Privacy Policy
This service exists to read financial transaction data and turn it into budget status. That makes privacy a product question rather than a disclosure exercise, so this policy is written to be specific about financial data in particular.
Scope of this policy
This policy covers the BudgetGaga budgeting and expense management service, including the web application, the account connections you establish within it, the reports it produces, and this website. It applies to the business that holds the subscription and to the individual users who are given access to that subscription, such as budget owners, finance reviewers and read-only viewers.
It does not cover your bank, card issuer or accounting software. Those relationships are governed by their own terms, and the consent you grant when connecting an account is a matter between you and that institution, even though it is initiated from inside this service.
Information we collect
Information you provide
- Account identity details: the name, work email address and role of each user you create, and the business name under which the subscription is held.
- Budget configuration: your category names and structure, the limits and near-limit thresholds you set, budget cycle definitions, category owners, and approval routing rules.
- Operational input: categorization overrides, rules you write, approval and decline decisions with any note attached, and delegation arrangements.
- Correspondence: what you send us through enquiry or support forms, including the business context you choose to include so we can answer usefully.
Information generated by use
- Derived budget figures: committed spend per category, percentage of limit, state transitions, projected close, flags raised, and the reallocation suggestions the engine produced.
- Activity records: sign-ins, connection changes, configuration edits, override actions and approval decisions, each recorded with the acting user and a timestamp.
- Technical records: device and browser characteristics, IP address and request logs, retained for security, abuse prevention and fault diagnosis.
Connected account data
When you connect a bank account or card, the connection is established with read-only scope. The service retrieves transaction records and the account metadata needed to interpret them. Specifically, for each transaction it reads the amount, the transaction and posting dates, the merchant or payee descriptor, the identifier of the account or card the spend came from, the settlement status, and where available the schedule of a recurring charge.
Each of those fields is retrieved because a defined part of the service requires it: amounts and dates to track against a limit within the right cycle, descriptors to assign a category, instrument identifiers to distinguish and report by source, status to avoid double counting pending authorizations, and recurrence to count a known future charge as committed.
The service holds no payment capability. It cannot initiate a transfer, release a payment, create a payee or alter a bank record, because the access it holds carries no scope to do so. Approving a reallocation changes budget limits held inside the service and has no effect on any bank account.
We do not see or store your banking credentials. Authentication with your institution happens with that institution, and what the service retains is a revocable access token rather than a username and password.
How the data is used
- To categorize transactions, track committed spend against category limits, raise threshold and pace flags, project cycle close, and identify reallocation sources.
- To route approval requests to the correct owner and record the decisions taken, which is what makes a mid-cycle budget change auditable.
- To produce the variance, trend, reallocation history and categorization quality reporting you export or have delivered.
- To deliver account creation details, service notices and responses to your enquiries, and to provide support when something is not working.
- To keep the service secure and available: detecting abuse, investigating incidents, diagnosing faults and maintaining backups.
- To meet legal, tax and regulatory obligations that apply to operating a subscription service.
We do not use your transaction data to build advertising profiles, and we do not sell or broker it. The subscription is how the service is funded.
Categorization and model use
Automatic categorization improves by learning from corrections. Within your own account, your overrides and rules directly change how future transactions from the same merchant are assigned, which is the behaviour the service is designed around.
Where categorization logic is improved across the service generally, it is developed using aggregated and de-identified signals, such as the statistical relationship between merchant descriptor patterns and category types. Your identifiable transaction records, category names, limits and figures are not used to serve or train anything for another customer.
Confidence bands exist so you can judge an assignment rather than inherit it. Low-confidence assignments are surfaced for review and genuinely unresolvable ones are held uncategorized rather than guessed into a category.
When data is shared
Transaction and budget data is disclosed only in these circumstances.
- Within your own subscription. Users you have granted access see data according to their role. A budget owner sees their categories; a finance role sees the whole account. You control who holds which role.
- To service providers that operate the platform. Hosting, database, account aggregation, transactional email and error monitoring providers process data strictly on our instructions, under contract, and only to the extent their function requires.
- Where the law requires it. In response to a valid legal demand, limited to what is actually required.
- In a business transfer. If the service changes hands, data may transfer as part of it, with this policy continuing to apply until you are notified of a replacement.
Retention and deletion
Budget configuration, categorized transactions and derived figures are retained while your subscription is active, because historical periods are what trend reporting is built from. Activity and approval records are retained according to the audit retention period of your plan.
Revoking an account connection stops retrieval immediately. Transactions already retrieved remain in your ledger so that closed-period reports stay intact, and you can delete that history explicitly if you would rather it were gone.
After a subscription ends, your data remains exportable for ninety days. Following that window it is deleted or irreversibly anonymised, other than records we are required to keep for legal, tax or accounting purposes, and backup copies which age out on their normal cycle.
Protection measures
- Encryption in transit using current TLS, and encryption of stored data at rest.
- Connection tokens held in a dedicated secret store, separate from application data.
- Account scoping enforced at the data layer rather than filtered in the interface, so one subscription's records are not reachable from another's session.
- Internal access restricted to personnel who require it to operate the service, granted individually and logged when used.
- Append-only activity and approval records, so an audit trail cannot be rewritten after the fact.
- Encrypted, access-controlled backups with restores tested rather than assumed.
No safeguard is absolute. If an incident affects your data we will tell you what happened, what was affected and what we did about it, without waiting to be asked.
Your choices and rights
- Access and export. Export your categories, limits, limit history, categorized transactions, flags and approval decisions at any time, in formats that open outside this service.
- Correction. Amend identity and configuration details directly. Categorization assignments can be corrected by you at any time and the correction is recorded.
- Deletion. Request deletion of your account and its data, subject to records we must retain by law.
- Withdrawal of connection consent. Disconnect any account or card whenever you choose, which halts further retrieval at once.
- Communication preferences. Opt out of non-essential messages. Service and security notices relating to an active subscription continue, because they are part of operating the account.
Requests of this kind can be made from the contact page and will be answered by a person.
Business use only
This is a service for businesses and is not directed at, or intended for use by, anyone under eighteen. We do not knowingly create accounts for minors and we do not knowingly collect their data.
Changes to this policy
If this policy changes in a way that materially affects how financial data is handled, we will notify account holders directly through the service or by mail before the change takes effect, rather than relying on you to re-read the page. Continued use after a notified change constitutes acceptance of it.
