Privacy Policy
Last updated: February 2025
1. Data Controller
For the purposes of the EU General Data Protection Regulation (GDPR) and applicable US privacy laws:
[Company Name]
[Registered Address]
Email: support@ypcashapp.com (for privacy requests and, if applicable, Data Protection Officer contact)
We are the Data Controller of personal data processed through the App.
2. Information We Collect
2.1 Information You Provide
- Transaction descriptions
- Income and expense amounts
- Category names
- Dates
- Currency selection
- Language and theme preferences
2.2 Authentication Data (Google Sign-In)
- Name
- Email address
- Google user ID
- Profile image (if provided)
We never collect your Google password.
2.3 Subscription Status
Subscription status is verified via the Apple App Store or Google Play. We do not process or store payment card or billing details.
3. How We Use Data
We process data to:
- Provide core app functionality
- Enable cloud synchronisation
- Authenticate users
- Verify subscription access
- Maintain system security
- Comply with legal obligations
Legal bases (GDPR): contract performance; legitimate interest (security, fraud prevention); consent (where used for authentication); and legal compliance.
4. Where Data Is Stored
4.1 Local Storage
Data you enter is stored on your device.
4.2 Cloud Storage
If sync is enabled, your synced data is hosted on Amazon Web Services (AWS EC2). Our servers are located in the European Union. Data is encrypted in transit (HTTPS).
5. International Transfers
If you access the App from outside the EU, your data may still be processed in the EU (where our servers are located). Where any transfer of personal data outside the European Economic Area occurs, we ensure appropriate safeguards are in place, such as adequacy decisions, Standard Contractual Clauses, or other mechanisms recognised under GDPR. We also comply with applicable US privacy laws where relevant.
6. Data Sharing
We share data only with:
- Amazon Web Services (AWS) — infrastructure hosting (EU)
- Google — authentication services
- Apple / Google Play — subscription processing
We do not sell personal data, use financial data for advertising, or share financial data with marketers. Processors act only on our instructions and under appropriate agreements.
7. Data Retention
- Local data remains on your device until you delete it or uninstall the App.
- Cloud data is retained until you delete your account.
- Account deletion permanently erases your data from our servers.
8. Your Rights (EU – GDPR)
If you are in the European Union (including the Netherlands), you have the right to:
- Access your data
- Rectify inaccuracies
- Erase your data ("right to be forgotten")
- Restrict processing
- Data portability
- Object to processing
- Lodge a complaint with a supervisory authority (e.g. the Dutch Autoriteit Persoonsgegevens)
Requests may be sent to: support@ypcashapp.com
9. Your Rights (California – CCPA/CPRA)
California residents have the right to:
- Know what personal data is collected
- Request deletion
- Correct inaccurate data
- Opt out of sale (we do not sell data)
- Non-discrimination for exercising these rights
Requests: support@ypcashapp.com
10. Data Security
We implement HTTPS encryption, token-based authentication, access controls, and server-level security. No system is 100% secure, but we use industry-standard safeguards.
11. Children's Privacy
The App is not directed at children under 13 (US) or under 16 (EU, where applicable). We do not knowingly collect children's data.
12. Changes to This Policy
We may update this Policy. Updated versions will be posted here with a revised "Last updated" date. We encourage you to review this Policy periodically.
13. Contact
[Company Name]
[Registered Address]
Email: support@ypcashapp.com