Privacy Policy
Pennyguard is an online personal finance and savings management service owned and operated by Pennyguard Limited, doing business as PennyGuard™ ("PennyGuard," "we," "us," or "our"). We value your privacy and are committed to being transparent about how we handle your personal information.
This Privacy Policy explains how we collect, use, share, and safeguard your information when you interact with our services, including our mobile applications, the PennyGuard website located at pennyguard.com (the "Website"), and any related features, content, or platforms (collectively referred to as the "Services") and is an integral part of our Terms of Use.
BY USING THE SERVICES, YOU PROMISE US THAT (I) YOU HAVE READ, UNDERSTAND AND AGREE TO THIS PRIVACY POLICY, AND (II) YOU ARE AT LEAST 18 YEARS OF AGE. If you do not agree, or are unable to make this promise, you must not use the Services. In such case, you must (a) contact us and request deletion of your data; (b) cancel any subscription using the functionality provided by instructions on the Website; and (c) leave the Website and not access or use it.
"GDPR" means the General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
"EEA" includes all current member states of the European Union and the European Economic Area. For the purpose of this policy, EEA shall include the United Kingdom of Great Britain and Northern Ireland.
"Process," in respect of personal data, includes to collect, store, and disclose to others.
"Partner" means a third-party provider of a financial or other product or service that is presented to you through the Services — including banks, lenders, credit card issuers, mortgage and loan brokers, insurance carriers and producers, savings and telecom providers, credit-building providers, and tax preparation providers — as well as the platforms that connect us to such providers.
"Connected Account" means any bank, card, loan, or email account that you choose to link to the Services.
Some states may provide additional privacy rights. Please refer to the "Additional State Privacy Rights" section to learn more.
TABLE OF CONTENTS
3. For what purposes we process your personal data
4. Credit score, Credit Insights, and Credit Building
5. Under what legal bases we process your personal data (Applies only to EEA-based users)
6. With whom we share your personal data
9. International data transfers
10. Changes to this privacy policy
11. Additional State Privacy Rights
12. Right to Limit Processing of Sensitive Personal Information
Personal Data Controller
Pennyguard Limited, a company registered under the laws of the Republic of Cyprus with registration number HE 498282, having its registered office at 2 Grammou Street, Paphos, 8025, Cyprus, and its principal place of business at Omega Business Center, 3rd floor, Riga Fereou 4, Limassol, 3095, Cyprus, will be the controller of your personal data.
What data do we collect
We collect data you give us voluntarily (for example, when you enter your name or email). We also collect data automatically (for example, your IP address), we receive data from Partners and other third parties, and we use third-party service providers for such collection
2.1. Data you give us
You provide us information about yourself when you register for and/or use the Services. The specific information we collect depends on the context in which you provide it, and could include:
Identification data
- Full name
- Email address
- Postal address
- Phone number
- Date of birth
- Government-issued identifiers, including all or part of your Social Security Number or taxpayer identification number, where this is necessary to retrieve your credit file, to verify your identity, to submit an application to a Partner, or to prepare or file a tax return
- Any other information you provide
Financial profile data
Where you use features that depend on it, you may provide information such as your income and employment status, housing costs, household size, dependants, assets, debts you add manually, and the financial goals you set in the Services. You are not required to provide this information, but some features will not work, or will produce less relevant results, without it.
Commercial information
When you make payments through the Services, you need to provide financial account data, such as your credit card number, to our third-party service providers that serve us as data and payment processors. We do not collect or store, or have access to, full credit card number data, though we may receive some limited information, including credit card-related data (including a secure token reflecting your payment method), data about products or services purchased, date, time and amount of the purchase, the type of payment method used, and limited digits of your card number.
Tax information
If you choose to use tax preparation and filing features, you or your documents will provide the information required to prepare a return, which may include your filing status, dependants, wage and income statements (such as W-2 and 1099 forms), deductions and credits you claim, prior-year return data, and the bank account details to which a refund should be sent.
Claims and settlement information
If you choose to use settlement or claim filing features, you may provide the information a claims administrator requires to process a claim, which may include proof of purchase, account identifiers, dates of use of a product or service, and a declaration made under penalty of perjury.
Comments you provide with your requests
You may also provide us with some personal information using our "Contact us" forms or by sending emails to our email addresses. This information may include any comments you include when you send your inquiry.
2.2 Data we collect automatically
Data about how you found us: we collect data about your referring URL (that is, the place on the Web where you were when you tapped on our ad).
Device and location data: we collect data from your device. Examples of such data include language settings, IP address, time zone, type and model of a device, device settings, and operating system and its version.
Usage data: we record how you interact with our Services. For example, we log your taps/clicks on certain areas of the interface, the features and content you interact with, how often you use the Services, how long you are in the Services, which offers you view and select, and your subscription orders. We also record the ads on our Website with which you interact (and the Internet links to which those ads lead).
Cookies: a cookie is a small text file that is stored on a user’s computer for record-keeping purposes. Cookies can be either session cookies or persistent cookies. A session cookie expires when you close your browser and is used to make it easier for you to navigate our Services. A persistent cookie remains on your hard drive for an extended period of time. We also use tracking pixels that set cookies to assist with delivering online advertising.
2.3. Data we collect from third-party providers
We may collect information about you from third-party sources in certain circumstances. Our Services offer or require integration with third-party platforms, allowing you to connect your account and securely import information directly into our system, so you do not have to enter it manually. The information we receive from such third parties varies depending on the information made available by those entities.
Plaid Technologies
We enable you to use Plaid Technologies, Inc. ("Plaid") to gather data from financial institutions. By using the Services, you acknowledge and agree that your information will be processed in accordance with the Plaid Privacy Policy (https://plaid.com/legal/#consumers), and you grant Pennyguard and Plaid the same rights, power, and authority as specified therein.
Examples of the types of information we receive through Plaid include financial account information, information about account balances, information about account transactions (including merchant name, amount, date, and category), identifiers, and information about account owners.
We use bank data to power the core of the Services: to build your accounts overview and budget tracker, to detect recurring charges, subscriptions, fees, and debt obligations, to identify where you may be overpaying, to determine which offers are likely to be relevant to you, and — where you ask us to — to support an action taken on your behalf. We do not sell your bank transaction data, and we do not disclose your raw bank transaction data to advertising networks or to Partners for their own independent marketing purposes. Where a Partner needs information to evaluate an application you have chosen to submit, we disclose the specific data elements necessary for that application, as described in Section 3.
Email account integrations
We may allow you to connect your email account in order to enable subscription, bill, and charge detection functionality.
For supported email providers other than Microsoft, we connect to your email account through our own integration using the relevant provider’s authorization process. For Microsoft email accounts, we may use Nylas, Inc. as our email integration provider.
If you choose to connect your email account, we will be provided with read-only access to that account. This access is limited solely to identifying and analyzing emails relevant to your money — such as payment receipts, billing statements, subscription, renewal, or cancellation notices, insurance and loan statements, and rewards or cashback confirmations — for the purpose of providing the Services.
The information we derive from those emails may include:
- Service or merchant names
- Subscription, bill, or premium amounts and currencies
- Billing frequency (for example, monthly or annual)
- Renewal, due, and cancellation dates
- Sender email addresses
We do not store or retain the full content of your emails, and we do not access personal or unrelated communications. We do not use the content of your email for advertising, and we do not disclose it to Partners. We may use information derived from your emails to improve our automated detection technology; this includes processing provider details and transaction data to enhance the accuracy of the Services. No other personal data or private communications are used for that purpose.
For Microsoft email accounts connected through Nylas, your information will be processed in accordance with the Nylas Privacy Policy (https://www.nylas.com/privacy-policy/) for the purposes described above.
You can revoke email access at any time in your account settings, by revoking access in your email provider’s own security settings, or by contacting us at privacy@pennyguard.com. Please note that revoking email access may limit or prevent the availability of certain core features of the Services.
Credit and liability data
Where you use credit score, credit insight, debt, or credit-building features, we obtain credit and liability information about you from one or more consumer reporting agencies or from a service provider that connects to them on our behalf. This information may include your credit score and the model used to generate it, the factors affecting that score, your open and closed tradelines, balances, limits, utilization, payment history, delinquencies, public records, inquiries, and student loan or other liability details.
We request this information only after you authorize us to do so. Please see Section 4 for further detail on how it is used.
Information we receive from Partners
When you engage with an offer, the relevant Partner or marketplace platform may tell us what happened next — for example, whether you clicked through, started or completed an application, were approved, were funded, or bound a policy, together with the amount or product concerned and the fee payable to us. We use this information to pay and reconcile our commercial arrangements, to measure which offers are useful to our users, to improve the relevance of the offers we show, and to calculate any success fee.
For what purposes we process your personal data
We process your personal data:
To provide our Services
As part of the Services, we process your information to build your money overview and budget tracker, to detect subscriptions, bills, fees, debts, and other recurring obligations, to identify where you are paying more than you need to, to help you cancel unwanted subscriptions, to help you secure eligible refunds, settlements, reimbursements, cashback, and rewards, and, where you instruct us, to take an action on your behalf. This includes enabling you to use the Services in a seamless manner and preventing or addressing Services errors or technical issues.
To host personal data and enable our Website to operate and be distributed, we use Amazon Web Services, which are hosting and backend services provided by Amazon.
To present personalized offers and connect you with Partners
We use the information available to us — your profile, your financial data from Connected Accounts, and, where you have authorized it, your credit data — to identify Partner products that are likely to be relevant and available to you. To do this, we may transmit a limited set of parameters (for example, state of residence, approximate income band, credit score band, and product type sought) to a marketplace platform such as Engine by MoneyLion or Insurify, Inc., which returns the offers that match. We aim to send the minimum information necessary to return a relevant set of offers.
Nothing is submitted to a Partner until you choose to proceed. When you do choose to proceed, we disclose to the relevant Partner the information necessary for that application, which may include your name, contact details, address, date of birth, income and employment details, identifiers required by law (including your Social Security Number where the Partner requires it), and the credit or financial parameters relevant to the product. You will be told, before you proceed, who the Partner is and what is being sent.
From that point onward the Partner processes your information under its own privacy policy and for its own purposes, and it — not PennyGuard — decides whether to offer you a product and on what terms. We do not control, and are not responsible for, the Partner’s processing.
To act on your behalf when you instruct us
When you instruct us to cancel a subscription, negotiate a bill, or terminate a service on your behalf, we act as your limited authorized agent for that specific purpose only. To complete the action, we may need to authenticate into a third-party account. We do not request or store passwords, we limit processing to the action you instructed, we use verification codes and session data once before deleting them, and we do not access your accounts without your explicit consent.
When you request us to cancel a subscription or terminate a service on your behalf, we process your request through automated systems in order to execute your instruction. Under certain data protection laws, this may qualify as a decision based solely on automated processing, as it results in the termination of a service contract. This processing is carried out strictly to perform the contract with you and to give effect to your explicit request.
To manage your account and provide you with customer support
Using your personal data to respond to your requests, provide technical support, service information, and send you important notifications, email, and updates about the performance of our Services, your account, security, payments, or our Terms of Use and policies.
To communicate with you regarding your use of our Services
Communicating with you and maintaining the history of communication. Freshdesk provides us with message and customer service tools, which enable us to communicate with you within the Services. When you chat with us via in-Service chat, some of your information is automatically transferred to Freshdesk. The transfer is required to enable us to identify you (if you shared any name-related data with us) and to communicate with you in the in-Service chat. Freshdesk uses this data to provide and fulfill its services (as set forth in their terms of service).
Note: To opt out of receiving emails, you should click the unsubscribe link in the footer of our email. The services that we use for these purposes may collect data concerning the date and time when the message was viewed by our users, as well as when they interacted with it, such as by clicking on links included in the message.
To research and analyze your use of the Services
Conducting internal research and analysis aimed at enhancing the quality of our Services, improving how you interact with our Website and mobile applications, revising our marketing strategies, and improving our offers to better meet your needs based on the results obtained from the processing of data.
To analyze how visitors use our Services and to measure the effectiveness of some ads, we use Google Analytics, a web analysis program of Google. In order to provide us with analytics, Google Analytics places cookies on your device. Through Google Analytics we obtain, in particular, aggregated information on the data you enter on our Services and users’ interactions within the Services. Google allows you to influence the collection and processing of information generated by Google, in particular by installing a browser plug-in.
We also use Amplitude, which is an analytics service provided by Amplitude, Inc. We use this tool to understand how customers use our Services. Amplitude collects various technical information, in particular time zone, type of device (phone or tablet), and unique identifiers. Amplitude also allows us to track various interactions that occur on the Website. As a result, Amplitude helps us to decide what features we should focus on. Amplitude provides more information on how it processes data in its Privacy Policy.
To send you marketing communications
Processing personal data for our marketing campaigns. We may add your email address and, where you have given the required consent, your phone number to our marketing list, provided we receive consent or otherwise establish a legal basis for sending you marketing communications. As a result, you will receive information about our products, such as special offers. If you do not want to receive marketing emails from us, you can unsubscribe by following the instructions in the footer of the marketing emails. If you have consented to receive marketing calls or text messages, you may withdraw that consent at any time as described in Section 7.
To communicate with you we use ActiveCampaign, which is a message sending service. We integrate Amplitude to create analytics-based audiences and track opening and conversion events.
To personalize our ads
In cooperation with Meta, Google, and TikTok, using your information to tailor your experience on our Website, such as showing you content and suggestions that match your preferences, interests, and past activity. We do not disclose your bank transaction data, the contents of your email, or your credit report data to advertising platforms for this purpose.
Online analytics and advertising: how to opt out
iOS: On your iPhone or iPad, go to "Settings," then "Privacy," and tap "Advertising" to select "Personalized Ads." In addition, you can reset your advertising identifier (this also may help you to see fewer personalized ads) in the same section.
Android: To opt out of ads on an Android device, open the Google Settings app on your mobile phone, tap "Ads," and enable "Opt out of interest-based ads." In addition, you can reset your advertising identifier in the same section.
macOS: On your MacBook, you can disable personalized ads: go to System Preferences > Security & Privacy > Privacy, select Apple Advertising, and deselect Personalized Ads.
Windows: On a laptop running Windows, select Start > Settings > Privacy and then turn off the setting for "Let apps use advertising ID to make ads more interesting to you based on your app activity."
In addition, you may get useful information and opt out of some interest-based advertising by visiting the following links:
- Network Advertising Initiative — http://optout.networkadvertising.org/
- Digital Advertising Alliance — http://optout.aboutads.info/
- Digital Advertising Alliance (Canada) — http://youradchoices.ca/choices
- Digital Advertising Alliance (EU) — http://www.youronlinechoices.com/
We value your right to influence the ads that you see, so we are letting you know what service providers we use for this purpose and how some of them allow you to control your ad preferences.
We use the Meta pixel on the Services. The Meta pixel is code placed on the Services that collects data helping us track conversions from Meta Ads, build targeted audiences, and remarket to people who have taken some actions on the Services (for example, made a purchase). We use Meta Ads Manager together with Meta Custom Audiences, which allows us to choose audiences that will see our ads on Meta or other Meta products (for example, Instagram). Meta also allows its users to influence the types of ads they see and to opt out of advertising delivered through Custom Audiences.
Google Ads is an ad delivery service provided by Google that can deliver ads to users. Google allows us to tailor ads so that they appear, for example, only to users that have conducted certain actions with our Services. Google allows its users to opt out of Google’s personalized ads and to prevent their data from being used by Google Analytics.
The TikTok pixel is a piece of JavaScript code that helps advertisers measure the cross-device impact of campaigns. TikTok Ads is the service provided by TikTok that can deliver ads to its users, and ads can be tailored to specific categories of users.
We may share, use, or publish aggregated or de-identified information that cannot reasonably be used to identify you, for any purpose, including marketing and industry benchmarking.
To process your payments
Using third-party services (Solidgate and other payment providers) for payment processing. As a result of this processing, you will be able to make a payment for our Services, and we will be notified that the payment has been made and will provide you with the Services.
Note: We will not store or collect your payment card details ourselves. This information will be provided directly to our third-party payment processors.
To enforce our Terms of Use and to prevent and combat fraud
Using personal data to enforce our agreements and contractual commitments, to verify your identity, and to detect, prevent, and combat fraud. As a result of such processing, we may share your information with others, including law enforcement agencies (in particular, if a dispute arises in connection with our Terms of Use).
To comply with legal obligations
Processing, using, or sharing your personal data to comply with applicable laws, regulations, and legal processes, and responding to governmental requests or court orders by available legal means.
Credit score, Credit Insights, and Credit Building
This section applies if you choose to use the credit features of the Services.
We obtain your credit score and credit file information from one or more consumer reporting agencies, directly or through a service provider that connects to them on our behalf. We do this only after you have authorized us to do so and have certified that you are requesting information about yourself. The score we display is an educational score; it may be calculated using a different model from the one a particular lender uses, and it may therefore differ from the score that lender sees.
We use your credit file information to display your score and the factors affecting it, to show your tradelines, balances, utilization, and payment history, to generate personalized insights and suggestions about actions that may affect your score, and to determine which offers you may be eligible for. Our requests for your credit information in connection with displaying your score and identifying offers are soft inquiries and do not affect your score. If you choose to proceed with an application to a Partner, that Partner may make a hard inquiry, which may affect your score; you will be told before this happens.
Where credit-building tools are offered, they may be provided by us or arranged through a Partner. If a Partner provides the product, we disclose to that Partner the information necessary to open and operate your account with it, and the Partner processes that information as an independent controller under its own privacy policy. Where a credit-building product results in information being furnished to a consumer reporting agency, you will be told which agencies receive it.
Pennyguard is not a consumer reporting agency, and we do not generate consumer reports about you or supply information about you to others for their credit, insurance, or employment eligibility decisions. Nothing we display is a guarantee that your score will change, that you will be approved for any product, or that any particular term will be offered to you. We do not charge for, and we do not provide, credit repair services.
Under what legal bases we process your personal data (Applies only to EEA-based users)
In this section we let you know what legal basis we use for each particular purpose of processing. For more information on a particular purpose, please refer to Section 3. This section applies only to EEA-based users.
We process your personal data under the following legal bases:
Your consent: we will send you marketing emails upon your explicit consent. We also rely on your explicit consent to access your Connected Accounts, to obtain your credit file, to transmit your application data to a Partner, and to use or disclose your tax return information. You have the right to withdraw your consent at any time, including by clicking the unsubscribe link in the footer of our marketing emails or by disconnecting an account in your settings.
To perform our contract with you: we will provide you with our Services and perform our obligations under the Terms of Use and other policies.
Legitimate interests: we will process your personal data to improve our Services and user experience, to promote our Services in a relevant and measured way, to personalize ads and tailor your experience to better match your interests, and to prevent fraud and secure the Services. We also may process and retain your personal data for purposes of legal compliance, dispute resolution, claims defense, or other legitimate business purposes. We rely on these interests only where they do not override your rights and freedoms, and you have the right to object to this type of processing at any time.
Legal obligations: we will process your personal data in order to comply with all and any applicable law.
With whom we share your personal data
We share information with third parties that help us operate, provide, improve, integrate, customize, support, and market our Services, with the following categories of third parties.
Operational service providers
- Cloud storage and hosting providers (Amazon Web Services)
- Payment processing providers (Solidgate, PayPal, Apple Pay, Google Pay)
- Financial data aggregation providers (Plaid Technologies, Inc.)
- Email integration providers (Nylas, Inc., for Microsoft email accounts)
- Credit and liability data providers and consumer reporting agencies (including through Spinwheel Solutions, Inc.)
- Customer support providers (Freshdesk)
- AI model providers acting as our processors under terms that prohibit training on your data
Partners and marketplace platforms
- Marketplace and offer platforms (such as Engine by MoneyLion and Insurify, Inc.)
- Banks, lenders, credit card issuers, brokers, insurance carriers and producers, savings, telecom, credit-building, and tax preparation providers whose offers you choose to proceed with
- Claims and settlement administrators, merchants, and service providers, where you instruct us to file a claim or take an action on your behalf
We disclose your information to a Partner only where you have chosen to proceed with that Partner’s offer or have instructed us to act, and only to the extent necessary for that purpose.
Business partners
- Data analytics providers (Meta, Google, Amplitude)
- Marketing partners (in particular, social media networks, marketing agencies, email delivery services, Meta, Google, TikTok, ActiveCampaign)
We also share personal information with your consent or at your direction, including but not limited to through third-party integrations you choose to enable.
Regulatory authorities
We may use and disclose personal data to enforce our Terms of Use, to protect our rights, privacy, safety, or property, and/or that of our affiliates, you, or others, and to respond to requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities, or in other cases provided for by law.
Affiliates
As we develop our business, we may buy or sell assets or business offerings. Customers’ information is generally one of the transferred business assets in these types of transactions. We may also share such information with any affiliated entity (for example, a parent company or subsidiary) and may transfer such information in the course of a corporate transaction, such as the sale of our business, a divestiture, merger, consolidation, or asset sale, or in the unlikely event of bankruptcy.
Your rights and choices
Right to be informed — to know how and why we collect and use your personal information.
Right of access — to request a copy of the personal data we hold about you.
Right to rectification — if any of your data is inaccurate or incomplete, you can ask us to correct it.
Right to erasure — to request that we delete your personal data.
Right to restrict processing — to limit how we use your data in specific circumstances.
Right to data portability — to receive your data in a structured, commonly used format, or to ask us to transfer it to another provider.
Right to object — to object to how we use your data, particularly if it is for direct marketing or profiling.
Note: You can request and exercise any of the rights mentioned above by sending us an email to privacy@pennyguard.com
In some cases we may be legally required to keep some of the data for a certain time; in such an event, we will fulfill your request after we have complied with our obligations. Please also note that a request to delete your data does not withdraw an instruction you have already given to a Partner, and it does not affect the data a Partner holds as an independent controller; you should contact the Partner directly for that.
Disconnecting accounts
You can disconnect a bank account, an email account, or your credit data at any time in your account settings. Disconnecting stops further collection from that source. Please note that disconnecting may limit or prevent the availability of core features of the Services.
Automated decision making
You will not be subject to any decision that has a legal effect on you, or similarly significantly affects you, based solely on automated decision-making by PennyGuard. Decisions about whether to grant you credit, insurance, or another product are made by the relevant Partner and not by us. The exception is the automated execution of an instruction you have given us, such as a cancellation request, as described in Section 3.
Marketing and communications
You can choose whether to receive promotional emails, calls, or text messages from us. To opt out of email marketing, use the unsubscribe link in the footer of our marketing emails; to stop text messages, reply STOP; to withdraw consent to marketing calls, contact us at privacy@pennyguard.com. To opt out of personalized advertising, please refer to Section 3.
Managing your personal data
You can access and review your personal data through your account settings. You may request us to update or correct your personal data collected during your use of the Services through privacy@pennyguard.com.
If you are based in the EEA, you have the right to lodge a complaint with a supervisory authority. We would prefer that you contact us directly so that we can address your concerns. Nevertheless, you have the right to lodge a complaint with a competent data protection supervisory authority, in particular in the EU Member State where you reside, work, or where the alleged infringement has taken place.
Based on our registered office, our relevant supervisory authority is the Office of the Commissioner for Personal Data Protection in Cyprus, with its address at 1682 Nicosia, Cyprus, P.O. Box 23378, telephone +357 22818456, or email commissioner@dataprotection.gov.cy.
Age Limitation
The Services are intended for adults. We do not knowingly process personal data from persons under 18 years of age. If you learn that anyone younger than 18 has provided us with personal data, please contact us at privacy@pennyguard.com and we will delete it.
International data transfers
We may transfer personal data to countries other than the country in which the data was originally collected in order to provide the Services set forth in the Terms of Use and for the purposes indicated in this Privacy Policy. If these countries do not have the same data protection laws as the country in which you initially provided the information, we deploy special safeguards.
In particular, if we transfer personal data originating from the EEA to countries without an adequate level of data protection, we rely on one of the following legal bases: (i) Standard Contractual Clauses approved by the European Commission, or (ii) the European Commission’s adequacy decisions about certain countries.
Changes to this privacy policy
We may modify this Privacy Policy from time to time. If we decide to make material changes to this Privacy Policy, you will be notified through our Services or by other available means and will have an opportunity to review the revised Privacy Policy. By continuing to access or use the Services after those changes become effective, you agree to be bound by the revised Privacy Policy.
Additional State Privacy Rights
This section provides additional details about how we process personal data of California consumers and the rights available to them under the California Consumer Privacy Act ("CCPA") and California’s Shine the Light law. California’s Shine the Light law gives California residents the right to ask companies once a year what personal information they share with third parties for those third parties’ direct marketing purposes.
We do not share your personal information with third parties for their own direct marketing purposes within the meaning of that law.
In addition, the CCPA, as well as other state privacy laws, provides you with the right to opt out of the sale or sharing of your personal information. We may share certain information about you with our partners for purposes of targeted advertising or data analytics, which could in certain circumstances be characterized as "selling," "sharing," or "targeted advertising" under California law. You have the right to opt out of such sale or sharing of your personal information.
Depending on the product you use, we will strive to provide a prominent link named "Your Privacy Choices" that would allow you to exercise this right. Most of the time it will be available to you in the footer, menu, profile, or a similar place (depending on the product and device you use). We will also strive to recognize and process your opt-out preference signal as soon as possible after receiving it.
Other state privacy laws require certain disclosures for companies that "sell" personal information pursuant to the respective state’s privacy law. Each state defines the "sale" of data differently. In some states, the "sale" of data means certain scenarios in which PennyGuard has shared personal information with third parties or affiliates in exchange for valuable consideration. Other states define the "sale" of data as PennyGuard exchanging personal information for monetary consideration with a non-affiliated third party. Under this definition, we do not "sell" your personal information.
Right to Limit Processing of Sensitive Personal Information
In California, you have the right to limit our processing of your Sensitive Personal Information to only those uses which are necessary to perform the services or provide the goods reasonably expected by an average consumer who requests such goods or services. When we collect your Sensitive Personal Information we collect and use that information to perform the services or provide the goods for which that information is necessary and as reasonably expected by you. We do not use or disclose Sensitive Personal Information for the purpose of inferring characteristics about you, and we do not use it for advertising.
Under other state privacy laws, we are only permitted to collect certain pieces of Sensitive Personal Information after we have obtained your consent to do so. Where required, we obtain your agreement to collect and use Sensitive Personal Information.
Data Retention
We will store your personal data for as long as it is reasonably necessary for achieving the purposes set forth in this Privacy Policy (including providing the Services to you), which includes, but is not limited to, the period during which PennyGuard and you have an agreement, and no longer than 5 years after termination of such agreement. We will also retain and use your personal data as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
Data Security
We implement industry-standard technical and organizational security measures to protect sensitive user data, including data obtained through Google APIs and through our financial data integrations. All data is encrypted in transit using TLS, and sensitive data, including OAuth access and refresh tokens and government identifiers, is encrypted at rest using secure key management systems. Access to user data is strictly limited to authorized systems and personnel based on the principle of least privilege.
Users may revoke access at any time through their account settings or through the relevant provider’s security settings, and may request deletion of their data by contacting us.
Federal Privacy Notice
Because the Services involve financial products and services, we are required to provide an additional privacy notice under the Gramm-Leach-Bliley Act ("GLBA"). That notice describes, in the standard federal format, the categories of nonpublic personal information we collect, the reasons we share it, whether you can limit that sharing, and how we protect it.
For convenience, the notice is provided at https://legal.pennyguard.com/glba-privacy-notice.pdf and is also made available to you at the time you become a customer and annually thereafter where required.
Where the GLBA notice and this Privacy Policy address the same information, the GLBA notice governs with respect to the nonpublic personal information it covers. Nothing in this Privacy Policy limits the rights you have under the GLBA or under the privacy rules of your state.
Date of last revision: September 17, 2026
Contact Us
Pennyguard Limited, Omega Business Center, 3rd floor, Riga Fereou 4, Limassol, 3095, Cyprus, HE 498282
Email: privacy@pennyguard.com
© Pennyguard Limited 2026 All rights reserved.