Skip to main content
Privacy

Privacy

Sanderwell Systems, LLC sells software to the organizations that use it, not advertising. We have no business model that involves your data, and this page says plainly what we hold, who else touches it, and what we have not done yet.

This website

There is no analytics on sanderwell.com. No Google Analytics, no tracking pixel, no advertising tag, and no third-party script of any kind—the site ships zero client-side JavaScript. Fonts are served from our own domain rather than a font CDN, so loading a page does not disclose your visit to anyone but us.

One cookie, and only on the contact page. Submitting the form requires an anti-forgery cookie, which is what stops another site posting the form on your behalf. It is strictly necessary, holds no identifier we can tie to you, and is set nowhere else on the site.

Server logs. Our hosting records the ordinary web-server detail—IP address, time, page requested, browser string. We use it to keep the site up and to rate limit the contact form, which is an unauthenticated endpoint that sends email and would otherwise be abused. It is not used to build a profile of you.

The contact form

The form collects your name, work email address, organization, optionally your role and roughly how many people travel for you in a year, and your message. It is delivered to us as email. Your address is used as the reply-to so a person can answer you.

We do not sell it, share it with data brokers, or add you to a marketing list you did not ask for. If you would like what you sent us deleted, say so and we will delete it.

Data inside the application

Travel & Expense holds your organization's records—travelers, trips, addresses, receipts, account codes, approvals. That data belongs to your organization, not to us. We process it to run the service under our agreement with them, on their instructions, and we do not use it to train anything, sell it, or mine it for our own purposes. When the agreement ends, we return or delete it at your organization's direction.

Inside the application, access to personal information is logged. Every audit-packet export is logged. Those records exist so your finance office can answer the question of who looked at what, which is a question auditors ask.

Who else is involved

We are a small company and we do not pretend to run our own datacentre. The service depends on:

  • A cloud infrastructure provider—hosting, the database, and secret storage. All application data is held in the United States. We name the provider and the region in writing on request and in the security questionnaire.
  • Google Maps—address lookup and driving distance. Addresses and place names are sent to compute mileage; traveler identity is not.
  • An email provider—notifications, approval requests, and password resets, which by their nature contain the recipient's address and the subject of the message.
  • An AI provider, only if you turn on the trip-draft feature described below. Off, nothing goes anywhere near one.

The optional AI trip draft

The draft feature lets a traveler describe a trip in plain language and get a filled-in form back to review. It is off until an administrator at your organization turns it on, per organization, and it can stay off permanently without affecting anything else in the product.

What is sent, when it is on: the sentence the traveler typed, today's date, and the list of location names your organization has configured. That is the whole payload. The traveler's name, employee record, home address, account codes, and prior trips are not part of it.

What comes back is a draft, not a calculation. Mileage, per diem, and account coding are computed by our own rules engine from your configured policy, exactly as they are on a form keyed by hand. The model proposes dates, stops, and labels; it does not produce the reimbursement amount, and the traveler edits every field before anything is submitted.

Where it goes. By default, a commercial AI provider we will name for you. Where your AI policy requires the request stay inside your own cloud tenant, the feature can be pointed at an equivalent model hosted there instead. Either way it runs on commercial API terms stating that content sent through the API is not used to train the model; we rely on those terms and will point you at them rather than paraphrase them in a sales conversation. If your policy requires a particular provider, tell us during the evaluation—this is a configuration setting, not a rebuild.

What we have not yet done

We do not publish a standard data processing agreement. One is in preparation. In the meantime we will review and sign yours, which is what most organizations want anyway, and we would rather tell you that than post a template we have not had counsel look at.

We hold no third-party security certification. No SOC 2, no StateRAMP. We are early, and a certification we have not earned is not something we are going to imply. Ask us specific questions about how the system is built and we will answer them specifically.

Asking us about your data

If you work for an organization that uses Sanderwell and you want to see, correct, or delete something about yourself, start with your own finance office—the records are theirs and they can act on them directly. If they need us, we will help. For anything else, including what we hold from a contact-form submission, write to us.

This notice covers sanderwell.com and the Sanderwell Travel & Expense application. It is reviewed whenever our position materially changes, and where it conflicts with a signed agreement, the agreement governs. Last updated August 2026.