Privacy Policy

Last updated: 2 May 2026

01 Introduction

Finvixy ("we", "our", "us") is a product of Enclivix, a South African company. This Privacy Policy explains how we collect, use, store, and protect your information when you use our receipt scanning and expense tracking service at finvixy.co.za.

By using Finvixy, you agree to the collection and use of information in accordance with this policy.

02 Information We Collect

Account Information

  • Name, email address, and WhatsApp number (provided at registration)
  • Organisation or business name
  • Account credentials (passwords are hashed and never stored in plain text)

Receipt and Expense Data

  • Receipt images and PDF documents you upload or send via WhatsApp
  • Extracted data: vendor names, dates, amounts, line items, and categories
  • This data is processed by AI (AWS Textract and Amazon Bedrock) to extract receipt information

Google Account Data

  • If you connect Google Drive, we request access to the drive.file scope only
  • This allows us to create and manage files and folders that Finvixy creates in your Google Drive — nothing else
  • We cannot read, modify, or delete any other files in your Google Drive
  • We store your Google OAuth token (encrypted) to maintain the connection
  • Your Google email address is stored to identify the connected account

03 How We Use Your Information

  • Receipt processing: We use AI services (AWS Textract and Amazon Bedrock) to extract text and categorise your receipts
  • Google Drive sync: Receipts are automatically organised into category folders in your own Google Drive. We only write to a dedicated Finvixy folder — your data stays in your Drive, under your control
  • WhatsApp scanning: When you send a receipt photo via WhatsApp, we process it and return the results to you
  • Reports and insights: We generate spending charts and analytics from your expense data
  • Account notifications: We send transactional emails (verification, password reset) via Postmark

04 Your Data, Your Control

You own your data. Finvixy is designed as an organiser — we help you structure and store your receipts, but the data belongs to you.

  • Google Drive: All synced receipts live in your own Google Drive. If you disconnect Finvixy, the files remain in your Drive
  • Export: Your receipts are always accessible through our app or directly in your Google Drive
  • Deletion: You can request full deletion of your account and all associated data by contacting us
  • Disconnect: You can disconnect Google Drive at any time from Settings → Connected Accounts

05 Data Storage and Security

  • Receipt images are stored in encrypted Amazon S3 buckets (EU region)
  • Application data is stored in a secured database with encryption at rest
  • Google OAuth credentials are encrypted using Laravel's encryption (AES-256-CBC)
  • All connections use HTTPS/TLS encryption in transit
  • We implement two-factor authentication (2FA) for additional account security

06 Third-Party Services

We use the following third-party services to operate Finvixy:

Amazon Web Services

S3 storage, Textract OCR, Bedrock AI processing

Google APIs

Google Drive sync (drive.file scope only)

Meta / WhatsApp Business

Receiving and sending WhatsApp messages

Postmark

Transactional email delivery

Each of these services has their own privacy policies. We encourage you to review them.

07 Google API Services User Data Policy

Finvixy's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • We only request the drive.file scope — the minimum needed
  • We do not use Google data for advertising purposes
  • We do not transfer Google data to third parties except as needed to provide the service
  • We do not use Google data to develop a surveillance tool or product

08 Data Retention

We retain your data for as long as your account is active. If you delete your account:

  • All personal data and expense records are permanently deleted from our systems
  • Receipt images in S3 are deleted
  • Files already synced to your Google Drive remain there (they are in your account)
  • Google OAuth tokens are revoked and deleted

09 Cookies

We use essential session cookies to maintain your login state. We do not use third-party tracking cookies or advertising cookies.

10 Children's Privacy

Finvixy is not intended for use by children under 18. We do not knowingly collect personal information from children.

11 Policy Changes

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or in-app notification. Continued use of Finvixy after changes constitutes acceptance.

12 Contact Us

If you have questions about this Privacy Policy or your data, contact us at:

Email: info@enclivix.com

Company: Enclivix, South Africa