Legal
Privacy Policy
This Privacy Policy explains how BouncySpark.com (“BouncySpark,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you use our mobile application and related services (collectively, “our application” or the “Service”).
By creating an account or using the Service, you agree to this Privacy Policy. If you do not agree, please do not use the Service.
1. Who we are
BouncySpark provides a consumer financial application that helps you track portfolios, link bank and investment accounts, and receive related notifications. We are the data controller for personal information described in this policy.
Privacy and data requests: security@bouncyspark.com
2. Information we collect
We collect information you provide, information generated when you use the Service, and information from third parties that help us operate the Service.
2.1 Information you provide
| Category | Examples |
|---|---|
| Account information | Phone number (required for sign-in), email address, display name, profile photo |
| Authentication data | SMS one-time passcodes you enter; optional authenticator-app codes if you enable two-factor authentication (2FA) |
| Financial linking choices | Institutions you choose to connect through Plaid; accounts you select to link |
| Portfolio data | Holdings, asset groups, custom assets, and related labels you enter |
| Communications | Messages you send to security@bouncyspark.com for support or data requests |
2.2 Information we collect automatically
| Category | Examples |
|---|---|
| Device and app data | Device type, operating system, app version, language, and general usage events needed to operate and secure the Service |
| Push notification tokens | Firebase Cloud Messaging (FCM) device tokens if you enable push notifications |
| Log data | Server logs such as request timestamps, IP address, and error diagnostics (we avoid logging full phone numbers, account numbers, or Plaid tokens) |
| Session data | Short-lived access tokens and refresh tokens used to keep you signed in |
2.3 Information from third parties
When you link a financial institution, Plaid provides account and financial data you authorize, such as institution name, account names, masked account numbers, balances, and holdings, depending on what you connect and what the institution makes available.
We may also receive market or reference data from data providers to display quotes and related information.
3. How we use your information
We use personal information to:
- Provide the Service — create and manage your account, authenticate you, display linked accounts and portfolio information, and deliver in-app and push notifications you expect
- Link financial accounts — initiate and maintain Plaid connections you request
- Protect the Service — detect fraud, abuse, and security incidents; enforce our terms; and troubleshoot errors
- Communicate with you — send SMS verification codes, service-related messages, and responses to support or privacy requests
- Improve the Service — understand aggregate usage patterns and fix bugs (we do not sell your personal information)
- Comply with law — respond to lawful requests and meet regulatory obligations
We use data only for purposes compatible with those above or as disclosed when we collect it.
4. Legal bases for processing (EEA/UK users)
If you are in the European Economic Area or United Kingdom, we process personal data based on:
| Purpose | Legal basis |
|---|---|
| Providing the Service you request | Performance of a contract |
| Security, fraud prevention, and service improvement | Legitimate interests (balanced against your rights) |
| SMS authentication and essential notices | Performance of a contract / legitimate interests |
| Optional push notifications | Your consent (you may disable notifications in device settings) |
| Legal compliance | Legal obligation |
You may withdraw consent where processing is consent-based without affecting the lawfulness of processing before withdrawal.
5. How we share information
We do not sell your personal information. We share information only as described below.
5.1 Service providers
We use trusted third parties that process data on our behalf under contractual obligations to protect it:
| Provider | Role | Data involved |
|---|---|---|
| Plaid Inc. | Bank and investment account linking | Link tokens, institution and account metadata, balances, holdings, and related financial data you authorize |
| Twilio Inc. | SMS one-time passcodes for sign-in | Your phone number and OTP delivery metadata |
| Google Cloud Platform (GCP) | Hosting, storage, logging, secrets management | Application data stored and processed in our production environment |
| Cockroach Labs (CockroachDB Cloud) | Managed database | Account, authentication, Plaid connection, and portfolio data |
| Google Cloud Storage (GCS) | Profile images and related files | Files you upload (e.g., profile photos) |
| Google Firebase | Push notifications (FCM) and optional market-data caching (Firestore) | Device tokens; non-financial reference or quote data where enabled |
These providers may only use your information to perform services for us, subject to their own privacy policies and applicable law.
5.2 Other disclosures
We may disclose information if we believe it is reasonably necessary to:
- Comply with law, regulation, legal process, or governmental request
- Protect the rights, property, or safety of BouncySpark, our users, or others
- Detect, prevent, or address fraud, security, or technical issues
- Complete a merger, acquisition, or sale of assets (with notice where required)
We may share aggregated or de-identified information that cannot reasonably identify you.
6. Plaid and your financial data
When you choose to link an account, you interact with Plaid Link, which is operated by Plaid. Plaid collects credentials and financial data according to its own privacy policy and the disclosures shown during linking.
What we receive from Plaid (when you connect): institution name; account identifiers and masks; balances; holdings and related financial data needed for portfolio tracking.
How we use it: to display linked accounts in our application and support features you request.
Your choices: you can disconnect an institution in the app. We call Plaid to remove the connection and delete related data from our systems. Disconnecting stops new data collection from that institution.
For more about Plaid’s practices, see Plaid’s End User Privacy Policy.
7. Authentication and sessions
7.1 SMS one-time passcodes (Twilio)
Sign-in uses your phone number as your account identifier. We send a one-time passcode by SMS through Twilio Verify. We store your phone number and account record; Twilio processes the phone number to deliver the message.
7.2 Optional authenticator app (TOTP)
You may optionally enable time-based one-time passwords (TOTP) using an authenticator app. If enabled, you must enter a code from your app in addition to SMS verification when signing in.
7.3 JWT sessions
After successful authentication, we issue a JSON Web Token (JWT) for short-lived API access and a refresh token stored securely to renew your session. You can sign out to invalidate active sessions. We do not include Plaid access tokens or full financial account numbers in JWTs.
8. Where we store data
Production data is hosted on Google Cloud Platform, primarily in the United States. Primary application data is stored in CockroachDB Cloud (PostgreSQL-compatible). Profile images and similar files are stored in Google Cloud Storage. Logs and operational telemetry are retained in GCP according to our retention schedule.
We use encryption in transit (TLS) and encryption at rest provided by our cloud infrastructure. Secrets such as API keys are stored in Google Secret Manager, not in application source code.
9. Data retention and deletion
We retain personal information only as long as needed to provide the Service and as described in our internal retention schedule. Summary:
| Data | Retention |
|---|---|
| Account and portfolio data | While your account is active |
| Plaid connections | While linked; removed when you unlink or delete your account |
| Authentication tokens | While active; deleted with account |
| Application logs | Approximately 90 days (operational; not a personal archive) |
| Database backups | Per provider schedule (typically 30–90 days); deleted account data may persist until backup expiry |
| Support correspondence | Up to 2 years, unless you request earlier deletion where feasible |
Account deletion: you may request deletion in the app (when available) or by emailing security@bouncyspark.com from your registered email or phone. We verify your identity, remove Plaid connections, delete associated data from our database and storage, and confirm when complete. We aim to complete automated deletions promptly and manual requests within 30 days.
Legal hold: we may retain data longer when required by law or to resolve disputes or investigations.
Detailed procedures are documented in our Data Retention and Deletion Policy (internal reference for operations and partners).
10. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, and to object to or restrict certain processing.
10.1 All users
You can:
- Update profile information in the app where available
- Disconnect financial institutions in the app
- Delete your account via in-app flow or by contacting security@bouncyspark.com
- Opt out of non-essential processing by disconnecting Plaid items, disabling push notifications, or contacting us
10.2 California residents (CCPA/CPRA)
California residents have additional rights, including:
- Know what personal information we collect, use, and disclose
- Delete personal information (subject to exceptions)
- Correct inaccurate personal information
- Opt out of sale or sharing — we do not sell or share personal information for cross-context behavioral advertising
To exercise rights, email security@bouncyspark.com. We verify requests using information associated with your account. You may designate an authorized agent where permitted by law. We do not discriminate against you for exercising privacy rights.
10.3 EEA/UK residents (GDPR)
Where GDPR applies, you may also have the right to lodge a complaint with your local supervisory authority. Our contact for GDPR requests is security@bouncyspark.com.
10.4 Response times
We acknowledge privacy requests within 10 business days and aim to complete them within 30 days, unless we notify you of a lawful extension.
11. Children’s privacy
Our Service is not directed to children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact security@bouncyspark.com and we will delete it.
12. International users
BouncySpark is based in the United States. If you access the Service from outside the United States, your information may be transferred to, stored in, and processed in the United States and other countries where our service providers operate. Those countries may have different data protection laws than your country. Where required, we rely on appropriate safeguards for international transfers.
13. Security
We implement administrative, technical, and organizational measures designed to protect personal information, including access controls, encryption, authenticated APIs, and monitoring. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
If you believe your account has been compromised, contact security@bouncyspark.com promptly.
14. Third-party links and services
The Service may link to third-party websites or services (for example, your financial institution through Plaid). Their privacy practices are governed by their own policies, not this one.
15. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will post the updated policy at https://bouncyspark.com/privacy and update the effective date. Continued use of the Service after changes become effective means you accept the updated policy. For significant changes, we may provide additional notice in the app or by email where appropriate.
16. Contact us
For privacy questions, data requests, or complaints:
Email: security@bouncyspark.com
Organization: BouncySpark.com
We will respond to verified requests in accordance with applicable law and the timelines described above.
17. Summary for app stores and Plaid
- Published URL (when live): https://bouncyspark.com/privacy
- Effective date: June 18, 2026
- Contact for privacy: security@bouncyspark.com
- Financial data: obtained only with your consent through Plaid; removable by unlinking or account deletion
- We do not sell personal information