Effective Date: January 4, 2026 | Last Updated: April 19, 2026 | Version: 2.0
Introduction
Welcome to Iris Financial. We are committed to protecting your privacy and handling your data transparently. This Privacy Policy explains how we collect, use, store, and protect your information when you use our financial management and payment processing services.
This policy covers:
Iris Secure Financial
Web-based accounting and expense management platform
Subscription Tracking Data: Third-party subscriptions you choose to track (Netflix, AWS, etc.)
1.2 Information Collected Automatically
Web Platform
IP address
Browser type and version
Device information
Usage data and session information
Cookies and session tokens
Mobile App
Device Information: Device type, operating system version, unique device identifiers
App Usage Data: Features used, screens viewed, session duration
Push Notification Token (iOS only, if notifications enabled)
Location Data: Country/region based on IP address (not precise GPS location)
Log Data: App version, crash reports, error logs
1.3 Information from Third Parties
Plaid Integration (Iris Secure Financial Only)
Bank account information, transaction history (up to 24 months), account balances, and account holder names. We receive this information only with your explicit consent through Plaid's secure connection flow.
Hosting Providers (Vercel, Abacus AI, AWS): Application hosting and database storage — Encrypted storage and transmission, SOC 2 Type II certified
Database Hosting: PostgreSQL database hosting — Encryption at rest and in transit
Communication Services
Email Service Providers: For transactional emails, support communications
Push Notification Services (iOS only): Apple Push Notification Service (APNs)
Analytics & Monitoring
Error Tracking: Crash reporting and performance monitoring (anonymized)
Usage Analytics: Feature usage patterns (aggregated and anonymized)
3.2 Legal Requirements
We may disclose your information to:
Comply with legal obligations (court orders, subpoenas)
Respond to lawful requests from government authorities
Protect our rights, property, or safety
Prevent fraud, security threats, or illegal activity
Enforce our Terms of Service
3.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you via email and prominent notice in the app/website.
4. Data Security
4.1 Security Measures
Encryption
TLS 1.2+ for all client-server communications, HTTPS enforced
PostgreSQL database encryption at rest
Password hashing using bcryptjs (cost factor 10)
JWT tokens stored as HTTP-only cookies (web), secure storage (mobile)
Access Controls
Role-Based Access Control (RBAC): ADMIN, MEMBER roles
Multi-Tenant Isolation: All queries enforce tenant-level separation
Automatic session expiry (30 days web, configurable mobile)
Essential Cookies: Session management, authentication (required for service)
Analytics Cookies: Usage patterns, feature adoption (optional, can be disabled)
Preference Cookies: UI settings, language preferences
Mobile App (Iris Money)
No Cookies: Mobile apps use secure storage instead of browser cookies
Analytics: In-app analytics for crash reporting and feature usage (can be disabled in settings)
Session Tokens: Stored securely in device keychain (iOS) or secure storage (Android)
Cookie Control
Web: Control via browser settings or cookie consent banner
Mobile: Control via app settings > Privacy
Note: Disabling essential cookies/storage may affect service functionality
8. Children's Privacy
Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children under 18.
If we discover that we have collected information from a child under 18, we will delete the information immediately, terminate the account, and notify the email address on file.
If you believe a child has provided us with personal information, contact: [email protected]
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States (cloud hosting, payment processors), the European Union (data centers), and other countries where our service providers operate.
Safeguards
Standard Contractual Clauses (SCCs): For EU data transfers
Adequacy Decisions: Transfer to countries with adequate data protection
Encryption: All data encrypted in transit and at rest
Contractual Protections: Data processing agreements with all vendors
10. Third-Party Links and Services
Our services may contain links to third-party websites, apps, or services (e.g., payment processors, social media).
Important:
We are not responsible for the privacy practices of third parties. Please review their privacy policies before providing information.
Selective Notifications: App Settings > Notifications (choose which types)
Note: Disabling may delay important account updates
iOS Only: Push notifications currently supported on iOS. Android support coming soon.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, new features or services, legal or regulatory requirements, and user feedback.
Notification of Changes
Material Changes: Email notification + in-app/website banner
Minor Changes: Updated "Last Updated" date + website posting
Effective Date: Changes take effect 30 days after notification
Your Options: Continued use = acceptance; object = account closure option
Version History
Version 1.0 (January 4, 2026): Initial policy for Iris Secure Financial
Version 2.0 (April 19, 2026): Updated to cover Iris Money mobile app and unified ecosystem
13. Product-Specific Privacy Information
Iris Secure Financial (Web)
Primary Data Flow: Plaid → Bank Transactions → Our Database → Your Dashboard
Key Risk: Bank account access via Plaid (you control, can revoke anytime)
Data Sharing: Only with Plaid for bank connection functionality
Unique Feature: Team access (admins can see all org data)
Iris Money (Mobile App)
Primary Data Flow: Customer Payment → Stripe/PawaPay → Our Database → Your Account
Key Risk: Payment processing (PCI-DSS compliant, we don't store card numbers)
Data Sharing: With Stripe and PawaPay for payment processing
Unique Feature: Public payment links (customer info shared only after payment)
14. Contact Us
For questions, concerns, or requests regarding this Privacy Policy: