1. Introduction
[Company Name] ("we," "us," or "our") operates the Stashbeat personal finance management platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
We are committed to protecting your privacy and ensuring the security of your personal data. This policy complies with the General Data Protection Regulation (GDPR) and applicable Hungarian data protection laws.
By using our Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our Service.
2. Information We Collect
2.1 Personal Information
When you register for an account, we collect:
- Email address
- Password (encrypted)
- Display name (optional)
- Profile picture (optional)
- Preferred currency and language settings
2.2 Financial Information
To provide our core services, we collect and process:
- Bank account information (account numbers, balances)
- Transaction data (amounts, dates, merchant names, categories)
- Financial institution identifiers
- Manually entered financial data
2.3 Usage Data
We automatically collect certain information when you access our Service:
- Device type and operating system
- Browser type and version
- IP address
- Pages visited and features used
- Date and time of access
- Referring website
2.4 Device Information
For security purposes (including two-factor authentication), we may collect device fingerprints and trusted device identifiers to recognize your devices and prevent unauthorized access.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Provide and maintain the Service: Including syncing your bank accounts, displaying transactions, and generating financial insights.
- Personalize your experience: Customizing dashboards, reports, and recommendations based on your financial data.
- Improve our Service: Analyzing usage patterns to enhance features and fix issues.
- Communicate with you: Sending service updates, security alerts, and (with your consent) marketing communications.
- Ensure security: Detecting and preventing fraud, unauthorized access, and other malicious activities.
- Legal compliance: Meeting our legal and regulatory obligations.
We process your data based on one or more of the following legal bases under GDPR: performance of a contract, legitimate interests, legal obligation, or your explicit consent.
4. Open Banking and Third-Party Data Providers
4.1 About Open Banking
Stashbeat uses Open Banking technology to securely connect to your bank accounts and retrieve your financial data. This is enabled through regulated third-party providers, including GoCardless (Enable Banking), which operates under the Payment Services Directive 2 (PSD2) framework.
4.2 How Bank Connections Work
When you connect a bank account:
- You are redirected to your bank's secure authentication page
- You authorize Stashbeat (via our Open Banking provider) to access your account data
- We receive read-only access to your account information and transactions
- We never receive, store, or have access to your bank login credentials
- We cannot initiate payments or modify your accounts in any way
4.3 Data Minimization
We only request access to the minimum data necessary to provide our services:
- Account holder name and account identifiers
- Account balances
- Transaction history (typically up to 90 days)
4.4 GoCardless (Enable Banking)
Our Open Banking integration is powered by GoCardless, a regulated Account Information Service Provider (AISP). GoCardless is authorized by the UK Financial Conduct Authority and operates across the European Economic Area under PSD2 regulations.
When you connect your bank through our Service, your data is transmitted securely via GoCardless. Their privacy policy and data handling practices are available at gocardless.com/privacy.
5. Data Sharing and Third Parties
We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:
5.1 Service Providers
We engage trusted third-party companies to perform services on our behalf, including:
- Cloud hosting and infrastructure (Supabase)
- Open Banking connectivity (GoCardless/Enable Banking)
- AI Assistant (OpenAI API)
- Email delivery services
- Analytics providers
These providers are contractually bound to protect your data and may only use it to provide services to us.
5.2 Legal Requirements
We may disclose your information if required by law, court order, or government regulation, or if we believe such action is necessary to:
- Comply with legal obligations
- Protect our rights or property
- Prevent fraud or illegal activity
- Protect the safety of users or the public
5.3 Conformitate GDPR / UE — Asistent AI
Asistentul nostru AI opțional îți permite să pui întrebări despre finanțele tale în limbaj natural. Această secțiune descrie modul în care funcția procesează datele personale conform GDPR și regulilor UE de protecție a datelor.
Asistentul AI folosește API-ul OpenAI pentru a genera răspunsuri. Când trimiți o întrebare, StashBeat transmite o solicitare către OpenAI în numele tău.
Date trimise către OpenAI
Limităm ce este transmis:
- Textul întrebării tale și un scurt istoric al conversației cu asistentul în StashBeat
- Rezultate ale unor instrumente doar în citire rulate pe serverele noastre (de exemplu sumare ale cheltuielilor, defalcare pe categorii, progresul obiectivelor sau starea bugetului) — nu baza ta completă de tranzacții brute sau extrasele bancare
- Cifre financiare agregate sau limitate necesare pentru a răspunde la întrebare; nu exportăm liste complete de tranzacții către OpenAI pentru întrebări generale
Păstrare la OpenAI: în setările implicite ale API-ului OpenAI, datele răspunsului pot fi păstrate până la 30 de zile pentru monitorizarea abuzurilor și siguranță, dacă organizația ta nu are un acord diferit cu OpenAI. StashBeat configurează noile apeluri ale asistentului pentru a minimiza stocarea acolo unde API-ul permite. Detalii: platform.openai.com/docs/guides/your-data.
Poți renunța la Asistentul AI oricând din Profil și securitate, continuând să folosești restul produsului (conexiuni bancare, bugete, obiective, rapoarte și alte funcții).
Poți șterge istoricul conversației AI oricând folosind Șterge istoricul chatului în Asistentul AI. Aceasta elimină definitiv conversația din StashBeat. Unde am stocat identificatori de răspuns OpenAI pentru acea conversație, solicităm ștergerea lor la OpenAI pe cât posibil.
6. Data Security
We implement robust security measures to protect your personal information:
- Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256)
- Access controls: Strict role-based access to systems and data
- Authentication: Secure password hashing and optional two-factor authentication
- Monitoring: Continuous security monitoring and logging
- Regular audits: Periodic security assessments and penetration testing
While we strive to protect your data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to maintaining industry-standard protections.
7. Data Retention
We retain your personal data for as long as necessary to provide our services and fulfill the purposes described in this policy:
- Account data: Retained while your account is active and for 30 days after deletion request
- Transaction data: Retained while your account is active
- Bank connection tokens: Automatically expire per PSD2 requirements (typically 90-180 days) and require re-authorization
- Usage logs: Retained for up to 12 months for security and analytics purposes
- Legal records: Retained as required by applicable law
When you delete your account, we will delete or anonymize your data within 30 days, except where we are required by law to retain certain information.
8. Your Rights Under GDPR
Under the General Data Protection Regulation, you have the following rights regarding your personal data:
- Right of Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can request that we correct inaccurate or incomplete data.
- Right to Erasure: You can request that we delete your personal data ("right to be forgotten").
- Right to Restrict Processing: You can request that we limit how we use your data.
- Right to Data Portability: You can request your data in a structured, machine-readable format.
- Right to Object: You can object to processing based on legitimate interests or for direct marketing.
- Right to Withdraw Consent: Where processing is based on consent, you can withdraw it at any time.
To exercise any of these rights, please contact us at dpo@stashbeat.com. We will respond to your request within 30 days.
You also have the right to lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) or your local supervisory authority.
10. Children's Privacy
Our Service is not intended for individuals under the age of 16 (in accordance with Hungarian law and GDPR). We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a child under 16, please contact us immediately at dpo@stashbeat.com, and we will take steps to delete such information.
11. International Data Transfers
Your data is primarily stored and processed within the European Economic Area (EEA). If we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as:
- European Commission adequacy decisions
- Standard Contractual Clauses (SCCs)
- Binding Corporate Rules where applicable
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by:
- Posting the updated policy on our website
- Updating the "Last updated" date at the top of this policy
- Sending you an email notification for significant changes
We encourage you to review this policy periodically to stay informed about how we protect your data.
13. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact our Data Protection Officer: