Privacy Policy
What data PhinApp handles, why, who it is shared with and what you can do about it.
Last updated on 9/1/26·Terms of Use
1.Who handles your data
This Privacy Policy explains what personal data we handle, what for, for how long, and what your rights are. It follows Brazilian Law no. 13,709/2018, the General Personal Data Protection Law (LGPD).
For anything concerning personal data, including exercising the rights described below, write to our data protection officer at .
2.Two different roles
PhinApp handles personal data in two distinct positions, and the rules are not the same in both.
- As controller, when the data is about you as a user of the service: your name, your e-mail, your phone number, what you do inside the product. We are the ones who decide why that data exists.
- As processor, when the data is about third parties and reaches us because your company entered or imported it: suppliers, customers, payables and receivables, bank statements. The organization that entered it decides what happens to it; we store and process it to deliver the service to that organization, on its instructions.
If you are a supplier or a customer of a company that uses PhinApp and want to know why there is data about you here, the request belongs to that company. If it reaches us, we will forward it to them.
3.What data we handle
Account data. Full name, e-mail address and profile picture received from Google when you sign in, phone number (optional), interface language and your notification preferences.
Organization data. Trade name, legal name, CNPJ, contact e-mail and phone, the company's country and language, plus the users invited to it and each one's access level.
Financial and operational data. Bank accounts and cards (institution, branch, number and balances), transactions, payables and receivables, chart of accounts, registered suppliers and customers, reconciliations, recurrences, comments written on forecast and actuals cells, and the files you import - OFX statements, statement spreadsheets and reports exported from your ERP.
Audit records. Who created, changed or deleted each record, when, and what changed. We also keep lifecycle events - organization created or deleted, user added or removed, invitation sent, accepted, declined or revoked - with the name and e-mail as they stood at the time of the event, because the record has to outlive the account it describes.
Technical data. IP address, access date and time, browser identification and error logs, generated automatically by the infrastructure to run and protect the service.
We do not handle sensitive personal data, and PhinApp is not built to receive it. We also never ask for, store or have access to banking passwords: your bank credentials never pass through here.
4.Where that data comes from
- From you, when you sign in, fill in your profile and register your company.
- From Google, when you use Google sign-in: we receive your name, e-mail, picture and account identifier, and nothing beyond that. Your password never passes through us.
- From the files you import - bank statements, card bills and ERP reports -, which also carry third-party data.
- From Open Finance connections, if and when you authorize them. That authorization is always yours, is given at the financial institution itself and can be revoked there.
5.What we use it for, and on what legal basis
- Creating and maintaining your account, authenticating access and keeping you signed in - performance of a contract (LGPD art. 7, V).
- Delivering the service: importing, classifying, reconciling, forecasting and displaying your company's financial data - performance of a contract.
- Sending what is indispensable about the account: invitations, access changes, security notices and changes to these documents - performance of a contract.
- Keeping the service secure, preventing fraud and abuse and investigating incidents - legitimate interest (art. 7, IX).
- Understanding how the product is used, fixing defects and improving it, on aggregated data wherever possible - legitimate interest.
- Complying with legal and regulatory obligations and exercising rights in proceedings - art. 7, II and VI.
- Sending news, tips and marketing content - consent (art. 7, I), which you give by ticking the corresponding option and withdraw whenever you like, from your profile or through the unsubscribe link in the e-mail itself.
We do not sell personal data, do not hand it over for third-party advertising and do not make automated decisions with legal effect over you. The projections PhinApp calculates are estimates presented to you - decisions about your business are yours to make.
8.International transfers
The providers above run servers outside Brazil, so your data may be stored and processed abroad. Those transfers are made under LGPD art. 33, on contractual clauses requiring the provider to offer a level of protection compatible with Brazilian law.
9.Security and internal access
Each organization is isolated inside the database itself: the separation is enforced by row-level security policies in Postgres, not merely by the interface. Every request runs with the token of the user who made it, so the database itself refuses any read or write outside the organizations that user belongs to. All traffic is encrypted in transit.
Our support access is deliberately narrow: the support account can read an organization's data to investigate a problem and cannot write anything - not even a comment. That is not an interface rule, it is a database rule. And everything changed inside the product is recorded with its author and date.
No system is immune. Should a security incident carry a relevant risk to your data, we will notify you and the Brazilian data protection authority, as LGPD art. 48 requires.
10.How long we keep it
For as long as your account exists, we keep your data in order to deliver the service.
When you delete your account, from your profile, your registration and your access are removed. What you wrote inside an organization - transactions, titles, comments - stays with it and stops pointing at you: it is the company's financial memory, not yours. An organization is never left without an administrator, so if you are the last one in any of them you will have to promote someone else or delete the organization first.
Once an organization is deleted, its financial data goes with it. After that we retain only what the law requires - tax and accounting records - and the minimum needed to exercise rights in proceedings, for the applicable statutory periods. Backups are overwritten on their normal retention cycles.
11.Your rights
The LGPD grants you, at any time and free of charge:
- confirmation that we handle data about you, and access to it;
- correction of incomplete, inaccurate or outdated data;
- anonymization, blocking or deletion of unnecessary or excessive data, or data handled outside the law;
- portability to another provider, upon express request;
- deletion of data handled on the basis of your consent;
- information about who we share your data with;
- information about the option not to consent and what follows from refusing;
- withdrawal of consent;
- objection to processing based on legitimate interest.
Much of that you can do yourself: your profile lets you correct your name and phone number, adjust notification preferences, withdraw marketing consent and delete your account. For the rest, write to - we answer within 15 days. You may also complain directly to the Brazilian data protection authority.
12.Minors
PhinApp is a business financial management tool and is not intended for anyone under 18. We do not knowingly collect data about children or adolescents; if we learn that we have, the account will be deleted.
13.Changes to this policy
We may update this policy to follow changes in the product or in the law. The date it was last updated is at the top of the page. When a change is material, we will tell you by e-mail or inside the application before it takes effect.
14.Contact
Data protection officer: .