Smart Fin 365Plan Smart. Live Better.
Smart Fin 365 Legal

Privacy Policy

How Smart Fin 365 handles account, Google Drive, subscription, payment and audit information.

Customer-facing legal document Version: next approved release Effective date: to be approved

Overview

This Privacy Policy explains how Smart Fin 365 processes information needed to provide secure personal and family financial services.

Core principle: your Smart Fin 365 financial files remain associated with and owned through your Google account, while Smart Fin 365 processes permitted information to provide the service.

Information we process

Smart Fin 365 may process registration identifiers, Role and Premium entitlement status, consent records, session and security events, Google authorization status, owner-scoped storage mappings, authorized financial records, backup and recovery metadata, support requests, subscription information and billing records.

For subscription and payment services, this may include the selected Plan, billing period, amount, payment or order reference, payment status, payment-verification status, subscription status, Premium entitlement status, renewal and expiry information, invoices, receipts, refunds and related billing and audit records.

Authentication and security

OAuth codes, access and refresh tokens, payment-provider credentials, secret keys, webhook secrets and other protected credentials are not intended to be exposed through the browser, support messages, user financial files or ordinary application logs.

Google authorization and your Google Drive

Smart Fin 365 uses Google authorization so that you can securely sign in and allow the application to maintain your Smart Fin 365 financial information in your own Google Drive. Your Google account remains the owner of that Drive storage.

Your Drive remains yours. Your Smart Fin 365 financial information is stored in Google Drive associated with your Google account. Smart Fin 365 does not transfer ownership of those files to Smart Fin 365, Cashfree, or another user.

Why Google asks for Drive permission

When you authorize Smart Fin 365, Google may display permission wording explaining that the application can create files or work with files that you open or make available to the application. This is Google's standard description of the Drive permission being requested. Smart Fin 365 uses that authorization to provide its private-storage functions, such as creating, locating, validating, reading and updating Smart Fin 365 data files, and supporting backup and recovery.

Smart Fin 365 uses Google's Drive file access permission for its application-managed storage rather than requesting unrestricted access to every file in your Google Drive. The application works with files it creates or files that have been made available to it through the permitted Google authorization.

Stored in your Google Drive Your Smart Fin 365 financial data and owner backups remain in storage associated with your Google account.
Owner-specific access Smart Fin 365 associates its managed Drive resources with the authenticated Smart Fin 365 registration so that one user's storage is not treated as another user's financial storage.
You remain in control You can review or revoke Smart Fin 365 access through your Google Account. Revoking access may prevent Smart Fin 365 from reading or updating your stored financial information until you authorize the application again.

What Smart Fin 365 uses the permission for

The Google Drive authorization may be used to create and maintain Smart Fin 365 storage, read your authorized Smart Fin 365 records when you use the application, save changes you make, validate that the correct owner storage is being used, maintain application data structure, and create or restore Smart Fin 365 backups where those functions are requested.

What this does not mean

Authorizing Smart Fin 365 does not mean that your entire Google Drive becomes Smart Fin 365 storage. The application is designed to use Google Drive for the files and storage resources required for Smart Fin 365 functionality. Unrelated personal documents, photographs, medical records, tax files and other Drive content are not part of your Smart Fin 365 financial dataset merely because they are stored in the same Google account.

Why the Google consent message can sound broader: Google describes the capabilities of the permission that an application receives. Smart Fin 365's use of that permission is limited by its own application design, owner-specific storage controls and this Privacy Policy.

How we protect against the wrong account or wrong storage

Smart Fin 365 validates the Google authorization and the registered storage relationship before using owner financial data. Application-managed Drive resources are associated with the relevant Smart Fin 365 registration and storage context. If the expected owner or storage relationship does not match, Smart Fin 365 is designed to stop the operation rather than silently treat another storage location as yours.

If you disconnect Google authorization

You may revoke Smart Fin 365's Google authorization through your Google Account. After authorization is revoked, Smart Fin 365 may no longer be able to load, synchronize, update, back up or restore the affected Drive information until you reconnect the appropriate Google account.

Disconnecting authorization does not automatically delete Smart Fin 365 files that remain in your Google Drive. This helps avoid an unexpected loss of your financial information simply because access was disconnected.

In simple terms: you authorize Smart Fin 365 to work with the Smart Fin 365 information required for the service, while your Google account remains the owner and storage location for your financial files. You can revoke that authorization through Google when you choose.

Payments and Cashfree

Smart Fin 365 currently uses Cashfree as its supported payment service provider. Information necessary to initiate, verify, reconcile or refund a payment may be exchanged with Cashfree.

Smart Fin 365 may receive payment status, transaction references, refund status and other provider evidence necessary to determine the outcome of a payment operation. Cashfree processes payment information according to its applicable terms and privacy practices.

Responsibility split: Cashfree processes the payment. Smart Fin 365 determines its own subscription, Premium entitlement, Role and application-access rules.

How we use information

Information may be processed for authentication, synchronization, financial calculations, reporting, reminders, backup and recovery, customer support, security, audit, Premium access, subscription administration, payment verification and payment reconciliation.

Smart Fin 365 does not sell user financial data.

Billing records and retention

Smart Fin 365 may retain invoices, receipts, payment and refund references, subscription history, accepted Plan/version information and related audit evidence where reasonably necessary for reconciliation, customer support, disputes, refunds, security, fraud prevention, accounting, audit or applicable legal requirements.

Ending a subscription, cancelling Premium or changing a Plan does not necessarily delete historical billing or subscription evidence.

Your choices

You may disconnect Google authorization and request appropriate access, correction or deletion assistance through Smart Fin 365 Support Assistant, subject to applicable security, audit and retention requirements.

Removing a Smart Fin 365 registration does not automatically delete Smart Fin 365 files remaining in your Google Drive.

Updates and contact

Material changes to this Privacy Policy receive a new version and may require acknowledgement.

For privacy questions, use Smart Fin 365 Support Assistant or contact support@smartfin365.com.