Privacy Policy
Last updated: January 15, 2025
Together Budget ("we," "our," or "us") is committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other relevant privacy regulations.
1. Information We Collect
1.1 Personal Information
- Account Information: Name, email address, password (encrypted), phone number
- Authentication Data: Google OAuth credentials (Firebase UID, provider information)
- Profile Information: User preferences, role assignments, account status
- Communication Data: Email communications, support requests
1.2 Financial Data
- Account Information: Bank account details, account names, account numbers, balances, currencies
- Transaction Data: Transaction amounts, dates, descriptions, categories, merchant information, receipt images
- Budget Information: Budget categories, amounts, spending limits, budget periods
- Goal Data: Financial goals, target amounts, contribution amounts, target dates
- Category Data: Custom expense/income categories, spending patterns
- Family Data: Family group information, member relationships, shared financial data
1.3 SMS and Communication Data
- SMS Content: Bank SMS notifications for automatic transaction parsing
- SMS Templates: Custom parsing rules and patterns for different banks
- Receipt Images: Photos of receipts uploaded for transaction documentation
1.4 Usage and Analytics Data
- App Usage: Feature usage patterns, screen views, user interactions
- Performance Data: App crashes, error logs, performance metrics
- Device Information: Device type, operating system, app version, unique device identifiers
- Location Data: General location information (if permitted by user)
- Advertising ID: Mobile advertising identifier for analytics purposes
1.5 Subscription and Payment Data
- Subscription Information: Subscription plans, payment status, billing periods
- Payment Processing: Payment method information (processed by third-party providers)
2. How We Use Your Information
2.1 Service Provision
- Provide and maintain our budgeting and financial management services
- Process and categorize your financial transactions
- Generate reports, analytics, and insights about your spending
- Enable family sharing and collaborative budgeting features
- Automatically parse SMS notifications to create transactions
- Provide customer support and respond to inquiries
2.2 Authentication and Security
- Verify your identity and authenticate your account
- Secure your account with Google OAuth integration
- Monitor for fraudulent activity and security threats
- Maintain audit logs for administrative actions
2.3 Analytics and Improvement
- Analyze app usage patterns to improve user experience
- Track feature adoption and user engagement
- Monitor app performance and identify technical issues
- Develop new features based on user behavior insights
2.4 Communication
- Send important service updates and notifications
- Provide customer support and respond to inquiries
- Send marketing communications (with your consent)
- Notify you about security issues or account changes
3. Legal Basis for Processing (GDPR)
- Contract Performance: Processing necessary to provide our services
- Legitimate Interests: Analytics, fraud prevention, service improvement
- Consent: Marketing communications, optional features, cookies
- Legal Obligation: Compliance with applicable laws and regulations
4. Third-Party Integrations
4.1 Google Services
- Google OAuth: For secure authentication and account creation
- Google Analytics: For usage analytics and app performance monitoring
- Firebase: For authentication, analytics, and crash reporting
- Google Play Services: For Android app functionality and updates
4.2 Other Third-Party Services
- Payment Processors: For subscription billing (data processed according to their privacy policies)
- Email Services: For sending notifications and communications
- Cloud Storage: For secure data storage and backup
5. Data Sharing and Disclosure
5.1 Within Your Family Group
- Financial data is shared among family members in your family group
- Transaction details, budgets, and goals are visible to all family members
- You can control family member permissions and access levels
5.2 Service Providers
- Third-party service providers who assist in app operations
- Cloud hosting providers for data storage and processing
- Analytics providers for usage insights and app improvement
- Payment processors for subscription management
5.3 Legal Requirements
- When required by law or legal process
- To protect our rights, property, or safety
- To prevent fraud or abuse
- In connection with a business transfer or acquisition
6. Data Security
- Encryption: All sensitive data is encrypted in transit and at rest
- Access Controls: Strict access controls and authentication requirements
- Regular Audits: Regular security audits and vulnerability assessments
- Data Minimization: We only collect and retain necessary data
- Secure Infrastructure: Hosted on secure, compliant cloud infrastructure
7. Your Rights and Choices
7.1 Data Access and Control
- Access: Request access to your personal data
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your account and data
- Portability: Export your data in a structured format
- Restriction: Restrict processing of your data
- Objection: Object to processing based on legitimate interests
7.2 Communication Preferences
- Opt out of marketing communications
- Manage notification preferences
- Control cookie and tracking preferences
7.3 Mobile App Permissions
- Camera: For receipt photo capture (optional)
- Storage: For saving receipt images and app data
- SMS Access: For automatic transaction parsing (optional)
- Internet: For syncing data and app functionality
- Notifications: For app updates and reminders
8. Data Retention
- Account Data: Retained while your account is active
- Financial Data: Retained according to legal and business requirements
- Analytics Data: Aggregated and anonymized after 26 months
- Support Data: Retained for 3 years for customer service purposes
- Deleted Accounts: Data permanently deleted within 30 days
9. International Data Transfers
Your data may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for international transfers, including:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions by relevant authorities
- Other appropriate safeguards as required by law
10. Children's Privacy
Our service is not intended for children under 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information.
11. Cookies and Tracking Technologies
- Essential Cookies: Required for app functionality
- Analytics Cookies: For understanding app usage and performance
- Preference Cookies: For remembering your settings
- Marketing Cookies: For personalized content (with consent)
You can manage your cookie preferences using the cookie consent banner or your browser settings.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the updated policy on our website
- Sending email notifications for significant changes
- Displaying in-app notifications
Your continued use of our service after changes constitutes acceptance of the updated policy.
13. Contact Information
For privacy-related questions, requests, or concerns, please contact us:
14. Regional Privacy Rights
14.1 European Union (GDPR)
If you are in the EU, you have additional rights under GDPR, including the right to lodge a complaint with your local data protection authority.
14.2 California (CCPA)
California residents have additional rights under CCPA, including the right to know what personal information is collected and the right to opt out of the sale of personal information.
14.3 Other Jurisdictions
We comply with applicable privacy laws in all jurisdictions where we operate.
This Privacy Policy is effective as of January 15, 2025, and was last updated on January 15, 2025.