src/config/site.ts and have this policy reviewed against the final production services and business structure.1. Who this policy covers
This Privacy Policy applies to the BudgetShape marketing website at budgetshape.com and the BudgetShape budgeting service at app.budgetshape.com. In this policy, “BudgetShape”, “we”, “us” and “our” refer to the operator of those services.
2. Our privacy approach
BudgetShape is designed to minimise unnecessary collection. The service does not require a bank connection. The marketing website is designed to use privacy-minimised first-party usage analytics so we can understand visits, navigation and conversion while avoiding advertising pixels, session recording, keystroke capture and collection of calculator input values.
3. Information we handle
Account information
We handle information needed to create and operate your account, including your email address, account identifiers and authentication/session information.
Budget information
When you use the app, we store the budgeting information you choose to enter, such as income, expenses, buckets/categories, recurrence frequencies, optional dates, budget names and shared-budget membership.
Security and operational information
We may process technical information such as IP-related information, user-agent/device information, request metadata and security events to operate, protect, troubleshoot and monitor the service. We avoid unnecessarily logging complete financial payloads.
Support communications
If you contact us, we handle the information contained in your message and any information reasonably required to respond.
Billing information
Public paid billing is not yet live. If paid plans launch, we expect a payment provider to handle payment-card details while BudgetShape stores only the billing identifiers and subscription information needed to manage your plan. This policy will be updated before public paid billing begins.
4. Why we handle information
We use information to provide and secure the service, authenticate users, calculate and display budgets, support sharing, send essential service messages, respond to support requests, detect abuse, maintain backups and meet legal obligations.
5. Service providers and disclosure
BudgetShape uses service providers to operate the service. The current production architecture includes cloud and infrastructure providers for website delivery, network/security delivery and email. These providers may process technical or account information where necessary to provide their services. We do not sell your personal information to advertisers.
Our launch architecture includes Amazon Web Services for the marketing website, Cloudflare for the application’s public network edge/tunnel, Microsoft Graph/Microsoft 365 for service email, and our own application/database infrastructure. Stripe is planned for future billing but is not yet used for public paid subscriptions.
6. Website analytics, cookies and similar technologies
When first-party marketing analytics is enabled, BudgetShape may record page views, clicks, referral/UTM attribution, broad device category, viewport size and an anonymous session identifier. The implementation is designed not to record typed form values, calculator amounts, keystrokes or BudgetShape app financial data. The anonymous marketing session identifier is stored in browser session storage rather than as a persistent advertising profile. The signed-in application uses an essential secure session cookie so web users can remain authenticated. See our Cookie Notice.
7. Security
We use administrative and technical controls designed to protect information, including HTTPS, passwordless one-time-code authentication, server-side session controls, budget-scoped authorisation, least-privilege production access and backups. No internet service can promise absolute security.
8. Retention and deletion
We keep personal information only for as long as reasonably required for the purpose it was collected, to maintain the service, meet legal obligations, resolve disputes or protect the service. We are documenting specific operational retention periods as part of launch readiness. You can request account deletion using the process on our Account & Data Deletion page.
9. Access and correction
You may contact us to ask about personal information we hold about you, request access or request correction. We may need to verify your identity before acting on a request.
10. Overseas processing
Some technology providers used by BudgetShape operate global infrastructure. Information may therefore be processed or stored outside Australia depending on provider configuration and service delivery. We will keep our provider register and this policy aligned with the actual production configuration.
11. Marketing communications
Essential authentication, security and invitation emails are service messages. If we later send optional marketing emails, we will use an appropriate consent and unsubscribe process. We do not currently mix promotional advertising into one-time-code or security messages.
12. Complaints and privacy contact
For privacy questions, access/correction requests or complaints, email privacy@budgetshape.com. We will review the matter and respond within a reasonable period.
13. Changes to this policy
We may update this policy as BudgetShape changes. Material changes will be reflected by updating the effective date and, where appropriate, by providing notice in the service.
