Version 0.1.0-draft
Privacy policy
Effective
Draft. This text is a draft under review and is not yet the operative policy.
What we collect
Pay Plan collects information you give us directly, such as your email address and the budget, goals and categories you set up. It also collects information indirectly: when you link a bank, your transaction data reaches us through Akahu, the open banking service the banks work with, without Pay Plan ever seeing your banking password.
The Privacy Act 2020's information privacy principle 3A, in force from 1 May 2026, extends the duty to notify collection to this indirect case, because bank data reaching us through Akahu is exactly that: information about you that we collect from someone other than you. This section will set out, category by category, what each one contains and how that notice is met.
Why we hold it
Each category of information is held for a reason a reader can check against what the product actually does: working out your safe-to-spend figure, running the notifications you have asked for, and, if you turn it on, letting Penny, the AI assistant, read your own plan to explain it. This section will list every category against the purpose it is held for, rather than one general statement covering all of them.
Who receives it
Akahu receives your bank login only at your own bank, through open banking, and sends your transaction data back to Pay Plan; it never gives Pay Plan your password.
Microsoft Azure New Zealand North hosts the servers that store your data.
The AI provider behind Penny, the optional AI assistant, receives the parts of your plan it needs to answer a question you asked it, or to propose a change you can accept or decline.
RevenueCat receives your subscription and purchase status, so a Plus or Household subscription bought through an app store is recognised by Pay Plan.
Stripe receives your payment details for a subscription bought on the web, so Pay Plan itself never stores your card number.
How long we keep it
Information is kept for as long as your account is active, and for a period after that this section will state once PROD-E06 has confirmed it. Deleting your account, described below, is one trigger for that period to start; a bank you disconnect is another, for the transaction data that came from it.
Asking to see or fix your information
You can ask to see the information Pay Plan holds about you, or ask for it to be corrected, consistent with the Privacy Act 2020's access and correction principles. This section will name the way to ask, beyond the support mailbox on the support page, and how long a response takes.
Deleting your account
Account deletion is a setting inside Pay Plan, not a request you have to write in for. Once you delete your account, your information is purged within thirty days, other than anything a law such as the Tax Administration Act requires Pay Plan to keep for longer, which this section will name specifically.
Sending information overseas
Akahu and the servers this site runs on, in Microsoft's New Zealand North region, hold your information in New Zealand. The AI provider, RevenueCat and Stripe are likely to hold or process information outside New Zealand, and the Privacy Act 2020's principle 12 is what governs sending it there: this section will confirm, for each of the three, the specific basis Pay Plan relies on, such as a comparable privacy law or a contract that requires equivalent safeguards.