This Privacy Policy explains how Spendle ("we", "us", "our") handles your personal information. We are committed to protecting your privacy and handling your information in line with the New Zealand Privacy Act 2020 and the Information Privacy Principles.
This is a draft document provided for transparency while Spendle is pre-launch. It is not yet final and is to be reviewed by a lawyer before launch.
Who we are
Spendle is a personal finance app made in New Zealand. You can contact us about privacy at privacy@spendle.co.nz.
Information we collect
We collect the following kinds of information.
Information you give us, which may include:
- Your name, email address and other contact details.
- Any messages you send us, such as questions or instructions.
Information from the bank and other accounts you connect, retrieved read-only through our open-banking provider Akahu, which may include:
- Account details, such as the provider, the account name and type, and account numbers.
- Financial information, such as balances, transactions and history, payment due dates, credit limits and product details.
- Identifiers held on the account, such as the account holder’s name.
We never see or store your internet banking login details. Where your bank offers an official open-banking service, the connection uses secure tokens, and Akahu handles any credentials directly rather than sharing them with us.
Usage information, such as how you interact with the app, to help us keep it working well and improve it. On this marketing website, analytics are only collected once you actively consent.
How the bank connection works (open banking via Akahu)
Spendle connects to your accounts through Akahu (Akahu Technologies Limited), a New Zealand open-banking provider. When you connect an account, you grant consent through Akahu, and Akahu retrieves the data you have agreed to share so that Spendle can do the maths for you. The connection is read-only: Spendle can see your transaction and balance information, but cannot move money.
Akahu applies the principle of least privilege, meaning it only retrieves the data that is reasonably necessary for the features you use. Akahu operates the connection under its own Privacy Notice and End User Terms, and stores that connection data securely. Akahu does not sell or rent your data.
You stay in control. You can view, manage and revoke your connections at any time, both inside Spendle and through Akahu at my.akahu.nz. When you revoke a connection, Akahu deletes the connection data it holds within 24 hours of that revocation or expiry.
How we use your information
- To calculate your safe-to-spend number, categorise spending and power the features you use.
- To provide the AI coach. AI processing and email are handled within Australia and New Zealand.
- To communicate with you about your account and, if you opt in, product updates.
- To keep Spendle secure and to meet our legal obligations.
Who we share information with
- Akahu, our open-banking provider, to establish and maintain your bank connection.
- Service providers who help us run Spendle, such as cloud hosting, AI processing and email, under agreements that require them to protect your information.
- Authorities or others, where we are required to by law, or where it is needed to protect people from fraud or harm.
- In connection with a future change in ownership of our business, in which case this policy continues to apply.
We do not sell or rent your personal information, and we never show ads.
Where your data is stored
Your information is stored securely on Amazon Web Services, a trusted cloud platform, with data centres in New Zealand and Australia. It is encrypted in transit and at rest, and protected by strict access controls. The bank-feed connection is handled separately by Akahu under its own Privacy Notice.
When information is held or processed overseas, we take reasonable steps to ensure it is protected to a standard comparable to the New Zealand Privacy Act 2020, including through our agreements with the providers involved.
Keeping your information safe
- Two-factor authentication is enforced on every account.
- Your information is encrypted in transit and at rest.
- We limit access to personal information to those who need it to do their job.
Your rights
Under the Privacy Act 2020 you have the right to:
- Access the personal information we hold about you.
- Ask us to correct information that is wrong.
- Export your data, and delete your account and data, at any time.
- Revoke your bank connection at any time.
To exercise any of these, contact privacy@spendle.co.nz.
Cookies and analytics
On this website, non-essential cookies and analytics are declined by default. Nothing loads until you actively accept. You can change your mind at any time by clearing your choice in your browser.
Complaints
If you are not happy with how we have handled your information, please tell us first so we can put it right. You can also contact the Office of the Privacy Commissioner at privacy.org.nz.
Changes to this policy
We will update this policy as Spendle grows, and we will let you know about any significant changes.
Spendle is not a registered bank, lender or licensed financial adviser. Information in the app is general in nature and is not personalised financial advice.