1. Data We Collect
FinTracker may process the following types of data depending on how the project is configured:
- Account data, including name, email address, Google account identifier, profile image URL, and role assignments.
- Workspace data, including businesses, cashbooks, active workspace selections, and administrative settings.
- Finance records, including contacts, categories, payment modes, transaction amounts, dates, remarks, and status fields.
- Operational data, including audit logs, email send logs, background job status, report filters, and error logs.
- Uploaded files and metadata, including file names, content types, sizes, storage keys, and related module records.
2. How We Use Data
Data is used to authenticate users, display dashboards, maintain module records, generate Excel/PDF exports, support workspace switching, deliver application emails, troubleshoot errors, maintain audit history, and improve operational reliability.
3. Authentication and Third-Party Services
FinTracker uses Google Sign-In for authentication and user identification. Google may provide only the minimum profile information needed to create or match an application user: Google account identifier, name, email address, verified email status, and profile image URL when available.
FinTracker does not request or access Gmail, Google Drive, Google Calendar, Google Contacts, Google Photos, payment methods, Google passwords, or files stored in your Google account. Google data is not sold and is not used for advertising. It is used only to authenticate the user, maintain the application account, display profile information, and protect access to FinTracker workspaces.
Hosting configurations may also use PostgreSQL, Redis, Cloudflare R2 compatible storage, SMTP providers, Hangfire, Serilog, Seq, and frontend CDN providers.
4. Files, Reports, and Exports
Users can attach files to supported records and download reports in Excel or PDF format. Exported files may contain financial and personal information from the selected filters. You should store and share exports according to your organization's data handling rules.
5. Retention
Retention depends on the deployment and storage configuration. Demo or reference deployments may reset records, while production deployments should define database, log, attachment, and backup retention policies separately.
6. Security
FinTracker uses authenticated routes, role-based admin areas, secure cookie settings, anti-forgery validation, audit logs, configurable file validation, and structured error handling. No web system can guarantee absolute security, so administrators should keep credentials, deployment secrets, and database access controls protected.
Financial records entered into FinTracker remain inside the configured application database and storage services. Google Sign-In is used for identity verification only; it does not give FinTracker access to read financial records from any Google product.
7. Your Choices
Depending on your deployment and applicable law, you may request access, correction, export, or deletion of personal data. Workspace owners and administrators should verify requests before making changes to financial or audit records.
8. Contact
Privacy questions can be sent to [email protected].