Privacy Policy
Last updated: July 21, 2026 · Version 2026-07-21.1
This Privacy Policy explains what personal information Waypenny,
operated by Tony Thomas Art LLC (“Waypenny,”
“we,” “us”)
collects when you use our web service, how we use it, who we share it with,
how long we keep it, and the choices you have. It works together with our
Terms of Service.
The short version. We collect only what we need to run the
Service you signed up for. We never sell your personal data. We do not run
third-party advertising. We do not use your financial data to train AI
models. Every administrator action against your account is logged.
1. What We Collect
Account information you give us
- Email address, first and last name, and password (or a Google account
identifier if you sign in with Google);
- Optional business profile fields you enter (business name, address, tax
basics you configure yourself);
- Subscription plan and status;
- Stripe customer and subscription identifiers (assigned by Stripe when
you subscribe).
Financial data you enter
- Income entries, bills, budgets, net-worth items, debts, retirement
accounts, savings goals;
- Sales, expenses, cash-flow transactions, products, sales pipeline,
client records, employee/payroll figures, tasks, documents you upload;
- Invoices you create, invoice statuses, and associated client contact
details;
- Snapshots (backups) of the data above, taken automatically after each
save.
You enter this data yourself. Waypenny does not pull it from
your bank in this release. If bank connections (Plaid) become available in
a later release, the additional data collected will be described in an
updated version of this Policy and you’ll be prompted to re-accept.
Data we generate
- Server-side records of when you signed in (IP address, timestamp);
- Terms-of-service acceptance records (version accepted, timestamp, IP
address, browser user agent) — needed to prove enforceable
consent;
- Administrative-action audit log (which internal operator touched what,
when, why) — needed for security and support accountability;
- Diagnostic logs (errors, request-level metadata) held for a short
window to fix bugs and detect abuse.
Data you send to support
Bug reports, feedback, and support messages you send us include the message
body, your email address, the page you were on, and your browser user
agent.
2. How We Use It
We use the information above to:
- Provide and maintain the Service you signed up for;
- Charge your subscription and process payments through Stripe;
- Send transactional emails (payment receipts, cancellation confirmations,
security alerts, invoice-related emails triggered by you);
- Respond to support requests;
- Diagnose bugs and outages;
- Detect and prevent abuse, fraud, or security incidents;
- Comply with our legal obligations;
- Prove enforceable consent to our Terms of Service.
We do not use your data to train AI models, we do
not use it to serve advertising, and we do
not profile you for marketing purposes.
3. Legal Basis for Processing
If you are in a jurisdiction that requires us to name a legal basis
(e.g., GDPR-covered European users), our bases are:
- Contract — running the Service you signed up
for;
- Legitimate interests — security, fraud
prevention, keeping the Service reliable;
- Legal obligation — where a law requires us to
keep or produce data;
- Consent — where you’ve explicitly opted
in (for example, connecting an integration).
4. Stripe as Payment Processor
Payments for your Waypenny subscription are handled by
Stripe, Inc. When you subscribe, we send Stripe your email
address, name, and the plan you selected; you enter your card details
directly into Stripe’s hosted checkout. Waypenny never sees or stores
your card number, CVV, or bank credentials. Stripe’s handling of your
payment data is governed by
Stripe’s
privacy policy.
If you use the invoicing feature and connect your own Stripe account
(Stripe Connect), your clients pay your Stripe account directly. Waypenny
receives back only the metadata needed to mark an invoice paid; we do
not hold your clients’ funds.
5. Integrations You Connect
Some features let you connect third-party services (for example, Shopify
for sales imports, Stripe Connect for accepting invoice payments). We only
collect data from a third-party service after you connect it,
and only the data needed to power the feature you enabled. You can
disconnect an integration from the Settings screen at any time; when you do,
we stop pulling data from it and delete the credentials we used to access
it.
6. Firebase & Google Cloud Infrastructure
Waypenny runs on Firebase and Google Cloud
Platform, operated by Google LLC. Your data is stored in Google
data centres. Google acts as our sub-processor and is contractually bound
to protect your data. Google’s privacy commitments for these products
are described at
cloud.google.com/terms/data-processing-addendum.
7. Sharing — What We Don’t Do
We do not sell your personal data. We do not
share it with third parties for their marketing.
We share data only with:
- Sub-processors we need to run the Service. Currently:
Google (Firebase / Google Cloud) for hosting, Stripe for payments,
Resend for transactional email delivery. Each is bound by contract to
use your data only to serve us.
- People you invite. If you add a workspace member and
grant them permissions, they can see the workspace data those
permissions cover. You choose the permission bits.
- Waypenny operators. An internal administrator may
access account data as described in
Terms § 11. All access is
logged.
- Legal requests. We may disclose data if required by
law (subpoena, court order, or similar) or to protect our rights or
the safety of others. We’ll narrow the disclosure to what the
request actually compels.
- Business transfer. If Waypenny is acquired or merges,
your data may transfer to the successor entity under the same
protections as this Policy.
8. Data Retention
We keep your data while your account is active. If you request deletion,
the retention timeline in Terms § 10
applies:
- 14-day grace period after you request deletion, during
which you can cancel.
- Purge after the grace period ends: profile, workspaces
you own, subcollections (payroll, invoices, tasks, documents), backups,
legacy records, and your Firebase Auth record are permanently deleted.
- Automated retention deletion of cancelled accounts
that remain inactive for 12 months, after two warning emails.
A limited audit-log record of administrative actions may be retained where
required for security or legal reasons. Diagnostic logs are held for up to
90 days. Financial records we’re required by law to keep for our own
tax purposes (payment records, invoices for our subscription revenue) are
retained per applicable law — typically seven years.
9. Security
- Encryption in transit. All connections are HTTPS/TLS.
- Encryption at rest. Data stored in Firestore, Firebase
Storage, and Cloud Functions state is encrypted at rest by Google
Cloud.
- Access controls. Server-side Firestore Security Rules
gate every read and write; workspace data is walled off by a
nine-bit per-permission model plus per-member module gates. API keys
for third-party services (Stripe, Claude, Plaid if enabled) live in
Firebase Secret Manager and never touch the client.
- Audit logging. Every administrator action against a
subscriber account is written to a server-side audit log.
- Password policy. Minimum 12 characters, enforced by
Firebase Authentication.
No online service is 100% secure. If we learn of a breach affecting your
data, we’ll notify you as required by law.
10. Your Rights
Wherever you are, you can:
- Access your data by signing in and viewing it in the
Service, or by contacting us for an export;
- Correct account information by editing it in the
Service;
- Delete your account from Settings (with the 14-day
grace period described above);
- Export your workspace data from the Settings screen.
If you are in a jurisdiction with additional statutory rights (right to
restrict processing, right to portability, right to object, right to
lodge a complaint with a supervisory authority), you can exercise those by
contacting privacy@waypenny.com.
We’ll respond within the timeframe required by the applicable law.
11. Cookies & Local Storage
We use a small number of first-party cookies and browser
localStorage entries, all of which are strictly necessary
to run the Service:
- Firebase Authentication session (so you stay signed in);
- Active workspace pointer, sidebar collapse state, and similar UI
preferences;
- A short-lived breadcrumb for invite-accept round-trips.
We do not use third-party analytics cookies, advertising cookies, or
cross-site trackers.
12. Children
The Service is not directed to children under 18 and we do not knowingly
collect data from anyone under 18. If you believe a child has provided us
data, contact us and we’ll delete it.
13. International Users
Waypenny is operated from the United States. If you access the Service from
outside the U.S., your data will be transferred to and processed in the
U.S. and other countries where our sub-processors operate. By using the
Service you consent to this transfer.
14. Changes to This Policy
We may update this Policy from time to time. If we make material changes,
we’ll notify you by email (to the address on file) and require you
to re-accept the updated Terms (which cover this Policy) the next time you
sign in before you can continue using the Service. The “Last
updated” date and Version number at the top of this page reflect the
current version.
For general privacy questions:
privacy@waypenny.com.
For general support:
support@waypenny.com.