Privacy Policy
This policy explains how MONVELOP handles account, budgeting and read-only bank data.
1. Who controls your data
The operator of MONVELOP is the controller of personal data processed to provide the application. Privacy and data-rights requests can be sent to support@monvelop.com.
MONVELOP is a budgeting tool. It is not a bank, payment institution or financial adviser, and it cannot initiate payments from your bank account.
2. Data we process
- Account data: email address, preferred language, account identifiers and timestamps.
- Authentication data: a password hash, session and password-reset token hashes, Google account identifier and login-security records. MONVELOP never receives your Google password.
- Bank-connection data: provider, selected institution, connection and account identifiers, currency, connection status and synchronization timestamps.
- Financial data: account balances and imported transaction amount, date, merchant, description, category, booking status and related identifiers.
- Budgeting data: income plans, envelopes, allocations, transfers, merchant rules, alerts, insights and choices made during onboarding.
- Technical and support data: IP address and login results used for abuse prevention, plus the topic and content of messages sent to support.
- Device-local data: language preference and unfinished onboarding choices may be stored in the browser on that device.
3. Where data comes from
Most data comes directly from you. When you connect a bank, account balances and transaction data are obtained from your financial institution through GoCardless Bank Account Data after you authorize access.
MONVELOP does not receive or store your online-banking password. Bank access is read-only and does not allow MONVELOP to make payments.
4. Why we use data and our legal bases
- To create and operate your account, synchronize bank data, build budgets and provide requested features — performance of our service agreement.
- To protect accounts, prevent abuse, investigate failures and maintain service reliability — our legitimate interests in security and operation.
- To send password-reset and support messages — performance of the requested service and our legitimate interest in assisting users.
- To comply with binding legal requests and applicable obligations — compliance with law.
- Where processing relies on consent, you may withdraw it without affecting processing already carried out.
5. Who may receive data
MONVELOP does not sell personal data and does not use bank transaction data for third-party advertising.
- GoCardless Ltd. and your financial institution, for read-only open-banking access that you authorize.
- Google, when you choose Sign in with Google and when configured email infrastructure delivers password-reset or support email.
- Infrastructure providers used to host the application, databases and network services, acting under appropriate contractual safeguards.
- Professional advisers, authorities or courts when disclosure is required by law or necessary to establish or defend legal claims.
6. Retention and deletion
Signed-in users can permanently delete their account in Account settings. If you cannot sign in, request deletion at support@monvelop.com; we may verify that the request comes from the account owner. Limited records may be retained only where required for security, legal obligations or claims.
- When you delete your account, MONVELOP removes the operational profile, bank connection, imported transactions and budgeting data. The GoCardless requisition is revoked before local financial data is removed.
- Refresh sessions expire after 30 days; expired records are removed by an automated cleanup process.
- Password-reset links expire after 30 minutes and are stored only as cryptographic hashes.
- Security logs and support correspondence are kept only as long as reasonably necessary to prevent abuse, resolve the request and meet legal obligations.
7. Security, rights and choices
We may update this policy when the product, providers or legal requirements change. The effective date will be updated and material changes will be communicated where required.
- Access tokens are short-lived; refresh sessions use an HttpOnly cookie, and stored reset/session tokens are hashed.
- Signed-in users can download a machine-readable ZIP export from Account settings after confirming their identity.
- You may request access, correction, deletion, restriction, portability or object to processing where GDPR provides that right.
- You may withdraw consent and complain to your competent supervisory authority; in Poland this is the President of the Personal Data Protection Office (UODO).
- MONVELOP may generate budgeting insights and categorization suggestions, but it does not make decisions that produce legal or similarly significant effects.
- MONVELOP is not directed to children. A parent or guardian should contact us if a child supplied personal data.
