StreamQuote

Legal

Privacy Notice

Effective June 23, 2026. Last updated August 19, 2026. This notice describes how StreamQuote handles account, workflow, and borrower-related information.

Information Collected

StreamQuote may collect account credentials, profile details, NMLS and licensed-state entries, billing identifiers, usage events, device and browser metadata, support communications, imported lead data, borrower scenario details, rate-sheet files, quote history, and integration data submitted by the user.

How Information Is Used

Information is used to provide the service, authenticate users, maintain trial and subscription access, generate quote previews, support account setup, improve product reliability, protect against misuse, and comply with legal or contractual obligations.

Sharing

StreamQuote may share information with service providers that help operate hosting, analytics, payment processing, messaging, storage, security, or support features. StreamQuote does not sell borrower personal information. Users remain responsible for any sharing they initiate through quote delivery, integrations, exports, uploads, or external systems.

Google Account Data

When a user connects Google Workspace or Gmail, StreamQuote uses the minimum authorization needed to send an Email Quote after the user reviews the recipient and confirms delivery. StreamQuote also uses that authorization to send a generated Auto-Quote email only when the user enables Email delivery and chooses a delay. StreamQuote does not read the user's inbox, unrelated messages, drafts, labels, contacts, or attachments. When a user separately connects Google Calendar, StreamQuote stores the connected calendar account identity and uses the minimum authorization needed to create a private appointment on a calendar that user owns. StreamQuote does not access calendars the user does not own, add attendees, or send borrower invitations.

Email and calendar-event content is transmitted to Google only to perform the connected feature requested or enabled by the user. Sent messages and created events remain in the user's Google account. StreamQuote does not sell Google user data, use it for advertising, use it to make credit or lending decisions, or use it to train generalized artificial-intelligence or machine-learning models. Google user data is shared only with service providers needed to operate and secure StreamQuote, or when required by law.

StreamQuote's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Disconnecting a Google integration attempts to revoke its Google authorization and removes the corresponding token and connected-account identity from StreamQuote. Users may also revoke access from their Google Account security settings. Sent messages and calendar events already created in Google remain there until the user removes them. Users may request deletion of their StreamQuote account and stored integration data through support, subject to legal record-retention requirements.

Data Protection and Security

StreamQuote uses technical and organizational safeguards designed to protect sensitive information and Google user data against unauthorized access, disclosure, alteration, and loss. In production, data is encrypted in transit using HTTPS/TLS. Stored Google OAuth refresh tokens are encrypted at rest using authenticated AES-256-GCM encryption, and Google access tokens are short-lived.

Access to StreamQuote data and connected integrations is limited through authenticated sessions, account-scoped authorization, and least-privilege Google OAuth permissions. Integration credentials are not displayed to other users and are decrypted only when the connected feature needs to make an authorized request. StreamQuote applies access controls and security monitoring appropriate to the service and limits service-provider access to what is needed to operate and secure StreamQuote.

Users can disconnect Google integrations to remove stored Google authorization from StreamQuote and can request deletion of their StreamQuote account and stored integration data through support. No security method is completely risk-free, but StreamQuote reviews and updates its safeguards as the service evolves.

Financial Privacy and Safeguards

Mortgage workflow data can include nonpublic personal information. StreamQuote should be used with appropriate administrative, technical, and physical safeguards, and users must follow their company privacy policies, Gramm-Leach-Bliley Act obligations, and applicable state and federal privacy laws.

Choices and Retention

Users may update account profile details in StreamQuote where available and may request support for account or data questions. StreamQuote retains information as needed to operate the service, maintain records, resolve disputes, enforce terms, and satisfy legal obligations.

Terms Mortgage Disclosures Licenses Subscription Terms