Back to WeBash

Privacy Policy

Last updated: 2026-06-09

1. Who we are

WeBash helps social groups plan events and split shared costs. This policy explains what personal data we collect, why, and your rights under the GDPR.

2. Data we collect

Account data (name, email, phone, locale); group and event data you create; expense records you enter (amounts and mark-as-paid status — we never store card or bank credentials); and security logs. Lawful bases: consent (registration), contract (expense tracking), and legitimate interest (security).

3. How we use it

To operate the service, send transactional notifications and emails you have not opted out of, enforce subscription limits, and keep the platform secure. We do not sell your data and do not use advertising or tracking cookies.

4. Retention

Account data is kept until you delete your account; deleted-account PII is anonymised and wiped within 30 days; financial records are anonymised and retained as required by law. Security logs are kept for 12 months.

5. Your rights

You can access and export your data (Profile → Export), correct it (Profile → Edit), and delete your account at any time. Deletion anonymises your records while preserving group ledger integrity.

6. Who we share data with

We use the following processors to run WeBash. None of them may use your data for their own purposes.

ProcessorPurposeDataLocation
RailwayApplication hostingAll application data in transit and at restUnited States
SupabaseDatabase and avatar image storageAll account, group, event, and expense data; uploaded avatar imagesEuropean Union (Frankfurt, Germany)
ResendTransactional email deliveryEmail address, name, and the content of transactional emails (OTP codes, invitations, payment requests, reminders)European Union (Ireland)
VercelWeb application hostingTraffic metadata for the pages you visit; no account data is stored by VercelTo be confirmed
GoogleCalendar import and address/place autocomplete, if you choose to connect themOAuth profile identifiers, calendar event data you import, and place search queriesTo be confirmed
HaveIBeenPwnedChecking new passwords against known data breaches at registration and password changeA partial, irreversible hash of the password you choose (k-anonymity — your actual password is never sent)To be confirmed

7. International transfers

Railway processes data in the United States; we rely on Standard Contractual Clauses or an equivalent safeguard recognised under GDPR Chapter V for this transfer. Supabase and Resend process data within the European Union, so no third-country transfer applies to them. Where a processor's location above is marked "to be confirmed", we are finalising that information and will update this policy once it is verified.

8. Contact

TODO(owner): a dedicated privacy mailbox has not yet been provisioned — see PRE-LAUNCH-AUDIT-2026-07.md, item O4.

Terms of Service

WeBash