👋
Quick summary: We collect financial transaction data through Plaid to power MoneyWise's features. We do not sell your personal information. We do not share it with advertisers or marketers. We use it to provide the Service to you, and for the limited purposes described below.
Section 01
Who We Are
CashSmart Inc. ("CashSmart," "we," "us," or "our") operates the MoneyWise mobile application and related services (collectively, the "Service"). MoneyWise helps you optimize credit card rewards, surface missed cashback, and understand how inflation affects your personal spending.
CashSmart Inc. is the data controller responsible for your information when you use MoneyWise. You can contact us at:
CashSmart Inc.
Email: dingdong@moneywise.finance
Section 02
Information We Collect
2.1 Information You Provide Directly
When you create an account or use MoneyWise, you may provide:
- Account information: name, email address, and password.
- Profile information: the credit cards you use, assumptions for the value of a point or mile, and other preferences you set within the app.
- Referral information: if you refer another user or are referred by one, we record that relationship to administer our referral program.
- Communications: messages you send us through support channels, surveys, or feedback forms.
- Uploaded documents: if you upload a credit card statement (PDF or image) for transaction import, we process that document as described in Section 3.
2.2 Financial Information Collected Through Plaid
MoneyWise uses Plaid Inc. ("Plaid") to securely connect to your financial institutions. When you link an account, you authenticate directly with your bank or card issuer through Plaid. We never see your banking credentials.
Through Plaid, we receive:
- Account metadata: institution name, account type, account nickname, masked account number, and balance information.
- Transaction data: transaction date, amount, merchant name, merchant category, and other details associated with each transaction on the accounts you link.
Plaid's use of your information is governed by Plaid's own privacy policy. We encourage you to read it.
2.3 Information We Generate About You
As you use MoneyWise, we generate derived information, including:
- Cashback Missed calculations: the rewards you would have earned if you had used a different card for a given transaction.
- Personalized inflation estimates based on the categories of your actual spending.
- Premium status: your current subscription tier and how it was granted (free trial, referral milestone, paid, etc.).
2.4 Information Collected Automatically
When you use the Service, we automatically collect:
- Device information: device type, operating system, app version, language settings, and unique device identifiers.
- Log data: IP address, access times, crash reports, and diagnostic information.
Section 03
How We Use Your Information
We use the information we collect for the following purposes:
- To provide the Service: connect your accounts, categorize transactions, calculate optimal card recommendations, surface missed cashback, and generate your personalized inflation tracker.
- To administer your account: authenticate you, manage your subscription tier, process referral rewards, and send service-related communications.
- To improve the Service: suggestions and feedback through the "Feedback" feature available to all users to understand which features are working, fix bugs, and develop new functionality.
- To extract data from documents you upload: when you upload a credit card statement or permit us to link to a credit card via Plaid, we use third-party AI services (currently Anthropic's Claude API) to extract only transaction data, NEVER personal information, providing only the information needed to understand how much was spent at which merchant at what time. Documents are NEVER retained by us. The MoneyWise app is hardcoded to send a backend DELETE call after each transaction parsing to ensure no files are retained by Anthropic. All API request logs are deleted after 7 days per Anthropic's API policy.
- To protect the Service: detect fraud, abuse, security incidents, and violations of our Terms of Service.
- To communicate with you: respond to support requests, send important account notices, and (with your express consent) send product updates.
- To comply with legal obligations: respond to lawful requests, enforce agreements, and meet regulatory requirements.
🚫
What we do not do: We do not sell your personal information. We do not share your transaction data with advertisers, data brokers, or marketing entities.
Section 04
How We Share Your Information
We share your information only in the limited circumstances described below.
4.1 Service Providers
We share information with vendors that help us operate the Service, including:
- Plaid, for bank and card account connectivity.
- Supabase, our backend infrastructure and database provider.
- Anthropic, for AI-assisted statement parsing (when you upload statements).
These providers may process your information only on our instructions and for the purposes we specify.
4.2 Legal Requirements
We may disclose information if we believe in good faith that doing so is required to comply with a law, regulation, legal process, or governmental request; to enforce our Terms of Service; to protect the rights, property, or safety of our users, the public, or CashSmart Inc.; or to investigate fraud or security issues.
4.3 Business Transfers
If CashSmart Inc. is involved in a merger, acquisition, financing, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership so you may elect to request the deletion of your information.
Section 05
Financial Privacy Notice (GLBA)
Because MoneyWise handles financial information, we are subject to the federal Gramm-Leach-Bliley Act ("GLBA"). Under GLBA:
- We collect nonpublic personal information about you from the sources described in Section 2.
- We do not disclose any nonpublic personal information about our customers or former customers to nonaffiliated third parties, except as permitted by law and as described in this policy.
- We restrict access to nonpublic personal information to employees and service providers who need to know that information to provide the Service.
- We maintain physical, electronic, and procedural safeguards designed to protect your nonpublic personal information.
Section 06
How We Protect Your Information
We implement reasonable administrative, technical, and physical safeguards to protect your information, including encryption in transit (TLS) and at rest, access controls, and ongoing security monitoring. We never store your bank login credentials. Those are held by Plaid under their security program.
No method of transmission or storage is 100% secure, however, and we cannot guarantee absolute security. If we become aware of a security incident affecting your personal information, we will notify you and applicable authorities as required by law.
Section 07
Data Retention
We retain your information for as long as your account is active or as needed to provide the Service. When you delete your account:
- We instruct Plaid to remove your linked items, which stops ongoing data collection.
- We delete or de-identify your personal and transaction data within a reasonable period, typically within 30 days, except where retention is required for legal, accounting, or fraud-prevention purposes.
- Aggregated or de-identified data that cannot reasonably be linked to you may be retained for analytics and product improvement.
Section 08
Your Choices and Rights
You have the following choices regarding your information:
- Access and update: you can view and update most of your account information directly within the app.
- Disconnect accounts: you can unlink any financial account at any time from within the app, which stops further data collection from that institution.
- Delete your account: you can delete your account from within the app or by contacting dingdong@moneywise.finance. Deletion is permanent.
- Communications preferences: you can opt out of non-essential emails at any time using the unsubscribe link or by contacting us. Service-related communications cannot be opted out of while your account is active.
8.1 California Residents (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, including:
- The right to know what personal information we collect, use, disclose, and (if applicable) sell or share.
- The right to request deletion of your personal information.
- The right to correct inaccurate personal information.
- The right to limit the use of sensitive personal information.
- The right to non-discrimination for exercising your privacy rights.
To exercise these rights, contact us at dingdong@moneywise.finance. We do not sell or share personal information for cross-context behavioral advertising as those terms are defined under the CCPA. Note that information governed by the GLBA is exempt from certain CCPA requirements.
Section 09
Children's Privacy
MoneyWise is not directed to children under the age of 18, and we do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from a minor, we will delete it promptly.
If you believe a child has provided us with personal information, please contact dingdong@moneywise.finance.
Section 10
International Users
MoneyWise is operated from the United States and is intended for users located in the United States. If you access the Service from outside the U.S., you understand that your information will be transferred to, processed, and stored in the United States, where data protection laws may differ from those in your jurisdiction.
Section 11
Third-Party Links and Services
The Service may contain links to third-party websites, products, or services (including credit card issuers). We are not responsible for the privacy practices of those third parties, and this policy does not apply to them. We encourage you to review their privacy policies separately.
Section 12
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we do, we will revise the "Last updated" date at the top of this page. If the changes are material, we will provide additional notice through the app or by email.
Your continued use of the Service after the updated policy takes effect constitutes your acceptance of the changes.
Section 13
How to Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact us. We will respond to your inquiry within a reasonable timeframe and in accordance with applicable law.