Privacy Policy

Last updated: June 27, 2026
Effective: June 27, 2026

Plain-English summary

We process bank statements and the transactions inside them so you can see, search, and export your own financial data. You own your data. We don't sell it, we don't train models on it, and we don't share it with anyone you haven't authorized.

We hold your data only as long as you keep your account active (plus a short period after deletion for backups and legal reasons). You can export or delete it at any time. If you're in India, the EU/UK, or California, you have additional rights described below.

This summary is not the legal version — it's a guide. The full sections below are the authoritative text.

1. Who we are

This Privacy Policy describes how [COMPANY NAME, INC.], a company incorporated in [STATE OF INCORPORATION], United States, with its registered address at [REGISTERED ADDRESS] (“FinOpsBricks,” “we,” “us,” or “our”), collects, uses, and shares personal data through the website statements.finopsbricks.com and related services (the “Service”).

We are the “data controller” (GDPR), “data fiduciary” (DPDP), or “business” (CCPA) for personal data we process about you, except where we act as a processor on behalf of your organization (e.g., when your employer has a paid account and you are an end user).

2. Data we collect

2.1 Account data

When you create an account, we collect:

  • Name and email address (from you, or from your Google account if you sign in with Google)
  • Organization name and members you invite
  • Authentication tokens and session data
  • Billing contact information for paid accounts

2.2 Financial data you upload

The core purpose of the Service is to process bank statements. When you upload a statement (CSV, PDF, XLSX, or similar), we extract and store:

  • Account metadata: bank name, account number or partial identifier, account holder name, statement period
  • Transactions: date, description/particulars, inflow amount, outflow amount, running balance, reference numbers
  • Source files: the original uploaded statement files
  • Derived data: categorizations, tags, notes, rules you create, and fingerprints used to detect duplicate transactions

We do not ask for or store online banking credentials, card numbers, CVVs, OTPs, or net-banking PINs. We work only with statements you yourself upload or authorize us to fetch.

2.3 Usage and device data

  • IP address, browser, operating system, and device identifiers
  • Pages viewed, features used, time spent, and error logs
  • Referrer URLs and approximate location derived from IP (city-level)

2.4 Communications

If you contact support or fill out a form, we keep a record of that correspondence, including the email address you provide and any attachments.

3. How we use your data

  • Provide the Service: parse statements, store transactions, run rules, render dashboards, and export data on your instruction.
  • Account and billing: authenticate you, manage organization membership, charge credits, and send receipts.
  • Improve the Service: monitor performance, debug errors, and improve parser coverage. We use aggregated and de-identified data for this — never your individual transactions to train models or for any other purpose.
  • Communicate with you: send transactional emails (account, billing, security), and — only if you've opted in — product updates.
  • Security and fraud prevention: detect abuse, enforce limits, and protect the Service.
  • Comply with law: respond to legal requests and meet regulatory obligations.

We do not: sell your data, share it with advertisers, use it to train third-party machine-learning models, or use it for any purpose unrelated to providing the Service to you.

5. How we share data

We share personal data only with:

  • Subprocessors we use to run the Service (see section 6).
  • Other members of your organization — anyone invited to your org account can see the data in that org, by design.
  • Authorities, when required by valid legal process. We will, where lawful, notify you first.
  • Acquirers, in the event of a merger, acquisition, or sale of assets — under confidentiality and continuity-of-protection commitments.

We never sell or rent personal data, and we do not share it with advertisers.

6. Subprocessors

We rely on a small number of vendors to operate the Service:

  • Hosting & infrastructure: AWS / cloud providers (United States and India regions)
  • Database: managed PostgreSQL on the same cloud provider
  • Email delivery: transactional email provider for receipts, password resets, etc.
  • Error monitoring: Sentry (for crash reports and error context — we scrub financial values where feasible)
  • Analytics: privacy-preserving product analytics (no third-party advertising trackers)
  • Payments: card and UPI processing via Stripe / Razorpay or equivalent
  • Authentication: Google OAuth (only if you choose Google sign-in)

A current, named list of subprocessors is available on request from [[email protected]]. Customers can subscribe to be notified before we add a new subprocessor that processes their data.

7. Where data is stored & cross-border transfers

Personal data is stored on cloud infrastructure in the United States and/or India depending on your account region. Because we are a US company, data may be transferred to, accessed from, or processed in the United States.

For users in the European Economic Area, United Kingdom, or India, this means your data may leave your home jurisdiction. We rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission for EU/UK transfers, plus supplementary measures (encryption in transit and at rest).
  • Contractual safeguards with subprocessors that bind them to comparable protections.
  • Your explicit consent obtained at sign-up, where DPDP or local law requires it.

8. How long we keep data

  • Account data: while your account is active, plus up to 90 days after deletion for backups and account-recovery windows.
  • Statements and transactions: until you delete them, or until your account is deleted plus the same 90-day window. You can delete individual statements at any time.
  • Billing records: up to 7 years, where required by tax/accounting law in the United States.
  • Support correspondence: up to 3 years.
  • Server and security logs: typically 30–90 days.

9. Security

We take engineering and operational measures to protect your data, including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Strict authentication and least-privilege access for our team
  • Multi-tenant data isolation enforced at the database query layer
  • Regular dependency patching and security review of code changes
  • Activity logs of administrative actions

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant authorities as required by law (e.g., within 72 hours for GDPR, and to the Data Protection Board of India for DPDP).

10. Your rights (global)

Regardless of where you live, you can:

  • Access the data we hold about you (most of it is visible in the app; for the rest, email us).
  • Correct inaccurate data — either yourself in the app or by writing to us.
  • Delete your account and the data inside it.
  • Export your transactions and statements in standard formats.
  • Withdraw consent at any time — note that this may limit what we can do for you.

To exercise these rights, write to [[email protected]]. We will respond within 30 days (or sooner where the law requires).

11. India — Digital Personal Data Protection Act, 2023

If you are in India, this section applies to you in addition to the rest of this policy. For the purposes of the DPDP Act, 2023, we are a Data Fiduciary and you are a Data Principal.

11.1 Purposes and categories

We process your personal data for the purposes listed in section 3 above. We process the categories of data listed in section 2.

11.2 Consent and withdrawal

We obtain your consent at sign-up and at points where we collect new categories of data. You can withdraw your consent at any time by emailing [[email protected]] or deleting your account. Withdrawing consent does not affect the lawfulness of processing before the withdrawal.

11.3 Your rights as a Data Principal

You have the right to:

  • Obtain a summary of the personal data we process about you and the processing activities
  • Obtain the identities of all Data Fiduciaries and Data Processors with whom we have shared your data
  • Correct, complete, update, or erase your personal data
  • Nominate another person to exercise these rights on your behalf in the event of your death or incapacity
  • Grievance redressal (section 11.5 below)

11.4 Cross-border transfer

Because we are a US company, your personal data will be transferred outside India to the United States and may be processed there. By signing up, you consent to this transfer. We maintain contractual safeguards with our subprocessors as described in section 7.

11.5 Grievance Officer

In accordance with Section 8(9) of the DPDP Act, 2023, our Grievance Officer is:

Name: [GRIEVANCE OFFICER NAME]
Address: [REGISTERED ADDRESS]
We aim to respond to grievances within 7 days and to resolve them within 30 days.

If you are not satisfied with our response, you may approach the Data Protection Board of India established under the DPDP Act.

12. EU / UK — GDPR and UK GDPR

If you are in the European Economic Area, the United Kingdom, or Switzerland, this section applies to you in addition to the rest of this policy.

12.1 Controller

[COMPANY NAME, INC.] is the data controller for personal data processed through the Service, except where we act as a processor on behalf of your organization.

12.2 Your rights

You have the right to:

  • Access your personal data and obtain a copy
  • Rectify inaccurate or incomplete data
  • Erase your personal data (“right to be forgotten”)
  • Restrict processing
  • Data portability — receive your data in a structured, machine-readable format
  • Object to processing based on legitimate interests
  • Withdraw consent at any time (without affecting prior lawful processing)
  • Lodge a complaint with your local supervisory authority
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects

We do not engage in automated decision-making with legal or similarly significant effects on you.

12.3 International transfers

For transfers of personal data from the EEA, UK, or Switzerland to the United States or India, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with technical and organizational safeguards including encryption.

12.4 Contact and complaints

For GDPR matters, write to [[email protected]]. You can also complain to your local data protection authority. A list is available at edpb.europa.eu.

13. California — CCPA / CPRA

If you are a California resident, this section applies to you in addition to the rest of this policy.

13.1 Categories of personal information

In the past 12 months, we have collected the following categories of personal information about California consumers:

  • Identifiers: name, email, IP address, account ID
  • Commercial information: subscription/credit balance, billing history
  • Internet/network activity: pages visited, features used, device/browser info
  • Geolocation: approximate (city-level) location from IP
  • Financial information you upload: bank statement and transaction data
  • Inferences: only those needed to operate the Service (e.g., duplicate detection)

13.2 Sources, purposes, and disclosure

We collect personal information directly from you, from your device when you use the Service, and from third parties only when you authorize them (e.g., Google for sign-in). We use it for the purposes in section 3. We disclose it to the subprocessors named in section 6.

13.3 "Sale" and "sharing" of personal information

We do not sell personal information for money, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA.

13.4 Your California rights

  • Right to know what personal information we collect, use, and disclose
  • Right to delete personal information we hold about you
  • Right to correct inaccurate personal information
  • Right to opt out of sale or sharing (we don't do either, but the right exists)
  • Right to limit use of sensitive personal information
  • Right to non-discrimination for exercising any of the above

To exercise these rights, write to [[email protected]]. We may need to verify your identity before fulfilling the request.

14. Cookies & tracking

We use a small set of cookies and similar technologies:

  • Strictly necessary: session and authentication cookies (you can't opt out — the Service won't work without them).
  • Functional: preferences like theme, currency, and last-used filters.
  • Analytics: privacy-preserving product analytics to understand which features get used. No third-party advertising cookies.

You can clear or block cookies from your browser at any time.

15. Children

The Service is not intended for individuals under 18. We do not knowingly collect data from children. If you believe a child has provided us personal data, contact us and we will delete it.

16. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the “Last updated” date at the top and, where required by law, notify you by email or in-app notice before the change takes effect. Your continued use of the Service after the effective date constitutes acceptance.

17. Contact us

For any privacy question, request, or grievance, write to:

Postal: [COMPANY NAME, INC.], [REGISTERED ADDRESS]

See our Terms of Service for the contract governing your use of the Service.