Anti-Money Laundering (AML) regulations, Office of Foreign Assets Control (OFAC) sanctions mandates, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), state-level comprehensive privacy frameworks, the Electronic Signatures in Global and National Commerce Act (ESIGN), and the Uniform Electronic Transactions Act (UETA). This Policy governs all natural persons interacting with our ecosystem, including business owners, guarantors, authorized corporate representatives, and applicants.
1. LEGAL & SYSTEMIC DEFINITIONS
-
“Personal Information” (PI): Any information that identifies, relates to, describes, or is reasonably capable of being associated or linked, directly or indirectly, with a particular natural person or household. This encompasses standard identifiers, commercial transaction records, and digital network signatures.
-
“Sensitive Personal Information” (SPI): Data elements requiring heightened regulatory protection, including Social Security Numbers (SSNs), Employer Identification Numbers (EINs), driver's licenses, state identification cards, passport numbers, financial account credentials, read-only account tokens, and beneficial ownership documentation.
-
“General Information”: Data that has been completely anonymized, de-identified, or aggregated such that it cannot be re-associated with an individual or household, utilized strictly for performance indexing and statistical analysis.
-
“Service Providers” & “Funding Partners”: Third-party corporate entities—including cloud storage networks, bank verification platforms, fraud-prevention systems, alternative asset managers, institutional lenders, merchant cash advance (MCA) providers, and commercial underwriters that ingest data to execute operational, compliance, or capital-allocation functions on our behalf.
-
2. SMS CONSENT, TELEPHONY, AND CARRIER COMPLIANCE
Reyes Commercial Capital LLC enforces strict physical and cryptographic isolation architectures for all operational and inbound telephony data arrays. In absolute alignment with cellular carrier regulations, A2P 10DLC compliance protocols, and statutory Telephone Consumer Protection Act (TCPA) frameworks: All customer mobile telephone numbers, text messaging metadata, and explicit SMS opt-in consent parameters captured during any stage of system ingestion are completely excluded from, and shielded against, any form of downstream third-party monetization, corporate disclosure, affiliate data-sharing pools, or promotional transfers. By executing a digital application, submitting localized intake forms, or provisioning a mobile telephone credential within our ecosystem, you grant Reyes Commercial Capital an explicit, irrevocable, and non-transferable operational license to transmit automated text messages, computerized alerts, interactive underwriting notifications, document remediation triggers, and algorithmic funding status updates directly to your provisioned wireless device. Standard commercial marketing telecommunications remain entirely discretionary; you retain the absolute right to unilaterally terminate promotional outbound carrier traffic at any time by transmitting a standard, single-word STOP command, which executes an immediate, programmatic opt-out across all internal messaging nodes.
3. TAXONOMY OF INFORMATION COLLECTED
Reyes Commercial Capital LLC maintains a multi‑tiered data‑classification framework that governs the collection, processing, transmission, storage, and retention of all information obtained throughout the lifecycle of a financing inquiry, pre‑qualification review, underwriting assessment, funding decision, renewal evaluation, or any ancillary commercial interaction. Each category below represents a distinct class of data subject to differentiated handling protocols, regulatory obligations, and internal access‑control restrictions.
Identifiers and Identity‑Linkable Attributes
This category encompasses all data elements capable of directly or indirectly identifying a natural person or business entity. These identifiers are collected at the initial point of inquiry and throughout the underwriting lifecycle. Such data includes, but is not limited to:
-
Full legal names, corporate legal names, and registered business entities
-
Trade names, fictitious business names, and “doing‑business‑as” (DBA) aliases
-
Physical, mailing, and operational business addresses
-
Primary and secondary email addresses
-
Corporate and personal telephone numbers
-
Unique device identifiers, browser fingerprints, and session‑level identifiers
-
Internet Protocol (IP) addresses, including IPv4/IPv6 variants and geolocation‑derived metadata
These identifiers are used for identity verification, fraud‑screening, underwriting, and regulatory compliance, including but not limited to AML, OFAC, and KYC obligations.
Statutory Sensitive Personal Information (SSPI)
This category includes information classified as sensitive under federal and state privacy statutes, including GLBA, FCRA, CCPA/CPRA, and other applicable regulations. SSPI is subject to heightened access controls, encryption requirements, and restricted internal handling. This category includes:
-
Government‑issued identification credentials (Social Security Numbers, Employer Identification Numbers, ITINs)
-
Driver’s licenses, state identification cards, passports, and other government‑issued documents
-
Dates of birth and age‑verification data
-
Financial institution account identifiers, routing numbers, and read‑only account‑access tokens
-
Identity‑verification artifacts obtained through third‑party verification platforms
SSPI is used exclusively for identity verification, underwriting, fraud detection, and regulatory compliance.
Commercial Financial Data and Transactional Records
This category includes all financial data necessary to evaluate business performance, cash‑flow stability, repayment capacity, and creditworthiness. These data elements are typically obtained during underwriting and may include:
-
Historical business bank statements (typically 3–12 months)
-
Merchant processing statements and point‑of‑sale (POS) transaction summaries
-
Average daily balances, ledger balances, and cash‑flow volatility metrics
-
Daily, weekly, and monthly revenue patterns
-
Payment behavior, NSF frequency, overdraft occurrences, and deposit trends
-
Existing debt obligations, loan amortization schedules, and repayment histories
-
Corporate tax returns, financial statements, and profit‑and‑loss (P&L) reports
-
Accounts receivable and accounts payable summaries
This category is essential for risk modeling, underwriting, and lender matching.
Credit, Background, and Public‑Record Profiles
This category includes data obtained from consumer reporting agencies, commercial credit bureaus, public‑record databases, and background‑screening vendors. Such data may include:
-
Personal and commercial credit scores
-
Credit inquiry histories and bureau‑pull timestamps
-
Tradeline data, utilization ratios, and payment histories
-
Public records, including liens, judgments, UCC filings, and bankruptcies
-
Identity‑verification results, fraud alerts, and bureau‑level risk indicators
This information is used to assess creditworthiness, evaluate risk, and comply with lender underwriting requirements.
Business Metadata and Corporate‑Structure Attributes
This category includes non‑financial business information used to classify, segment, and evaluate the applicant’s operational profile. Such data includes:
-
Industry classification codes (NAICS, SIC, MCC)
-
Corporate structure (LLC, S‑Corp, C‑Corp, Sole Proprietorship, Partnership)
-
Time in business, operational history, and business‑continuity indicators
-
Employee headcount, ownership percentages, and beneficial ownership data
-
Business licensing information, permits, and regulatory registrations
Beneficial ownership information is collected in accordance with federal AML and FinCEN requirements.
Telemetry, Behavioral, and Electronic Interaction Logs
This category includes digital interaction data automatically collected through our website, applications, and integrated systems. These telemetry‑based data elements include:
-
Browser configurations, device types, operating systems, and user‑agent strings
-
Session durations, page‑view sequences, clickstream pathing, and navigation behavior
-
Cookie identifiers, tracking pixels, and analytics‑platform metadata
-
Geolocation indicators derived from IP‑based or device‑based signals
-
Form‑completion metrics, error logs, and submission timestamps
-
Behavioral indicators used for fraud detection, bot‑prevention, and identity‑risk scoring
This category is used for security, analytics, fraud prevention, and optimization of user experience.
4. DATA UTILIZATION FUNCTIONAL RESTRICTIONS AND OPERATIONAL TARGETS
The processing, computational manipulation, and downstream routing of ingested Personal Information and Sensitive Personal Information by Reyes Commercial Capital are restricted to the following business, legal, and operational objectives:
-
Underwriting, Credit Evaluation, and Capital Structuring Optimization: The execution of identity authentication workflows, multi-layered verification of corporate legitimacy, and the extraction and analysis of daily transactional cash-flow metrics. This involves algorithmic risk profiling, ledger liquidity mapping, personal and commercial creditworthiness evaluations, and the systemic calculation of maximum capital exposure limits.
-
Regulatory Compliance, Financial Crime Mitigation, and Fraud Prevention: Fulfilling mandatory federal Know-Your-Customer (KYC) directives and executing anti-money laundering (AML) protocols under the Bank Secrecy Act. This includes cross-referencing identity data against the Office of Foreign Assets Control (OFAC) Specially Designated Nationals (SDN) registries, running anti-fraud matching loops, detecting network or session anomalies, preventing corporate identity spoofing, and preparing mandatory regulatory filings.
-
Platform System Architecture Optimization and Algorithmic Security: Improving system architecture security, executing internal predictive telemetry and database statistical analytics, debugging website and application infrastructure, and training internal proprietary risk-mitigation, fraud-detection, and lead-matching algorithms.
-
Communication Orchestration, Document Management, and Transactional Alerts: Delivering automated transactional notices and system alerts, orchestrating secure multi-channel pipelines for the retrieval and remediation of supporting financial documents (such as bank statements or tax filings), and conveying automated capital-matching and financing offers.
-
5. PROTOCOLS FOR DISCLOSURE AND INTER-ENTITY TRANSFERS
Reyes Commercial Capital LLC executes the extraction, transmission, and downstream dissemination of ingested datasets to external corporate and sovereign entities strictly under the following restrictive legal and contractual frameworks:
-
Downstream Institutional Capital Allocation and Funder Disclosures: Ingested personal profiles, corporate financial ledgers, transactional histories, and credit bureau extracts are transmitted directly via secure application programming interfaces (APIs) or encrypted portals to authorized alternative financing institutions, asset-based lenders, institutional capital providers, and merchant cash advance underwriters solely to facilitate the algorithmic structuring, risk-pricing, issuance, and legal settlement of commercial financing offers. Upon successful transmission and handshake confirmation, the independent privacy policies, data governance charters, and security protocols of the receiving financial institutions immediately supersede this document, assuming exclusive legal custodianship; Reyes Commercial Capital disclaims all downstream tort, regulatory, or operational liability arising from secondary processing or third-party data management anomalies.
-
Service Provider Data Processing and Technical Vendor Enclosure: Information assets are shared with specialized, contractually bound technology vendors—including read-only bank verification protocols, cloud-native hosting infrastructures, identity verification (KYC) engines, and secure credit reporting utilities—strictly under executing Master Service Agreements (MSAs) containing zero-tolerance non-disclosure clauses and definitive data-use limitations that legally prohibit the storage, monetization, or processing of data for any objective outside the explicitly contracted technical task.
-
Sovereign Mandates, Regulatory Compulsion, and Judicial Disclosures: Personal and corporate information arrays are subject to warrantless disclosure and un-notified systemic transfer when compelled to satisfy valid judicial subpoenas, federal grand jury indictments, court orders, or administrative civil investigative demands issued by sovereign enforcement agencies, including but not limited to the Financial Crimes Enforcement Network (FinCEN), the Internal Revenue Service (IRS), the Securities and Exchange Commission (SEC), or state-level financial services regulatory bureaus.
-
Corporate Reconstruction, Capital Structuring, and Asset Liquidation Transfers: In the event of an executed corporate merger, asset acquisition, institutional stock buy-out, Chapter 11 restructuring, or systemic liquidation of enterprise assets, all proprietary database objects and historical consumer files will be transferred to the successor entity, subject to mandatory continuity provisions and standard confidentiality covenants ensuring the uninterrupted preservation of pre-existing data rights.
6. RETENTION SCHEDULES AND DATA SECURITY ARCHITECTURE
-
Regulatory Data Retention Eras and Statutory Preservation Mandates: To enforce absolute compliance with the Bank Secrecy Act (BSA), federal anti-money laundering (AML) recordkeeping mandates, internal audit standards, and state-level contractual statutes of limitations, Reyes Commercial Capital subjects all core application objects, real-time transaction logs, historical credit bureau extracts, and regulatory compliance files to a mandatory preservation lifecycle. These assets are retained within active or secondary digital archives for a strict minimum duration of five (5) to seven (7) years, calculated continuously from the initial date of system ingestion, transaction finality, or formal account termination, whichever occurs last.
-
Cryptographic Data Security Matrix and Infrastructure Isolation: Universal information assets in transit across external networks are symmetrically encrypted utilizing industry-standard Transport Layer Security (TLS) 256-bit protocols coupled with advanced cipher suites. Information assets at rest are systematically isolated inside hyper-secure, redundant cloud repositories anchored by physical hardware security modules (HSMs). System access is gatekept by multi-layered multi-factor authentication (MFA) requirements, zero-trust role-based access control (RBAC) matrices, continuous data loss prevention (DLP) packet filters, automated intrusion detection and prevention systems (IDPS), and real-time, immutable event-log telemetry monitoring for anomalous access vectors.
-
Systemic Sanitization Mechanisms and Cryptographic Erasure Protocols: Upon the verified expiration of the legally mandated retention timeline, all associated digital and physical records are systematically rendered permanently irretrievable. This lifecycle phase executes via automated cryptographic erasure protocols (overwriting the underlying decryption keys to render the ciphertext permanently undecipherable) or through high-security physical media shredding and degaussing methodologies aligned with National Institute of Standards and Technology (NIST) Special Publication 800-88 Revision 1 guidelines for media sanitization.
DISCLOSURES
This section establishes an integrated, localized disclosure framework governing the distinct individual consumer privacy rights enacted under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), alongside subsequent comprehensive state privacy statutes—including but not limited to the active and effective frameworks of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Oregon (OCPA), Texas (TDPA), Indiana (ICDPA), Kentucky (KCDPA), New Jersey (NJPA), Rhode Island (RIDTPPA), Maryland (MODPA), and Oklahoma (OCDPA).
These provisions apply exclusively to natural persons residing within jurisdictions possessing comprehensive consumer privacy frameworks ("Consumers").
A. STATUTORY INTER-REGULATORY EXEMPTIONS (GLBA ENCLOSURE)
Pursuant to the statutory text of the federal Gramm-Leach-Bliley Act, also known as GLBA, found in Title 15 of the United States Code, Section 6801 and following, the Fair Credit Reporting Act, also known as FCRA, found in Title 15 of the United States Code, Section 1681 and following, and the institutional exemptions explicitly codified within state-level consumer privacy laws, the vast majority of data ingested by Reyes Commercial Capital during the commercial credit evaluation, financing matchmaking, and commercial underwriting lifecycles constitutes exempt financial data. Consequently, individual rights of access, correction, deletion, and portability enumerated under state comprehensive privacy frameworks do not apply to data elements processed under our capacity as a commercial financial services intermediary.
The individual consumer controls detailed herein apply exclusively to non-exempt personal data pools including marketing telemetry, website metadata, unstructured digital inquiries, and general corporate communications unattached to a finalized credit determination or active commercial funding transaction.
1. MATRIX OF DATA RETROSPECTIVELY DISCLOSED
Within the immediately preceding twelve (12) month temporal window, Reyes Commercial Capital has systematically compiled, computationally processed, and distributed to third-party corporate and sovereign entities for explicitly defined operational business objectives the following formalized categories of information assets:
Regulatory Category of Data Inter-Systemic Operational Business Objective Authorized Third-Party Recipient Frameworks
Category A: Core System Identifiers Direct identity authentication; network session synchronization; cryptographic channel optimization; endpoint security auditing. Multi-institution underwriters; automated platform security platforms; intrusion prevention architectures.
Category B: Commercial Financial Records & Ledgers Institutional capital analysis; transactional cash flow stability indexing; historical credit liability matching; ledger liquidity evaluation. Licensed alternative funding partners; asset-based syndicates; merchant cash advance underwriting networks.
Category C: Protected Legal Classifications Statutory identity verification; federal age and birthdate attestation; background screen validation; identity theft mitigation. Specialized Know-Your-Customer (KYC) verification vendors; automated anti-fraud registries.
Category D: Electronic Activity Data & Telemetry Predictive consumer analytics tracking; telemetry footprint debugging; infrastructure monitoring; threat detection and perimeter defense. Cloud-native infrastructure hosts; secure cloud computing networks; algorithmic monitoring utilities.
Category E: Regulated Sensitive Personal Data (SSN/EIN) Strict federal statutory compliance enforcement; Bank Secrecy Act anti-money laundering (AML) screening; Office of Foreign Assets Control (OFAC) list match audits. National consumer credit bureaus; secure enterprise portals; sovereign regulatory oversight platforms.
2. ENUMERATION OF CONSUMER PRIVACY RIGHTS
Eligible consumers possess specific legal rights designed to manage and audit their data footprint:
-
The Right to Access & Confirm Processing: The right to verify if Reyes Commercial Capital is actively processing your data and to receive an inventory of the specific information assets maintained.
-
The Right to Data Portability: The right to export your personal data in a clean, technically structured, machine-readable, and portable format to facilitate transfer to an alternative enterprise.
-
The Right to Rectification: The right to compel the modification and correction of verified inaccuracies within your profile records.
-
The Right to Deletion: The right to request the permanent erasure of collected data assets, subject to our overriding legal mandates to preserve financial underwriting and AML compliance logs.
-
The Right to Restrict Sensitive Data Processing: The right to limit the deployment of Sensitive Personal Information to necessary actions. Reyes Commercial Capital strictly restricts SPI processing to core underwriting and identity verification functions.
-
The Right to Opt-Out of Automated Profiling: The right to challenge and opt-out of automated processing configurations that produce legal or similarly significant financial effects. If algorithmic configurations evaluate your application, you can demand final human manual review of the credit determination.
-
The Right to Opt-Out of Sale or Behavioral Tracking: We do not sell data or trade information for cross-context behavioral marketing. Our system is engineered to automatically detect and honor universal browser opt-out preference choices, including the Global Privacy Control (GPC) signal, immediately blocking optional analytical tracking scripts.
-
The Right to Appeal: If a request is declined due to a conflicting legal framework (e.g., an active audit hold or a statutory retention mandate), you may formally appeal our decision within 45 days of receiving the denial notice.
-
The Right to Non-Discrimination: We are prohibited from altering rates, degrading system performance, or denying services based on your assertion of privacy rights.
-
3. RIGHT OF INQUIRY AND DISCLOSURE VERIFICATION
To initiate the formal execution of individual state-level consumer privacy controls including requests for data erasure, systemic rectification, complete portfolio access, data portability, or automated profiling restrictions or to formally file a administrative appeal regarding a previously declined data directive, consumers must interface directly with our corporate data governance office through the following official, secure communication nodes:
-
Secure Inbound Email Ingestion Node: Funding@reyescommercialcapital.com
-
Toll-Free Corporate Telephony Portal: (212)875-5626
All incoming consumer directives are subject to a mandatory, multi-tiered identity verification protocol. To execute any data request, applicants must provision comprehensive administrative criteria sufficient to achieve cross-system verification against our active internal databases, including but not limited to the full legal enterprise name, matching corporate Employer Identification Number (EIN), and the original verified applicant email address.
To safeguard proprietary corporate metadata and sensitive financial records, requests submitted via external third-party proxies or designated legal agents are rejected systematically unless accompanied by an explicit, legally binding written power of attorney or notarized agency authorization form executed directly by the principal applicant.
CORPORATE CONTACT DATA
All communication regarding our technical data handling methodologies, legal policy adjustments, or compliance audits must be directed to:
Reyes Commercial Capital LLC Website Infrastructure: www.reyescommercialcapital.com
Direct Processing Mailbox: 40 Wall Street 28th Floor Suite 2890 New York City, NY 10005-1304
⚠️ Corporate Legal Notice: This document establishes an institutional data compliance architecture aligned with 2026 commercial finance practices. Because state interpretations and physical operational models shift, this policy must undergo formal annual evaluation by your corporate counsel prior to production rollout.
