Booting Spendrz...

Privacy Policy

Effective date: August 2, 2026

1. Introduction

Welcome to Spendrz. This Privacy Policy explains how SHOP DU MAINE SASU, trading as "Spendrz", collects, uses, shares, and protects your personal data when you use our website at spendrz.com and our personal finance application (collectively, the "Service").

We are committed to protecting your privacy and processing your personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and applicable French data protection law. Please read this policy carefully. By using the Service, you acknowledge that you have read and understood this policy.

2. Data Controller

The data controller responsible for your personal data is:

SHOP DU MAINE SASU

Trading as: Spendrz

90 avenue du Maine, 75014 Paris, France

SIREN: 852 644 798

SIRET: 852 644 798 00013

RCS Paris

Privacy contact: admin@spendrz.com

3. Data We Collect

We collect the following categories of personal data:

Identity Data

Your first name, last name, and profile picture, obtained via Google OAuth when you create an account.

Contact Data

Your email address, used for authentication, transactional notifications, and support communications.

Financial Data — Manual Uploads

Transaction data that you voluntarily upload via CSV files exported from your bank. This includes transaction dates, amounts, merchant names, descriptions, and any other fields present in your export file. This data is processed and stored solely to provide the categorization and analytics features of the Service.

Financial Data — Bank Sync via Enable Banking (Pro tier, coming soon)

For users who opt-in to the Pro tier, Spendrz integrates with Enable Banking Oy (a licensed Account Information Service Provider regulated under PSD2, headquartered in Finland) to retrieve read-only transaction data directly from your bank. The data retrieved includes: account balances, transaction history, merchant names, amounts, dates, and reference data. We never receive or store your bank login credentials; authentication flows directly and securely through Enable Banking's infrastructure.

Technical Data

IP address, browser type and version, device type, operating system, and session information, collected automatically when you use the Service for security and operational purposes.

Usage Data

Information about how you interact with the Service, such as features used and actions taken, used to improve product functionality. We do not use third-party behavioral analytics or advertising trackers.

4. How We Use Your Data

We process your personal data only where we have a lawful basis to do so under the GDPR:

Performance of a Contract (Article 6(1)(b))

To provide and operate the Service — including authenticating your account, storing and displaying your transaction data, applying categorization rules, and generating financial analytics and reports.

Legitimate Interests (Article 6(1)(f))

To maintain the security and integrity of the Service, detect and prevent fraud or abuse, improve product features based on aggregated usage patterns, and communicate important service updates. We have assessed that these interests are not overridden by your rights.

Legal Obligation (Article 6(1)(c))

To comply with applicable laws and regulations, including French accounting obligations and responding to lawful requests from public authorities.

Consent (Article 6(1)(a))

Where you have explicitly provided consent, such as opting into bank synchronization via Enable Banking. You may withdraw consent at any time by disconnecting your bank account in the Settings page, without affecting the lawfulness of processing prior to withdrawal.

5. Data Sharing & Sub-Processors

We never sell your personal or financial data to third parties.

We share your data only with the following sub-processors, who are contractually bound to process it securely and solely for the stated purpose:

ProviderPurposeLocation
Vercel Inc.Application hosting & serverless functionsUSA (EU edge nodes)
Neon Inc.PostgreSQL database hostingEU (Frankfurt, Germany)
Enable Banking OyPSD2-licensed bank data aggregation (Pro tier)EU (Finland)
Google LLCOAuth 2.0 authentication (Sign in with Google)USA / Global
Stripe Payments Europe, Ltd.Pro subscription billing & payment processingEU (Ireland)

We may also disclose personal data if required to do so by law or in response to valid requests by public authorities (e.g. a court or government agency).

6. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service.

  • Account deletion: When you delete your account, all personal data — including your transaction history, categories, rules, and bank connection tokens — will be permanently deleted within 30 days of your deletion request.
  • Bank sync tokens: OAuth access tokens issued by Enable Banking are encrypted at rest and deleted immediately upon account disconnection or account deletion.
  • Backups: Database backup snapshots are retained for up to 30 days for disaster recovery purposes, after which they are automatically and permanently destroyed.
  • Billing records: Records related to paid subscriptions may be retained for up to 10 years to comply with French accounting obligations (Code de commerce, Article L123-22). This data is limited to billing amounts, dates, and invoice references — not your financial transaction data.

7. International Data Transfers

Your primary transaction and account data is stored on Neon's PostgreSQL infrastructure located in Frankfurt, Germany (EU) and does not leave the EEA for storage purposes.

Our application is hosted on Vercel, a US-based provider. Vercel processes request data (including IP addresses) through edge nodes globally. Vercel operates under Standard Contractual Clauses (SCCs) approved by the European Commission, which serve as the legal mechanism for any transfer of personal data outside the EEA.

Google LLC processes authentication data under SCCs and participates in the EU-US Data Privacy Framework. Enable Banking Oy is an EU-based entity and processes data within the EEA.

8. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Encryption in transit: All communications between your browser and our Service are encrypted using TLS 1.2 or higher (HTTPS).
  • Encryption at rest: Database data is encrypted at rest by Neon. OAuth access tokens (bank connection credentials) are additionally encrypted using AES-256-GCM before being stored in the database.
  • No bank credentials stored: Spendrz never receives, processes, or stores your bank username or password. Bank authentication flows entirely through Enable Banking's secure OAuth infrastructure under PSD2.
  • Read-only bank access: Bank connections via Enable Banking are strictly read-only. Spendrz cannot initiate payments or move funds of any kind.
  • Access controls: Access to production systems and user data is restricted to authorized personnel only, on a strict need-to-know basis.

While we strive to protect your data, no method of electronic transmission or storage is 100% secure. In the event of a personal data breach likely to result in a risk to your rights, we will notify the CNIL within 72 hours and, where required, notify affected users directly.

9. Your Rights (GDPR)

Under the GDPR, you have the following rights regarding your personal data:

Right of Access: You may request a copy of the personal data we hold about you.
Right to Rectification: You may request that we correct inaccurate or incomplete personal data.
Right to Erasure: You may request that we delete your personal data (the "right to be forgotten"), subject to legal retention obligations.
Right to Data Portability: You may request your personal data in a structured, machine-readable format (e.g. JSON or CSV), and have it transferred to another controller where technically feasible.
Right to Restriction: You may request that we restrict the processing of your data in certain circumstances.
Right to Object: You may object to processing based on our legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your rights.
Right to Withdraw Consent: Where processing is based on consent (e.g. bank sync), you may withdraw consent at any time without affecting the lawfulness of prior processing.
Right to Lodge a Complaint: You have the right to lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés) at www.cnil.fr, or with the supervisory authority in your country of residence within the EU.

To exercise any of these rights, contact us at admin@spendrz.com. We will respond within 30 days.

10. Cookies

Spendrz uses only strictly necessary cookies required for the Service to function. These include:

  • Session cookie: Maintains your authenticated login state. Expires at end of session or after 30 days.
  • CSRF cookie: Protects against cross-site request forgery attacks.

We do not use advertising cookies, behavioral tracking cookies, or third-party analytics cookies. No cookie consent banner is required as we only use strictly necessary cookies.

11. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a minor, please contact us immediately at admin@spendrz.com and we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal obligations. When we make material changes, we will notify you by email to your registered address and by updating the "Effective date" at the top of this page. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

13. Contact Us

For any privacy-related questions, requests, or complaints, please contact:

SHOP DU MAINE SASU (trading as Spendrz)

90 avenue du Maine, 75014 Paris, France

Email: admin@spendrz.com