Skip to main content

Privacy

We believe your financial commitments are your business, not ours.

Minimal Data

We aim to store as little data as possible on our servers.

No Tracking

We don't use invasive trackers or sell your behavioral data.

Secure

Industry standard encryption for any data that must be synced.

Data Controller

Buxloop is operated by Apostolia, an individual based in Greece. For any data protection matters, you can reach us at buxloop.team@gmail.com.

Our Commitment

Buxloop is built with privacy in mind. Unlike traditional fintech apps that profit from selling your financial data to advertisers, Buxloop's business model is based on providing a tool for tracking your recurring expenses.

Legal Basis for Processing

Under GDPR, we only process personal data where we have a legal basis to do so. For waitlist email, the basis is consent because you actively submitted the form. For IP address rate limiting, the basis is legitimate interest in preventing automated abuse of our infrastructure. For Umami Analytics, since Umami does not collect personal data by design, GDPR's data processing requirements do not strictly apply. We still mention it here for full transparency.

What we collect

Waitlist email (Loops.so)

When you submit the waitlist form, your email is sent to our server and then to Loops (Loops.so), which acts as our email service provider. Loops stores your contact, sends confirmation and waitlist-related messages (including double opt-in where we have it enabled), and handles unsubscribe links. We pass your email plus a signup source label (e.g. that you joined from this marketing site). We do not collect your name or phone. The waitlist form only asks for email. How Loops processes data is covered in their privacy policy.

International transfer: Loops.so is a US-based company. By submitting the waitlist form, your email is transferred to and processed in the United States. Loops relies on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection. See their privacy policy linked above for details.

Retention: Your email is retained on Loops until you unsubscribe or request removal.

IP address (rate limiting only): To limit automated abuse on the waitlist endpoint, our server may use your IP address for about fifteen minutes in server memory only (sliding window of request counts). We also use form-level abuse prevention on submissions. We do not store your IP in our product database for waitlist signup, and the data we send to Loops is only your email and the source label, not your IP. On serverless hosting, that in-memory data does not last indefinitely (for example when an instance shuts down).

Subscription Data (when the app launches)

Buxloop is currently in pre-launch. The full app is not yet available. When it does launch, your expense data (names, amounts, frequencies, payment dates) will be stored securely in our database to power your dashboard. It will never be shared or sold.

Anonymized Usage

We use Umami Analytics to collect anonymous usage data. Umami Analytics is a privacy-first service that does not use cookies or collect personally identifiable information. All data is aggregated and anonymized to help us improve the website without identifying you.

Your Rights

You own your data. Once the app launches, you will be able to request an export or deletion of your entire Buxloop account and all associated information at any time. For waitlist-related data, you can unsubscribe using the link in any email from us, or contact us directly to request removal. Under GDPR, you also have the right to access, rectify, or erase your personal data, and the right to object to or restrict processing. If you believe your data is being handled unlawfully, you have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA).

Contact

If you have any questions about this policy or how we handle your data, reach us at buxloop.team@gmail.com.

Last updated: April 5, 2026