Privacy Policy
Your privacy is our priority. We believe managing money should feel calm, secure, and empowering — not invasive.
Effective Date: January 2025|Last Updated: January 2025
Your privacy is our priority.
We believe managing money should feel calm, secure, and empowering — not invasive.
1Overview
At Ovr Finance™ (operated by JRM Creative Ventures LLC), your privacy is our priority. We believe managing money should feel calm, secure, and empowering — not invasive.
This Privacy Policy explains how we collect, use, store, share, and protect your information when you use our mobile application, website, or related services (collectively, the "Services").
By using Ovr Finance™, you agree to this Privacy Policy and our Terms of Use. If you do not agree, please discontinue use immediately.
Who We Are
- Business Name: Ovr Finance™
- Legal Entity: JRM Creative Ventures LLC
- Registered State: New Jersey, USA
- Contact: support@ovrfinance.io
Scope of This Policy
This Privacy Policy applies to:
- ✓ Our mobile application (iOS and Android)
- ✓ Our website at www.ovrfinance.io
- ✓ Related services and features
- ✓ Communications with us
This Policy does not apply to:
- ✗ Third-party websites, apps, or services we link to
- ✗ Third-party service providers' own data practices (see their privacy policies)
2Information We Collect
We collect only the information necessary to provide, improve, and secure our Services. We practice data minimization — collecting the least amount of data required.
2.1 Information You Provide Directly
Account Information:
- • Full name
- • Email address
- • Password (stored as encrypted hash, never plain text)
- • Phone number (optional, for SMS notifications if you opt-in)
Financial Goals and Preferences:
- • Debt payoff goals
- • Payment preferences
- • Budget targets
- • Notification preferences
Support Communications:
- • Messages, screenshots, or attachments you send when contacting customer support
- • Feedback and survey responses
Payment Information:
- • Payment method details for subscriptions (processed by Stripe, Apple, or Google)
- • We do NOT store full credit card numbers or CVV codes
- • Bank account information for ACH payments (tokenized through Plaid and Stripe)
Subscription Tier and Usage Limits:
- • Current subscription tier (Basic, Starter, Premium, Elite)
- • Features enabled for your tier
- • Usage against tier limits (AI recalibrations used this week, autopay transactions this month)
- • Upgrade/downgrade history
- • Add-on purchase history
Purpose: Enforce tier limits, track usage quotas, calculate overage charges, personalize upgrade prompts
2.2 Information Collected Automatically
Usage Data:
- • Pages or screens viewed
- • Features used and interaction patterns
- • Time spent in app
- • Frequency of use
- • Error logs and crash reports
Device Information:
- • Device type and model
- • Operating system and version
- • Unique device identifiers (advertising ID, if permitted)
- • Mobile network information
- • IP address, browser type, time zone, language settings
Location Data:
- • We do NOT collect precise GPS location
- • We may infer general location (city/state/country) from IP address for fraud prevention, compliance, and localization
2.3 Connected Financial Data
When you link your bank accounts or credit cards, we use Plaid Inc., a secure, SOC 2 Type II certified third-party service.
What Plaid Collects:
- • Account balances
- • Transaction history
- • Account holder name
- • Account and routing numbers (tokenized)
- • Credit card details (balances, limits, payment due dates)
Important Clarifications:
- • Plaid, not Ovr Finance, directly accesses your financial institution
- • We NEVER see or store your banking credentials (username/password)
- • You authorize Plaid to share specific data with us
- • You can revoke Plaid access at any time through your Ovr Finance settings
2.4 Information from Third Parties
We may receive information from:
- • Identity verification services (to comply with financial regulations)
- • Fraud prevention services (to protect your account)
- • Analytics providers (aggregated, non-identifiable usage statistics)
- • App stores (Apple, Google) regarding app downloads and updates
2.5 Information We Do NOT Collect
- ✗ Social Security Numbers
- ✗ Driver's license numbers (unless required by law for identity verification)
- ✗ Passport information
- ✗ Credit scores or credit reports (unless you explicitly provide them)
- ✗ Biometric data (unless you enable device biometric authentication, which is stored locally on your device, not our servers)
3How We Use Your Information
We use your information only for legitimate purposes related to providing and improving our Services.
3.1 Provide Core Services
- Account management: Create and maintain your account
- Financial insights: Calculate debt payoff projections, optimize payment strategies
- Payment processing: Facilitate ACH payments from your bank to credit card issuers (via Stripe)
- Data synchronization: Update balances and transactions from linked accounts (via Plaid)
- Personalization: Customize recommendations based on your financial profile
3.2 Improve and Secure Services
- Performance optimization: Identify bugs, crashes, and areas for improvement
- Security monitoring: Detect and prevent fraud, unauthorized access, and security threats
- Product development: Analyze usage patterns to develop new features
- Quality assurance: Test new features and ensure reliability
3.3 Communicate With You
Transactional communications:
- • Account notifications (payment confirmations, failed payments)
- • Security alerts (login from new device, password changes)
- • Service updates (maintenance, downtime, new features)
- • Legal notices (Terms or Privacy Policy changes)
Customer support:
Respond to inquiries and resolve issues
Optional marketing:
Promotional offers, tips, or product updates (only if you opt-in)
3.4 Legal and Compliance
- Comply with laws: Respond to legal requests, court orders, or regulatory requirements
- Enforce Terms: Investigate violations of our Terms of Use
- Protect rights: Defend against legal claims or protect our users' safety
- Financial compliance: Meet Anti-Money Laundering (AML) and Know Your Customer (KYC) obligations where required
3.5 Aggregated Analytics
- • Create anonymized, non-identifiable statistics about app usage trends, feature popularity, and general demographic insights
- • Aggregated data cannot be traced back to individual users
3.6 What We Do NOT Do
- ✗ Sell your personal data to third parties
- ✗ Rent or trade your information for marketing purposes
- ✗ Use your data for advertising targeting across other websites or apps
- ✗ Transfer or move funds from your accounts without your explicit consent
- ✗ Share your specific financial details with third parties except as disclosed in this Policy
4Legal Bases for Processing
Depending on your jurisdiction (especially if you're in the EU/EEA/UK), we process your personal data based on the following lawful bases under GDPR and similar laws:
4.1 Contractual Necessity
To provide Services you've requested (account creation, payment processing, financial insights)
4.2 Legitimate Interests
To improve, secure, and personalize our platform (fraud prevention, product development, customer support)
4.3 Consent
For optional features where you've given explicit consent:
- • Linking bank accounts via Plaid
- • Receiving marketing emails or SMS
- • Enabling biometric authentication
- • Allowing push notifications
You may withdraw consent at any time through account settings or by contacting us.
4.4 Legal Compliance
Where required by law, regulation, or legal process (tax reporting, AML compliance, court orders, data protection laws)
5Data Security
We take your security seriously and employ multiple layers of protection.
5.1 Security Measures
Encryption:
- • In transit: TLS 1.3 encryption for all data transmitted
- • At rest: AES-256 encryption for data stored in databases
- • Payment data: Tokenization through Stripe and Plaid
Infrastructure Security:
- • Cloud hosting: Google Cloud Platform / AWS with ISO 27001, SOC 2 Type II certification
- • Zero-trust architecture with least-privilege access controls
- • Multi-factor authentication (MFA) for internal team access
- • Regular security audits, penetration testing, and vulnerability assessments
- • Real-time intrusion detection and monitoring
Third-Party Compliance:
- • Plaid: SOC 2 Type II, ISO 27001
- • Stripe: PCI-DSS Level 1 (highest security standard), SOC 2 Type II
5.2 Your Security Responsibilities
- • Use strong passwords: At least 12 characters with letters, numbers, and symbols
- • Enable two-factor authentication (2FA) when available
- • Keep devices secure: Use device passcodes, biometric locks
- • Don't share credentials: Never share your password or authentication codes
- • Monitor account activity: Report suspicious activity immediately
- • Beware of phishing: We will never ask for your password via email or text
5.3 Limitations
No system is 100% secure. While we implement industry-leading security measures, we cannot guarantee absolute security against sophisticated cyberattacks, unauthorized third-party breaches, or your own security lapses.
If you suspect unauthorized access, contact us immediately at: security@ovrfinance.io
6Data Retention
We retain personal data only as long as necessary to fulfill the purposes described in this Policy or as required by law.
6.1 Retention Periods
| Data Type | Retention Period | Reason |
|---|---|---|
| Active account data | While account is active | Provide Services |
| After account deletion | 30 days | Grace period for reactivation |
| Encrypted backups | 90 days | Security auditing, disaster recovery |
| Financial transaction records | 7 years | Tax compliance, legal requirements |
| Support communications | 3 years | Legal defense, quality improvement |
| Anonymized analytics | Indefinite | Non-identifiable |
6.2 Deletion Process
When you delete your account:
- Personal data is flagged for deletion within 24 hours
- Data is permanently erased from production systems within 30 days
- Encrypted backups are purged within 90 days
- You will receive confirmation of deletion via email
To delete your account:
- • In-app: Settings → Account → Delete Account
- • Email: support@ovrfinance.io with subject "Account Deletion Request"
7Data Sharing and Transfers
We share personal data only with trusted third parties essential to delivering our Services. We do NOT sell your data.
7.1 Service Providers
| Purpose | Provider | Compliance |
|---|---|---|
| Financial account linking | Plaid Inc. | SOC 2 Type II, GDPR, CCPA |
| Payment processing | Stripe, Inc. | PCI-DSS Level 1, SOC 2 |
| Subscription billing | Apple, Google | PCI-DSS, Privacy Shield |
| Cloud hosting | Google Cloud / AWS | ISO 27001, SOC 2 |
| Authentication | Firebase (Google) | SOC 2, ISO 27001 |
7.2 Legal Disclosures
We may disclose personal data when required by law or to protect rights:
- • Court orders and subpoenas
- • Government requests (law enforcement, regulatory inquiries)
- • Tax authorities as required by law
- • Fraud prevention and safety protection
- • Enforce Terms of Use
7.4 International Data Transfers
Ovr Finance™ operates primarily in the United States. If you access our Services from outside the U.S., your data may be transferred to, stored, and processed in the United States.
Safeguards: Standard Contractual Clauses (SCCs), EU-U.S. Data Privacy Framework compliance, encryption, and access controls.
7.5 No Sale of Personal Data
We do NOT sell, rent, or trade your personal data to third parties for monetary or other valuable consideration. This includes no selling to data brokers, no sharing for cross-context behavioral advertising, and no monetizing your financial information.
8Your Rights
Depending on where you live, you have specific rights regarding your personal data.
8.1 Right to Access
Request a copy of the personal data we hold about you
8.2 Right to Rectification
Request correction of inaccurate or incomplete data
8.3 Right to Erasure
Request deletion of your personal data ("Right to be Forgotten")
8.4 Right to Restriction
Request that we limit how we process your data
8.5 Right to Data Portability
Request a copy in a structured, machine-readable format (CSV, JSON)
8.6 Right to Object
Object to processing for direct marketing or legitimate interests
8.7 Right to Withdraw Consent
Withdraw consent at any time for consent-based processing
8.8 Right to Lodge a Complaint
File a complaint with your local data protection authority
How to exercise your rights: Email privacy@ovrfinance.io with your request. Response time: 30 days (or sooner as required by law).
8.10 No Discrimination
We will not discriminate against you for exercising your privacy rights, including denying services, charging different prices, or providing different quality of service.
9Children's Privacy
Ovr Finance™ is NOT intended for individuals under 18 years old (or the age of majority in your jurisdiction, whichever is greater).
9.1 No Knowing Collection
We do not knowingly collect, use, or share personal information from children under 18. If we discover a minor has provided data:
- • We will delete it immediately
- • We will notify parents/guardians (if contact information is available)
- • We will terminate the account
9.3 COPPA Compliance (U.S.)
We comply with the Children's Online Privacy Protection Act (COPPA). We do not collect personal information from children under 13, allow children under 13 to create accounts, or target advertising to children.
11Third-Party Links and Integrations
Our Services may contain links to third-party websites, apps, or services. We do NOT control these third parties and are NOT responsible for their content, privacy practices, or security.
11.2 Third-Party Integrations
We integrate with trusted third parties to provide core functionality:
- • Plaid: Financial account linking
- • Stripe: Payment processing
- • Firebase: Authentication and notifications
- • Apple/Google: App distribution and subscriptions
12Payment Processing
12.1 Subscription Payments
Processed by: Stripe (web), Apple (iOS), Google (Android)
Important: We do NOT store full credit card numbers or CVV codes. Payment data is tokenized by processors.
12.2 ACH Payments (Bank-to-Credit Card)
When you use the "Pay Now" feature:
- You link bank account via Plaid
- You authorize payment in Ovr Finance
- We instruct Stripe to initiate ACH debit
- Stripe processes payment to your credit card issuer
Important: Ovr Finance does NOT hold or custody funds. We do NOT see your bank login credentials. Stripe is a licensed payment processor.
13App Store Privacy
13.3 App Permissions
iOS Permissions:
- • Notifications: For payment reminders
- • Biometric: For secure login (optional)
- • Contacts: NOT requested
- • Location: NOT requested
Android Permissions:
- • Notifications: For payment reminders
- • Biometric: For secure login (optional)
- • Contacts: NOT requested
- • Location: NOT requested
14Biometric Data
Biometric data is stored locally on your device, not on our servers. Apple and Google handle biometric processing. We only receive a success/failure signal when you authenticate.
14.2 State-Specific Biometric Laws
- • Illinois (BIPA): We do NOT collect, capture, or store biometric data ourselves
- • Texas and Washington: We comply with biometric privacy laws. No biometric data is sold or shared.
15International Data Protection & Compliance
Ovr Finance™ complies with major global data protection frameworks.
GDPR (EU/EEA)
Full compliance with all rights in Section 8
UK GDPR
UK GDPR mirrors EU GDPR with UK adaptations
CCPA/CPRA (California)
See Section 16.1 for detailed rights
PIPEDA (Canada)
Right to access, correct, withdraw consent
LGPD (Brazil)
Rights similar to GDPR
Privacy Act 1988 (Australia)
Australian Privacy Principles (APPs)
16State-Specific Privacy Rights (U.S.)
16.1 California Residents (CCPA/CPRA)
- Right to Know: Request disclosure of categories and specific pieces of personal information collected
- Right to Delete: Request deletion of personal information
- Right to Correct: Request correction of inaccurate information
- Right to Opt-Out of Sale/Sharing: We do NOT sell or share personal information
- Right to Non-Discrimination: We will not discriminate for exercising CCPA rights
How to Exercise: Email privacy@ovrfinance.io with subject "CCPA Request - [Right Being Exercised]"
Other U.S. States
We comply with privacy laws in all U.S. states, including:
- • Virginia (VCDPA)
- • Colorado (CPA)
- • Connecticut (CTDPA)
- • Utah (UCPA)
- • Montana, Oregon, Texas, and other emerging state laws
Email privacy@ovrfinance.io with your state in the subject line.
17Data Breach Notification
17.1 Our Commitment
In the unlikely event of a data breach, we will:
- Investigate immediately to determine scope and cause
- Contain the breach to prevent further unauthorized access
- Notify affected users within 72 hours (or sooner where required)
- Report to authorities as required
- Provide guidance on steps to protect yourself
- Implement measures to prevent recurrence
17.5 Reporting Security Issues
If you discover a security vulnerability, email security@ovrfinance.io with subject "Security Vulnerability Report". We appreciate responsible disclosure.
18Automated Decision-Making and AI
18.1 Use of AI and Algorithms
Ovr Finance™ uses AI and algorithms to:
- • Calculate optimal debt payoff strategies
- • Recommend payment amounts and timing
- • Predict debt-free dates
- • Personalize financial insights
- • Detect anomalies or unusual spending patterns
18.2 Human Oversight
- • AI recommendations are algorithmic outputs, not professional financial advice
- • No AI decision has legal or similarly significant effects without human review
- • You are NOT obligated to follow AI recommendations
- • All final financial decisions are yours
18.6 No Profiling for Adverse Decisions
We do NOT use AI or profiling to deny services, charge different prices based on protected characteristics, or discriminate based on race, ethnicity, religion, gender, etc.
19Marketing and Communications
19.1 Types of Communications
Transactional (Cannot Opt-Out):
- • Account notifications
- • Security alerts
- • Service updates
- • Legal notices
Marketing (Can Opt-Out):
- • New feature announcements
- • Tips and educational content
- • Special offers
- • Surveys
19.2 How to Opt-Out of Marketing
- • Email: Click "Unsubscribe" at the bottom of any marketing email
- • SMS: Reply STOP to any marketing text
- • Push Notifications: Device settings or in-app Settings → Notifications
20Do Not Track Signals
We do NOT respond to Do Not Track signals because there is no industry standard for DNT implementation, and we do NOT track you across third-party websites or apps.
Global Privacy Control (GPC): We respect GPC signals for users in jurisdictions where recognized (California, Colorado, Connecticut). More info: globalprivacycontrol.org
21Limitation of Liability
While we implement robust security measures, we cannot guarantee absolute security. We are NOT liable for unauthorized access due to circumstances beyond our control, cyberattacks that bypass security measures, your own security lapses, or third-party breaches.
Liability Cap: Where liability cannot be excluded by law, our total aggregate liability is limited to the lesser of $100 USD or the total amount you paid to Ovr Finance in the 12 months prior to the claim.
21.6 No Waiver of Rights
Nothing in this section limits your rights under GDPR (EU/EEA), UK GDPR, CCPA/CPRA (California), or other applicable consumer protection laws.
22Updates to This Policy
We may update this Privacy Policy to reflect new features, legal changes, or improvements to our data practices.
For Material Changes:
- • Email notification to your registered address
- • In-app notification upon next login
- • At least 30 days' advance notice
For Minor Changes:
- • Updated "Effective Date" at top of Policy
- • Notice on website
Previous versions available upon request: privacy@ovrfinance.io
23Contact Us
Mailing Address
JRM Creative Ventures LLC
Attn: Privacy Officer
111 Town Square Pl Ste 1238 PMB 877216
Jersey City, NJ 073