Data Collection Policy

Last updated: 26 July 2026

Owner: WAW Group Global Limited (Company No. 15008409) — responsible person: Abdullahi Warsame, Director

Applies to: all Finvestodia products, staff, and any contractors or collaborators

This policy sets out what data Finvestodia collects, the rules governing collection, and the standards every feature must meet before it ships. The public-facing Privacy Policy describes our practices to users; this document governs them internally and can also be published for transparency.

1. Principles

All data collection at Finvestodia must satisfy the UK GDPR principles:

  1. Lawfulness, fairness, transparency — every data point has a documented legal basis and is disclosed in the Privacy Policy before collection begins.
  2. Purpose limitation — data collected for one purpose is not reused for an incompatible one without a new basis (and, where needed, consent).
  3. Data minimisation — we collect the minimum needed for the feature to work. "Might be useful later" is not a reason to collect.
  4. Accuracy — users can view and correct their data in-app.
  5. Storage limitation — every data category has a retention period and an owner (see schedule below).
  6. Integrity and confidentiality — encryption in transit and at rest; least-privilege access.
  7. Accountability — collection decisions are recorded in the Record of Processing Activities (ROPA).

2. Data collection register

CategoryExamplesCollected viaPurposeLegal basisRetention
Identity & accountName, email, hashed password, country, currencySign-up, settingsAccount provisionContractLife of account + 30 days
WaitlistEmail, sign-up date/sourceWebsite formLaunch communicationsConsentUntil unsubscribe / 24 months post-launch
Transactions & budgetsAmounts, merchants, categories, notesManual entry, receipt scanCore features, reports, AI coachingContractLife of account + 30 days
Receipt imagesPhoto, extracted merchant/amount/dateCamera / photo uploadExpense creationContractUntil the user deletes the receipt, the related transaction, or their account
Savings goals & shopping listsGoal names, targets, progress, planned purchasesManual entryCore featuresContractLife of account + 30 days
InvestmentsHoldings, quantities, valuesManual entryPortfolio trackingContractLife of account + 30 days
Kids profilesDisplay name, age band, goalsParent/guardian entryKids featureContract (with account holder)Life of profile; parent can delete anytime
PaymentsPlan, status, billing country (never full card numbers)Payment processorBillingContract; legal obligation6 years (tax law)
Usage analyticsFeature use, session dataApp/site instrumentationProduct improvementLegitimate interests / consent (cookies)24 months, then aggregated
Device & technicalDevice type, OS, app version, IPAutomaticSecurity, compatibilityLegitimate interests12 months
SupportMessages, attachmentsContact form, emailSupportLegitimate interests24 months after resolution

3. What we deliberately do not collect

  • Bank account connections — all transactions are entered manually or via receipt scanning.
  • Full card numbers or CVVs (handled by the payment processor).
  • Biometric data — Face ID/Touch ID stays on the user's device.
  • Precise GPS location.
  • Special category data (health, religion, ethnicity, etc.). If a user enters such information in free-text fields, it is treated as confidential, never analysed for profiling, and deleted on request.
  • Children's data beyond what a parent enters into a Kids Profile.
  • Data from data brokers or third-party enrichment services.

4. Rules for specific collection methods

Receipt scanning

Camera access is requested only when the user initiates a scan, with a clear in-app explanation. Images are processed for extraction only and retained under the user's control (deletable with the receipt, transaction, or account). Any third-party OCR/extraction service must be under a data processing agreement (DPA) and barred from using images for its own purposes, including model training.

AI MoneyPilot Coach

Only the fields needed for the specific insight are passed to the AI pipeline. Any third-party AI infrastructure provider acts as a processor under a DPA, may use the data only to provide the service, and is not permitted to use it for its own purposes, including model training. AI outputs are suggestions, never automated decisions with legal or similarly significant effect.

Forms and sign-ups

No pre-ticked consent boxes. Marketing consent is separate from account creation and never a condition of service. Every field must be justified; optional fields are labelled optional.

Analytics and cookies

Non-essential cookies fire only after consent. Analytics is configured for minimisation (IP truncation/anonymisation where the tool supports it). No cross-site advertising trackers.

5. New features: privacy by design

Before any new feature that collects or uses personal data ships:

  1. Complete a short Data Protection Impact Assessment (DPIA) screening; run a full DPIA where processing is likely high-risk (e.g. anything touching children's data, financial profiling, or new AI processing).
  2. Update the data collection register (section 2) and the ROPA.
  3. Update the public Privacy Policy if the change is user-visible, with notice before it takes effect.
  4. Confirm any new vendor has a signed DPA and, for non-UK vendors, valid transfer safeguards (IDTA / UK Addendum).

6. Access, sharing, and vendors

  • Access to personal data is least-privilege and logged.
  • Personal data is shared only with processors under DPAs, professional advisers, or authorities where legally required.
  • We never sell personal data or share individual financial data with advertisers.
  • An approved vendor list is maintained internally and reviewed annually.

7. Retention and deletion

  • Retention periods in section 2 are enforced by scheduled deletion routines.
  • Account deletion (user-initiated in-app or by email request to finvestodia.support@gmail.com) removes or anonymises personal data within 30 days, excluding billing records kept for 6 years and encrypted backups purged within 35 days.
  • Kids Profile data is deleted immediately when a parent deletes the profile.

8. Incidents

Suspected personal data breaches are reported internally to the responsible person (Abdullahi Warsame) immediately. Breaches likely to risk individuals' rights are reported to the ICO within 72 hours, and affected users are notified where the risk is high.

9. Review

This policy is reviewed annually or after any material change to the product, vendors, or law. Next review due: July 2027.