1. Who is responsible for your data
ELI EISENBACH, Canada, operator of Smart Money (https://smartmoney-app.com and smartmoney-app.base44.app), is the organisation accountable for the personal information described here. Under CCPA/CPRA we are the "business"; under GDPR we would be the "controller".
Privacy Officer — the person accountable for our compliance under PIPEDA s.4.1 and Quebec Law 25 s.3.1 — can be reached at eliezereisenbach@gmail.com.
Postal address: [to be completed before launch].
2. What we collect
Account information — name, email address, profile picture and language, received from your Google sign-in or entered by you. Optionally a phone number if you use the SMS/WhatsApp bot.
Financial information you enter — transactions, amounts, merchants, categories, notes, budgets, goals, debts, assets, liabilities, investments, invoices and receipt images.
Financial information from your bank, if you connect one — account name, type, masked account number, balances and transaction history, retrieved through Plaid or Salt Edge. We never receive your banking username or password.
Subscription information — plan, status, renewal date and the payment-processor reference. Card numbers are handled by the payment processor and never reach our systems.
Technical and usage information — device and browser type, approximate region derived from IP address, pages viewed, features used, error reports, and the timestamps of your visits.
Support and communications — messages you send us, support tickets, and the delivery status of emails we send you.
- Sensitive personal information under CPRA: the contents and history of your financial accounts. We use it only to provide the service you asked for. We do not use or disclose it to infer characteristics about you, which means the CPRA "limit the use of my sensitive personal information" right has nothing further to limit.
We do not collect Social Insurance Numbers, Social Security Numbers, government identity documents, biometric identifiers, precise geolocation, or health information. Please do not put them in a free-text note.
3. Why we use it, and on what legal basis
To provide the service — showing your balances, budgets, forecasts, reports and reminders. Basis: performance of our contract with you, and your consent under PIPEDA and Law 25 for the specific purpose of personal financial management.
To generate insights, categorisation suggestions and forecasts, including with AI models. Basis: contract and consent. This processing does not produce a legal or similarly significant decision about you — nothing here approves or refuses credit, insurance or employment.
To operate paid subscriptions and comply with tax and accounting obligations. Basis: contract and legal obligation.
To keep the service secure, prevent abuse and investigate incidents. Basis: our legitimate interest in a secure service, which is also permitted under PIPEDA s.7.
To send service messages you asked for — budget alerts, scheduled reports, reminders. Basis: consent, withdrawable per channel in Settings.
To send occasional product news. Basis: consent (CASL express consent; CAN-SPAM). Every such message has a one-click unsubscribe.
To improve the product using aggregated, de-identified statistics that cannot be linked back to you.
We do not sell your personal information. We do not share it for cross-context behavioural advertising. We have not done either in the preceding 12 months. There is therefore no "Do Not Sell or Share My Personal Information" transaction to opt out of — but you can still switch off all optional analytics from the cookie settings on any page.
We do not use your financial data to train third-party AI models, and our AI providers are contractually barred from training on it.
5. Where your data is stored and cross-border transfers
Smart Money is hosted on infrastructure located in the United States. If you are in Canada, your personal information is therefore stored and processed outside Canada, and while it is there it is subject to the laws of that country — including lawful access by United States courts, law enforcement and national security authorities.
PIPEDA and Quebec Law 25 permit this provided we remain accountable for the information and use contractual safeguards. Before transferring, we assess each provider under Law 25 s.17: what the data is, how sensitive it is, the purpose, the protections in place, and the legal framework of the destination. Those assessments are recorded and available to the Privacy Officer.
For any user in the EU or UK, transfers rely on the European Commission's Standard Contractual Clauses, held by our processors.
If you would prefer your information not to leave Canada, we cannot offer that today, and you should not use the service.
6. How long we keep it
- Financial records and account data — for as long as your account is open, and deleted when you delete your account.
- Bank connection tokens — until you disconnect the institution or delete your account, then revoked with the provider.
- Backups — encrypted, rolling 30-day window. Deleted records disappear from backups within 30 days of deletion.
- Billing and tax records — 7 years, as required by the Income Tax Act (Canada) and IRS rules. This is the one category we keep after account deletion, and it holds no transaction-level financial detail.
- Support tickets and email delivery logs — 24 months.
- Security and audit logs — 12 months.
- Aggregated de-identified statistics — indefinitely, because they are no longer personal information.
An account that has been inactive for 24 months is flagged for deletion; we email you 30 days before anything is removed.
7. Your rights
Wherever you live, you can do the following — most of them yourself, immediately, from Settings › Privacy:
- Know and access — see what we hold about you and get a copy.
- Portability — download everything in machine-readable JSON or CSV. (Law 25 s.27, CPRA §1798.130, and the state privacy laws all require this; the in-app export satisfies it.)
- Correction — fix anything inaccurate, directly in the app.
- Deletion / erasure — delete your account and all associated records.
- Withdraw consent — turn off notifications, disconnect a bank, or switch off optional analytics at any time.
- Complain — to us first, and then to a regulator.
Canada — you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca, 1-800-282-1376). Quebec residents may complain to the Commission d'accès à l'information (cai.gouv.qc.ca) and additionally have the right to de-indexing (cessation of dissemination) and the right not to be subject to a decision based exclusively on automated processing. We make no such decisions; if we ever did, you would be told and could ask a human to review it.
California — under CCPA/CPRA you have the rights to know, delete, correct, opt out of sale/sharing (we do neither), limit sensitive-information use, and to non-discrimination for exercising any of them. We do not offer financial incentives for personal information. You may use an authorised agent; we will verify their authority.
Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and other states with comprehensive privacy laws — the same access, correction, deletion, portability and opt-out rights apply, plus a right to appeal a refused request. To appeal, reply to our decision email and we will respond within 45 days with a written explanation and, where applicable, the address of your state Attorney General.
Nevada residents may direct us not to sell covered information; we do not sell it.
How to exercise a right that is not self-serve: email eliezereisenbach@gmail.com from the address on your account. We respond within 30 days (PIPEDA and Law 25) or 45 days (US state laws), extendable once where the law allows, and we will tell you if we need an extension. There is no charge unless a request is manifestly unfounded or excessive.
Global Privacy Control: our site honours the GPC browser signal automatically as an opt-out of all optional processing.
8. How we protect it
- All traffic is encrypted in transit with TLS 1.2 or higher; the site is HTTPS-only with HSTS.
- Data is encrypted at rest by our hosting provider.
- Optional end-to-end encryption: you can add a personal password that encrypts your financial records so that even we cannot read them.
- Every database query is scoped to the signed-in account. No role — including administrator — can read another user's financial records.
- Access to production systems is limited to those who need it, protected by multi-factor authentication, and logged.
- Sign-in is delegated to Google OAuth; we never hold your Google password.
- Bank credentials never touch our systems; connections are token-based and revocable.
No system is perfectly secure. If a breach creates a real risk of significant harm, we will notify affected users and the Office of the Privacy Commissioner of Canada without unreasonable delay, notify under Quebec Law 25 where it applies, and meet the notification deadlines of every US state whose residents are affected. We keep a breach register as PIPEDA requires.
9. Children
Smart Money is for adults. We do not knowingly collect personal information from anyone under 13 (COPPA), and we do not knowingly collect information from a minor under 16 for sale or sharing — activities we do not engage in at all.
If you believe a child has given us information, write to eliezereisenbach@gmail.com and we will delete the account and its data promptly. Quebec Law 25 treats a minor's information as sensitive by default, and we apply that standard.
11. Changes to this policy
If we change this policy in a way that materially affects you, we will email you and show a notice in the application at least 30 days before it takes effect. Previous versions are available on request. The date at the top is always the current effective date.
Questions, requests or complaints: eliezereisenbach@gmail.com. Nous répondons également en français.