Privacy Policy
Last updated: 26 April 2026
Who we are
Funance is operated by Troy Popovic, an Australian individual based in Melbourne, Victoria. For the purposes of the Privacy Act 1988 (Cth) and the Australian Privacy Principles, Funance is the entity collecting and managing your data.
Contact: hello@funance.com.au
What information we collect
Account information
- Email address (for account creation and magic-link login)
- Display name (optional)
- Authentication session tokens (managed by Supabase)
Financial data you enter
- Income, expenses, debts, assets, savings goals, subscriptions
- Names you give to budget categories or partners
- Property values, super balances, novated lease details
- Birth years (used for retirement projections only)
This data is what we exist to help you manage. It is encrypted in transit (TLS 1.3) and at rest in our database.
Payment information
Payments are processed by Stripe. We never see or store your full credit card number. We retain only the Stripe customer ID and subscription status, which is enough for us to know whether your account is active.
Technical information
- IP address (used for rate limiting and abuse prevention; not stored long-term)
- Browser user-agent string (for debugging)
- Sync activity logs (timestamp + payload size only, not contents)
What we do NOT collect
- We do not use third-party analytics that profile you (e.g. Google Analytics, Facebook Pixel)
- We do not sell your data to anyone, ever
- We do not share your data with advertisers or data brokers
- We do not access bank accounts via Open Banking or screen scraping — all data you see in Funance is data you entered yourself
How we use your information
- Provide the service: store and sync your financial data across your devices
- Authenticate you: verify your identity at login via magic-link email
- Process payments: via Stripe, for subscription billing
- Send essential emails: account confirmation, payment receipts, password resets, security alerts. You cannot opt out of these as they are required for the service to function.
- Improve the product: we may look at aggregated usage patterns (e.g. which tabs are most-used) but never at individual user data without your consent
- Provide support: if you contact us, we may temporarily access your account to diagnose the issue. We log such access.
Where your data is stored
Funance uses several service providers to deliver the product. Each is selected for security and reliability. Some of these providers store or process data outside Australia.
Application data (Supabase)
Your financial data, account profile, and session information are stored with Supabase in their Sydney region (ap-southeast-2) — physically located in Australia.
Payment processing (Stripe)
Stripe processes payment information per their own privacy practices. Stripe processes payment data in the United States. View Stripe's privacy policy.
Transactional email (Resend)
Email delivery (magic links, payment receipts, trial-ending notices) is handled by Resend, which processes email metadata (your email address, the message subject, and timestamps) on AWS infrastructure in the United States. The body content of the emails passes through this infrastructure during delivery but is not retained beyond Resend's standard logging period.
Hosting (Vercel)
The Funance website and API are deployed on Vercel. Static page content is served via Vercel's global CDN (which has nodes worldwide), and our API functions execute in Vercel's Sydney region (syd1).
Cross-border disclosure (APP 8)
Some of the service providers above are located outside Australia. Under Australian Privacy Principle 8, we are required to disclose this to you and to take reasonable steps to ensure overseas recipients comply with the APPs.
By using Funance, you consent to your personal information being disclosed to the following overseas recipients:
- Stripe (United States) — for payment processing
- Resend (United States) — for transactional email delivery
- Vercel (United States, with Sydney edge nodes) — for hosting and content delivery
You acknowledge that, by giving this consent, APP 8 will not apply to these disclosures. This means that if an overseas recipient handles your information in a way that would breach the APPs, Funance will not be accountable under Section 16C of the Privacy Act for that breach. You may withdraw this consent at any time by deleting your account, which will stop further data being sent to these providers.
We choose providers we consider to have substantially similar privacy and security standards to the APPs. All data in transit is encrypted with TLS 1.3.
Your rights
Under Australian privacy law, you have the right to:
- Access your data — there's an export button in the app, or email us
- Correct your data — you can edit anything in the app at any time
- Delete your data — there's a delete-account button in the app, which removes all data and cancels any active subscription. Email us if you can't access your account.
- Object to specific uses — contact us
- Lodge a complaint — with the Office of the Australian Information Commissioner (oaic.gov.au)
How long we keep your data
- Active accounts: as long as the account exists
- Deleted accounts: all financial data and profile information removed immediately on deletion request
- Payment records: retained by Stripe per their policies (typically 7 years for tax compliance)
- Server logs: 30 days, then deleted
Cookies
We use first-party cookies for authentication (keeping you logged in). We do not use tracking cookies, advertising cookies, or third-party cookies. No cookie consent banner is required.
Children
Funance is not intended for users under 18. We do not knowingly collect data from minors. If you believe a child has used Funance, please contact us so we can delete the account.
Security
We take security seriously. Specifically:
- All data in transit is encrypted with TLS 1.3
- Authentication is passwordless (magic-link); we never store passwords
- Database access is restricted by Row Level Security policies
- Application secrets are stored in encrypted environment variables, never in code
- We will notify you within 72 hours of any breach affecting your data, in line with the Notifiable Data Breaches scheme
Changes to this policy
We may update this policy occasionally. Material changes will be communicated by email at least 14 days before they take effect. Minor changes (e.g. typo corrections) may be made silently. The "last updated" date at the top of this page reflects the most recent change.