You need to enable JavaScript to run this app.
By Travis Yule — CEO & Founder, Full Send Funding
Linking shares a read-only feed of the accounts you pick — 90 days by default, up to 730 — that refreshes until the Item is removed. It cannot move money.
In one sentence: Linking a business bank account shares a read-only, product-scoped feed that runs to the day you connect and refreshes until the Item is removed — so what matters is which products, how many days, which accounts and what the funder retains, because no federal data-rights rule answers those for a business account.
Linking your business bank account to a funder shares a read-only feed of the accounts you select: every transaction in the window the funder asked for — amount, date, description — the account's current and available balance, the name and contact details the bank holds for the account, and, only if the funder requested that product, the account and routing numbers.[11] It does not share your password with the funder.[9] It cannot move money. And it reaches back exactly as far as the funder configured it to, which by default is 90 days and can be as much as two years.[1]
Two things about the usual framing are wrong. The first is the fear: most owners imagine the link as handing over a login, and at the institutions that use OAuth you never type a password anywhere except your own bank's site.[14] The second is the complacency: a link is not a snapshot the way a PDF is. It is a standing connection that keeps refreshing until somebody removes it, the access token behind it does not expire on its own, and if you later disconnect it, the funder keeps whatever it already pulled.[8][10] The right posture is neither fear nor complacency. It is knowing the scope, the window, the retention and the revocation path before you click the button — and knowing that, for a business account, the federal data-rights rule everyone cites is not what stands behind you.
Here we give both routes. You can send us three to four months of statements as PDFs, or you can link the account through Plaid; underwriting reads the same deposit history either way. This article is about what the second route actually transmits, what we do with it, what any funder could do with it, and how to decide.
The service under the button is Plaid, which many bank-linking flows in American lending run on. The sequence has four parts, and each part fixes something about what gets shared.
The consent pane. The first screen in Plaid Link is a consent pane, where you agree to Plaid's end-user privacy policy; where the requester has enabled Plaid's data transparency messaging, that screen also names the data types being requested and the use case for each.[13] Read it. It is the one place the scope is written down before you commit.
Authentication at the bank. At institutions that support OAuth, Link hands you to the bank's own site or app to sign in and authorize, then returns you to Link; your credentials go to the bank, not to Plaid and not to the funder.[14] At institutions that do not, you enter credentials inside Plaid's flow and Plaid connects on your behalf. In either case Plaid states that it never shares credentials with the app you are connecting to.[9]
Account selection. Link then shows an account-select pane — a required step where you choose which accounts under that login to share; the requester can configure it for a single account, several, or all preselected, and can filter to show only checking accounts.[13] Everything that follows is limited to the accounts you tick. A savings account you leave unticked is not shared.
The token. What the funder receives at the end is not your data. It is an access token tied to an Item — Plaid's word for one login at one institution and the accounts under it — and the funder then calls Plaid's endpoints, product by product, to retrieve what the token permits.[7] The token is the whole relationship. Understanding what it can and cannot fetch is the substance of this article.
Plaid sells access as separate products, and a funder only receives what it enabled. This is why "what does linking share" has no single answer — it depends on the products in the request. The end-user privacy policy lists the categories Plaid may collect across all of them: account data such as institution and account name, type, ownership, account and routing numbers; transaction data covering amount, date, type and description; and balance data covering current and available balance.[11] The products a working-capital funder is likely to use are these.
Product scope from Plaid’s developer documentation for each product, cited in the prose. The third column is Full Send Funding’s own reading of what a decision on a three-month, $10,000-a-month bar requires.
Transactions is the product underwriting actually runs on. It returns the ledger — each debit and credit with its amount, date and description — for the number of days the requester specified, which defaults to 90 and cannot exceed 730.[1] This is the same information a PDF statement carries, in machine-readable form, without the transcription step.
Balance returns the real-time current and available balance for each account, fetched fresh from the bank at the moment of the call rather than from a cache.[5] For underwriting it is a single point; for a funder that later debits the account, it is a way to check that the money is there before a pull.
Identity returns the account holder's name, and usually email, phone and mailing address, as the bank has them on file; Plaid guarantees the name and says the rest may be null.[4] Its purpose is fraud prevention — confirming that the account belongs to the applicant — not underwriting.
Auth returns the account and routing numbers, so the requester can initiate ACH credits or debits.[3] This is the product to notice. It does not itself move money, but it delivers the numbers that a funder's own bank needs to. Our application asks for a voided business check, and our own link request includes Auth so that the account and routing numbers behind the link can be matched to that check. A link does not have to carry them, and a funder that requests Auth should be able to say why.
Assets produces an asset report — a point-in-time document aggregating balances, account-holder identity and transactions for up to 731 days.[2] It is the product built for lenders who want a fixed snapshot rather than a live feed.
Statements is the one that surprises people: through the same link, a requester can retrieve the bank's own PDF statements exactly as the institution produced them.[6] Linking and uploading are not as different as the two buttons suggest.
The window has two edges, and the second one is the one owners forget.
Backward. The Transactions product reaches back by the number of days the requester wrote into the request — 90 by default, up to 730 — and that setting applies at the moment the link is initialized.[1] A funder that asked for 730 days sees two years of your account. Nothing in the flow tells you the number unless the consent pane states it, so ask.
Forward. Once Transactions is set up on an Item, Plaid keeps checking the institution for new activity, typically one to four times a day depending on the bank, and notifies the requester when there is something new to pull.[15] The access token that permits all of this does not expire on its own; it needs updating only if you change your bank password or, for some European institutions, on a consent clock.[8] So the honest description of a link is a feed with a start date and no end date until someone ends it.
Ending it. The requester can end it by removing the Item, which revokes the token's access to the associated data; it can also rotate a compromised token, which immediately invalidates the old one.[7] You can end it yourself through the Plaid Portal, where you can see which apps are connected to which accounts, what data types each receives, and disconnect any of them.[10] But the portal's own help text is precise about what that does: disconnecting stops future sharing only, and the app may keep what it already collected — to delete that, you contact the app directly.[16]
That last sentence is the one to carry around. The feed can be turned off at any time. The copy already taken cannot be recalled through Plaid; only the funder can delete it.
We ask for the last three to four months of business bank statements, and a link is simply the other way of delivering them. The link request we make enables two Plaid products. The first is Transactions, pulled for 90 days on the accounts you select, with the balances that come back alongside it, because that is what working capital underwriting actually reads: deposit consistency, average daily balance, negative days, and the debits that belong to other funders. The second is Auth, which returns the account and routing numbers so the account behind the link can be matched to the voided check on the application. We do not enable Identity, Assets or Statements. We do not need your bank login and never see it. We do not need two years of history for a decision on a three-month bar, and we do not ask for it.
What the link changes for you is speed and accuracy, not scope. A file with linked statements skips the step where a PDF is downloaded, attached, opened and read, and it removes the class of error where a statement is missing a page or a month. Decision comes within 24 business hours either way; funding follows within 24 hours of approval, and a complete file in before 2pm ET can fund the same day. The link is how the "complete" part happens faster.
The difference in evidence between the two routes is not that one shares more. It is that one shares later. Statements close on a calendar boundary; a link runs to the day you connect. Take a landscaping company in Saratoga County applying on Monday, September 21.
Its three most recent PDF statements cover June 1 through August 31: 92 days. A 90-day link taken on September 21 covers June 24 through September 21 — the last seven days of June, all of July and August, and the first 21 days of September. The two windows overlap by 69 days and differ at both ends.
The company's deposits, by segment, were $27,000 in June 1–23, $11,000 in June 24–30, $41,000 in July, $36,000 in August and $33,000 in September 1–21, the last of which includes a $14,000 municipal contract payment on September 15.
A stated example, not a client. Segment deposits are the inputs: $27,000 (June 1–23), $11,000 (June 24–30), $41,000 (July), $36,000 (August), $33,000 (September 1–21). Each window total is the sum of the segments it contains; per-day is the total divided by the window’s days (92 and 90); the 30-day equivalent is per-day × 30; the sizing range is 80% and 150% of the 30-day equivalent, per the published rule. Dollar figures rounded to the nearest dollar.
Three statements total $115,000 across 92 days, or $1,250 a day, which is $37,500 on a 30-day basis. The link totals $121,000 across 90 days, or $1,344 a day, which is $40,333 on a 30-day basis. Applied to the published sizing range of 80% to 150% of monthly revenue, the PDFs imply $30,000 to $56,250 and the link implies $32,267 to $60,500.
On this account the link window runs $2,833 a month higher than the closed statements because September was a strong partial month; it also contains two negative days the PDFs do not.
Inputs as stated in the worked example: segment deposits of $27,000 (June 1–23), $11,000 (June 24–30), $41,000 (July), $36,000 (August) and $33,000 (September 1–21). PDF window = June 1–August 31 = $115,000 over 92 days; link window = June 24–September 21 = $121,000 over 90 days. 30-day equivalent = window total ÷ days × 30; sizing bounds = 80% and 150% of that figure, rounded to the nearest dollar.
Two observations. The first is that the difference is modest for a business with steady deposits — about 7.6% on the 30-day figure here — and it runs the link's way only because September was a strong partial month. Reverse the September number and the link is the worse window. The second is the part the totals do not show: this account dipped below zero on September 9 and 10 while waiting for the municipal payment. Those two negative days are in the link window and in none of the three PDFs. A link shares more recent evidence in both directions — the strong deposit and the overdraft — and an owner deciding which route to take should know which direction their own last three weeks point.
The scope of a token is fixed by the products enabled and the accounts selected, and Plaid's developer policy adds a layer above the technical one. Plaid states that customers may only access the data types the user consented to, that adding data types or use cases after the initial link requires a separate consent, and that apps cannot retroactively pull unapproved data or reach accounts that were not permissioned at onboarding.[12]
Within that scope, what a funder holding a token can do:
What it cannot do with the token alone:
The important practical consequence is that the debit authority and the data authority live in different documents. Revoking the link at the Plaid Portal does not touch an ACH authorization; that is revoked with the funder and, if necessary, with your bank. Anyone reading the funding agreement clause by clause should find both authorities and know which page each is on.
After a link, the same information sits in three places with three different rules.
At your bank. Nothing changes. The bank's records are the bank's records.
At Plaid. Plaid's end-user privacy policy says its systems are designed to delete your data automatically when the developer removes the connection, subject to exceptions: an active connection with another app, a Plaid service you still use, a legal requirement to keep it, fraud prevention and support, data that has been de-identified, or a longer retention you specifically agreed to.[11] You can also delete your data from Plaid's systems yourself through the portal or a privacy request form.[10]
At the funder. This is the copy the regulation and the portal do not reach. The funder keeps what it collected under its own policy and your agreement. Disconnecting stops new data; deleting the old requires asking the funder.[16] For a funder that has funded you, some of that retention is legitimate and expected — the file behind an active agreement is not going to be deleted mid-term. For a funder that declined you, or that you declined, the question of what happens to the pulled data is a fair one and it should have a written answer.
There is no public dataset on how long working-capital funders retain linked bank data after a declined or abandoned application, and no rule in this space sets a maximum. That absence is itself the finding: retention is a term you have to ask for.
In November 2024 the Consumer Financial Protection Bureau issued the Personal Financial Data Rights rule, implementing section 1033 of the Dodd-Frank Act: a framework under which data providers must make covered data available to consumers and to authorized third parties, in usable electronic form, at the consumer's direction.[17] The obligations it places on authorized third parties are the ones a borrower would want behind a link: limiting collection, use and retention to what is reasonably necessary for the requested product or service; a revocation method as easy as the original authorization, with no cost or penalty for using it; and a contractual flow-down of the same obligations to anyone the third party passes the data to.[18]
Two facts about the rule matter more than its text for a business owner.
Its scope is consumer accounts. The rule covers a "covered consumer financial product or service", defined as a Regulation E account, a Regulation Z credit card, or the facilitation of payments from one.[19] A Regulation E account is a checking, savings or other consumer asset account "established primarily for personal, family, or household purposes".[20] A business operating account is not that. When your LLC links its checking account to a funder, the third-party obligations above are not what applies by force of law; what applies is Plaid's own policy, the funder's own policy, and the agreement you signed.
It is not in force. On October 29, 2025, the rule's compliance dates — which had been staggered from April 1, 2026 to April 1, 2030 by institution size — were stayed by the court in Forcht Bank, N.A. v. CFPB, and the Bureau had already opened a reconsideration in August 2025 with a stated plan to propose extending the dates.[21][22] As of this writing the rule exists on the books, its compliance dates do not, and its future shape is under review.
So the honest statement of the legal position is this: for a business account, there is no federal data-rights rule standing between you and the funder, and even the consumer rule is currently stayed. The practical protections are contractual and reputational. That makes the questions below more important, not less. This is information, not legal advice; the regulation and your funding agreement control, and an attorney in your state should read yours.
Sending statements as PDFs shares the same ledger for the same months. What it does not do is open a standing connection, deliver a real-time balance, or leave a token in anyone's system. It is slower by the time it takes to download and attach three or four files, and it is the route where files arrive incomplete.
The link is the wrong tool, and the PDF is the right one, when:
The link is the right tool when you have chosen your funder, you want the decision and funding timeline to run at its fastest, and the request matches the decision: transactions and balances, on the accounts you choose, for the window the statements would have covered.
These are the questions we would want answered about our own link, and they are the ones to put to anyone else's. Each has a specific answer; a vague one is itself information.
If you want to see how we answer them, the online application takes about ten minutes, needs no fee, uses a soft credit pull only, and takes the statements as attachments; the bank link is offered from the customer portal once your file is open. Or call 518-312-0382 and ask before you link anything.
Linking a bank account through Plaid shares a read-only feed of the accounts you select: transactions in the window the funder set — 90 days by default, up to 730 — plus balances, and the identity and account numbers only if those products were requested. It never shares your password with the funder and cannot move money; debit authority comes from the ACH authorization in the agreement, not from the token. The feed keeps refreshing until the Item is removed, the token does not expire on its own, and disconnecting at the Plaid Portal stops future sharing without recalling what a funder already holds. A business account sits outside the CFPB's Personal Financial Data Rights rule, and that rule is stayed anyway, so the protections are Plaid's policy, the funder's policy and your contract. Three PDF statements share the same ledger to a calendar boundary; a link runs to today, in both directions. Send PDFs while shopping; link with the funder you choose, after asking which products, how many days, which accounts, when the Item is removed, and what is retained.
The description of what a link transmits, how far back it reaches, how often it refreshes, how it is revoked and what happens to the data afterward is stated from Plaid’s own developer documentation, developer policy, end-user privacy policy and consumer help center, each cited where relied on; no claim about Plaid’s behaviour is made beyond what those documents say. The account of Full Send Funding’s own request — the Transactions and Auth products, with transactions pulled for 90 days on the accounts the applicant selects and the account and routing numbers matched to the voided check on the application — is stated from the firm’s deployed link configuration, not assumed. The third column of the product table is the firm’s judgment of what a decision on its published bar requires, and other funders configure their requests differently.
The worked example is a stated case, not a client: five segment deposit figures and an application date are the only inputs, and every number in the ledger table and the figure — window totals, per-day rates, 30-day equivalents and the 80%–150% sizing bounds — is arithmetic on those inputs, recomputed by the site’s arithmetic audit before publication. The legal position is stated from the text of 12 CFR part 1033 and Regulation E’s definition of an account, and the status of the rule from the Bureau’s own notices; no assertion is made about how the rule will be amended. Where no public dataset exists — funder retention periods for linked data on declined applications — the article says so rather than estimating one.
Only what the lender’s request enabled, on the accounts you selected: transactions (amount, date, description) for the requested window, current and available balance, and — if those products are in the request — the account holder’s name and contact details on file and the account and routing numbers. Plaid does not share your bank credentials with the lender.
No. The link is read-only. Plaid’s Auth product can supply account and routing numbers, but a debit is initiated through the funder’s own bank under the ACH authorization in your funding agreement, not through the token. Revoking the link does not revoke that authorization; it is cancelled with the funder and, if needed, your bank.
As far as the requester configured. Plaid’s Transactions product defaults to 90 days and allows up to 730; its Assets product allows up to 731. The number is not shown unless the consent screen states it, so ask. Full Send Funding’s link pulls 90 days of transactions, the shorter end of the three to four months of statements it would otherwise ask for.
Until someone ends it. Plaid keeps checking the bank for new transactions, typically one to four times a day, and the access token does not expire on its own. The funder can remove the Item, and you can disconnect it at the Plaid Portal — which stops future sharing but leaves the funder holding whatever it already pulled.
It is narrower. PDFs share the same ledger for the same months without opening a standing connection or a real-time balance, and they stop at the last statement date. Uploading is the better route while comparing several funders or when the request asks for more than the decision needs. Linking is faster and removes missing-page errors once you have chosen a funder.
Not by its terms. The Personal Financial Data Rights rule covers Regulation E accounts, which are consumer accounts established primarily for personal, family or household purposes, and Regulation Z credit cards. A business operating account is outside it. The rule’s compliance dates were also stayed by a court on October 29, 2025, and the CFPB is reconsidering it.
Only by asking the funder. Plaid’s portal lets you disconnect an app and delete data from Plaid’s own systems, and Plaid deletes data when the developer removes the connection, subject to stated exceptions. The copy the funder already retrieved sits under the funder’s policy and your agreement, so ask for the retention policy in writing before linking.
Travis Yule founded Full Send Funding in 2021 and leads it from Middle Grove, New York. He writes about working capital from the underwriting side of the table — what the numbers actually have to say before a business gets funded.