1. Who we are
WeBash helps social groups plan events and split shared costs. This policy explains what personal data we collect, why, and your rights under the GDPR.
2. Data we collect
Account data (name, email, phone, locale); group and event data you create; expense records you enter (amounts and mark-as-paid status — we never store card or bank credentials); and security logs. Lawful bases: consent (registration), contract (expense tracking), and legitimate interest (security).
3. How we use it
To operate the service, send transactional notifications and emails you have not opted out of, enforce subscription limits, and keep the platform secure. We do not sell your data and do not use advertising or tracking cookies.
4. Retention
Account data is kept until you delete your account; deleted-account PII is anonymised and wiped within 30 days; financial records are anonymised and retained as required by law. Security logs are kept for 12 months.
5. Your rights
You can access and export your data (Profile → Export), correct it (Profile → Edit), and delete your account at any time. Deletion anonymises your records while preserving group ledger integrity.
6. Who we share data with
We use the following processors to run WeBash. None of them may use your data for their own purposes.
| Processor | Purpose | Data | Location |
|---|---|---|---|
| Railway | Application hosting | All application data in transit and at rest | United States |
| Supabase | Database and avatar image storage | All account, group, event, and expense data; uploaded avatar images | European Union (Frankfurt, Germany) |
| Resend | Transactional email delivery | Email address, name, and the content of transactional emails (OTP codes, invitations, payment requests, reminders) | European Union (Ireland) |
| Vercel | Web application hosting | Traffic metadata for the pages you visit; no account data is stored by Vercel | To be confirmed |
| Calendar import and address/place autocomplete, if you choose to connect them | OAuth profile identifiers, calendar event data you import, and place search queries | To be confirmed | |
| HaveIBeenPwned | Checking new passwords against known data breaches at registration and password change | A partial, irreversible hash of the password you choose (k-anonymity — your actual password is never sent) | To be confirmed |
7. International transfers
Railway processes data in the United States; we rely on Standard Contractual Clauses or an equivalent safeguard recognised under GDPR Chapter V for this transfer. Supabase and Resend process data within the European Union, so no third-country transfer applies to them. Where a processor's location above is marked "to be confirmed", we are finalising that information and will update this policy once it is verified.
8. Contact
TODO(owner): a dedicated privacy mailbox has not yet been provisioned — see PRE-LAUNCH-AUDIT-2026-07.md, item O4.