Privacy Policy – BudFin
Last Updated: 22 May 2026
J AND K WEB COLLECTIVE (PTY) LTD (“we”, “us”, “our”) operates the BudFin mobile application (“App”, “Service”). This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our App.
Your privacy is important to us. By using the App, you agree to the data practices described in this Privacy Policy.
1. Scope and Applicability
This Privacy Policy applies to users of the App distributed via the Google Play Store. We act as the responsible party under POPIA and, where applicable, the data controller for purposes of GDPR-equivalent frameworks.
2. Information We Collect
2.1 Information You Provide Directly
Account Information
- Email address (when signing in with Google)
- Display name
- Profile picture (if provided by Google)
- Google account identifier
Financial Data
- Budget entries (income and expenses)
- Transaction records
- Recurring schedules
- Budget categories
- Spending limits and thresholds
- Savings goals and progress
- Financial profile data
- Gamification data (XP, levels, achievements)
Application Preferences
- Currency preference
- Theme configuration
- Notification preferences
2.2 Information Collected Automatically
Device Information
- Device type and model
- Operating system and version
- Unique device identifiers
- App version
Usage and Diagnostic Data
- Features accessed
- Time spent in the App
- Crash reports and diagnostics
- Performance data
2.3 Information from Third-Party Services
Google Sign-In (Firebase Authentication)
When you sign in with Google, we receive:
- Google account email
- Display name
- Profile photo URL
- Unique Google identifier
Google AdMob (Advertising)
AdMob may collect:
- Device advertising identifiers
- IP address
- General location data (city-level)
- App usage data for ad targeting and measurement
Google Play Billing
- Purchase history
- Subscription status
Note: Payment information is handled entirely by Google Play. We do not collect or store payment card details.
3. Legal Basis for Processing (GDPR)
Where applicable, we rely on:
- Contract: To provide the Service and core functionality
- Consent: For advertising personalisation (where applicable)
- Legitimate Interests: Analytics, fraud prevention, and security
- Legal Obligation: Where required by law
4. How We Use Your Information
We use personal information to:
- Provide core budgeting functionality
- Display financial insights, charts, and analytics
- Enable cross-device sync (if signed in)
- Maintain platform security and prevent abuse
- Diagnose issues and improve performance
- Serve advertisements in the free version (where applicable)
We do not sell personal information.
5. Third-Party Services
5.1 Firebase (Google)
We use Firebase for:
- Authentication: Secure sign-in and account management (email, display name, profile photo, Google ID)
- Firestore: Cloud storage and synchronisation (user-provided financial data)
- Analytics & Crash Reporting: App performance and stability metrics
More information:
https://policies.google.com/privacy
5.2 Google AdMob
For free users, advertisements may be provided via Google AdMob.
- Data collected: Advertising ID, IP address, usage data
- Purpose: Ad delivery and performance measurement
- Opt-out: Available via Android device ad settings
More information:
https://policies.google.com/technologies/ads
5.3 Google Play Billing
For subscription management:
- Data collected: Purchase history, subscription status
- Purpose: Subscription verification, entitlement management, trials, discounts, offers, cancellations, and refunds
- Note: Payment information is handled entirely by Google Play
6. Data Storage and Security
6.1 Local Storage
Most financial data is stored locally on your device using encrypted storage (Hive). If you do not sign in, your data remains on your device.
6.2 Cloud Storage
If you sign in, your data is stored securely using Firebase with:
- Encryption in transit (TLS/SSL)
- Encryption at rest
- Access controls and authentication safeguards
6.3 Data Retention
- Local data: Until deleted or app uninstalled
- Cloud data: Until deleted in-app or full account deletion requested
- Analytics data: Retained for up to 14 months
7. Your Rights and Choices
7.1 Access Your Data
You can view your financial data within the App at any time.
7.2 Export Your Data
You can export your financial records (budget entries and transaction data only) via Settings → Data Management.
Export does not include authentication data, device information, analytics data, or advertising identifiers.
7.3 Delete Your Data
-
In-App Data Deletion: Settings → Account → Delete My Data
You will be required to review the notice, type DELETE, and select Delete Everything to confirm. This permanently removes your financial data from local storage and cloud storage (if applicable). Authentication remains active unless full account deletion is requested. - Full Account Deletion: Contact us at support@jnkwebcollective.co.za. We will process verified requests within 30 days.
- Uninstalling the App: Removes local data only. Cloud-synced data remains unless deleted in-app or via full account deletion.
7.4 Advertising Preferences
You can manage advertising personalisation via your Android device settings.
7.5 Disable Cloud Sync
You can use the App without signing in, keeping your data local to your device.
8. Financial Data Sensitivity
Financial data is treated as sensitive personal information.
- We do not sell financial data to third parties.
- We do not share financial data with banks, insurers, credit bureaus, or similar entities.
- We do not use financial data for credit profiling.
9. International Data Transfers
Your information may be processed in countries other than your own. Where required, we implement appropriate safeguards (including contractual protections).
10. Children’s Privacy
10.1 Minimum Age Requirement
BudFin is intended for individuals aged 13 years and older. The App is not directed to children under 13.
We do not knowingly collect personal information from children under 13. If you are under 13, you must not use the App.
10.2 Parental Requests
If a parent or legal guardian believes that a child under 13 has provided personal information to us, they may contact us at support@jnkwebcollective.co.za. We will take reasonable steps to investigate and delete such information promptly where appropriate.
10.3 International Age Requirements
In jurisdictions where the minimum age of digital consent is higher than 13 (for example, under certain provisions of the GDPR in the European Union), users must meet the minimum age requirement applicable in their country of residence.
We do not knowingly conduct behavioural advertising directed at children under 13.
11. California Privacy Rights (CCPA)
California residents may have the right to:
- Know what personal data is collected
- Request deletion of personal data
- Opt out of the sale of personal data (we do not sell data)
- Non-discrimination for exercising rights
Requests can be sent to: support@jnkwebcollective.co.za
12. European Privacy Rights (GDPR)
Where applicable, you may have rights to:
- Access, rectification, erasure
- Restriction and objection
- Data portability
- Withdraw consent
You may lodge a complaint with your local supervisory authority.
13. South African Privacy Rights (POPIA)
Responsible Party: J AND K WEB COLLECTIVE (PTY) LTD
You may:
- Request access, correction, or deletion of personal information
- Object to processing (where applicable)
- Lodge a complaint with the Information Regulator
Contact: support@jnkwebcollective.co.za
14. Changes to This Privacy Policy
We may update this Privacy Policy periodically. Changes will be reflected by updating the "Last Updated" date and may be communicated in-app where appropriate.
Continued use of the App constitutes acceptance of the updated Privacy Policy.
15. Contact Us
For privacy questions or requests:
Email: support@jnkwebcollective.co.za
Response Time: Within 30 days