← Home

Privacy Policy

Last updated: [Effective Date] · Version 1.1

Draft — pending legal review. This is a working template. Highlighted fields must be completed and the whole document reviewed by a lawyer before launch.

This policy explains how Finachiva (“we”, “us”), operated by [Company Legal Name], handles your personal data when you use our portfolio-tracking service. It is intended to align with India's Digital Personal Data Protection Act, 2023.

1. Data we collect

  • Account data — your email address (sign-in), and optionally your name and mobile number.
  • Portfolio data you enter — investments, transactions, fixed deposits, loans, and goals. This is your data; we process it only to run the service for you.
  • Payment data — handled entirely by our payment processor (Razorpay). We do not store your card, UPI, or bank details; we keep only a record that a payment succeeded.
  • Security & technical data — sign-in and two-factor events, and standard logs, used to secure your account.
  • Usage measurement — first-party, in our own database, with no analytics company involved:
    • On public pages (home, sign-in, sign-up): a count per day of the page and how you arrived — from a search engine, YouTube, another website, a campaign link, or directly (or “other” when we cannot tell). No cookie, no identifier and no IP address is stored, and we cannot tell one visitor from another; these counts are not personal data.
    • When you are signed in: the calendar days on which you used Finachiva — a date per day and nothing else (no pages, no actions, no amounts). Used only to understand whether people return, and recorded only if you accepted this version (1.1) or a later version of this policy.
    Your IP address and browser identity are processed transiently to deliver each request; for this measurement we do not use them to build any identifier and store neither. Our hosting and network providers keep their own standard request logs (see Who we share it with).
  • Cookies — essential session cookies to keep you signed in. We do not use advertising or tracking cookies.

2. How we use it

To provide and secure the service: authenticate you, compute your portfolio's value and projections, process subscriptions, prevent abuse, and provide support. We do not use your portfolio data for advertising.

We also measure how Finachiva is used (see Data we collect) for one purpose: to see which pages and channels bring people to Finachiva, whether new users reach a working portfolio, and whether they return, so we can improve onboarding and decide where to spend effort. This measurement is never used for advertising, never combined with the contents of your portfolio (amounts, holdings, names), and never shared with an analytics company.

4. Who we share it with

We never sell your data. We share it only with the service providers needed to run Finachiva, under contract:

  • Supabase — database, authentication, and hosting (region: [ap-south-1 / Mumbai]).
  • Razorpay — payment processing.
  • Supabase Auth — transactional emails (sign-in links, password resets).
  • Vercel — application hosting, which keeps standard request logs for security.
  • Cloudflare — network security and DNS, which keeps standard request logs for security.

We use no third-party analytics provider; usage measurement (see Data we collect) stays in our own database.

Market prices are sourced from public, third-party end-of-day market data and are not personal to you.

5. Storage, security & retention

Data is encrypted in transit. Each user's data is isolated at the database level (row-level security), and accounts can be protected with two-factor authentication (required on paid plans). We retain your data while your account is active.

When you delete your account (Account → Your data → Delete account):

  • Deleted immediately & permanently — your portfolio data (investments, transactions, fixed deposits, loans, goals, manual valuations), your profile, and your subscription and credit records.
  • Retained, de-identified — payment and order records, which we are required to keep for tax and accounting. These are retained without your account link (they can no longer be traced back to you through the app).
  • Retained, de-identified — security and sign-in logs, kept in de-identified form for up to [12 months] to protect the service and investigate abuse, then deleted.

Usage measurement — the public-page counts contain no personal data and are kept for about 400 days (the prune runs weekly). Your usage days are deleted with your account, and in any case after about 400 days.

Where the law requires a longer retention period for specific records, we keep only those records for the required period.

6. Your rights

Subject to applicable law, you can:

  • Access and correct your personal data (edit it in your account, or ask us).
  • Export all your data (Account → Your data → Export, as JSON, including your usage days; portfolio history is also available as CSV).
  • Delete your account and all associated data at any time (Account → Your data → Delete account).
  • Raise a grievance with our Grievance Officer (see Grievance Officer).
  • Nominate another person to exercise your rights, as provided under the DPDP Act.

To exercise these, email privacy@finachiva.com.

7. Children

Finachiva is not intended for anyone under 18, and we do not knowingly collect their data.

8. Grievance Officer

Name: [Grievance Officer Name] · Email: grievance@finachiva.com · Address: [Registered Business Address].

If your grievance is not resolved to your satisfaction, you may escalate it to the Data Protection Board of India, as provided under the DPDP Act.

9. Changes

We may update this policy; we'll post the new date here and, for material changes, notify you.

10. Contact

privacy@finachiva.com · [Company Legal Name], [Registered Address].