Privacy Policy
What we collect, why, how we protect it, and your rights as a user.
Heads up: this is a placeholder document. The final policy will be reviewed by privacy counsel before launch and may differ. If you need definitive answers in the meantime, email support@reservwise.com.
Plain-English summary
ReservWise is a financial tool for entrepreneurs with variable income. We collect the minimum data we need to run the service, we never sell it, and we never see your bank password (Plaid handles bank auth on its own infrastructure). You can export or delete your data at any time.
What we collect
- Account data — your email, name, hashed password, business entity type, and timezone.
- Financial data via Plaid — read-only transaction lists, account balances, and account metadata. Never your bank login credentials.
- Stripe data — invoice and payout metadata if you connect Stripe. We don't see your customers' card numbers.
- Usage data — pages visited, features used, error logs. Used to improve the product.
- Billing data — handled by Stripe. We see plan and last 4 digits, not your full card.
How we use it
- Run the core product: reserve allocation, forecasting, tax math, owner draws.
- Send transactional email: receipts, alerts you opted into, security notices.
- Improve the product based on aggregated, anonymized usage patterns.
- Comply with legal and tax obligations.
We do not sell your data, share it with advertisers, or use it to train external AI models.
Who we share with
A short list of essential subprocessors:
- Plaid — bank link infrastructure
- Stripe — billing + (optionally) your customer invoicing
- Hostinger / our cloud provider — application hosting
- An email provider — transactional email delivery (final vendor pending)
- An error-logging provider — bug detection and triage (final vendor pending)
A complete, current subprocessor list will live at support.reservwise.com/legal/subprocessors at launch.
Bank and financial data
Bank credentials are handled by Plaid. We never see your bank username or password. We receive a read-only token and use it to fetch transactions and balances.
You can revoke our access at any time from inside ReservWise (Settings → Connected Accounts) or from your bank's portal.
Read more in Security.
Data retention
- Active accounts — we retain your data for as long as your account is open.
- Closed accounts — we delete personal data within 30 days of closure, except where law requires retention (e.g., financial records).
- Backups — backups are rotated within 90 days.
- Anonymized analytics — may be retained indefinitely.
Your rights
You can:
- Export all your data in CSV and JSON (Settings → Data Export).
- Correct any inaccurate data.
- Delete your account and associated data.
- Object to specific processing.
- If you are in the EU/UK, exercise rights under GDPR.
- If you are in California, exercise rights under CCPA.
To exercise any right, email support@reservwise.com.
Cookies & tracking
We use a minimal set of first-party cookies for authentication and session state. We do not use advertising cookies. A full cookie list will accompany the production policy.
Children's privacy
ReservWise is not intended for users under 18. We do not knowingly collect data from minors.
Contact
Questions about this policy: support@reservwise.com
Privacy-specific concerns: privacy@reservwise.com (placeholder address — will be active before launch)
Security disclosures: security@reservwise.com