1. Who We Are
MoneySorted ("we", "us", "our") is a UK-based software service available at getmoneysorted.co.uk. We provide a bank statement analysis tool that allows users to upload PDF bank statements and receive spending insights and data exports.
This Privacy Policy explains how we collect, use, store, and protect your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. What Data We Collect
Account Data
When you create an account, we collect:
- Your name and email address
- A hashed version of your password (we never store your password in plain text)
- Your subscription plan and billing status
Bank Statement Data
When you upload a bank statement PDF:
- The PDF is processed in server memory to extract transaction data
- The original PDF file is deleted immediately after processing — it is never written to permanent storage
- Extracted transaction data (dates, amounts, merchant names, categories) is stored in your account for as long as you maintain an account with us
Payment Data
Payments are handled entirely by Stripe. We do not store your card number, sort code, or any raw payment credentials. We receive a Stripe customer ID and subscription status from Stripe after a successful payment.
Usage Data
We may collect anonymised usage data including pages visited, features used, and browser type to improve the service. This data cannot be used to identify you individually.
3. Legal Basis for Processing
We process your personal data under the following legal bases:
- Contract performance — processing your account data and bank statement data is necessary to provide the service you have signed up for
- Legitimate interests — improving and securing the service, preventing fraud
- Legal obligation — retaining billing records as required by UK law
- Consent — where you have explicitly opted in to marketing communications
4. How We Store Your Data
Your account data and processed transaction records are stored in a secured PostgreSQL database hosted on infrastructure within the UK or EEA. We use encryption in transit (HTTPS/TLS) and at rest for sensitive data fields.
Your original PDF bank statement files are never stored. They exist only in server memory during processing and are discarded immediately after your transaction data has been extracted.
5. Third Parties We Share Data With
We share your data with the following third parties only to the extent necessary to operate the service:
- Stripe — payment processing. Stripe's privacy policy applies to data they collect: stripe.com/gb/privacy
- Railway / hosting infrastructure — server hosting. Your data is processed on their infrastructure under data processing agreements
- Google Analytics — anonymised usage analytics. No personally identifiable information is shared
We do not sell your personal data to any third party, ever.
6. Data Retention
- Account data: retained for the duration of your account, plus 30 days after deletion to allow for recovery requests
- Transaction data: retained for the duration of your account
- Billing records: retained for 7 years as required by HMRC regulations
- PDF uploads: deleted immediately after processing — zero retention
7. Your Rights Under UK GDPR
You have the following rights regarding your personal data:
- Right of access — request a copy of the personal data we hold about you
- Right to rectification — request correction of inaccurate data
- Right to erasure — request deletion of your personal data ("right to be forgotten")
- Right to data portability — receive your data in a machine-readable format
- Right to object — object to processing based on legitimate interests
- Right to restrict processing — request we limit how we use your data
To exercise any of these rights, contact us at hello@getmoneysorted.co.uk. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
8. Cookies
MoneySorted uses the following cookies:
- Session cookie — required for authentication. Deleted when you close your browser or sign out
- Google Analytics cookies — anonymised usage tracking. You can opt out via your browser settings or a browser extension
We do not use advertising, tracking, or profiling cookies.
9. Children's Privacy
MoneySorted is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes by email. The "last updated" date at the top of this page reflects the most recent revision. Continued use of MoneySorted after changes are posted constitutes acceptance of the updated policy.
11. Contact
For any privacy-related questions or to exercise your data rights, contact us at: