PRIVACY POLICY
- Download and use
our mobile application( whatsgoon) , or any other application of ours that links to this Privacy Notice
- Use
whatsgoon .whatsgoon is a personal finance management mobile application designed to automate and simplify expense tracking. The application features 'WAI,' an advanced artificial intelligence tool that allows users to upload bank statements and scan physical receipts. WAI parses these documents to extract transaction dates, amounts, and merchant names, providing automated categorization for better financial insights. Users maintain full control by reviewing and approving all AI-generated data before it is saved to their personal records. whatsgoon does not require direct access to bank accounts and operates solely on user-uploaded documents.
- Engage with us in other related ways, including
any marketing or events
SUMMARY OF KEY POINTS
TABLE OF CONTENTS
1. WHAT INFORMATION DO WE COLLECT?
Personal information you disclose to us
In Short: We collect personal information that you provide to us.-
names
-
email addresses
-
passwords
-
contact or authentication data
-
contact preferences
-
transaction and expense data
- Mobile Device
Access. We may request access or permission to certain features from
your mobile device, including your mobile device's
camera ,storage ,and other features. If you wish to change our access or permissions, you may do so in your device's settings.
- Mobile Device
Data. We automatically collect device information (such as your mobile
device ID, model, and manufacturer), operating system, version information and
system configuration information, device and application identification numbers,
browser type and version, hardware model Internet service provider and/or mobile
carrier, and Internet Protocol (IP) address (or proxy server). If you are using
our application(s), we may also collect information about the phone network
associated with your mobile device, your mobile device’s operating system or
platform, the type of mobile device you use, your mobile device’s unique device
ID, and information about the features of our application(s) you accessed.
- Push
Notifications. We may request to send you push notifications regarding
your account or certain features of the application(s). If you wish to opt out
from receiving these types of communications, you may turn them off in your
device's settings.
Information automatically collected
In Short: Some information — such as your Internet Protocol (IP) address and/or browser and device characteristics — is collected automatically when you visit our Services.- Log and Usage Data. Log and usage
data is service-related, diagnostic, usage, and performance information our
servers automatically collect when you access or use our Services and which
we record in log files. Depending on how you interact with us, this log data
may include your IP address, device information, browser type, and settings
and information about your activity in the Services (such as the date/time stamps
associated with your usage, pages and files viewed, searches, and other
actions you take such as which features you use), device event information
(such as system activity, error reports (sometimes called
"crash dumps" ), and hardware settings).
- Device Data. We collect device data
such as information about your computer, phone, tablet, or other device you
use to access the Services. Depending on the device used, this device data
may include information such as your IP address (or proxy server), device
and application identification numbers, location, browser type, hardware
model, Internet service provider and/or mobile carrier, operating system,
and system configuration information.
- Location Data. We collect location
data such as information about your device's location, which can be either
precise or imprecise. How much information we collect depends on the type
and settings of the device you use to access the Services. For example, we
may use GPS and other technologies to collect geolocation data that tells us
your current location (based on your IP address). You can opt out of
allowing us to collect this information either by refusing access to the
information or by disabling your Location setting on your device. However,
if you choose to opt out, you may not be able to use certain aspects of the
Services.
Google API
Our use of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.2. HOW DO WE PROCESS YOUR INFORMATION?
In Short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law.- To facilitate account creation and
authentication and otherwise manage user accounts. We may
process your information so you can create and log in to your account, as
well as keep your account in working order.
- To deliver and facilitate delivery
of services to the user. We may process your information to
provide you with the requested service.
- To respond to user
inquiries/offer support to users. We may process your
information to respond to your inquiries and solve any potential
issues you might have with the requested service.
- To send administrative
information to you. We may process your information
to send you details about our products and services, changes to
our terms and policies, and other similar information.
- To
fulfill and manage your orders. We may process your information to fulfill and manage your orders, payments, returns, and exchanges made through the Services.
- To
protect our Services. We
may process your information as part of
our efforts to keep our Services safe
and secure, including fraud monitoring
and prevention.
- To
identify usage
trends. We may
process information about
how you use our Services to
better understand how they
are being used so we can
improve them.
-
To
save or
protect an
individual's
vital
interest.
We may process
your information
when necessary
to save or
protect an
individual’s
vital interest,
such as to
prevent
harm.
-
WAI .To provide automated AI-powered categorization and extraction of transaction data from user-uploaded receipts and bank statements.
-
__________ .__________
-
AI Resource Management and Rate Limiting .Monitoring the number of receipts and statements processed by each user via WAI and tracking unique identifiers to enforce usage limits.
-
__________ .__________
3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR INFORMATION?
In Short: We only process your personal information when we believe it is necessary and we have a valid legal reason (i.e.-
Consent. We
may process your
information if
you have given
us permission
(i.e.
, consent) to use your personal information for a specific purpose. You can withdraw your consent at any time. Learn more about withdrawing your consent.
-
Performance
of a
Contract.
We may process
your personal
information when
we believe it is
necessary to
fulfill our contractual obligations to you, including providing our Services or at your request prior to entering into a contract with you.
- Legitimate Interests. We may process your information when we believe it is reasonably necessary to achieve our legitimate business interests and those interests do not outweigh your interests and fundamental rights and freedoms. For example, we may process your personal information for some of the purposes described in order to:
-
Analyze how our Services are used so we can improve them to engage and retain users
-
Diagnose
problems
and/or
prevent
fraudulent
activities
-
In order to maintain the financial sustainability of the service and prevent unauthorized or excessive use of expensive AI computing resources.
-
__________
-
Legal
Obligations.
We
may
process
your
information
where
we
believe
it
is
necessary
for
compliance
with
our
legal
obligations,
such
as
to
cooperate
with
a
law
enforcement
body
or
regulatory
agency,
exercise
or
defend
our
legal
rights,
or
disclose
your
information
as
evidence
in
litigation
in
which
we
are
involved.
-
Vital
Interests.
We
may
process
your
information
where
we
believe
it
is
necessary
to
protect
your
vital
interests
or
the
vital
interests
of
a
third
party,
such
as
situations
involving
potential
threats
to
the
safety
of
any
person.
- If collection is clearly in the interests of an individual and consent cannot be obtained in a timely way
-
For
investigations
and
fraud
detection
and
prevention
-
For
business
transactions
provided
certain
conditions
are
met
-
If
it
is
contained
in
a
witness
statement
and
the
collection
is
necessary
to
assess,
process,
or
settle
an
insurance
claim
-
For
identifying
injured,
ill,
or
deceased
persons
and
communicating
with
next
of
kin
-
If
we
have
reasonable
grounds
to
believe
an
individual
has
been,
is,
or
may
be
victim
of
financial
abuse
-
If
it
is
reasonable
to
expect
collection
and
use
with
consent
would
compromise
the
availability
or
the
accuracy
of
the
information
and
the
collection
is
reasonable
for
purposes
related
to
investigating
a
breach
of
an
agreement
or
a
contravention
of
the
laws
of
Canada
or
a
province
-
If
disclosure
is
required
to
comply
with
a
subpoena,
warrant,
court
order,
or
rules
of
the
court
relating
to
the
production
of
records
-
If
it
was
produced
by
an
individual
in
the
course
of
their
employment,
business,
or
profession
and
the
collection
is
consistent
with
the
purposes
for
which
the
information
was
produced
-
If
the
collection
is
solely
for
journalistic,
artistic,
or
literary
purposes
-
If
the
information
is
publicly
available
and
is
specified
by
the
regulations
-
We
may
disclose
de-identified
information
for
approved
research
or
statistics
projects,
subject
to
ethics
oversight
and
confidentiality
commitments
-
AI Platforms
-
Cloud Computing Services
-
Data Analytics Services
-
Data Storage Service Providers
-
Payment Processors
-
Performance Monitoring Tools
-
User Account Registration & Authentication Services
-
Website Hosting Service Providers
- Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
6. DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?
In Short: We offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies.-
Image analysis
-
AI insights
-
AI document generation
-
AI deployment
-
Log in to your account settings and update your user account
-
Contact us using the contact information provided
8. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?
In Short: We may transfer, store, and process your information in countries other than your own.9. HOW LONG DO WE KEEP YOUR INFORMATION?
In Short: We keep your information for as long as necessary to10. HOW DO WE KEEP YOUR INFORMATION SAFE?
In Short: We aim to protect your personal information through a system of11. DO WE COLLECT INFORMATION FROM MINORS?
In Short: We do not knowingly collect data from or market to12. WHAT ARE YOUR PRIVACY RIGHTS?
In Short:Account Information
If you would at any time like to review or change the information in your account or terminate your account, you can:-
Log in to your account settings and update your user account.
-
Contact us using the contact information provided.
13. CONTROLS FOR DO-NOT-TRACK FEATURES
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track (14. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
In Short: If you are a resident ofCategories of Personal Information We Collect
The table below shows the categories of personal information we have collected in the past twelve (12) months. The table includes illustrative examples of each category and does not reflect the personal information we collect from you. For a comprehensive inventory of all personal information we process, please refer to the section| Category | Examples | Collected |
|---|---|---|
|
A.
Identifiers
|
Contact
details,
such
as
real
name,
alias,
postal
address,
telephone
or
mobile
contact
number,
unique
personal
identifier,
online
identifier,
Internet
Protocol
address,
email
address,
and
account
name
|
|
|
B.
Personal
information
as
defined
in
the
California
Customer
Records
statute
|
Name,
contact
information,
education,
employment,
employment
history,
and
financial
information
|
|
|
|
Gender,
age,
date
of
birth,
race
and
ethnicity,
national
origin,
marital
status,
and
other
demographic
data
|
|
|
|
Transaction
information,
purchase
history,
financial
details,
and
payment
information
|
|
|
|
Fingerprints
and
voiceprints
|
|
|
|
Browsing
history,
search
history,
online
|
|
|
|
Device
location
|
|
|
|
Images
and
audio,
video
or
call
recordings
created
in
connection
with
our
business
activities
|
|
|
|
Business
contact
details
in
order
to
provide
you
our
Services
at
a
business
level
or
job
title,
work
history,
and
professional
qualifications
if
you
apply
for
a
job
with
us
|
|
|
|
Student
records
and
directory
information
|
|
|
|
Inferences
drawn
from
any
of
the
collected
personal
information
listed
above
to
create
a
profile
or
summary
about,
for
example,
an
individual’s
preferences
and
characteristics
|
|
|
|
|
|
-
Receiving
help
through
our
customer
support
channels;
-
Participation
in
customer
surveys
or
contests;
and
-
Facilitation
in
the
delivery
of
our
Services
and
to
respond
to
your
inquiries.
-
Category
A
-
As long as the user has an account with us
-
Category
B
-
As long as the user has an account with us
-
Category
D -As long as the user has an account with us
-
Category
F -As long as the user has an account with us
-
Category
H -Receipt images and statements are permanently deleted from our servers immediately after AI analysis and data extraction are completed.
-
Category
K -As long as the user has an account with us
Sources of Personal Information
Learn more about the sources of personal information we collect inHow We Use and Share Personal Information
-
Beacons/Pixels/Tags
-
Category
A.
Identifiers
- Category B. Personal information as defined in the California Customer Records law
-
Category
D . Commercial information
-
Category
F . Internet or other electronic network activity information
-
Category
H . Audio, electronic, visual, and similar information
-
Category
K . Inferences drawn from collected personal information
Your Rights
You have rights under certain US state data protection laws. However, these rights are not absolute, and in certain cases, we may decline your request as permitted by law. These rights include:-
Right
to
know
whether
or
not
we
are
processing
your
personal
data
-
Right
to
access your
personal
data
-
Right
to
correct inaccuracies
in
your
personal
data
-
Right
to
request
the
deletion
of
your
personal
data
-
Right
to
obtain
a
copy of
the
personal
data
you
previously
shared
with
us
-
Right
to
non-discrimination
for
exercising
your
rights
-
Right
to
opt
out
of
the
processing
of
your
personal
data
if
it
is
used
for
targeted
advertising
(or sharing as defined under California’s privacy law) , the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects ( "profiling" )
-
Right
to
access
the
categories
of
personal
data
being
processed
(as
permitted
by
applicable
law,
including
the
privacy
law
in
Minnesota)
-
Right
to
obtain
a
list
of
the
categories
of
third
parties
to
which
we
have
disclosed
personal
data
(as
permitted
by
applicable
law,
including
the
privacy
law
in
California, Delaware, and Maryland )
-
Right
to
obtain
a
list
of
specific
third
parties
to
which
we
have
disclosed
personal
data
(as
permitted
by
applicable
law,
including
the
privacy
law
in
Minnesota and Oregon )
-
Right
to
obtain
a
list
of
third
parties
to
which
we
have
sold
personal
data
(as
permitted
by
applicable
law,
including
the
privacy
law
in
Connecticut)
-
Right
to
review,
understand,
question,
and
depending
on
where
you
live,
correct
how
personal
data
has
been
profiled
(as
permitted
by
applicable
law,
including
the
privacy
law
in
Connecticut and Minnesota )
-
Right
to
limit
use
and
disclosure
of
sensitive
personal
data
(as
permitted
by
applicable
law,
including
the
privacy
law
in
California)
-
Right
to
opt
out
of
the
collection
of
sensitive
data
and
personal
data
collected
through
the
operation
of
a
voice
or
facial
recognition
feature
(as
permitted
by
applicable
law,
including
the
privacy
law
in
Florida)
How to Exercise Your Rights
To exercise these rights, you can contact usRequest Verification
Upon receiving your request, we will need to verify your identity to determine you are the same person about whom we have the information in our system. We will only use personal information provided in your request to verify your identity or authority to make the request. However, if we cannot verify your identity from the information already maintained by us, we may request that you provide additional information for the purposes of verifying your identity and for security or fraud-prevention purposes.Appeals
Under certain US state data protection laws, if we decline to take action regarding your request, you may appeal our decision by emailing us atCalifornia
"Shine
The
Light"
Law
California
Civil
Code
Section
1798.83,
also
known
as
the
15. DATA MINIMIZATION AND RECEIPT PROCESSING
16. DO WE MAKE UPDATES TO THIS NOTICE?
In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.17. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
If you have questions or comments about this notice, you may18. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?
19. ACCOUNT DELETION AND DATA MANAGEMENT
You have the right to delete your account and all associated data at any time. Users can delete individual transaction records, images, or history at any time through the app interface without needing to delete their entire account. To do so, you can use one of the following methods:In-App Deletion: Go to Settings > Delete Account and follow the instructions to permanently remove your account.
Request via Email: You can send an email to hey@whatsgoon.app from the email address registered with your account, requesting the deletion of your account and data.
What Happens When You Delete Your Account?
Upon receiving a deletion request, your profile information, transaction history, budget records, and any stored receipt images will be permanently and irreversibly deleted from our servers.
Data Retention: We do not keep your personal financial data once the account is deleted.
Processing Time: Account deletion requests are processed within 30 days.
7. HOW DO WE HANDLE YOUR SOCIAL LOGINS?
In Short: If you choose to register or log in to our Services using a social media account, we may have access to certain information about you.