Privacy Policy
Last updated 20 July 2026
This policy explains what information FinStitch collects, how we use it, and the choices and rights you have. Financial information is among the most sensitive data there is, and protecting it is fundamental to how we build and run FinStitch.
1. Introduction
FinStitch is committed to handling your personal information responsibly, securely and transparently. This Privacy Policy explains how FinStitch Limited (“FinStitch”, “we”, “our” or “us”) collects, uses, stores, shares and protects your personal information when you use our website, applications and related services (the “Services”). By creating an account or using the Services, you acknowledge that your personal information will be processed in accordance with this policy.
2. About FinStitch
The Services are provided by FinStitch Limited, a company registered in England & Wales (company number 17242791). FinStitch Limited is the data controller for your personal data under the UK GDPR and the Data Protection Act 2018, and is registered with the UK Information Commissioner's Office (ICO) under registration reference ZC168633.
- Privacy enquiries and data requests — privacy@finstitch.com
- General support — the Support page in the FinStitch app, or support@finstitch.com
- Security reports — security@finstitch.com
3. Scope of this policy
This policy applies to the FinStitch website, our web and mobile app, customer-support interactions, Open Banking and investment-account connections, and any other services we provide. It does not apply to third-party websites, financial institutions or brokerages you reach through links in FinStitch — those organisations have their own privacy policies and are responsible for their own processing.
4. Who can use FinStitch
The Services are intended for individuals who are at least 18 years of age. We do not knowingly collect personal information from children, and if we learn that we have, we will take reasonable steps to delete it.
5. The information we collect
A. Information you provide
When you create an account or use FinStitch, you may provide details such as your name, email address, country of residence, preferred currency, time zone, account preferences, financial goals, notes, feedback and support enquiries. Sign-in is handled through Amazon Cognito — we never see or store your password.
You may also choose to manually enter financial information, such as cash balances, investment holdings, property values, pensions, liabilities, loan and mortgage balances, and other assets.
B. Connected investment and broker accounts
If you choose to connect a supported broker (for example Trading 212), we access it read-only to import information such as balances, holdings, valuations and dividends. A read-only connection means FinStitch cannot place trades, withdraw money, or change anything in your account. Any API keys you provide are encrypted at rest with AWS KMS and are never logged or shown back to you.
C. Open Banking data
Where you choose to connect a bank account through a regulated Open Banking provider, we collect the information you authorise during the consent process — which may include account details, balances, transaction history and descriptions, scheduled payments, standing orders and direct debits. Your bank login credentials are never shared with or stored by FinStitch; authentication happens directly between you, your bank and the regulated provider. You stay in control and can revoke access at any time through FinStitch or your bank, where supported.
D. Information we collect automatically
When you use the Services we automatically collect limited technical data such as your IP address, browser and device type, operating system, session identifiers, timestamps, crash reports and error logs. We use this only to operate, secure and improve the Services.
E. Cookies and similar technologies
We use strictly necessary cookies and local storage to run the service — keeping you signed in, protecting your account and remembering preferences such as your light/dark theme — and, where you consent, functional and analytics cookies to understand and improve how the service is used. We do not use advertising cookies. See our Cookie Policy for the full breakdown and how to manage your preferences.
6. How we use your information
- Providing the Services — creating and managing your account, authenticating you, connecting accounts, and calculating your net worth, true allocation, income and FIRE projections.
- Improving the Services — diagnosing technical issues, improving usability and reliability, and developing new features.
- Security — detecting fraud, preventing unauthorised access, and investigating security incidents.
- Communications — sending security notifications, account and service messages, and (where permitted or with your consent) product updates.
We never sell your personal or financial data, and we never use it to move money on your behalf.
7. Lawful basis for processing
Under UK GDPR we need a lawful basis to use your personal data. Here is what we rely on:
| What we do | Lawful basis |
|---|---|
| Creating and managing your account, and providing portfolio tracking and analytics | Performance of a contract |
| Sending essential service communications | Performance of a contract |
| Connecting accounts via Open Banking, and product updates and marketing emails | Consent (which you can withdraw at any time) |
| Fraud prevention, security and improving the Services | Legitimate interests |
| Legal, tax and regulatory compliance | Legal obligation |
Withdrawing consent does not affect the lawfulness of any processing carried out before you withdrew it.
8. Who we share it with
We do not sell your personal information. We share data only where necessary to run the Services, comply with the law, or where you have asked us to. This includes carefully selected service providers — for cloud hosting, authentication, transactional email, error monitoring, payment processing and account connectivity — each under contract and only as needed. You can see the current list on our Subprocessors page.
Where you connect a financial account, information is exchanged with your institution or the regulated connectivity provider solely to deliver what you have requested. We may also disclose information where required by law, and — in the event of a merger, acquisition or sale of assets — your information may be transferred as part of that transaction, with continued protection and notice where the law requires it.
9. Where your data is stored & international transfers
You can use FinStitch from anywhere in the world. Wherever you access it from, your data is stored on AWS in the United Kingdom (London / eu-west-2), encrypted in transit and at rest. Some service providers may process limited data outside the UK. When they do, we rely on appropriate safeguards — such as UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the Standard Contractual Clauses — so your data keeps the same level of protection.
10. Data retention
We keep your personal and financial data while your account is active, and delete it within 30 days of account closure or a verified erasure request. Connected-account access tokens and API keys are revoked and deleted immediately when you disconnect an account or close your account. Records we are legally required to keep — for example billing records under UK tax and accounting law (retained for 6 years) — are kept only for that period and then securely deleted. Deleted data also ages out of our encrypted backups within the backup cycle (a rolling window of up to 35 days).
11. How we protect your information
Protecting your data is core to the product. Our technical and organisational measures include:
- Encryption in transit (modern TLS) and at rest.
- Broker credentials encrypted with AWS KMS, and secure secrets management.
- Sign-in through Amazon Cognito with multi-factor authentication.
- Read-only broker connections — FinStitch can never move your money.
- Role-based, least-privilege access controls.
- Infrastructure and security monitoring, and regular review of our controls.
- Encrypted backups and disaster-recovery procedures.
When we dispose of encrypted secrets we destroy the associated key material (crypto-shredding) so residual copies are unrecoverable. No system is perfectly secure, but if a breach ever affects your data we follow our breach-response process, including notifying the ICO within 72 hours where required. You can read more on our Security page.
12. Account security
You are responsible for keeping your account credentials confidential. Please choose a strong password, keep your login details private, sign out of shared devices, and tell us at security@finstitch.com if you suspect any unauthorised access to your account.
13. Your rights
Under UK GDPR you have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — ask us to correct data that is wrong or incomplete.
- Erasure — ask us to delete your personal data.
- Restriction — ask us to pause how we use your data.
- Portability — receive your data in a portable format.
- Objection — object to certain processing, such as direct marketing.
- Withdraw consent — change your mind at any time where we rely on consent.
- Complain — lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
To exercise any of these rights, email privacy@finstitch.com and we'll respond within the statutory timelines. We'd appreciate the chance to put things right before you approach the ICO. For more detail, see our GDPR & Your Rights page.
14. Open Banking consent
When you connect a financial account through Open Banking, you authorise FinStitch to access the information you consent to share. You remain in control of that consent and may revoke access at any time through FinStitch or your financial institution, where supported. Revoking consent may limit or prevent certain features from working.
15. Automated decision-making
FinStitch does not make decisions that produce legal or similarly significant effects solely through automated processing.
16. Third-party links
FinStitch may link to other websites and services we don't control. Those have their own privacy policies, and we're not responsible for how they handle your data — please review their policies before sharing any information.
17. Data accuracy
We rely on information you provide and on data from connected institutions to deliver the Services. While we take reasonable steps to display financial information accurately, we cannot guarantee that third-party data is always complete or up to date. Please review your information and let us know if anything looks wrong.
18. Marketing communications
Today we only send essential service messages — security notifications, account emails and legal notices. We do not currently send marketing emails. If we introduce them, we'll only do so where permitted by law, every marketing email will include an unsubscribe link, and you'll be able to manage your preference in your account settings or by emailing privacy@finstitch.com. Opting out of marketing never affects essential service messages.
19. Data breaches
If we become aware of a personal data breach likely to risk your rights and freedoms, we will investigate promptly, take steps to contain and remediate it, notify the ICO within the required timeframe, and tell affected users where the law requires or where the breach presents a high risk.
20. Children
FinStitch is intended for adults (18+) and is not directed at children. If you believe a child has provided us with personal information, contact us at privacy@finstitch.com and we'll delete it.
21. Changes to this policy
We may update this policy from time to time to reflect changes to the Services, the law, or our practices. We'll change the “last updated” date above and, for material changes, give appropriate notice.
22. Contact us
FinStitch is operated by FinStitch Limited, registered in England & Wales (company number 17242791), ICO registration ZC168633. For privacy enquiries and data requests, email privacy@finstitch.com; for general help, support@finstitch.com; to report a security issue, security@finstitch.com.