Privacy Policy

Last updated: March 9, 2026

Overview

Basis (“we”, “our”, or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web application and related services.

Information We Collect

Account Information

When you create an account, we collect your name, email address, and authentication credentials. We use Supabase for authentication and do not store passwords directly.

Financial Data

When you upload bank statements, credit card statements, or receipts, we process and store the transaction data contained in those documents. This may include transaction dates, amounts, vendor names, and the last four digits of account numbers. We never store full account numbers — even if a full account number appears on an uploaded statement, only the last four digits are retained. This data is used solely to provide you with expense tracking and reporting services.

Property Information

We collect property details you provide, including addresses, property types, and unit information, to organize your financial data by property.

Usage Data

We automatically collect certain information when you access our service, including your IP address, browser type, device information, and pages visited. This information is used to improve our service and is not linked to your financial data.

How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our expense tracking services
  • Parse and categorize your financial transactions
  • Generate reports including IRS Schedule E
  • Train and improve our AI categorization models using anonymized, aggregated data
  • Send you service-related communications
  • Respond to your requests and support inquiries

Data Storage and Security

Your data is stored securely using Supabase's infrastructure with row-level security policies ensuring you can only access your own data. All data is encrypted in transit using TLS and at rest. We do not store sensitive account numbers — only the last four digits are retained for identification purposes. We implement industry-standard security measures to protect against unauthorized access, alteration, or destruction of your data. For more details, see our Security page.

Data Sharing

We do not sell, trade, or rent your personal or financial information to third parties. We may share information only in the following circumstances:

  • Service Providers: We use third-party services (hosting, authentication, AI processing) that may process your data on our behalf, subject to confidentiality obligations.
  • Legal Requirements: We may disclose your information if required by law, regulation, or legal process.
  • With Your Consent: We may share information when you explicitly authorize us to do so, such as exporting reports.

Data Retention

We retain your data for as long as your account is active or as needed to provide you services. You can request deletion of your account and associated data at any time by contacting us.

Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Export your data in standard formats (CSV, PDF)
  • Opt out of non-essential communications

Cookies and Tracking

We use essential cookies for authentication and session management.

We also use the Meta (Facebook) Pixel, a small piece of code that helps us measure the effectiveness of our advertising by understanding the actions people take on our website. The pixel may collect information such as your IP address, browser information, and page views. This data is used to deliver relevant ads and measure ad conversions. You can opt out of Meta's data collection by adjusting your Facebook ad preferences or by using browser-level ad-blocking tools.

Children's Privacy

Our service is not directed to individuals under 18. We do not knowingly collect personal information from children.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised “Last updated” date.

Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at privacy@getbasis.io.