01 Introduction
Finvixy ("we", "our", "us") is a product of Enclivix, a South African company. This Privacy Policy explains how we collect, use, store, and protect your information when you use our receipt scanning and expense tracking service at finvixy.co.za.
By using Finvixy, you agree to the collection and use of information in accordance with this policy.
02 Information We Collect
Account Information
- Name, email address, and WhatsApp number (provided at registration)
- Organisation or business name
- Account credentials (passwords are hashed and never stored in plain text)
Receipt and Expense Data
- Receipt images and PDF documents you upload or send via WhatsApp
- Extracted data: vendor names, dates, amounts, line items, and categories
- This data is processed by AI (AWS Textract and Amazon Bedrock) to extract receipt information
Google Account Data
- If you connect Google Drive, we request access to the
drive.filescope only - This allows us to create and manage files and folders that Finvixy creates in your Google Drive — nothing else
- We cannot read, modify, or delete any other files in your Google Drive
- We store your Google OAuth token (encrypted) to maintain the connection
- Your Google email address is stored to identify the connected account
03 How We Use Your Information
- Receipt processing: We use AI services (AWS Textract and Amazon Bedrock) to extract text and categorise your receipts
- Google Drive sync: Receipts are automatically organised into category folders in your own Google Drive. We only write to a dedicated Finvixy folder — your data stays in your Drive, under your control
- WhatsApp scanning: When you send a receipt photo via WhatsApp, we process it and return the results to you
- Reports and insights: We generate spending charts and analytics from your expense data
- Account notifications: We send transactional emails (verification, password reset) via Postmark
04 Your Data, Your Control
You own your data. Finvixy is designed as an organiser — we help you structure and store your receipts, but the data belongs to you.
- Google Drive: All synced receipts live in your own Google Drive. If you disconnect Finvixy, the files remain in your Drive
- Export: Your receipts are always accessible through our app or directly in your Google Drive
- Deletion: You can request full deletion of your account and all associated data by contacting us
- Disconnect: You can disconnect Google Drive at any time from Settings → Connected Accounts
05 Data Storage and Security
- Receipt images are stored in encrypted Amazon S3 buckets (EU region)
- Application data is stored in a secured database with encryption at rest
- Google OAuth credentials are encrypted using Laravel's encryption (AES-256-CBC)
- All connections use HTTPS/TLS encryption in transit
- We implement two-factor authentication (2FA) for additional account security
06 Third-Party Services
We use the following third-party services to operate Finvixy:
Amazon Web Services
S3 storage, Textract OCR, Bedrock AI processing
Google APIs
Google Drive sync (drive.file scope only)
Meta / WhatsApp Business
Receiving and sending WhatsApp messages
Postmark
Transactional email delivery
Each of these services has their own privacy policies. We encourage you to review them.
07 Google API Services User Data Policy
Finvixy's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We only request the
drive.filescope — the minimum needed - We do not use Google data for advertising purposes
- We do not transfer Google data to third parties except as needed to provide the service
- We do not use Google data to develop a surveillance tool or product
08 Data Retention
We retain your data for as long as your account is active. If you delete your account:
- All personal data and expense records are permanently deleted from our systems
- Receipt images in S3 are deleted
- Files already synced to your Google Drive remain there (they are in your account)
- Google OAuth tokens are revoked and deleted
10 Children's Privacy
Finvixy is not intended for use by children under 18. We do not knowingly collect personal information from children.
11 Policy Changes
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or in-app notification. Continued use of Finvixy after changes constitutes acceptance.
12 Contact Us
If you have questions about this Privacy Policy or your data, contact us at:
Email: info@enclivix.com
Company: Enclivix, South Africa