Pace Privacy Policy
Overview
Pace is a personal budgeting and cash-flow management application. This policy explains what information we collect, why we collect it, how it is stored, and how users can request deletion.
Information We Collect
We collect information users provide directly, including name, email address, account settings, budget categories, manual transactions, CSV imports, and support or security communications.
When a user connects an account through Plaid or another financial data provider, we may collect read-only financial account data authorized by the user, including account metadata, account balances, transaction history, transaction categories, merchant names, dates, amounts, pending status, and recurring transaction signals when available.
We also collect limited operational metadata such as request timestamps, API paths without query strings, response status, duration, and content length. We do not intentionally log cookies, request bodies, response bodies, provider access tokens, API keys, bank credentials, or full financial payloads.
How We Use Information
- Authenticate users and maintain sessions.
- Display account balances and transactions.
- Categorize spending and track budgets.
- Identify bills, subscriptions, and recurring transactions.
- Provide cash-flow and safe-to-spend insights.
- Import and deduplicate CSV transactions.
- Operate, secure, debug, and improve the application.
We do not use Plaid data for investment advice, brokerage, lending decisions, payment initiation, ACH transfers, KYC/AML screening, eligibility decisions, or unrelated advertising.
Financial Data Providers
When Plaid Link is enabled, users will be asked to authorize access before any provider data is collected. Plaid may collect and process information according to its own end-user privacy policy. Pace receives only the data authorized for the selected product scope.
Provider access tokens are stored server-side and encrypted before database storage. Provider tokens are not returned to the browser in API responses.
Storage and Security
Production data is stored in Google Cloud services. Cloud Run provides HTTPS for client traffic, Cloud SQL provides encrypted database storage, and GCP Secret Manager stores production secrets. Provider access tokens are encrypted at the application layer using AES-256-GCM before storage.
Financial application state is stored server-side. The application does not intentionally store sensitive financial state in browser localStorage.
Sharing
We share information only with service providers needed to operate the application, such as Google Cloud Platform for hosting and storage, Plaid for user-authorized financial account connectivity, OpenAI for assistant responses using limited app context when enabled, and source-control or security tooling used to operate the service.
We do not sell consumer financial data.
User Choices
Users can disconnect linked accounts, reset app data, or request deletion of account data. Disconnecting a linked account removes the stored provider token and stops future syncing for that account. Deletion requests remove application financial data and active sessions, subject to backup retention, security, legal, and operational requirements.
Data Retention
We retain user data while the account is active and while needed to provide the budgeting service. Backup copies may remain for a limited retention period before aging out automatically. See the Data Retention and Deletion Policy.
Children
Pace is not intended for children under 13 and does not knowingly collect information from children under 13.
Changes
We may update this policy as the application, provider scope, or legal requirements change. Material changes will be reflected by updating the effective date and policy text.
Contact
Patrick Gloria
patrickrgloria@gmail.com