Privacy Policy

Privacy Policy

Our approach to privacy

Monflow’s mission is to help users manage their personal finances more effectively. We believe that financial data is among the most private types of information and should remain fully under the user’s control.

We do not sell, rent or share users’ personal data with third parties for marketing purposes.

Personal data is processed only to the extent necessary to provide Monflow services, ensure the security of the application and support its further development.

1. General information

This Privacy Policy sets out the rules for the processing of personal data of users of the Monflow application available at:

https://monflow.app

By using the application, you confirm that you have read this Privacy Policy.

2. Data controller

Netview Agency Spółka z ograniczoną odpowiedzialnością

Tax ID (NIP): 7343608489

REGON: 521685180

Registered office address: ul. Lwowska 35/6, 33-300 Nowy Sącz, Poland

Contact email: [email protected]

The Controller processes personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).

3. Scope of processed data

Data provided during registration
  • email address
  • password (stored in encrypted form)
Data related to the use of the application
  • financial data entered by the user (expenses, income, categories)
  • history of operations within the application
  • subscription status
Payment data
  • Stripe customer ID (customer_id)
  • subscription ID
  • payment status information

Payment card data is not stored by the Controller. Payments are handled by an external payment provider.

Technical data
  • IP address
  • browser and device data
  • cookies
  • system logs

4. Purposes and legal bases for data processing

Performance of a contract (Article 6(1)(b) GDPR)
  • creating and maintaining the user account
  • providing application services
  • managing subscriptions
Legal obligations (Article 6(1)(c) GDPR)
  • fulfilling obligations arising from legal provisions
Legitimate interest of the controller (Article 6(1)(f) GDPR)
  • ensuring system security
  • preventing abuse
  • statistical analysis of application performance
User consent (Article 6(1)(a) GDPR)
  • marketing (if the user has given consent)
  • analytical or marketing cookies

5. Data recipients

  • Stripe – payment and subscription processing
  • Google – analytics (Google Analytics)
  • Cookiebot – cookie consent management
  • Cloudflare – infrastructure protection and security
  • hosting and server infrastructure providers
  • IT service providers

6. Form security and bot protection

In order to protect registration and login forms against abuse and automated bot traffic, the service may use security tools provided by Cloudflare (e.g. Cloudflare Turnstile).

This solution may process technical data such as IP address, browser information or device information in order to assess whether a given action comes from a user or from an automated system.

7. Transfers of data outside the European Economic Area

Some data may be transferred to third countries (e.g. the USA) in connection with the use of services such as Stripe, Google or OpenAI.

Data transfers are carried out on the basis of appropriate legal mechanisms such as Standard Contractual Clauses (SCCs) or a European Commission adequacy decision.

8. Data retention period

  • account data – for the duration of the contract and until the account is deleted
  • accounting data – for the period required by law
  • marketing data – until consent is withdrawn
  • technical data and logs – up to 12 months

9. User rights

  • right of access to data
  • right to rectification
  • right to erasure
  • right to restriction of processing
  • right to data portability
  • right to object
  • right to withdraw consent

The user also has the right to lodge a complaint with the President of the Personal Data Protection Office (UODO).

10. Is providing data mandatory?

Providing data is voluntary, but necessary to create an account and use the application’s features.

11. Data security

  • password encryption
  • encrypted HTTPS connections
  • restricted administrative access
  • server infrastructure security measures

12. Cookies (Cookie Policy)

The service uses cookies to ensure the proper functioning of the application and to analyse website traffic.

Cookie consent is managed using the Cookiebot tool. The user may change or withdraw consent at any time using the consent management panel.

13. Changes to the Privacy Policy

The Controller reserves the right to make changes to this Privacy Policy.

The current version of the document is always available at: monflow.app