Last updated 2026-06-17
Privacy Policy
Rinalance is designed for personal finance data, so this policy explains what we collect, why we use it, who helps us process it, and what controls you have.
Controller and Contact
Controller: Rinade d.o.o.
Registered address: Bolnička cesta 15, 10090, Zagreb, Croatia
Privacy contact: marko.uremovic@rinadely.com
Product URL: https://www.rinalance.com
Data We Process
- Account identity data, including email, name, and profile image.
- Financial app data you enter, including accounts, assets, transactions, budgets, categories, subscriptions, recurring transactions, and notification preferences.
- Billing state handled through Stripe, such as subscription status, customer identifier, invoice access, and limited payment method display data.
- Technical data needed to run the service, including sessions, device/browser information, security logs, and app diagnostics.
- Aggregated public-page analytics through Vercel Analytics, with authenticated routes excluded and query strings or hash fragments stripped before pageview events are sent.
Purposes and Legal Bases
- Provide the app, authenticate users, sync account data, and save preferences because this is necessary to perform the service.
- Process subscriptions and billing because this is necessary for paid plans and related contract administration.
- Maintain security, prevent abuse, troubleshoot errors, and improve reliability based on legitimate interests.
- Send requested service messages and enabled reminders because they are part of the service or based on your preferences.
- Measure public website traffic and improve marketing pages using cookie-free aggregated analytics based on legitimate interests.
Processors and Recipients
We use service providers to operate the app. They process data only for the purposes described here and under their own security and data protection terms.
- Clerk: Authentication, account management, and user sessions
- Convex: Application database, real-time sync, and backend functions
- Stripe: Checkout, subscriptions, billing portal, invoices, and payments
- Vercel Analytics: Cookie-free aggregated web analytics for public pages with sensitive URL data stripped
- Vercel Inc.: Hosting, delivery, logs, and operational security
Retention, Export, and Deletion
We keep account and finance data while your account is active or as needed to provide the service, meet legal obligations, resolve disputes, and maintain security. You can export your account data from Settings. You can delete your account from Settings; deletion removes your Rinalance user record and associated app data in Convex through backend cleanup triggers. Active paid subscriptions must be canceled in Stripe before account deletion.
Your Privacy Rights
Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to processing of your personal data and to withdraw consent where processing is based on consent. You may also have the right to complain to your local data protection authority.
Transfers and Security
Our providers may process data in countries outside your own. Where required, transfers should be protected by appropriate safeguards such as standard contractual clauses, adequacy decisions, or provider data processing terms. We use HTTPS in production, authenticated sessions, access controls, provider security controls, and data minimization practices to protect personal data.
Cookies and Analytics
Essential storage is used for authentication, security, preferences, and app functionality. Public-page analytics use Vercel Web Analytics without third-party analytics cookies. See the Cookies and Storage page for more detail.