Privacy Policy
This Privacy Policy explains how Foundation Home and Financial collects, uses, discloses, and protects information about you.
Who we are
Foundation Home and Financial ("Foundation," "we," "us," or "our") is a fintech company building a modern mortgage experience. Foundation Home and Financial is not a mortgage lender. Mortgage services referenced or offered through our platform are provided by licensed third-party lending partners, including Fidelity Direct Mortgage, LLC (NMLS#: 188829).
Information we collect
Information you provide directly
When you sign up for or use our web or mobile applications, we collect information you provide, including:
- Identity and contact information: first and last name, email address, and mobile phone number.
- Account preferences and communication settings.
- Messages and support inquiries you send to us.
Information collected automatically
When you use our services, we automatically collect limited technical information, including:
- Device and usage data (device type, operating system, browser, IP address, approximate location based on IP).
- Log data (timestamps, actions taken, authentication events).
- Cookies and similar technologies used to keep you signed in and to maintain session state.
How we use your information
We use the information we collect to:
- Create and maintain your account and verify your identity (including sending SMS one-time passcodes for authentication).
- Provide, operate, and improve our web and mobile applications.
- Respond to your support requests and communicate with you about your account.
- Detect, investigate, and prevent fraud, abuse, and security incidents.
- Comply with legal obligations and enforce our terms of use.
How we share your information
We do not sell your personal information. We do not share your personal information with third parties or affiliates for their own marketing or promotional purposes. We share information only in the following limited circumstances:
- Service providers: We share information with vendors who perform services on our behalf, including cloud hosting (Amazon Web Services), SMS delivery, email delivery, analytics, and identity verification. These providers are contractually obligated to protect your information and use it only as instructed by us.
- Lending partners: If you choose to apply for a mortgage through our platform, we share application information with the licensed lending partner(s) you authorize.
- Legal and safety: We may share information when required by law, subpoena, or court order, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
- Business transfers: If Foundation is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction, subject to standard confidentiality protections.
SMS messaging
We send SMS text messages solely for authentication purposes. For complete details about our SMS program, including opt-in, opt-out, message frequency, and carrier information, see our SMS Terms & Opt-In.
We do not share your mobile phone number, SMS opt-in data, or the contents of any SMS messages with any third parties, affiliates, or lead generators for marketing or promotional purposes at any time. Phone numbers are shared only with our SMS delivery provider and the carrier networks for the sole purpose of delivering the authentication messages you have requested. No mobile information collected as part of the SMS opt-in process will be shared or sold to third parties or affiliates for marketing purposes at any time.
Data security
We implement administrative, technical, and physical safeguards designed to protect your information, aligned with federal standards for financial services (including NIST 800-53r5 controls). These include:
- Encryption of data in transit using TLS 1.2 or higher.
- Encryption of data at rest.
- Passwordless authentication using one-time SMS codes, eliminating common password-based attack vectors.
- Access controls and audit logging for all system access.
No security measure is perfect. While we work hard to protect your information, we cannot guarantee absolute security.
Data retention
We retain personal information for as long as your account is active and as necessary to provide services, comply with legal obligations, resolve disputes, and enforce our agreements. When no longer needed, we delete or anonymize the information in accordance with our retention policies.
Your rights and choices
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate personal information.
- Request deletion of your personal information.
- Opt out of certain uses of your information.
To exercise any of these rights, contact us at privacy@foundationhomeandfinancial.com.
Children's privacy
Our services are not directed to children under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us and we will delete it.
Changes to this Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date above and, where appropriate, notify you in-app or by email.
Contact us
If you have questions about this Privacy Policy or our privacy practices, contact us at: