Privacy Policy

Last updated: 2026-07-12

Fintecy Ltd ("Fintecy", "we", "us") is committed to protecting and respecting your privacy. This policy explains what personal data we collect, why we collect it, how we use and protect it, and the rights you have over it.

This policy applies to our website at https://fintecy.co, the Fintecy application at https://app.fintecy.co, and the associated APIs (collectively, "our service"). It should be read together with our Website Terms, App Terms and Cookie Policy.

Who We Are

For the purposes of the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018, the data controller is:

  • Fintecy Ltd, a company registered in England and Wales under company number 12721337
  • Registered office: 47 Amelia House, 2 Strand Drive, Richmond, England, TW9 4EZ
  • Registered with the Information Commissioner's Office (ICO) as a data controller under registration number ZB474426
  • Data protection contact: privacy@fintecy.co

Information We Collect

We collect only what is needed to provide the service. Specifically:

  • Account data. When you register we collect your email address and, where you sign in with Google, the identity information Google shares (email address and account identifier). We do not operate a password database — authentication is passwordless (OAuth or magic link, optionally with TOTP multi-factor authentication).
  • Financial data you add. Accounts, balances, transactions, holdings, plans, documents and other records you create, import (for example via CSV) or connect. This is the substance of the product — it is stored for you, belongs to you, and is exportable in full at any time.
  • Connected account data. If you connect a bank, broker or other financial institution, we receive the data described in the "Connected Accounts & Open Banking" section below.
  • Waitlist data. If you join the invitation waitlist we collect your email address, processed by Mailjet (our email provider) and used only to contact you about access and product updates.
  • Correspondence. If you contact us we keep a record of that correspondence.
  • Technical data. IP address, browser type and version, and pages visited — collected as server logs by our hosting providers for security and reliability, and, only if you consent, by Google Analytics as described in our Cookie Policy.

We do not request or knowingly collect special category data as defined by UK GDPR Article 9 (such as health, ethnicity, religion, or biometric data). If we become aware of such data in our systems, we will take reasonable steps to erase it.

Connected Accounts & Open Banking

When you choose to connect a financial account, the connection is made through the institution's official API, using read-only keys that you generate with that institution. When you use such a connection:

  • We never ask for, see or store your online banking username or password.
  • We receive, and store in your ledger, the data needed to provide the service: account details (name, type, masked account number), balances, transactions and holdings.
  • Connections are read-only. Fintecy cannot move your money.
  • You can disconnect any linked account at any time in the app. Disconnecting stops all further data collection from that institution; the data already synced remains in your ledger under your control, and you can delete it, or your whole account, whenever you choose.

Automatic bank feeds via open banking are in development and not yet live. When launched, they will use a regulated third-party account information provider (an "aggregator"). Before any bank data flows we will name the provider in this policy, in the Open Banking & Connected Accounts disclosure and in the subprocessor list on our security page, and link to its privacy policy.

How We Use Your Data & Lawful Bases

| Purpose | Lawful basis | | --------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------- | | Providing the service: storing and displaying your financial picture, syncing connected accounts, running projections | Performance of a contract (UK GDPR Art. 6(1)(b)) | | Account security: authentication, MFA, session management, fraud and abuse prevention | Contract and our legitimate interests in keeping the service secure | | Service emails: magic links, security notifications, material changes to terms | Contract and legal obligation | | Invitation waitlist and product updates | Consent — you can unsubscribe at any time via the link in every email | | Website analytics (Google Analytics) | Consent — collected only if you accept analytics cookies | | Responding to enquiries and support requests | Our legitimate interests in operating the service | | Complying with law, regulation or valid legal process | Legal obligation |

We do not sell your personal data, share it with advertisers, or use your financial data to train AI models. AI access to your data exists only as a product feature (the MCP server) under OAuth consent that you grant and can revoke.

Where Your Data Is Stored & Who Processes It

Your data is hosted on Google Cloud Platform; a migration of all data processing to an EU region is in progress. A small number of service providers (subprocessors) process limited data on our behalf — the current list, including what each one processes and where, is published on our security page.

Where data is transferred outside the UK or EEA, we rely on appropriate safeguards under UK GDPR — the UK International Data Transfer Agreement or Addendum, or EU Standard Contractual Clauses — with the relevant provider.

All connections to our service are encrypted in transit (TLS). Data is encrypted at rest, and credentials for connected integrations are additionally encrypted at the application layer. Details of our security controls are published and kept current on the security page.

How Long We Keep Your Data

We keep your data for as long as you hold an account. If you delete your account, we remove your data from our systems within 30 days, except where a longer period is required by law. Waitlist emails are kept until you unsubscribe or the waitlist is closed. Server logs are retained for a short, rolling period for security purposes.

Breach Notification

If a personal data breach occurs, we will notify the ICO within 72 hours of becoming aware of it where the breach is likely to result in a risk to your rights and freedoms, and we will inform affected users without undue delay where the risk is high, as required by UK GDPR Articles 33 and 34.

Your Rights

Under UK GDPR you have the right to:

  • Access your personal data (a Subject Access Request) — and, separately, export your entire ledger yourself from the app at any time, in a machine-readable format;
  • Rectify inaccurate data — every record in the app is directly editable;
  • Erase your data ("right to be forgotten");
  • Restrict or object to processing, including any processing based on legitimate interests;
  • Data portability (UK GDPR Art. 20);
  • Withdraw consent at any time where processing is based on consent — including unsubscribing from emails and changing your cookie choice;
  • Complain to the ICO — you can raise a concern at ico.org.uk/make-a-complaint or by calling 0303 123 1113. We would appreciate the chance to address your concern first: privacy@fintecy.co.

To exercise any of these rights, email privacy@fintecy.co from the email address associated with your account. We will respond within one month, free of charge. We may need to verify your identity before acting on a request.

Cookies

Our website uses one strictly necessary cookie and, only with your consent, Google Analytics cookies. Full details, including how to change your choice at any time, are in our Cookie Policy.

Children

The service is not directed at children and we do not knowingly collect personal data from anyone under 18.

Other Websites

Our site contains links to third-party websites (for example, GitHub or our social profiles). Those sites have their own privacy policies, and we are not responsible for them.

Changes To This Policy

We will post any changes to this policy on this page and update the "Last updated" date. If a change materially affects how we process your personal data, we will notify registered users by email before it takes effect.

Contact

Questions about this policy or your personal data: privacy@fintecy.co, or see our contact page.

Privacy Policy · Fintecy