Trust Center
How GroFi handles data and access.
JRJ Group Holdings LLC D/B/A UNIFY publishes these policies for the GroFi application. They are the public record for privacy, terms, and how we secure merchant and applicant data.
Effective August 27, 2026 · 40 Wall Street, 21FL, New York, NY 10005
Legal
Public terms
Data security
Security policies
- Information Security PolicyThe umbrella security program for GroFi systems that store or process consumer data.
- Access Control PolicyRole-based access, least privilege, and how GroFi staff and brokers reach merchant data.
- Identity and Access ManagementCentralized accounts, roles, password rules, and how access is granted and revoked.
- Data Encryption PracticesTLS in transit, AES-256-GCM field encryption for SSN, date of birth, and EIN, and storage encryption.
- Data Deletion and Retention PolicyHow long application, bank, broker, and lead data is kept, and how deletion requests are handled.
- Access Reviews and AuditsPeriodic review of staff and broker access to systems that store consumer data.
- Multi-Factor Authentication PolicyMFA on internal systems that store consumer data, and on consumer-facing GroFi surfaces where Plaid Link is deployed.
- Vulnerability Management PolicyHow we find, rank, and patch vulnerabilities inside a defined SLA.