Privacy Policy
Last updated: July 2026
1. Information We Collect
We collect information you provide directly to us:
- Account information: name, email, password, currency preferences
- Financial data: transactions, budgets, accounts, categories you create
- Usage data: how you interact with our service (pages visited, features used)
2. How We Use Your Information (GDPR Article 6 — Lawful Basis)
We process your personal data under the following lawful bases:
- Contract performance (Art. 6(1)(b)): Processing necessary to provide our financial management service to you
- Consent (Art. 6(1)(a)): Analytics and optional tracking with your explicit consent via our cookie banner
- Legitimate interests (Art. 6(1)(f)): Security monitoring, fraud prevention, and service improvement
- Legal obligations (Art. 6(1)(c)): Compliance with applicable laws and regulations
3. Data Sharing
We do not sell, trade, or rent your personal information to third parties. We may share your data only in the following limited circumstances:
- With your explicit consent
- To comply with legal requirements
- To protect our rights and safety
- With service providers who help us operate (hosting, analytics, payment processing)
4. Data Security
We use industry-standard AES-256 encryption to protect your data both in transit and at rest. Your financial data is stored securely and is never shared with advertising networks.
5. Your Rights
Right of Access (Article 15)
You can view all your data in your account and request a full export at any time from Settings.
Right to Rectification (Article 16)
You have the right to correct inaccurate or incomplete personal data. You can update your profile information anytime from your account settings. For data you cannot correct yourself, contact us and we will rectify it within 30 days.
Right to Erasure (Article 17)
You can request deletion of your account and all associated data. To protect against accidental loss, deletion is scheduled with a 30-day grace period during which you can cancel. After 30 days, all data is permanently removed.
Right to Restriction of Processing (Article 18)
You have the right to request that we limit the processing of your personal data. When granted, we will only store your data and will not process it further without your consent, except for legal claims. To request restriction, contact us at [email protected].
Right to Data Portability (Article 20)
You can export your data at any time in JSON format from Settings, receiving a machine-readable copy of all your personal data.
Right to Object (Article 21)
You have the right to object to processing of your personal data based on legitimate interests. You can opt out of analytics tracking at any time via the cookie preferences. For other processing, contact us and we will cease processing unless we can demonstrate compelling legitimate grounds.
6. Data Retention
We retain your data for as long as your account is active. Upon account deletion, we permanently delete your data within 30 days, except where retention is required by law. Account deletion requests include a 30-day grace period during which you can cancel the request.
7. Processing Activities Register (Article 30)
We maintain a record of all processing activities as required by GDPR Article 30. The main categories of processing include:
- Account management: registration, authentication, profile updates
- Financial data processing: storage and computation of transactions, budgets, debts, accounts
- Analytics: usage tracking with explicit user consent only
- Security monitoring: login attempts, 2FA, audit logging
- Notifications: email and in-app notifications for service updates
- Payment processing: billing subscriptions via LemonSqueezy
A detailed register is available upon request by contacting our DPO.
8. Data Breach Notification (Articles 33 & 34)
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the supervisory authority within 72 hours of becoming aware of the breach (Article 33). If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay (Article 34). Notifications will describe the nature of the breach, the likely consequences, and the measures taken or proposed to address it.
9. Data Protection Impact Assessment (Article 35)
We conduct Data Protection Impact Assessments (DPIAs) before implementing new processing activities that are likely to result in a high risk to the rights and freedoms of individuals. This includes deployment of new analytics technologies, changes to data encryption, and introduction of automated decision-making. DPIAs evaluate the necessity, proportionality, and risks of the processing, along with measures to mitigate those risks.
10. Philippines Data Privacy Act Compliance (R.A. 10173)
Iponify is fully compliant with the Philippines Data Privacy Act of 2012 (Republic Act No. 10173). As a financial management platform serving Filipino families and OFWs worldwide, we adhere to the following DPA principles:
- Transparency: We clearly inform you about how your data is collected and used
- Legitimate purpose: Your data is processed only for specified, explicit, and legitimate purposes
- Proportionality: We collect only data that is necessary and relevant to our services
Under the DPA, you have the right to be informed, object to processing, access your data, rectify errors, suspend or block processing, and data portability. We fulfill all these rights through our platform features and responsive support.
For more information about your rights under Philippine data privacy law, visit the National Privacy Commission at www.privacy.gov.ph.
11. Contact Our Data Protection Officer
For any privacy-related questions, data subject requests, or concerns about how we handle your information, please contact our Data Protection Officer:
We respond to all data subject requests within 30 days as required by both GDPR and the Philippines DPA.