At Waliyy Holdings LLC ("FinaFold," "we," "us," or "our"), we respect your privacy and are committed to protecting the personal data you share with us. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application (the "App") available on iOS and Android.
Please read this Privacy Policy carefully. By using the App, you consent to the data practices described in this policy.
1. Information We Collect
We collect information that you provide directly to us, information collected automatically when you use the App, and information from third-party services.
A. Information You Provide
- Account Information: When you register, we collect your name, email address, and password.
- User Content: We collect receipt images you upload and the data extracted from them (vendor name, amount, date, and category).
- Support Communications: If you contact us for support, we collect the content of your message and any attachments.
B. Location Data (Background Tracking)
To provide our core mileage tracking service, FinaFold collects precise location data (GPS) from your mobile device.
- Background Usage: We collect this data even when the App is closed or not in use to automatically detect and log your business trips.
- Purpose: This data is used solely to calculate mileage for your records and expense reporting purposes.
- Control: You can enable or disable location tracking at any time via your device settings, though disabling it will prevent the App from tracking mileage automatically.
C. Financial Data (Plaid)
We use Plaid to connect your bank accounts to FinaFold.
- Transactions: FinaFold imports transaction data (description, amount, date, category) to help you track business expenses.
- Security: FinaFold never sees or stores your bank login credentials. These are handled securely by Plaid. By linking your account, you agree to Plaid's Privacy Policy.
D. Receipt Data (OCR Processing)
We use AWS Textract to process receipt images.
- Extraction: When you upload a receipt, the image is sent to AWS servers where Optical Character Recognition (OCR) identifies the vendor, total amount, and date.
- Storage: The extracted data and original images are stored securely on our cloud infrastructure.
E. Technical and Usage Data
- Device Information: We collect information about your mobile device, including hardware model, operating system version, unique device identifiers, and mobile network information.
- Log Data: We record details of your App usage, such as time of access, features viewed, and system crashes.
2. How We Use Your Information
We use the collected information to:
- Provide, maintain, and improve the FinaFold platform.
- Calculate business mileage and generate PDF and CSV mileage and expense reports.
- Categorize expenses and track financial performance.
- Process subscriptions and manage billing via RevenueCat and app stores.
- Send push notifications regarding trip detection or account updates.
- Analyze usage trends to enhance user experience.
- Comply with legal obligations and protect against fraudulent activity.
3. Data Sharing and Third Parties
We do not sell your personal data. We share information only with the following service providers necessary to operate the App:
| Provider |
Purpose |
| Supabase |
Primary database and cloud storage (hosted on AWS infrastructure) |
| Plaid |
Securely accessing and importing bank transactions |
| Amazon Web Services (AWS) |
Receipt image storage (S3) and OCR processing (Textract) |
| RevenueCat |
Subscription and entitlement management across iOS and Android |
| Apple App Store / Google Play |
Payment processing and app distribution |
We may also disclose information if required by law, such as to comply with a subpoena or similar legal process.
4. Data Security
We implement industry-standard security measures to protect your data:
- All data transmitted between the App and our servers is encrypted via SSL/TLS.
- Data stored in Supabase and AWS is protected by robust access controls and encryption at rest.
- We use Row-Level Security (RLS) in our database so each user can only access their own data.
No method of transmission over the internet or electronic storage is 100% secure; therefore, we cannot guarantee absolute security.
5. Data Retention and Deletion
- Retention: We retain your personal data for as long as your account is active or as needed to provide you with our services.
- Account Deletion: You may delete your account at any time through the App settings. Upon deletion, we will remove your personal data from our active databases, subject to legal requirements to retain certain records.
- Manual Request: You may also request data deletion by contacting us at support@finafold.com.
6. Your Rights
A. General Rights
You have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information.
- Request deletion of your data.
- Withdraw consent for location tracking or bank connections at any time.
B. California Residents (CCPA)
Under the California Consumer Privacy Act, California residents have the right to:
- Request disclosure of what personal information we collect.
- Request deletion of personal information.
- Opt-out of any "sale" of personal information (Note: FinaFold does not sell your data).
- Not be discriminated against for exercising these rights.
To exercise your CCPA rights, contact us at support@finafold.com.
C. EU and EEA Users (GDPR)
If you are located in the European Economic Area, you have rights under the General Data Protection Regulation (GDPR), including:
- The right to data portability.
- The right to withdraw consent at any time without affecting prior processing.
- The right to lodge a complaint with a supervisory authority.
Our legal basis for processing your data is the performance of our contract with you (providing the App services) and your explicit consent (for location tracking and bank connections).
7. Children's Privacy
FinaFold is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will take steps to delete such information immediately. If you believe a child has provided us their information, please contact us at support@finafold.com.
8. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy in the App and updating the "Effective Date" at the top of this page. We encourage you to review this policy periodically.
9. Contact Us
If you have any questions about this Privacy Policy, your data, or your privacy rights, please contact us:
Waliyy Holdings LLC
Email: support@finafold.com
Website: www.finafold.com