Privacy Policy

This Privacy Policy explains how Expensia ("we", "us", "our") collects, uses, discloses, and protects personal information when you use our website, dashboard, mobile experiences, and related services (collectively, the "Services").

1. Information We Collect

  • Account Data: name, WhatsApp phone number, email (if provided), currency, timezone.
  • Authentication Data: access and refresh tokens, CSRF tokens.
  • Usage Data: app interactions, feature usage, device/browser info, approximate location from IP.
  • Transactional Data: subscription plan, payment status, receipts (processed via our payment provider).
  • Support Data: messages, feedback, and related attachments you send to us.

2. How We Use Your Information

  • Provide, operate, and maintain the Services.
  • Authenticate users, maintain sessions, and secure accounts.
  • Process payments and manage subscriptions.
  • Improve and personalize the user experience and features.
  • Detect, prevent, and address technical, fraud, or security issues.
  • Comply with legal obligations and enforce our Terms.
  • Communicate service updates, security notices, and support responses.

3. Legal Bases for Processing

Where applicable, we process personal data based on:

  • Contract necessity (to provide the Services you request).
  • Legitimate interests (e.g., security, product improvement).
  • Consent (e.g., certain marketing or optional features).
  • Compliance with legal obligations.

4. Sharing and Disclosure

We do not sell your personal information. We may share limited data with:

  • Service providers that help deliver our Services (hosting, analytics, payments).
  • Security and fraud-prevention partners.
  • Authorities when required by law or to protect rights, safety, and property.

5. Data Retention

We retain personal information for as long as necessary to provide the Services, comply with our legal obligations, resolve disputes, and enforce agreements. Retention periods vary by data type.

6. Security

We implement administrative, technical, and organizational measures designed to protect information against unauthorized access, loss, misuse, or alteration. No method is 100% secure; we continually improve our safeguards.

7. International Transfers

Your information may be processed and stored in countries other than your own. Where required, we use appropriate safeguards for cross-border data transfers.

8. Your Rights

  • Access, correct, update, or delete your personal information.
  • Object to or restrict certain processing.
  • Withdraw consent where processing is based on consent.
  • Portability of certain data, where applicable.

To exercise rights, contact us using the details below.

9. Cookies and Similar Technologies

We use cookies and similar technologies for authentication, security, preferences, and analytics. You can control cookies through your browser settings.

10. Children’s Privacy

Our Services are not directed to children under the age of 13 (or as defined by local law). We do not knowingly collect personal information from children.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version and revise the effective date. Material changes may be communicated via the Service.

12. Contact Us

If you have questions or requests, please contact our support team.

Effective Date: 2025-01-01