Privacy Policy

At Xpensy, we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use our website, mobile applications, and services (collectively, the "Services").

1. Who We Are

Xpensy is a financial technology solution developed by Finkeeping MB, focused on simplifying expense reporting, approvals, and corporate finance automation. We provide both web-based and mobile app services designed to help businesses manage their financial operations efficiently.

You can visit the website without telling us who you are or revealing any information, by which someone could identify you as a specific, identifiable individual. If, however, you wish to use some of the website’s features, or you wish to receive our newsletter or provide other details by filling a form, you may provide personal data to us, such as your email, first name, last name, city of residence, organization, telephone number. You can choose not to provide us with your personal data, but then you may not be able to take advantage of some of the website’s features. For example, you won’t be able to receive our Newsletter or contact us directly from the website. Users who are uncertain about what information is mandatory are welcome to contact us via info@xpensy.com.

2. What Information We Collect

We collect the following types of information:

Personal Information

  • Name, email address, phone number, job title, and company name

  • Login credentials

Usage & Device Data

  • IP address, browser type, and operating system

  • Session data and usage logs

  • Device information for mobile users (e.g., device type, OS version)

Financial Data

  • Uploaded expense receipts and invoice files

  • Expense report submissions

3. How We Use Your Information

We use your data to:

  • Provide and maintain the Xpensy Services

  • Enable features like expense tracking, approval workflows, and reporting

  • Process payments and manage billing

  • Communicate with you about your account or updates

  • Comply with legal obligations

4. Legal Bases for Processing (for EU Users)

Under the General Data Protection Regulation (GDPR), our legal basis for processing personal data includes:

  • Your consent (e.g., newsletter signup)

  • Performance of a contract (e.g., to provide you access to the platform)

  • Compliance with legal obligations

  • Legitimate business interests (e.g., improving user experience)

5. GDPR Compliance

If you are located in the European Union (EU) or European Economic Area (EEA), the following GDPR rights apply:

  • Right to Access – You can request access to the personal data we hold about you.

  • Right to Rectification – You can ask us to correct inaccurate or incomplete data.

  • Right to Erasure – You can request deletion of your data when it is no longer needed or when consent is withdrawn.

  • Right to Restrict Processing – You may request that we limit the use of your data under certain circumstances.

  • Right to Data Portability – You can request your data in a structured, commonly used, and machine-readable format.

  • Right to Object – You may object to our processing based on legitimate interests or for marketing purposes.

  • Right to Lodge a Complaint – You have the right to file a complaint with your national data protection authority.

To exercise any of these rights, please contact us at info@xpensy.com.

We ensure that any international data transfers are performed in accordance with GDPR requirements, using appropriate safeguards such as Standard Contractual Clauses.

6. Sharing Your Information

We do not sell your personal data. We may share information with:

  • Service providers (e.g., hosting, analytics, payment processors)

  • Third-party integrations (only with your explicit consent)

  • Legal authorities if required by law

7. Data Retention

We retain your data only for as long as necessary to provide our services and fulfill legal obligations. Users can request deletion of their data at any time.

8. Data Security

We secure information you provide on computer servers in a controlled, secure environment, protected from unauthorized access, use, or disclosure. We keep reasonable administrative, technical, and physical safeguards to protect against unauthorized access, use, modification, and personal data disclosure in its control and custody. However, no data transmission over the Internet or wireless network can be guaranteed.

9. International Data Transfers

If you are located outside the EU, your information may be transferred and processed in countries where our servers or partners are located. We ensure such transfers comply with applicable laws.

10. Cookies and Tracking

We use cookies and similar tracking technologies to:

  • Maintain session state

  • Analyze usage trends

  • Improve user experience

You can control cookies through your browser settings.

11. Children’s Privacy

Xpensy is not intended for children under the age of 16. We do not knowingly collect personal data from children.

12. Changes to This Policy

We may update this Privacy Policy periodically. Changes will be posted on this page with an updated "Effective Date."

13. Legal disclosure

We will disclose any information we collect, use or receive if required or permitted by law, such as to comply with a subpoena or similar legal process, and when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.

14. Contact Us

If you would like to contact us to understand more about this Policy or wish to contact us concerning any matter relating to individual rights and your Personal Information, you may send an email to info@xpensy.com.