Privacy Policy
Last updated: 11 September 2026
This policy explains what FinTrack collects, why, who it is shared with, and what you can require us to do with it. Abhimanyu Sharma is the data controller. Contact: aksharma223@gmail.com.
The data you put into this Service is financial data about your own life. We treat it as sensitive, and the short version is: we do not sell it, we do not advertise against it, and we do not share it with anyone except the infrastructure providers listed below that are needed to run the Service.
1. What we collect
Account data. Your email address, a securely hashed password, and the dates your account was created and last updated. We never store your password in a readable form.
Financial data you enter. Accounts and their opening balances, transactions (amount, date, category, and any merchant or note you add), transfers, budgets, and any CSV statements you import. This is the substance of the Service and is visible only to you.
Preferences. Display currency, locale and whether you want notification emails.
Operational records. A log of notification emails sent to you, so the same one is not sent twice. Server logs may record IP address, timestamp and error details for security and debugging.
Usage analytics. We use Google Analytics to count visits and see which pages people arrive on. It records the page address, referrer, approximate location derived from IP, and device and browser type. It is never given your name, your email address, or anything about your accounts, transactions or balances.
We do not use advertising trackers and we do not sell or share data for advertising, and we do not connect to your bank or any account aggregation service.
2. Why we use it, and on what legal basis
- To provide the Service — storing and displaying your records, deriving balances and budgets. Basis: performance of our contract with you.
- To authenticate you and keep accounts secure — sign-in, password reset, abuse prevention. Basis: contract, and our legitimate interest in a secure service.
- To send service email — confirmation and password reset. Basis: contract.
- To send notification email — welcome, budget alerts, monthly summaries. Basis: legitimate interest, and you can switch these off at any time in Settings without losing access to anything.
- To comply with law — where we are legally required to retain or disclose information. Basis: legal obligation.
We do not carry out automated decision-making that produces legal or similarly significant effects about you. Budget alerts are arithmetic thresholds, not profiling.
3. Who processes it
We use a small number of processors, each bound by contract to handle data only on our instructions:
- Supabase — database, authentication and storage. Holds your account and financial records.
- Resend — email delivery. Receives your email address and the content of messages sent to you, which may include summary figures such as monthly totals and category names.
- Our hosting provider — serves the application and processes requests in transit.
- Google Analytics — usage measurement. Receives page addresses, referrer, device and browser details, and an IP-derived approximate location. It receives no account data and nothing that identifies you by name.
These providers may process data outside your country. Where that involves a transfer out of a region with transfer restrictions, it is made under an approved mechanism such as Standard Contractual Clauses.
We do not sell personal data, and we do not share it for advertising. We will disclose data to authorities only where legally compelled, and will tell you unless prohibited from doing so.
4. Who can see your financial records
Access is enforced by the database itself, not only by the application. Every table carries row-level security tied to your user id, so one user’s query cannot return another user’s rows.
Administrators of this application cannot read your transactions. The admin interface is restricted to aggregate information — the number of accounts and transactions on an account, a net worth total, dates of activity, your email and currency. It exposes no individual transaction, merchant or note, and administrators hold no database permission that would let them read one. Administrative actions affecting an account (suspension, deletion, role changes) are recorded in an audit log.
Staff at our infrastructure providers may technically be able to access stored data in the course of operating their platforms; they are contractually restricted from doing so except as necessary.
5. How long we keep it
Your data is kept for as long as your account exists. If you delete your account, your profile, accounts, transactions, categories and budgets are deleted along with it.
Backups and server logs may persist for up to 90 days before being overwritten. Audit records of administrative actions, and minimal records we are legally required to keep, are retained after deletion; these do not contain your financial records.
6. Your rights
Depending on where you live — including under the GDPR in the EU/UK and the Digital Personal Data Protection Act in India — you have the right to:
- Access the personal data we hold about you, and receive a copy;
- Correct data that is inaccurate or incomplete;
- Delete your account and data;
- Export your data in a portable format (CSV export is built into the app);
- Object to or restrict processing based on legitimate interests;
- Withdraw consent for notification emails, at any time, in Settings;
- Complain to your data protection authority.
Write to aksharma223@gmail.com. We will respond within the period your law requires, and within 30 days in any case.
7. Security, honestly stated
We use transport encryption, hashed passwords, database-level row isolation, a strict content security policy, and scoped credentials. Administrative endpoints require both an application check and a database permission check.
No system is perfectly secure. We cannot guarantee that your data will never be accessed without authorisation. Use a strong, unique password, and tell us at aksharma223@gmail.com if you suspect a problem. If a breach occurs that is likely to pose a risk to you, we will notify you and the relevant authority as required by law.
8. Children
The Service is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.
9. Cookies
We set the cookies needed to keep you signed in and to protect against cross-site request forgery. Google Analytics sets its own cookies to tell one visit from the next; they carry a random identifier, not anything about you or your money.
There are no advertising cookies. Where consent is required — the EEA, the UK and Switzerland — analytics is switched off until you accept it, and nothing is stored or measured before you answer. You can at any time; declining changes nothing about how the application works. Any browser setting or extension that blocks Google Analytics stops it as well.
10. Changes
We may update this policy. The date at the top will change, and we will notify you of material changes by email or in the application. See also our Terms of Service and Disclaimer.