Privacy Policy

Effective Date: January 1, 2025
Last Updated: November 15, 2025
Version: 2.1

πŸ“‹ Table of Contents

  1. Introduction
  2. Information We Collect
  3. How We Use Your Information
  4. Cookies and Tracking Technologies
  5. Information Sharing and Disclosure
  6. Data Security
  7. Your Rights and Choices
  8. Third-Party Services
  9. International Data Transfers
  10. Children's Privacy
  11. Data Retention
  12. Changes to This Policy
  13. Contact Us

1. Introduction

XPlus Finance ("we", "our", or "the Company") is committed to protecting your privacy and ensuring the security of your personal and financial information. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our financial management platform.

πŸ“Œ This policy applies to:
β€’ Web Application (Next.js)
β€’ Mobile Applications (iOS and Android)
β€’ API Services (FastAPI)
β€’ AI Financial Assistant (OpenAI)
β€’ Banking Integrations (Plaid)
β€’ Payment Processing (Stripe)
βœ… Regulatory Compliance:
GDPR CCPA/CPRA LGPD GLBA PCI DSS

2. Information We Collect

2.1 Personal Information

Account Data

Financial Information

2.2 Usage Information

2.3 Sensitive Information

⚠️ Legal Basis: Explicit Consent (GDPR Art. 9)

β€’ Biometric Data: Fingerprints, facial recognition (stored ONLY on your device, NEVER on our servers)
β€’ Wellness Data: Wellness journal, mood tracking
β€’ AI Conversations: Chat history with financial assistant

3. How We Use Your Information

3.1 Core Financial Services

Legal Basis: Contract Performance (GDPR Art. 6.1.b)

3.2 AI-Powered Features

Legal Basis: Legitimate Interest (GDPR Art. 6.1.f) and consent

3.3 Security and Fraud Prevention

Legal Basis: Legitimate interest and legal compliance

4. Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience. For complete details, see our Cookie Policy.

Cookie Summary

Type Purpose Consent
Strictly Necessary Authentication, security, basic functionality ❌ Not required
Functional/Preferences Language, currency, theme, settings βœ… Required
Analytics Usage metrics, performance (own system) βœ… Required
Marketing Not currently implemented N/A

5. Information Sharing and Disclosure

🚫 WE DO NOT SELL, RENT, OR TRADE YOUR PERSONAL INFORMATION.

5.1 Service Providers

Provider Service Data Shared Safeguards
AWS Cloud hosting All data SCCs, EU region
Plaid Bank connection Credentials (temporary) SOC 2, SCCs
Stripe Payment processing Payment data PCI DSS Level 1
OpenAI AI assistant AI queries (anonymized) DPA, anonymization
Mailgun Transactional emails Email, name Encryption in transit
Twilio SMS/2FA Phone number SOC 2
Sentry Error monitoring Technical logs PII removal

6. Data Security

We implement robust enterprise-level security measures:

Technical Measures

Administrative Measures

Monitoring

7. Your Rights and Choices

Rights under GDPR (EU/EEA Users)

Rights under CCPA (California Users)

How to Exercise Your Rights

In the App: Settings β†’ Privacy β†’ Data Rights

By Email: [email protected] | [email protected]

Response Time: 30 days (standard requests), 72 hours (urgent)

8. Third-Party Services

For complete functionality, we integrate third-party services. Each has their own terms and policies:

9. International Data Transfers

Primary Storage: EU data centers (Frankfurt, Ireland)

Transfers outside EEA: Protected with Standard Contractual Clauses (SCCs)

All transfers comply with GDPR Chapter V and international data protection standards.

10. Children's Privacy

⚠️ Age Restriction: 18+

β€’ We do NOT collect information from persons under 18
β€’ We do NOT allow accounts for persons under 18
β€’ We comply with COPPA (under 13 - USA)
β€’ If we discover data from a minor: immediate deletion and notification to parents/guardians

11. Data Retention

Data Category Retention Period Reason
Account Data While account is active + 7 years Legal/tax requirements
Transaction Data 7 years from transaction Regulatory compliance (IRS, SEC)
Analytics Data 2 years, then anonymized Service improvement
Audit Logs 5 years GDPR Art. 5.2 (Accountability)
Cookie Data 1 year from last update Consent management

Grace Period: 30 days to recover deleted account. Permanent deletion after 90 days (except legally retained data).

12. Changes to This Policy

Minor Changes: Date update, in-app notification

Material Changes: Email with 30 days advance notice, push notification, renewed consent request if required

Version History:

13. Contact Us

General Email: [email protected]

Data Protection Officer (DPO): [email protected]

Website: https://xplusfinance.org

Data Protection Authorities

πŸ“„ Related Documents:
β€’ Terms of Service
β€’ Cookie Policy