1. Who we are
MJL Collective LLC (“MJL Collective,” “MJL,” “we,” “us,” or “our”) is a New Jersey limited liability company. This Privacy Policy explains how we collect, use, store, share, and delete information in connection with:
- our public website at https://mjlcollective.com;
- our internal business tools used to operate MJL Collective and related ventures; and
- our use of Plaid Inc. (“Plaid”) to retrieve read-only financial account information for internal bookkeeping and business reporting.
This policy is written for visitors to our website, clients and prospects who interact with us, and for Plaid’s application review of the financial-connection flow we use for our own business accounts.
Primary contact
Mitchell Lisa
mitchell@mjlcollective.com
2. Scope of this policy
This policy covers personal information and financial account information we process in the United States for MJL Collective’s own operations.
It does not authorize third parties to access your bank or card accounts through MJL. The Plaid Link connection described below is intended for MJL Collective’s own business financial accounts (for example, American Express business card activity used for company expenses), connected by an authorized MJL account holder for internal finance use.
If you are a client or website visitor and never connect a financial account through our Plaid Link flow, sections about Plaid financial data do not apply to you, except where we otherwise receive information from you (for example, by email).
3. Plaid and financial account connections
3.1 Why we use Plaid
MJL Collective uses Plaid so we can pull read-only transaction and related account information into our internal finance systems for business financial management and bookkeeping.
This supports:
- expense tracking;
- transaction categorization;
- subscription reconciliation;
- cash-flow reporting; and
- internal profit-and-loss (P&L) and other business reporting.
3.2 Plaid product used
We use Plaid’s Transactions product only.
We do not use Plaid to:
- initiate bank transfers;
- move money;
- make or collect payments;
- initiate payment orders; or
- enable Auth, Transfer, Payment Initiation, Identity, or similar money-movement products for this integration.
The connection is read-only.
3.3 Institutions and data that may be retrieved
When an authorized MJL user completes Plaid Link for a supported institution, Plaid may retrieve information from that institution and make it available to us through Plaid’s APIs. For our current intended production use, this includes American Express transaction and related account information associated with the connected business account(s).
Depending on what the institution and Plaid return for a Transactions connection, categories of data may include:
- account identifiers and metadata (for example, institution name, account name or mask, account type);
- transaction history (dates, amounts, merchant or description text, pending vs posted status);
- categorizations or enrichment fields provided by Plaid or derived by our systems for bookkeeping;
- connection status and sync timestamps; and
- technical tokens required to maintain the read-only connection (such as access tokens), which we treat as confidential credentials.
We use this information only for the internal business purposes listed above, and for related security, audit, troubleshooting, and legal compliance.
3.4 What we do not do with financial data
We do not:
- sell financial account or transaction data;
- use Plaid financial data to market unrelated products to consumers;
- use this integration to transfer funds or initiate payments; or
- grant public or unauthenticated access to Command Center or finance databases.
4. Other information we collect
4.1 Information you provide directly
When you email us, hire us, or otherwise communicate with MJL, we may collect information you choose to share, such as your name, email address, company name, project details, and billing or contract details needed to deliver services.
4.2 Website and operational data
Our public website and infrastructure may process limited technical data such as IP address, browser type, timestamps, and basic server logs needed to operate and secure the site. We may also process business records in our internal systems (for example, client project status, invoices, and related correspondence) as part of operating MJL Collective.
4.3 Payment processors (separate from Plaid)
Separately from Plaid, we may use payment processors such as Stripe to receive client payments. Stripe processes payment card data according to its own terms and privacy policy. Card numbers are handled by the processor; we receive business records such as payment amounts, fees, and payout status needed for bookkeeping.
5. How we use information
We use information to:
- operate MJL Collective’s website and services;
- communicate with clients, prospects, and vendors;
- track and categorize business expenses and subscriptions;
- reconcile software and other recurring charges;
- prepare cash-flow, P&L, and internal management reports;
- maintain security, audit trails, and system reliability;
- comply with law, respond to lawful requests, and protect our rights; and
- improve our internal tools in ways that do not require selling personal or financial data.
6. Service providers and sharing
We share information only as needed to run the business, including with:
- Plaid, which facilitates the financial account connection and provides Transactions data under Plaid’s terms and privacy policy (https://plaid.com/legal);
- hosting and infrastructure providers that run our servers, databases, and related systems (currently including cloud virtual private server hosting used for MJL operations);
- payment processors such as Stripe, when you pay us;
- email and productivity providers (for example, Google) used for business communications and files;
- professional advisors (legal, accounting) when required; and
- authorities when required by law or to protect rights and safety.
We require service providers to use information only to perform services for us or as required by law. We do not sell personal information or financial account data.
Plaid’s handling of data is also described in Plaid’s end-user materials presented during Link. Please review those disclosures when connecting an account.
7. How we store and protect information
Financial and operational records are stored in our controlled business systems (including databases and application services on our private infrastructure). Access to internal finance dashboards is restricted (authenticated access only).
In transit: connections to our public sites and APIs are protected with HTTPS/TLS where those services are served over HTTPS.
At rest (verified production controls):
- Plaid-derived financial data (including transaction and related account records stored in our database for expense tracking, categorization, subscription reconciliation, cash-flow reporting, and internal P&L / business reporting) is encrypted at rest using full-volume encryption (LUKS) on the dedicated secure storage path that holds our Postgres database files.
- Database backups that contain financial data are encrypted before persistent storage (age encryption) and retained on that same encrypted volume. Temporary dump files used during backup are written only to the encrypted volume and removed after the encrypted backup is created.
- Plaid access tokens are not stored in plaintext in the database. They are application-sealed and stored on the encrypted database volume.
- Production credentials used for financial integrations (including Plaid client credentials and related API secrets such as Stripe) are stored in protected host configuration with restricted file permissions. They are not stored in the database, public source repositories, chat logs, or public web pages.
Encryption keys for volume encryption and backup encryption are stored outside the database on the host with restricted permissions.
We also apply least-privilege application design for the Plaid integration (Transactions product only; read-only; no bank transfers or payment initiation through this integration).
No security measure is perfect. We work to reduce risk of unauthorized access, loss, or misuse, but we cannot guarantee absolute security.
8. Retention and deletion
We retain financial and business records for as long as needed for bookkeeping, tax, audit, dispute resolution, and legal obligations, then delete or de-identify them when retention is no longer required.
Plaid-derived transaction and account records used for expense tracking and reporting are retained while the connection is active and afterward as needed for historical books, reconciliation, and legal retention. When we no longer need specific records and are not required to keep them, we delete them from production systems according to our operational deletion process.
Backups may retain copies for a limited period after deletion from live systems. Backup retention is reviewed as part of our security and privacy practices.
9. Disconnecting a financial account
An authorized MJL account holder can disconnect a Plaid-linked financial institution by contacting us at mitchell@mjlcollective.com and requesting disconnection, or through any in-product disconnect control we provide when available.
After disconnection, we will stop new syncs from that item through our integration. We may retain historical transactions already imported if needed for books, taxes, or legal retention, unless you also request deletion and no retention obligation requires us to keep them.
You may also manage or revoke access through your financial institution’s settings and through Plaid’s consumer tools where available (see Plaid’s help resources).
10. Access, correction, and deletion requests
To request access to, correction of, or deletion of personal information we hold about you, or to ask us to delete Plaid-derived financial data we control (subject to legal retention requirements), email:
Mitchell Lisa
mitchell@mjlcollective.com
Please include enough detail for us to verify the request and locate the relevant records. We will respond within a reasonable time. We may decline or limit a request where the law requires or allows us to retain information (for example, completed transactions needed for tax or accounting records), and we will explain when that applies.
If your request concerns data held by Plaid or your financial institution directly, we may need to direct you to those parties for portions of the request we do not control.
11. Children’s privacy
Our services are directed to businesses and adults. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, contact us and we will take appropriate steps to delete it.
12. International users
MJL Collective operates primarily in the United States. If you access our website from outside the United States, information may be processed in the United States, where privacy laws may differ from those in your jurisdiction.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will post the updated policy at this URL, revise the “Last updated” date, and, when changes are material, take additional steps we consider appropriate (for example, a notice on the website or an email to a relevant contact).
Continued use of our website or continued maintenance of a financial connection after an update means the updated policy applies going forward, except where a different consent is required by law.
14. Contact
Questions about this Privacy Policy or our privacy practices:
Mitchell Lisa
MJL Collective LLC
mitchell@mjlcollective.com
Moorestown, New Jersey, United States
