Privacy Policy
Your privacy matters to us. This Privacy Policy explains how Coral Dash collects, uses, stores, and protects your information when you use our service.
1. Introduction
Coral Dash ("we", "us", "our") is committed to protecting your privacy and handling your personal data responsibly. This Privacy Policy describes our practices regarding the collection, use, and disclosure of your information.
Important: Coral Dash is an independent project and is not affiliated with, endorsed by, or connected to Monzo Bank Ltd. We do not have direct access to your Monzo account or banking credentials.
By using Coral Dash, you consent to the data practices described in this policy. If you do not agree with our practices, please do not use our service.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address (via Google OAuth)
- Name and profile information (as provided by Google)
- Account preferences and settings you configure
2.2 Google Sheets Data
When you connect your Google Sheets account, we access your spreadsheet data in read-only mode to:
- Retrieve your transaction data from the connected spreadsheet
- Process and display your financial information in the dashboard
- Generate insights, summaries, and reports
We only access the specific spreadsheet you authorise. We do not access, read, or store any other files in your Google Drive or Google account.
2.3 Usage Data
We may automatically collect information about how you use the service:
- Pages and features you access
- Time spent on the service
- Device information (browser type, operating system)
- IP address
2.4 Payment Information
Payment processing is handled entirely by Stripe, a PCI-compliant payment processor. We do not store your complete credit card number, CVV, or other sensitive payment details on our servers. We may receive and store:
- Last four digits of your card (for display purposes)
- Card type and expiry date
- Billing address
- Stripe customer ID
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Coral Dash service
- Process your subscription and manage your account
- Display your financial data and generate insights
- Send you service-related communications (account updates, billing notices)
- Respond to your enquiries and provide customer support
- Improve and optimise the service
- Detect and prevent fraud or abuse
- Comply with legal obligations
We do not sell, rent, or share your personal data with third parties for their marketing purposes.
4. Third-Party Services & Technology Stack
Coral Dash uses the following third-party services to operate. By using our service, you acknowledge that your data may be processed by these providers in accordance with their respective privacy policies:
Our Technology Stack
- Supabase (Database & Authentication)
Your account data and application data are stored on Supabase's cloud infrastructure. Supabase provides row-level security and encryption. We adhere to Supabase's security best practices.
- Vercel (Hosting & Infrastructure)
The Coral Dash application is hosted on Vercel's global edge network. Vercel may process request logs and performance data.
- Stripe (Payment Processing)
All payment transactions are processed by Stripe, a PCI DSS Level 1 certified payment processor. We never have access to your full card details.
- Google (OAuth & Sheets API)
We use Google OAuth for authentication and the Google Sheets API to access your authorised spreadsheet data.
We follow the security best practices and guidelines established by these providers. However, we cannot guarantee the security practices of third-party services beyond what they publicly disclose.
5. Data Storage & Security
We implement industry-standard security measures to protect your data:
- All data is transmitted over HTTPS (TLS encryption)
- Database access is protected by row-level security policies
- Authentication is handled via secure OAuth protocols
- Access to production systems is restricted and logged
Your data is primarily stored on Supabase's cloud infrastructure, which may be located in data centres in the United States or other regions. Vercel's edge network operates globally.
6. Data Loss Disclaimer
IMPORTANT NOTICE
While we take reasonable measures to protect your data, we cannot guarantee the absolute security or availability of your data. By using Coral Dash, you acknowledge and accept the following:
- No guarantee of data availability: Service interruptions, outages, or technical failures may occur at any time, potentially resulting in temporary or permanent loss of access to your data.
- No responsibility for data loss: We are not responsible for any loss, corruption, or unauthorised access to your data, whether caused by system failures, security breaches, third-party actions, or any other circumstances.
- Third-party dependencies: We rely on Supabase, Vercel, Google, and other third-party providers. Failures or issues with these services may impact your data and are outside our control.
- User responsibility: You are solely responsible for maintaining your own records and backups of your financial data. Coral Dash should not be your only source of financial records.
- No data recovery guarantee: In the event of data loss, we cannot guarantee that your data can be recovered.
We strongly recommend that you maintain independent records of your financial information and do not rely solely on Coral Dash for critical financial data storage.
7. Data Retention
We retain your personal data for as long as your account is active or as needed to provide you with the service.
- Active accounts: Data is retained while your subscription is active.
- Account deletion: Upon your request to delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal purposes.
- Legal retention: We may retain certain data as required by law (e.g., transaction records for tax purposes) or to protect our legal rights.
8. Your Rights
If you are located in the UK or European Economic Area (EEA), you have certain rights under the General Data Protection Regulation (GDPR):
- Right of access: You can request a copy of the personal data we hold about you.
- Right to rectification: You can request that we correct any inaccurate or incomplete data.
- Right to erasure: You can request that we delete your personal data (subject to legal retention requirements).
- Right to data portability: You can request a copy of your data in a structured, machine-readable format.
- Right to object: You can object to certain types of processing.
- Right to withdraw consent: Where we process data based on your consent, you can withdraw that consent at any time.
To exercise any of these rights, please contact us through our contact page or delete your account through your account settings.
9. Cookies
Coral Dash uses cookies for the following purposes:
- Essential cookies: Required for authentication and maintaining your session. These cannot be disabled.
- Preference cookies: Remember your settings and preferences (e.g., theme selection).
We do not use third-party tracking cookies or advertising cookies. We do not share cookie data with third parties for advertising purposes.
10. Children's Privacy
Coral Dash is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without parental consent, we will take steps to delete that information.
11. International Data Transfers
Your data may be processed and stored in countries outside the United Kingdom and European Economic Area, including the United States, where our third-party service providers (Supabase, Vercel, Stripe, Google) maintain their infrastructure.
These providers are selected for their compliance with applicable data protection standards and, where applicable, participate in data protection frameworks recognised by UK and EU authorities.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Notify you via email for significant changes
Your continued use of the service after any changes indicates your acceptance of the updated policy.
13. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us through our contact page.