BouncySpark BouncySpark

HQ Portfolio Let's chat! Our story

Legal

Privacy Policy

Version
1.0
Effective date
June 18, 2026
Contact
security@bouncyspark.com

This Privacy Policy explains how BouncySpark.com (“BouncySpark,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you use our mobile application and related services (collectively, “our application” or the “Service”).

By creating an account or using the Service, you agree to this Privacy Policy. If you do not agree, please do not use the Service.


1. Who we are

BouncySpark provides a consumer financial application that helps you track portfolios, link bank and investment accounts, and receive related notifications. We are the data controller for personal information described in this policy.

Privacy and data requests: security@bouncyspark.com


2. Information we collect

We collect information you provide, information generated when you use the Service, and information from third parties that help us operate the Service.

2.1 Information you provide

CategoryExamples
Account informationPhone number (required for sign-in), email address, display name, profile photo
Authentication dataSMS one-time passcodes you enter; optional authenticator-app codes if you enable two-factor authentication (2FA)
Financial linking choicesInstitutions you choose to connect through Plaid; accounts you select to link
Portfolio dataHoldings, asset groups, custom assets, and related labels you enter
CommunicationsMessages you send to security@bouncyspark.com for support or data requests

2.2 Information we collect automatically

CategoryExamples
Device and app dataDevice type, operating system, app version, language, and general usage events needed to operate and secure the Service
Push notification tokensFirebase Cloud Messaging (FCM) device tokens if you enable push notifications
Log dataServer logs such as request timestamps, IP address, and error diagnostics (we avoid logging full phone numbers, account numbers, or Plaid tokens)
Session dataShort-lived access tokens and refresh tokens used to keep you signed in

2.3 Information from third parties

When you link a financial institution, Plaid provides account and financial data you authorize, such as institution name, account names, masked account numbers, balances, and holdings, depending on what you connect and what the institution makes available.

We may also receive market or reference data from data providers to display quotes and related information.


3. How we use your information

We use personal information to:

  • Provide the Service — create and manage your account, authenticate you, display linked accounts and portfolio information, and deliver in-app and push notifications you expect
  • Link financial accounts — initiate and maintain Plaid connections you request
  • Protect the Service — detect fraud, abuse, and security incidents; enforce our terms; and troubleshoot errors
  • Communicate with you — send SMS verification codes, service-related messages, and responses to support or privacy requests
  • Improve the Service — understand aggregate usage patterns and fix bugs (we do not sell your personal information)
  • Comply with law — respond to lawful requests and meet regulatory obligations

We use data only for purposes compatible with those above or as disclosed when we collect it.


4. Legal bases for processing (EEA/UK users)

If you are in the European Economic Area or United Kingdom, we process personal data based on:

PurposeLegal basis
Providing the Service you requestPerformance of a contract
Security, fraud prevention, and service improvementLegitimate interests (balanced against your rights)
SMS authentication and essential noticesPerformance of a contract / legitimate interests
Optional push notificationsYour consent (you may disable notifications in device settings)
Legal complianceLegal obligation

You may withdraw consent where processing is consent-based without affecting the lawfulness of processing before withdrawal.


5. How we share information

We do not sell your personal information. We share information only as described below.

5.1 Service providers

We use trusted third parties that process data on our behalf under contractual obligations to protect it:

ProviderRoleData involved
Plaid Inc.Bank and investment account linkingLink tokens, institution and account metadata, balances, holdings, and related financial data you authorize
Twilio Inc.SMS one-time passcodes for sign-inYour phone number and OTP delivery metadata
Google Cloud Platform (GCP)Hosting, storage, logging, secrets managementApplication data stored and processed in our production environment
Cockroach Labs (CockroachDB Cloud)Managed databaseAccount, authentication, Plaid connection, and portfolio data
Google Cloud Storage (GCS)Profile images and related filesFiles you upload (e.g., profile photos)
Google FirebasePush notifications (FCM) and optional market-data caching (Firestore)Device tokens; non-financial reference or quote data where enabled

These providers may only use your information to perform services for us, subject to their own privacy policies and applicable law.

5.2 Other disclosures

We may disclose information if we believe it is reasonably necessary to:

  • Comply with law, regulation, legal process, or governmental request
  • Protect the rights, property, or safety of BouncySpark, our users, or others
  • Detect, prevent, or address fraud, security, or technical issues
  • Complete a merger, acquisition, or sale of assets (with notice where required)

We may share aggregated or de-identified information that cannot reasonably identify you.


6. Plaid and your financial data

When you choose to link an account, you interact with Plaid Link, which is operated by Plaid. Plaid collects credentials and financial data according to its own privacy policy and the disclosures shown during linking.

What we receive from Plaid (when you connect): institution name; account identifiers and masks; balances; holdings and related financial data needed for portfolio tracking.

How we use it: to display linked accounts in our application and support features you request.

Your choices: you can disconnect an institution in the app. We call Plaid to remove the connection and delete related data from our systems. Disconnecting stops new data collection from that institution.

For more about Plaid’s practices, see Plaid’s End User Privacy Policy.


7. Authentication and sessions

7.1 SMS one-time passcodes (Twilio)

Sign-in uses your phone number as your account identifier. We send a one-time passcode by SMS through Twilio Verify. We store your phone number and account record; Twilio processes the phone number to deliver the message.

7.2 Optional authenticator app (TOTP)

You may optionally enable time-based one-time passwords (TOTP) using an authenticator app. If enabled, you must enter a code from your app in addition to SMS verification when signing in.

7.3 JWT sessions

After successful authentication, we issue a JSON Web Token (JWT) for short-lived API access and a refresh token stored securely to renew your session. You can sign out to invalidate active sessions. We do not include Plaid access tokens or full financial account numbers in JWTs.


8. Where we store data

Production data is hosted on Google Cloud Platform, primarily in the United States. Primary application data is stored in CockroachDB Cloud (PostgreSQL-compatible). Profile images and similar files are stored in Google Cloud Storage. Logs and operational telemetry are retained in GCP according to our retention schedule.

We use encryption in transit (TLS) and encryption at rest provided by our cloud infrastructure. Secrets such as API keys are stored in Google Secret Manager, not in application source code.


9. Data retention and deletion

We retain personal information only as long as needed to provide the Service and as described in our internal retention schedule. Summary:

DataRetention
Account and portfolio dataWhile your account is active
Plaid connectionsWhile linked; removed when you unlink or delete your account
Authentication tokensWhile active; deleted with account
Application logsApproximately 90 days (operational; not a personal archive)
Database backupsPer provider schedule (typically 30–90 days); deleted account data may persist until backup expiry
Support correspondenceUp to 2 years, unless you request earlier deletion where feasible

Account deletion: you may request deletion in the app (when available) or by emailing security@bouncyspark.com from your registered email or phone. We verify your identity, remove Plaid connections, delete associated data from our database and storage, and confirm when complete. We aim to complete automated deletions promptly and manual requests within 30 days.

Legal hold: we may retain data longer when required by law or to resolve disputes or investigations.

Detailed procedures are documented in our Data Retention and Deletion Policy (internal reference for operations and partners).


10. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, or port your personal information, and to object to or restrict certain processing.

10.1 All users

You can:

  • Update profile information in the app where available
  • Disconnect financial institutions in the app
  • Delete your account via in-app flow or by contacting security@bouncyspark.com
  • Opt out of non-essential processing by disconnecting Plaid items, disabling push notifications, or contacting us

10.2 California residents (CCPA/CPRA)

California residents have additional rights, including:

  • Know what personal information we collect, use, and disclose
  • Delete personal information (subject to exceptions)
  • Correct inaccurate personal information
  • Opt out of sale or sharing — we do not sell or share personal information for cross-context behavioral advertising

To exercise rights, email security@bouncyspark.com. We verify requests using information associated with your account. You may designate an authorized agent where permitted by law. We do not discriminate against you for exercising privacy rights.

10.3 EEA/UK residents (GDPR)

Where GDPR applies, you may also have the right to lodge a complaint with your local supervisory authority. Our contact for GDPR requests is security@bouncyspark.com.

10.4 Response times

We acknowledge privacy requests within 10 business days and aim to complete them within 30 days, unless we notify you of a lawful extension.


11. Children’s privacy

Our Service is not directed to children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact security@bouncyspark.com and we will delete it.


12. International users

BouncySpark is based in the United States. If you access the Service from outside the United States, your information may be transferred to, stored in, and processed in the United States and other countries where our service providers operate. Those countries may have different data protection laws than your country. Where required, we rely on appropriate safeguards for international transfers.


13. Security

We implement administrative, technical, and organizational measures designed to protect personal information, including access controls, encryption, authenticated APIs, and monitoring. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

If you believe your account has been compromised, contact security@bouncyspark.com promptly.


14. Third-party links and services

The Service may link to third-party websites or services (for example, your financial institution through Plaid). Their privacy practices are governed by their own policies, not this one.


15. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will post the updated policy at https://bouncyspark.com/privacy and update the effective date. Continued use of the Service after changes become effective means you accept the updated policy. For significant changes, we may provide additional notice in the app or by email where appropriate.


16. Contact us

For privacy questions, data requests, or complaints:

Email: security@bouncyspark.com
Organization: BouncySpark.com

We will respond to verified requests in accordance with applicable law and the timelines described above.


17. Summary for app stores and Plaid

  • Published URL (when live): https://bouncyspark.com/privacy
  • Effective date: June 18, 2026
  • Contact for privacy: security@bouncyspark.com
  • Financial data: obtained only with your consent through Plaid; removable by unlinking or account deletion
  • We do not sell personal information
HQ Portfolio Let's chat! Our story Privacy Terms

© 2026 BouncySpark · All rights reserved.