Privacy Policy
This Privacy Policy describes how FIO-PAYPATH ("we," "us," or "our") collects, uses, stores, and protects your personal and financial information when you use our cash-flow tracking platform.
Privacy at a Glance
The full details are below — we recommend reading them before signing up.
1. Information We Collect
a. Account Information
When you register, we collect your name, email address, and a hashed password. We do not store plain-text passwords.
b. Financial Data You Enter
Paycheck details, bill amounts, categories, savings goals, and transaction records that you manually enter or import are stored in your account database and are only accessible to you.
c. Manual Bank Snapshot & Future Plaid Services
Manual Bank Snapshot is the live feature: you upload a bank statement export to help detect transactions, income patterns, and recurring expenses. Instant Bank Snapshot with Plaid is Coming Soon and will be optional if enabled.
d. Payment Information via Stripe
Subscription payments are processed by Stripe, Inc. We do not store credit card numbers or CVVs. All payment data is handled by Stripe in compliance with PCI-DSS Level 1 standards. By making a payment, you agree to Stripe's Privacy Policy.
e. Usage & Analytics Data
We may collect anonymized usage events to improve the product. No personally identifiable financial data is included in analytics events. We use cookies and local storage for session management and user preferences.
2. How We Use Your Information
- To provide, maintain, and improve the FIO-PAYPATH platform
- To calculate cash-flow projections, paycheck-linked expense coverage, and savings runway
- To send optional email notifications (bill reminders, budget alerts) if enabled by you
- To process subscription payments and manage your account tier
- To detect recurring transactions and spending anomalies on your behalf
- To comply with applicable laws and respond to lawful legal requests
We do not sell, rent, or trade your personal or financial data to any third party for advertising or marketing purposes.
3. Data Retention
We retain your account data for as long as your account is active. If you delete your account, we will permanently delete your personal data within 30 days, except where retention is required by law (e.g., billing records retained for 7 years for tax compliance).
Bank transaction data imported through Manual Bank Snapshot is retained in your account until you delete it or request deletion. Future Plaid-powered snapshot data, if enabled, will be optional and revocable.
4. Data Security
We implement industry-standard security measures to protect your data:
- Encryption in transit: All data is protected using TLS 1.3 (HTTPS).
- Encryption at rest: Database records are stored on AES-256 encrypted infrastructure.
- No raw bank credentials: We never receive, store, or log your bank username or password.
- Access controls: Database access is row-level restricted so you can only access your own records.
- SOC 2-aligned infrastructure: Our hosting provider operates on SOC 2-mapped security controls.
- Multi-factor authentication: MFA is enforced on all administrative access.
5. Cookies & Tracking Technologies
We use cookies and browser local storage for:
- Session management: Keeping you logged in securely
- Preferences: Remembering your UI settings (dark mode, period selection)
- Analytics: Anonymized product usage metrics to improve the platform
You may clear cookies in your browser at any time, though this will log you out and reset preferences.
6. Third-Party Services
| Service | Purpose | Data Shared |
|---|---|---|
| Plaid Technologies | Instant Bank Snapshot — Coming Soon | Future optional OAuth token exchange; no passwords |
| Stripe, Inc. | Payment processing | Email, billing name; no card stored by us |
| Base44 Platform | App hosting & database | All app data (SOC 2-aligned infrastructure) |
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access a copy of the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and associated data
- Delete manually imported bank snapshot data or withdraw future bank-connection consent if Plaid is enabled
- Opt out of non-essential communications
To exercise any of these rights, contact us at support@fio-paypath.com. We will respond within 1 month.
7A. International Data Protection & Privacy Rights
1. European Economic Area (GDPR) & United Kingdom (UK GDPR)
We process your data strictly on the lawful bases of User Consent and Contractual Necessity.
- Right to Erasure: Delete your account and all transaction data at any time via Account Settings. All parsed CSV/OFX data is permanently purged upon deletion.
- Data Portability: Export your processed data at any time in CSV or PDF format.
2. North America (CCPA/CPRA — California · PIPEDA — Canada)
- We Do Not Sell Your Data: FIO-PAYPATH does not sell, rent, or trade your personal or financial data to third parties, data brokers, or advertising networks.
- Right to Know: You may request a full disclosure of the categories of personal data we have collected about you over the past 12 months.
3. South America (LGPD — Brazil)
In compliance with the Lei Geral de Proteção de Dados, users in Brazil have the right to confirmation of data processing, access to data, and correction of incomplete or inaccurate data. Because our application relies on user-uploaded statements, you retain full control over correcting your data directly within the dashboard.
4. Asia-Pacific (PDPA — Singapore · APPI — Japan · Privacy Act — Australia)
We comply with cross-border data transfer regulations by ensuring your data is encrypted in transit (TLS 1.3) and at rest (AES-256). We adhere to the Australian Privacy Principles (APPs) regarding transparent management of personal information and data minimization.
5. Africa (POPIA — South Africa)
We process personal information lawfully and reasonably, without infringing on the privacy of the data subject. Data retention is limited strictly to the duration your account remains active.
How to Exercise Your Global Privacy Rights
To exercise any rights regarding data access, correction, or deletion, contact us at support@fio-paypath.com. Because FIO-PAYPATH does not collect identifying financial credentials, we may ask you to verify your account email address before processing a request. We will respond within 30 days.
7B. GDPR Detailed Compliance — EU/UK Residents
Legal Basis for Processing
We process your personal data based on the "Performance of a Contract" (Article 6(1)(b)) when providing our financial tracking services. When you sign up for marketing communications or our Euro-Launch Waitlist, we process your data on the basis of your "Consent" (Article 6(1)(a)), which you may withdraw at any time.
Data Controller
FIO-Paypath, LLC (operating as FIO-PAYPATH) is the Data Controller for your personal data. For any data-related inquiries, contact us at: compliance@fio-paypath.com.
Data Subject Rights (GDPR Articles 15–22)
- Right of Access (Article 15): You may request a copy of the personal data we hold about you at any time.
- Right to Erasure (Article 17): You have the right to request the deletion of your account and associated financial data history, except where retention is required by law.
- Right to Data Portability (Article 20): You may request your data in a structured, machine-readable format (JSON/CSV).
- Right to Restrict Processing (Article 18): You may request that we pause processing your data while you resolve a dispute.
- Right to Object (Article 21): You may object to processing based on legitimate interests, including analytics and profiling.
To exercise any of these rights, contact us at compliance@fio-paypath.com. We will respond within 1 calendar month.
International Data Transfers
FIO-Paypath, LLC is based in the United States. Your data is transferred to and processed in the US via our hosting provider, Base44. We protect your data during these transfers by adhering to the EU-US Data Privacy Framework and utilizing Standard Contractual Clauses (SCCs) (Article 46) where applicable.
Data Retention (GDPR Article 17)
- Account data is retained for the duration of your subscription
- Billing records are retained for seven years to comply with US and international tax reporting requirements
- Upon account deletion, all other personal data is removed within 30 days
Supervisory Authority
- UK: Information Commissioner's Office (ICO) — ico.org.uk
- France: Commission Nationale de l'Informatique et des Libertés (CNIL) — cnil.fr
- Germany: Bundesbeauftragte für den Datenschutz (BfDI) — bfdi.bund.de
7B-ii. Regulatory Posture & Non-Custodial Declaration
FIO-PAYPATH is a non-custodial, read-only Personal Finance Management (PFM) tool. We do not hold, manage, or transfer funds. We are strictly an observer of your financial data — never an actor.
| Regulatory Framework | Region | Our Status |
|---|---|---|
| PSD2 / Open Banking | EU / EEA | AISP-aligned (read-only, consent-based). Not a PISP — no payment initiation. |
| CFPB Data Aggregation Rules | USA | PFM Safe Harbor — transparent, read-only, non-custodial. |
| GDPR / UK GDPR | EU / UK | Data Controller. Processing on contract & consent bases only. |
| CCPA / CPRA | California, USA | Do Not Sell posture. Full data rights honored. |
This regulatory mapping is maintained for informational transparency. It does not constitute legal advice or a formal regulatory filing.
7C. Affirmative Consent (Clickwrap)
To ensure global legal enforceability of our Terms of Service and Privacy Policy, FIO-PAYPATH uses Clickwrap consent — the gold standard recognized by courts worldwide.
"I have read and agree to the Terms of Service and Privacy Policy."
- This constitutes your informed, affirmative consent to data processing under GDPR Article 6(1)(a) and equivalent laws globally.
- A timestamp and version of the Terms accepted is logged at the time of consent.
- You may withdraw consent at any time by deleting your account. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
- "Browsewrap" (passive agreement by continued use) is not relied upon as a mechanism of legal consent by FIO-PAYPATH.
7D. GDPR Lawful Bases for Processing (Article 6)
The following table maps each category of data processing to its lawful basis under GDPR Article 6:
| Processing Activity | Lawful Basis | GDPR Article |
|---|---|---|
| Account creation & login | Contract performance | Art. 6(1)(b) |
| Cash-flow projections & AI insights | Contract performance | Art. 6(1)(b) |
| Payment processing via Stripe | Contract performance | Art. 6(1)(b) |
| Manual Bank Snapshot imports | Contract performance | Art. 6(1)(b) |
| Future bank connectivity via Plaid | Consent (revocable) | Art. 6(1)(a) |
| Marketing emails & waitlist | Consent (revocable) | Art. 6(1)(a) |
| Anonymized usage analytics | Legitimate interests | Art. 6(1)(f) |
| Legal compliance & fraud prevention | Legal obligation | Art. 6(1)(c) |
7E. Cookie Policy (GDPR / EU ePrivacy Directive)
FIO-PAYPATH uses cookies and similar technologies. EU/UK visitors are presented with a consent banner before any non-essential cookies are activated.
| Cookie Type | Purpose | Consent Required? |
|---|---|---|
| Strictly Necessary | Session management, authentication, security | No — essential |
| Functional | UI preferences (dark mode, currency, period) | No — essential |
| Analytics | Anonymized product usage metrics | Yes — opt-in |
| Third-party (Stripe) | Fraud prevention & payment processing | Yes — disclosed at checkout |
You may withdraw cookie consent at any time by clearing browser storage or adjusting your browser settings.
7F. Exercising Your Data Rights — How to Act
You do not need to contact us for routine data actions — most rights can be exercised directly inside the app:
For requests not covered above, contact compliance@fio-paypath.com. We respond within 1 calendar month as required by GDPR Article 12.
7G. AI Disclosure & Decision Boundaries
FIO-PAYPATH AI may help you:
- Explain cash-flow outcomes in plain language
- Interpret what-if scenarios
- Detect recurring costs, spending anomalies, and patterns
FIO-PAYPATH AI does not:
- Make financial decisions for you
- Move money or execute transactions
- Modify your financial records without your action
- Replace professional financial, legal, or tax advice
You control all inputs, imports, exports, and account deletion actions. Manual Bank Snapshot is live and does not require bank credentials; Plaid-powered Instant Bank Snapshot is Coming Soon.
8. Children's Privacy
FIO-PAYPATH is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has created an account, contact us immediately at support@fio-paypath.com.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by displaying a prominent notice in the app. Your continued use of FIO-PAYPATH after the effective date of a revised policy constitutes your acceptance of the updated terms.
10. Contact Us
If you have questions or concerns about this Privacy Policy, please contact:
FIO-Paypath, LLC (operating as FIO-PAYPATH)
Email: support@fio-paypath.com
© 2026 FIO-Paypath, LLC. All rights reserved.
FIO-PAYPATH is a product of FIO-Paypath, LLC.