Legal
Privacy Policy
Effective date: July 22, 2026
1. Who We Are
CIMA ("CIMA," "we," "us," or "our") is a marketing platform for mortgage companies, available at cima.ai. CIMA provides AI-powered advertising management, marketing attribution and analytics, CRM integration, and website services to the mortgage businesses that use the platform ("Customers"). This Privacy Policy describes what information CIMA collects, how it is used, how it is protected, and the choices available to Customers and the individuals whose information Customers process through the platform.
CIMA operates primarily as a service provider: most of the data on the platform is collected and processed on behalf of a Customer, at that Customer's direction, to run their marketing and sales operations.
2. Information We Collect
2.1 Data from connected advertising platforms
When a Customer connects an advertising account, CIMA accesses data through that platform's official APIs, limited to the scopes the Customer authorizes:
- Meta (Facebook and Instagram): ad account details, campaign, ad set, and ad structures, spend and performance metrics, Facebook Page metadata, lead information submitted through lead ads, and conversion events associated with the Customer's advertising.
- Google: Google Ads account details, campaign structures, and spend and performance data.
Authorization credentials (OAuth tokens) for these connections are stored encrypted and are used only to operate the connection the Customer created.
2.2 Data from Customer business systems
- CRM data: contact records, lead records, and pipeline or opportunity data synced from the CRM systems a Customer connects.
- Website form submissions: information visitors submit through forms on Customer websites operated on the platform, such as name, email address, phone number, and loan inquiry details.
- Analytics events: website session and page view data, referral and campaign parameters, and conversion events collected from Customer websites to power attribution reporting.
2.3 Platform account information
For people who sign in to CIMA directly, we collect account information such as name, email address, and authentication credentials (passwords are stored only as secure hashes).
2.4 Technical information
Like most services, our infrastructure records technical logs, including IP addresses, request identifiers, and timestamps, used for security, debugging, and reliability.
3. How We Use Information
Information on the platform is used to:
- Operate advertising campaigns on behalf of the connected Customer.
- Compute attribution and analytics reporting for the Customer, connecting marketing activity to leads and outcomes.
- Sync leads, contacts, and pipeline data between the platform and the Customer's connected systems.
- Operate, secure, maintain, and improve the platform itself.
- Communicate with Customers about the service.
We do not sell personal information, and we do not use data obtained from one Customer's connections for another customer or any unrelated purpose.
4. How Information Is Shared
- Connected platforms: data is shared with Meta, Google, and CRM providers only as needed to operate the connections the Customer has created, for example sending conversion events or syncing a lead record.
- Infrastructure providers: we use hosting and managed database providers to run the service. Production infrastructure is hosted in the United States.
- Legal requirements: we may disclose information when required by law or to protect the rights, safety, or property of CIMA, our Customers, or others.
We never sell personal information and never share it with third parties for their own advertising or marketing purposes.
5. Storage and Security
- Platform credentials and other sensitive secrets are encrypted at rest using AES-256 encryption.
- All data in transit is protected with TLS.
- Production systems are hosted on Fly.io and managed database infrastructure located in the United States.
- Access to production data is restricted, logged, and limited to what is necessary to operate the service.
6. Retention
We retain data for as long as the related Customer connection or account remains active. When a Customer disconnects an integration or requests deletion, the associated tokens and synced data are deleted within 30 days. See our Data Deletion Instructions for the exact process.
7. Your Choices and Deletion
Customers can disconnect any integration at any time from their platform settings, or request deletion by contacting us. Individuals whose information was submitted to a Customer through the platform (for example, through a website form) may contact us or the relevant Customer to request access or deletion, and we will assist the Customer in honoring the request.
8. California Privacy Rights
If you are a California resident, the California Consumer Privacy Act (CCPA) provides the following rights:
- Right to know: you may request the categories and specific pieces of personal information we have collected about you.
- Right to delete: you may request that we delete personal information we hold about you, subject to legal exceptions.
- Right to correct: you may request that we correct inaccurate personal information.
- Right to non-discrimination: we will not discriminate against you for exercising any of these rights.
To exercise these rights, email support@cima.ai. We will verify your request using the email address associated with your information and respond within the timeframe required by law. We do not sell personal information as defined by the CCPA.
9. Third-Party Platform Policies
Use of data received from platform APIs is also governed by those platforms' policies. CIMA's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. CIMA's use of Meta platform data complies with the Meta Platform Terms and Developer Policies.
10. Children
CIMA is a business service and is not directed to individuals under 18. We do not knowingly collect information from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The current version will always be available at cima.ai/privacy, and the effective date at the top of this page will reflect the latest revision.
12. Contact
For privacy questions or requests, contact support@cima.ai.
Last updated: July 22, 2026