Privacy & data use

Your planning data should stay under your control.

This page explains how the current Finance Place product handles information while the platform is being built: local planning, optional account sync and professional enquiries are separate choices.

Build-stage noticeThis is a factual product-data notice, not the final formal UK privacy notice.

Before commercial public launch, the final legal entity/controller details, lawful bases, formal retention schedule, privacy-rights contact process and processor/international-transfer wording should be confirmed and legally reviewed. This page deliberately does not invent those details before they are settled.

PlanningLocal first

Most saved tool and Money Plan data stays in this browser unless you deliberately export, sync or share it.

CloudOptional

Signing in does not upload your plan. You choose whether the local or cloud copy is used.

Professional sharingExplicit

A saved plan is not an enquiry. Context is included only when you deliberately add it and submit.

TrackingNo analytics or ad pixels in the current app

The current application code does not include an analytics platform, advertising pixel or behavioural-tracking integration.

01 · Local planning

Using the tools does not require an account.

The current product stores many Money Plan, checklist and calculator records in your browser's local storage. That lets you leave a tool and return to it without automatically sending the underlying plan to The Finance Place.

  • Local data normally stays within the browser profile and device where it was created.
  • Another device, another browser or a private browsing session will not automatically have the same copy.
  • Browser or device settings can clear local storage, so important plans should be backed up using the Account page or optional sync.
  • The local export intentionally excludes account-session tokens, sync metadata and the generated professional Handoff Pack.

02 · Optional cloud sync

Account sign-in and plan upload are separate actions.

If you choose the optional account feature, email sign-in is used to establish your account session. Signing in by itself does not upload the Money Plan. The sync panel asks you which copy to keep when the local and cloud versions differ.

  • Cloud plan snapshots are stored in Supabase and are protected by account-ownership row-level access rules.
  • The public website uses the browser-safe publishable key, not a privileged service key, to access a signed-in user's snapshot.
  • You can delete the cloud copy without deleting the plan stored on the current device.
  • Your account session is stored locally in the browser so the site can recognise the signed-in session.
  • The generated professional Handoff Pack is intentionally excluded from automatic plan snapshot collection.

03 · Professional enquiries

Information is submitted only when you choose to send an enquiry.

The enquiry form can collect the service/category requested, name, email address, phone number, postcode, preferred contact method, message and the professional you selected. A saved Money Plan is not automatically attached.

Plan context is customer-controlled.

Money Plan or Handoff Pack information is included only when you deliberately add it to the enquiry. The submission records whether plan context was shared.

Submitted enquiries are stored in private database tables. If you choose a particular professional, the submission process checks that the profile is currently published and marked verified in the Finance Place directory before recording that requested referral.

04 · Security & anti-abuse

The current enquiry flow uses several technical safeguards.

  • Enquiry submissions are accepted only from approved Finance Place website origins and require the site's publishable API key.
  • Input fields are validated and length-limited before storage.
  • Enquiry and referral records are kept in private database tables rather than exposed through the public data API.
  • For rate limiting, the enquiry endpoint derives a SHA-256 hash from the requesting IP address. The application removes those rate-limit records when they are more than two days old.
  • No internet service can promise absolute security; these controls reduce risk but do not make a system invulnerable.

05 · Browser storage & tracking

The current application does not include an analytics or advertising-tracking integration.

Finance Place planning currently relies heavily on browser local storage. The application code does not currently include Google Analytics, advertising pixels or a comparable behavioural analytics platform.

This is not a promise that hosting, authentication or other infrastructure can never use strictly technical browser or request data. If non-essential analytics, advertising technology or similar tracking is added later, the privacy and consent position should be reviewed before it is enabled.

06 · Infrastructure providers

The current product uses external infrastructure to operate.

Vercel

Hosts and deploys the web application. Hosting infrastructure can process technical request information needed to deliver and protect the site.

Supabase

Provides the current account authentication, database and server-side enquiry infrastructure, including optional Money Plan cloud snapshots.

The final launch privacy notice should document the relevant processor arrangements, locations and transfer safeguards once the operating legal entity and production configuration are final.

07 · Your controls

The current product gives you several direct data choices.

  • Keep planning local and do not create an account.
  • Export the Finance Place planning records held in the current browser.
  • Restore a recognised local export after an explicit confirmation step.
  • Choose whether to create and update an optional cloud copy.
  • Delete the cloud Money Plan copy while retaining the device copy.
  • Sign out without deleting local planning data.
  • Select exactly which Money Plan areas belong in a Handoff Pack.
  • Choose whether that handoff is inserted into a professional enquiry.

There is not currently an in-product self-service control for deleting a professional enquiry after it has been submitted. The formal launch privacy process should provide the appropriate rights/contact route and retention rules for those records.

08 · Before commercial public launch

Items that still need formal legal completion.

The product behavior above can be documented now, but the final privacy notice should be completed against the actual operating business. That includes:

  • the legal controller name, registered/contact address and privacy contact;
  • the lawful basis for each processing purpose;
  • the final retention schedule for enquiries, referrals, accounts and operational logs;
  • the process for privacy rights requests and complaints;
  • processor agreements, hosting locations and any international-transfer wording;
  • updated cookie/analytics wording and consent controls if non-essential tracking is introduced.

Related

Planning data and financial guidance are separate issues.

Read the platform boundaries around calculators, professional listings and regulated advice as well.

Important information →Account & data controls