Data Collection Policy
Last updated: 26 July 2026
Owner: WAW Group Global Limited (Company No. 15008409) — responsible person: Abdullahi Warsame, Director
Applies to: all Finvestodia products, staff, and any contractors or collaborators
This policy sets out what data Finvestodia collects, the rules governing collection, and the standards every feature must meet before it ships. The public-facing Privacy Policy describes our practices to users; this document governs them internally and can also be published for transparency.
1. Principles
All data collection at Finvestodia must satisfy the UK GDPR principles:
- Lawfulness, fairness, transparency — every data point has a documented legal basis and is disclosed in the Privacy Policy before collection begins.
- Purpose limitation — data collected for one purpose is not reused for an incompatible one without a new basis (and, where needed, consent).
- Data minimisation — we collect the minimum needed for the feature to work. "Might be useful later" is not a reason to collect.
- Accuracy — users can view and correct their data in-app.
- Storage limitation — every data category has a retention period and an owner (see schedule below).
- Integrity and confidentiality — encryption in transit and at rest; least-privilege access.
- Accountability — collection decisions are recorded in the Record of Processing Activities (ROPA).
2. Data collection register
| Category | Examples | Collected via | Purpose | Legal basis | Retention |
|---|---|---|---|---|---|
| Identity & account | Name, email, hashed password, country, currency | Sign-up, settings | Account provision | Contract | Life of account + 30 days |
| Waitlist | Email, sign-up date/source | Website form | Launch communications | Consent | Until unsubscribe / 24 months post-launch |
| Transactions & budgets | Amounts, merchants, categories, notes | Manual entry, receipt scan | Core features, reports, AI coaching | Contract | Life of account + 30 days |
| Receipt images | Photo, extracted merchant/amount/date | Camera / photo upload | Expense creation | Contract | Until the user deletes the receipt, the related transaction, or their account |
| Savings goals & shopping lists | Goal names, targets, progress, planned purchases | Manual entry | Core features | Contract | Life of account + 30 days |
| Investments | Holdings, quantities, values | Manual entry | Portfolio tracking | Contract | Life of account + 30 days |
| Kids profiles | Display name, age band, goals | Parent/guardian entry | Kids feature | Contract (with account holder) | Life of profile; parent can delete anytime |
| Payments | Plan, status, billing country (never full card numbers) | Payment processor | Billing | Contract; legal obligation | 6 years (tax law) |
| Usage analytics | Feature use, session data | App/site instrumentation | Product improvement | Legitimate interests / consent (cookies) | 24 months, then aggregated |
| Device & technical | Device type, OS, app version, IP | Automatic | Security, compatibility | Legitimate interests | 12 months |
| Support | Messages, attachments | Contact form, email | Support | Legitimate interests | 24 months after resolution |
3. What we deliberately do not collect
- Bank account connections — all transactions are entered manually or via receipt scanning.
- Full card numbers or CVVs (handled by the payment processor).
- Biometric data — Face ID/Touch ID stays on the user's device.
- Precise GPS location.
- Special category data (health, religion, ethnicity, etc.). If a user enters such information in free-text fields, it is treated as confidential, never analysed for profiling, and deleted on request.
- Children's data beyond what a parent enters into a Kids Profile.
- Data from data brokers or third-party enrichment services.
4. Rules for specific collection methods
Receipt scanning
Camera access is requested only when the user initiates a scan, with a clear in-app explanation. Images are processed for extraction only and retained under the user's control (deletable with the receipt, transaction, or account). Any third-party OCR/extraction service must be under a data processing agreement (DPA) and barred from using images for its own purposes, including model training.
AI MoneyPilot Coach
Only the fields needed for the specific insight are passed to the AI pipeline. Any third-party AI infrastructure provider acts as a processor under a DPA, may use the data only to provide the service, and is not permitted to use it for its own purposes, including model training. AI outputs are suggestions, never automated decisions with legal or similarly significant effect.
Forms and sign-ups
No pre-ticked consent boxes. Marketing consent is separate from account creation and never a condition of service. Every field must be justified; optional fields are labelled optional.
Analytics and cookies
Non-essential cookies fire only after consent. Analytics is configured for minimisation (IP truncation/anonymisation where the tool supports it). No cross-site advertising trackers.
5. New features: privacy by design
Before any new feature that collects or uses personal data ships:
- Complete a short Data Protection Impact Assessment (DPIA) screening; run a full DPIA where processing is likely high-risk (e.g. anything touching children's data, financial profiling, or new AI processing).
- Update the data collection register (section 2) and the ROPA.
- Update the public Privacy Policy if the change is user-visible, with notice before it takes effect.
- Confirm any new vendor has a signed DPA and, for non-UK vendors, valid transfer safeguards (IDTA / UK Addendum).
6. Access, sharing, and vendors
- Access to personal data is least-privilege and logged.
- Personal data is shared only with processors under DPAs, professional advisers, or authorities where legally required.
- We never sell personal data or share individual financial data with advertisers.
- An approved vendor list is maintained internally and reviewed annually.
7. Retention and deletion
- Retention periods in section 2 are enforced by scheduled deletion routines.
- Account deletion (user-initiated in-app or by email request to finvestodia.support@gmail.com) removes or anonymises personal data within 30 days, excluding billing records kept for 6 years and encrypted backups purged within 35 days.
- Kids Profile data is deleted immediately when a parent deletes the profile.
8. Incidents
Suspected personal data breaches are reported internally to the responsible person (Abdullahi Warsame) immediately. Breaches likely to risk individuals' rights are reported to the ICO within 72 hours, and affected users are notified where the risk is high.
9. Review
This policy is reviewed annually or after any material change to the product, vendors, or law. Next review due: July 2027.