Privacy by design

Privacy Policy

This page explains how VestFin currently handles personal data when you use the website, create an account, manage your finances or contact us.

Last updated: 21 September 2026

01

Data we process

  • Account and authentication data, such as your email address, authentication identifier and session information managed by Clerk.
  • Financial data that you choose to enter, including income, expenses, budgets, trips, savings, net worth and investments.
  • Display preferences such as language and currency.
  • Contact information and the content of a message when you use the Contact form. Providing an email address there is optional.
  • For paid plans, Paddle processes the billing, payment and transaction data needed to manage the subscription. VestFin does not store complete card details.
  • Basic technical information needed to operate and protect the service. The public contact form uses the client network address temporarily to limit abuse.

VestFin does not currently connect to bank accounts, sell financial data or use it for advertising.

02

Why we use the data

  • To create and secure your account and keep your session working.
  • To manage your account and provide support when you request it.
  • To save, calculate and display the financial information you enter.
  • The financial data you enter is used for your own personal organisation and use within your account.
  • To apply your language and currency preferences across your account.
  • To manage paid subscriptions, billing, taxes, refunds and payment fraud prevention.
  • To receive, manage and answer contact requests.
  • To prevent abuse, keep the service secure and diagnose technical problems.

03

Legal grounds

The main legal ground for managing your account and providing the service is performance of the contractual relationship that begins when you register and accept the Terms and Conditions. Depending on the specific processing, the legal ground may also be our legitimate interest in keeping the service secure and functional, compliance with a legal obligation, or your consent where we ask for it. We do not use financial data for unrelated marketing.

04

Service providers

  • Clerk: authentication, account access and sessions.
  • Replit: application hosting and managed PostgreSQL storage. VestFin’s published infrastructure is located in Europe.
  • Resend: delivery of transactional and administrative emails, including welcome messages, Contact notifications and internal operational notifications about account registrations, account deletions and subscription cancellations. If you provide an email in a Contact message, it may be included as Reply-To so we can answer you.
  • Paddle: payment provider and merchant of record for paid subscriptions. Paddle processes checkout, billing, applicable taxes, refunds and payment fraud prevention under its own privacy terms.

VestFin does not sell personal data. Data is only communicated to the technical and operational providers essential to provide the service, listed above, and only to the extent needed for their respective functions.

International transfers and applicable safeguards

  • Clerk: authentication data is hosted on infrastructure in the United States. Transfers from the EEA to Clerk are covered by Clerk’s certification under the EU-U.S. Data Privacy Framework. If Clerk cannot rely on that framework, its Data Processing Addendum incorporates the European Commission’s Standard Contractual Clauses (Modules 2 and 3, as applicable). Clerk transfer safeguards.
  • Resend: data used to deliver emails is stored in the United States. Transfers from the EEA are covered by the Standard Contractual Clauses included in Resend’s Data Processing Addendum and, additionally, by its certification under the EU-U.S. Data Privacy Framework. Resend transfer safeguards.
  • Paddle: as merchant of record, Paddle may transfer payment and transaction data outside the EEA or the United Kingdom. For transfers to countries without an adequacy decision, Paddle states that it uses the European Commission’s Standard Contractual Clauses (Module 1, controller to controller) and, where UK law applies, the UK Approved Addendum. Paddle transfer safeguards.
  • Replit: VestFin’s published application runtime, primary database and storage are located in Europe. However, certain platform administration, support, monitoring, technical logging, analytics and metadata services may be processed in the United States or other countries. Where those operations constitute international transfers subject to the GDPR, Replit’s Data Processing Addendum establishes the European Commission’s Standard Contractual Clauses (Modules 2 or 3, as applicable) as the applicable safeguard. Replit transfer safeguards.

05

Storage and retention

Account and financial information is kept while your account and the service relationship remain active. You can delete your account from Settings; after explicit confirmation, VestFin deletes the financial records, investments, preferences, subscription information, linked Contact messages and Clerk sign-in identity associated with the account. Before deletion, you should export any information you want to keep.

Contact messages are kept for a maximum of 12 months from receipt and may be deleted earlier when the linked account is deleted. Information that must be retained to meet a legal obligation, resolve a dispute, prevent fraud or protect the service may be kept for the strictly necessary period.

Replit manages encrypted database recovery copies separately from the active service. Deleted data may remain in those isolated copies until the configured recovery window expires, for a maximum of 28 days. Deployment logs are retained by the hosting provider for up to 30 days and are configured not to include authentication headers or cookies.

06

Your rights

Subject to applicable law, you may request access, rectification, deletion, restriction, objection or portability of your personal data. You can exercise these rights through the Contact form or by writing to vestfin@vestfin.app, explaining what you need and the account email concerned. If you believe that the processing of your personal data does not comply with applicable law, you have the right to lodge a complaint with the data protection authority in your country of residence or, failing that, with the Spanish Data Protection Agency (AEPD) at www.aepd.es.

07

Security

VestFin uses encrypted connections, managed database encryption, Clerk authentication and account-level data isolation. Logs are configured to redact authentication headers and cookies. No online service can guarantee absolute security, so keep your password private and sign out of shared devices.

08

Cookies and local storage

VestFin uses the storage required for authentication and session continuity. The browser may also store display preferences such as language and currency. VestFin does not currently use non-essential advertising cookies or third-party analytics.

09

Changes to this policy

We may update this policy when the service, providers or legal requirements change. The date at the top of this page will show when it was last updated.

10

Data controller and contact

Show identification and contact details
Data controller
Ana Belén García Fernández
Tax ID
09423390Z
Address
Calle Luna, 30, 3º Izq. B, 28004 Madrid, España
Email
vestfin@vestfin.app

In compliance with Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD), users are informed that the personal data provided through this platform will be processed under the responsibility of the data controller identified above.

Privacy questions and rights requests may also be submitted through the public Contact form.

Questions about privacy?

Use the Contact form and tell us how we can help.