Beta legal (draft, pending counsel review)
Privacy Policy
Beta draft, pending counsel review
- Controller:
- Lozort Federal LLC (“Beltway,” “we,” “us”).
- Contact:
- contact@lozortfederal.com
- Last updated:
- July 16, 2026
This Privacy Policy explains what information we collect, how we use and share it, and the choices available to you. It applies to the Beltway Service. For the business and accounting data you upload, you are generally the controller and we act as a processor on your behalf, as described in our Terms of Service and any Data Processing Addendum.
1. Information we collect
- Account and contact data: name, work email, organization name, role.
- Authentication data: hashed credentials, session data, and access tokens. Personal Access Tokens and AI-connector authorizations are stored hashed.
- Billing data: billing contact and subscription state. Payment card data is collected and stored by Stripe, not by Beltway.
- Customer Data: the accounting, contract, vendor, customer, labor and timekeeping, and document data you submit to operate your books.
- Usage and device data: product analytics events, log and error data, IP address, and browser and device metadata.
- AI interaction data: the prompts, tool results, and conversation history generated when you use the AI Copilot.
We do not intentionally collect special-category personal data, and you should not upload more personal data than necessary to operate your accounting, for example avoid storing Social Security numbers in free-text fields.
2. How we use information
- To provide, secure, and operate the Service.
- To process subscriptions and billing.
- To send transactional and lifecycle email (welcome, trial reminders, billing, activation nudges) through Resend.
- To provide AI Copilot answers and drafts (see Section 4).
- To monitor reliability and security, including error monitoring, abuse prevention, and rate-limiting, and to improve the Service.
- To comply with law and enforce our Terms.
We do not sell personal information, and we do not use Customer Data to train third-party foundation models.
4. AI processing
- AI Copilot (in-app): when you use the Copilot, the relevant portion of your workspace's accounting data is sent to our configured AI provider to generate a response. Beltway's Copilot runs on Anthropic's Claude models; we may also support OpenAI as an alternate provider depending on configuration. An organization may optionally connect its own AI provider API key (bring-your-own-key); in that case requests run under that organization's own account with the provider.
- External AI connector (Model Context Protocol): if you connect your own separate AI client, for example your own Claude account, to Beltway through the MCP connector, that client accesses the data scopes you authorize on the consent screen, and inference runs under your account with that provider, governed by your own agreement with them. Beltway authorizes and audit-logs the access but does not process that request itself.
- The Copilot prepares drafts and previews only; it does not post or finalize records without your explicit confirmation.
5. Data retention
- Customer Data is retained while your account is active and for 30 days after termination to allow export, after which it is deleted or anonymized, subject to legal retention requirements. As a government contractor you may have independent records-retention obligations, for example under DCAA; you remain responsible for retaining your own records.
- Logs and analytics are retained for a limited period consistent with our security and product needs; the exact retention schedule is being finalized with counsel.
6. Security
We use administrative, technical, and physical safeguards, including encryption in transit, hashed credentials and tokens, role-based access control, tenant isolation, audit logging, rate-limiting, and least-privilege access. See the Security Overview for more detail. No method of transmission or storage is 100% secure.
7. Your rights and choices
Depending on your location, you may have rights to access, correct, delete, or port personal data, or to object to or restrict certain processing. Because we often process Customer Data on your organization's behalf, please direct such requests to your organization's administrator or to contact@lozortfederal.com, and we will assist. The applicability of CCPA, CPRA, other state privacy laws, and GDPR, along with the corresponding rights language, is being finalized with counsel.
8. International data transfers
The Service is operated in the United States. If you access it from outside the U.S., your data will be processed in the U.S.
9. Children
The Service is not directed to individuals under 18 and is intended for business use only.
10. Changes
We will post changes here and update the “Last updated” date above; we will notify you of material changes by email or in-app.
11. Contact
Questions or requests: contact@lozortfederal.com.
12. Subprocessors
Beltway is operated by Lozort Federal LLC. We use the following third parties to process customer data on our behalf. This list is reviewed as our stack changes; we will not add a subprocessor that touches Customer Data without updating this list.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Supabase | Primary application database | All customer accounting, contract, labor, and user data | United States |
| Vercel | Application hosting and serverless compute | Request data and transient processing of all application data | United States |
| Stripe | Subscription billing and payments | Billing contact and subscription state; payment card data is held by Stripe, not Beltway | United States |
| Resend | Transactional and lifecycle email delivery | Recipient name and email, message contents | United States |
| Plaid | Bank account connection and transaction sync for the Banking feature | Bank login and account tokens and transaction data needed to link and sync accounts | United States |
| Anthropic | AI Copilot inference (primary provider) | Accounting data included in Copilot prompts and tool results during a Copilot session | United States |
| OpenAI | AI Copilot inference (alternate provider, configuration-dependent) | Accounting data included in Copilot prompts and tool results, when configured as the active provider | United States |
| Sentry | Error monitoring | Error traces, which may incidentally include request metadata | United States |
| PostHog | Product analytics | Usage events and pseudonymous user and organization identifiers | United States |
If you connect your own AI client through the MCP connector (see Section 4), that client and its provider are not a Beltway subprocessor: the data leaves under your own relationship with that provider, and Beltway only authorizes and audit-logs the scoped access.
Questions or requests: contact@lozortfederal.com.