Privacy Policy
1. Who we are
Sweet Bennies (operated by Landjourney Technologies, “Sweet Bennies,” “we,” “us”) provides a benefits-administration platform used by employers (“Customers”) to run programs like Lifestyle Spending Accounts (LSA), Health Reimbursement Arrangements (HRA), Individual Coverage HRAs (ICHRA), COBRA administration, expense reimbursements, and incentive programs, and used by their employees to submit and track claims. This policy explains what information we collect through the Service, why, and how it’s protected.
If you are an employee using the Service, your employer (the Customer) has engaged Sweet Bennies to administer these programs on its behalf. For programs involving group health plan data, Sweet Bennies typically acts as a business associateof the plan under HIPAA, and processes protected health information (“PHI”) under a Business Associate Agreement (“BAA”) with the Customer or its plan.
2. Information we collect
Account and identity information: name, work email, employer, and role, obtained when you sign in via Google or your organization’s single sign-on provider.
Claim and receipt information: the details you submit with a claim — amounts, dates, vendors, categories, notes, and receipt images or PDFs you upload. For health-benefit claims, this may include PHI such as the nature of a medical expense or the name of the person who received care.
Payment information: information needed to process reimbursements, such as bank routing/account details for ACH transfers, handled through our payment processor.
Usage and audit information: sign-in events, approvals, and administrative actions, kept in an audit log for security and compliance purposes.
3. How we use information
- To operate the Service: authenticate you, route you to your employer’s workspace, and process, review, and pay claims;
- To apply plan rules: check claims against your employer’s configured policies and coverage limits;
- To assist review: use AI-assisted tools to read receipts, pre-fill claim fields, and flag possible duplicates, policy mismatches, or miscategorized submissions for human review — these tools are advisory and do not make final decisions;
- For security and compliance: detect fraud, maintain audit trails, and meet legal and regulatory recordkeeping requirements; and
- To communicate with you about your claims and account. We do not put PHI in the body or subject line of email notifications — notifications direct you back into the Service to view details.
We do not sell your personal information, and we do not use your health information for marketing.
4. Who we share information with
We share information with service providers who help us operate the platform, each bound by contract (and, where PHI is involved, a BAA) to protect it and use it only to provide services to us:
- Cloud hosting and database: to run the application and store claim data;
- Identity providers: Google and, where an organization uses enterprise single sign-on, WorkOS, to authenticate you;
- Cloud file storage: to store uploaded receipts and documents;
- Payment processor: to process reimbursement payments (including ACH transfers) and, where applicable, subscription billing;
- Email delivery: to send account and claim-status notifications (no PHI is included in these messages);
- AI provider: to power receipt-reading and policy-check features described above; and
- Accounting integrations you or your employer connect (for example, QuickBooks Online or Xero), which receive reimbursement transaction data your employer chooses to sync — connected only with your employer’s authorization, and disconnectable at any time by your employer’s administrator.
We may also disclose information where required by law, to protect the rights and safety of Sweet Bennies or others, or in connection with a merger, acquisition, or sale of assets (with notice as required by law).
5. Data retention
We retain claim and PHI data for as long as needed to administer your employer’s programs and to meet legal, tax, and regulatory recordkeeping obligations, after which it is disposed of on a scheduled basis. Your employer’s administrator can set retention periods within the limits our platform supports.
6. Security
We use administrative, technical, and physical safeguards designed to protect your information, including encryption of sensitive identifiers, audit logging of access to claims, and role-based access controls so only authorized reviewers can see your claim details. No system is perfectly secure, and we can’t guarantee absolute security.
7. Your choices and rights
You can review and correct the information in a claim before submitting it. Depending on your state of residence, you may have rights to access, correct, or delete certain personal information, or to opt out of certain processing — for most employees, these requests are best directed to your employer as the plan sponsor or Customer, who can route them to us. You can also contact us directly at hello@sweetbennies.com.
Where HIPAA applies to your health-benefit information, your health plan’s Notice of Privacy Practices (provided separately by your employer or plan) governs your HIPAA rights, including the right to access and request amendment of your PHI.
8. Children’s information
The Service is intended for use by working-age adults in an employment context and is not directed to children. We do not knowingly collect personal information directly from children.
9. International users
The Service is hosted in the United States and intended for use by U.S. employers and their employees. If you access the Service from outside the United States, your information will be transferred to and processed in the United States.
10. Changes to this policy
We may update this policy from time to time. We’ll update the “Last updated” date above when we do, and for material changes we’ll provide additional notice where required by law.
11. Contact us
Questions about this policy or how your information is handled? Contact us at hello@sweetbennies.com. See also our End User License Agreement.