Privacy Policy

Your privacy is our priority. We believe managing money should feel calm, secure, and empowering — not invasive.

Bank-Level Encryption
SOC 2 Compliant
No Data Selling

Effective Date: January 2025|Last Updated: January 2025

Your privacy is our priority.

We believe managing money should feel calm, secure, and empowering — not invasive.

🔒 Bank-Level Encryption SOC 2 Compliant🚫 No Data Selling

1Overview

At Ovr Finance™ (operated by JRM Creative Ventures LLC), your privacy is our priority. We believe managing money should feel calm, secure, and empowering — not invasive.

This Privacy Policy explains how we collect, use, store, share, and protect your information when you use our mobile application, website, or related services (collectively, the "Services").

By using Ovr Finance™, you agree to this Privacy Policy and our Terms of Use. If you do not agree, please discontinue use immediately.

Who We Are

  • Business Name: Ovr Finance™
  • Legal Entity: JRM Creative Ventures LLC
  • Registered State: New Jersey, USA
  • Contact: support@ovrfinance.io

Scope of This Policy

This Privacy Policy applies to:

  • Our mobile application (iOS and Android)
  • Our website at www.ovrfinance.io
  • Related services and features
  • Communications with us

This Policy does not apply to:

  • Third-party websites, apps, or services we link to
  • Third-party service providers' own data practices (see their privacy policies)

2Information We Collect

We collect only the information necessary to provide, improve, and secure our Services. We practice data minimization — collecting the least amount of data required.

2.1 Information You Provide Directly

Account Information:

  • • Full name
  • • Email address
  • • Password (stored as encrypted hash, never plain text)
  • • Phone number (optional, for SMS notifications if you opt-in)

Financial Goals and Preferences:

  • • Debt payoff goals
  • • Payment preferences
  • • Budget targets
  • • Notification preferences

Support Communications:

  • • Messages, screenshots, or attachments you send when contacting customer support
  • • Feedback and survey responses

Payment Information:

  • • Payment method details for subscriptions (processed by Stripe, Apple, or Google)
  • • We do NOT store full credit card numbers or CVV codes
  • • Bank account information for ACH payments (tokenized through Plaid and Stripe)

Subscription Tier and Usage Limits:

  • • Current subscription tier (Basic, Starter, Premium, Elite)
  • • Features enabled for your tier
  • • Usage against tier limits (AI recalibrations used this week, autopay transactions this month)
  • • Upgrade/downgrade history
  • • Add-on purchase history

Purpose: Enforce tier limits, track usage quotas, calculate overage charges, personalize upgrade prompts

2.2 Information Collected Automatically

Usage Data:

  • • Pages or screens viewed
  • • Features used and interaction patterns
  • • Time spent in app
  • • Frequency of use
  • • Error logs and crash reports

Device Information:

  • • Device type and model
  • • Operating system and version
  • • Unique device identifiers (advertising ID, if permitted)
  • • Mobile network information
  • • IP address, browser type, time zone, language settings

Location Data:

  • • We do NOT collect precise GPS location
  • • We may infer general location (city/state/country) from IP address for fraud prevention, compliance, and localization

2.3 Connected Financial Data

When you link your bank accounts or credit cards, we use Plaid Inc., a secure, SOC 2 Type II certified third-party service.

What Plaid Collects:

  • • Account balances
  • • Transaction history
  • • Account holder name
  • • Account and routing numbers (tokenized)
  • • Credit card details (balances, limits, payment due dates)

Important Clarifications:

  • • Plaid, not Ovr Finance, directly accesses your financial institution
  • • We NEVER see or store your banking credentials (username/password)
  • • You authorize Plaid to share specific data with us
  • • You can revoke Plaid access at any time through your Ovr Finance settings

Plaid's Privacy Policy →

2.4 Information from Third Parties

We may receive information from:

  • • Identity verification services (to comply with financial regulations)
  • • Fraud prevention services (to protect your account)
  • • Analytics providers (aggregated, non-identifiable usage statistics)
  • • App stores (Apple, Google) regarding app downloads and updates

2.5 Information We Do NOT Collect

  • Social Security Numbers
  • Driver's license numbers (unless required by law for identity verification)
  • Passport information
  • Credit scores or credit reports (unless you explicitly provide them)
  • Biometric data (unless you enable device biometric authentication, which is stored locally on your device, not our servers)

3How We Use Your Information

We use your information only for legitimate purposes related to providing and improving our Services.

3.1 Provide Core Services

  • Account management: Create and maintain your account
  • Financial insights: Calculate debt payoff projections, optimize payment strategies
  • Payment processing: Facilitate ACH payments from your bank to credit card issuers (via Stripe)
  • Data synchronization: Update balances and transactions from linked accounts (via Plaid)
  • Personalization: Customize recommendations based on your financial profile

3.2 Improve and Secure Services

  • Performance optimization: Identify bugs, crashes, and areas for improvement
  • Security monitoring: Detect and prevent fraud, unauthorized access, and security threats
  • Product development: Analyze usage patterns to develop new features
  • Quality assurance: Test new features and ensure reliability

3.3 Communicate With You

Transactional communications:

  • • Account notifications (payment confirmations, failed payments)
  • • Security alerts (login from new device, password changes)
  • • Service updates (maintenance, downtime, new features)
  • • Legal notices (Terms or Privacy Policy changes)

Customer support:

Respond to inquiries and resolve issues

Optional marketing:

Promotional offers, tips, or product updates (only if you opt-in)

3.4 Legal and Compliance

  • Comply with laws: Respond to legal requests, court orders, or regulatory requirements
  • Enforce Terms: Investigate violations of our Terms of Use
  • Protect rights: Defend against legal claims or protect our users' safety
  • Financial compliance: Meet Anti-Money Laundering (AML) and Know Your Customer (KYC) obligations where required

3.5 Aggregated Analytics

  • • Create anonymized, non-identifiable statistics about app usage trends, feature popularity, and general demographic insights
  • • Aggregated data cannot be traced back to individual users

3.6 What We Do NOT Do

  • Sell your personal data to third parties
  • Rent or trade your information for marketing purposes
  • Use your data for advertising targeting across other websites or apps
  • Transfer or move funds from your accounts without your explicit consent
  • Share your specific financial details with third parties except as disclosed in this Policy

5Data Security

We take your security seriously and employ multiple layers of protection.

5.1 Security Measures

Encryption:

  • In transit: TLS 1.3 encryption for all data transmitted
  • At rest: AES-256 encryption for data stored in databases
  • Payment data: Tokenization through Stripe and Plaid

Infrastructure Security:

  • • Cloud hosting: Google Cloud Platform / AWS with ISO 27001, SOC 2 Type II certification
  • • Zero-trust architecture with least-privilege access controls
  • • Multi-factor authentication (MFA) for internal team access
  • • Regular security audits, penetration testing, and vulnerability assessments
  • • Real-time intrusion detection and monitoring

Third-Party Compliance:

  • Plaid: SOC 2 Type II, ISO 27001
  • Stripe: PCI-DSS Level 1 (highest security standard), SOC 2 Type II

5.2 Your Security Responsibilities

  • Use strong passwords: At least 12 characters with letters, numbers, and symbols
  • Enable two-factor authentication (2FA) when available
  • Keep devices secure: Use device passcodes, biometric locks
  • Don't share credentials: Never share your password or authentication codes
  • Monitor account activity: Report suspicious activity immediately
  • Beware of phishing: We will never ask for your password via email or text

5.3 Limitations

No system is 100% secure. While we implement industry-leading security measures, we cannot guarantee absolute security against sophisticated cyberattacks, unauthorized third-party breaches, or your own security lapses.

If you suspect unauthorized access, contact us immediately at: security@ovrfinance.io

6Data Retention

We retain personal data only as long as necessary to fulfill the purposes described in this Policy or as required by law.

6.1 Retention Periods

Data TypeRetention PeriodReason
Active account dataWhile account is activeProvide Services
After account deletion30 daysGrace period for reactivation
Encrypted backups90 daysSecurity auditing, disaster recovery
Financial transaction records7 yearsTax compliance, legal requirements
Support communications3 yearsLegal defense, quality improvement
Anonymized analyticsIndefiniteNon-identifiable

6.2 Deletion Process

When you delete your account:

  1. Personal data is flagged for deletion within 24 hours
  2. Data is permanently erased from production systems within 30 days
  3. Encrypted backups are purged within 90 days
  4. You will receive confirmation of deletion via email

To delete your account:

  • • In-app: Settings → Account → Delete Account
  • • Email: support@ovrfinance.io with subject "Account Deletion Request"

7Data Sharing and Transfers

We share personal data only with trusted third parties essential to delivering our Services. We do NOT sell your data.

7.1 Service Providers

PurposeProviderCompliance
Financial account linkingPlaid Inc.SOC 2 Type II, GDPR, CCPA
Payment processingStripe, Inc.PCI-DSS Level 1, SOC 2
Subscription billingApple, GooglePCI-DSS, Privacy Shield
Cloud hostingGoogle Cloud / AWSISO 27001, SOC 2
AuthenticationFirebase (Google)SOC 2, ISO 27001

7.2 Legal Disclosures

We may disclose personal data when required by law or to protect rights:

  • • Court orders and subpoenas
  • • Government requests (law enforcement, regulatory inquiries)
  • • Tax authorities as required by law
  • • Fraud prevention and safety protection
  • • Enforce Terms of Use

7.4 International Data Transfers

Ovr Finance™ operates primarily in the United States. If you access our Services from outside the U.S., your data may be transferred to, stored, and processed in the United States.

Safeguards: Standard Contractual Clauses (SCCs), EU-U.S. Data Privacy Framework compliance, encryption, and access controls.

7.5 No Sale of Personal Data

We do NOT sell, rent, or trade your personal data to third parties for monetary or other valuable consideration. This includes no selling to data brokers, no sharing for cross-context behavioral advertising, and no monetizing your financial information.

8Your Rights

Depending on where you live, you have specific rights regarding your personal data.

8.1 Right to Access

Request a copy of the personal data we hold about you

8.2 Right to Rectification

Request correction of inaccurate or incomplete data

8.3 Right to Erasure

Request deletion of your personal data ("Right to be Forgotten")

8.4 Right to Restriction

Request that we limit how we process your data

8.5 Right to Data Portability

Request a copy in a structured, machine-readable format (CSV, JSON)

8.6 Right to Object

Object to processing for direct marketing or legitimate interests

8.7 Right to Withdraw Consent

Withdraw consent at any time for consent-based processing

8.8 Right to Lodge a Complaint

File a complaint with your local data protection authority

How to exercise your rights: Email privacy@ovrfinance.io with your request. Response time: 30 days (or sooner as required by law).

8.10 No Discrimination

We will not discriminate against you for exercising your privacy rights, including denying services, charging different prices, or providing different quality of service.

9Children's Privacy

Ovr Finance™ is NOT intended for individuals under 18 years old (or the age of majority in your jurisdiction, whichever is greater).

9.1 No Knowing Collection

We do not knowingly collect, use, or share personal information from children under 18. If we discover a minor has provided data:

  • • We will delete it immediately
  • • We will notify parents/guardians (if contact information is available)
  • • We will terminate the account

9.3 COPPA Compliance (U.S.)

We comply with the Children's Online Privacy Protection Act (COPPA). We do not collect personal information from children under 13, allow children under 13 to create accounts, or target advertising to children.

10Cookies and Tracking

10.2 Types of Cookies We Use

Strictly Necessary Cookies:

Essential for app functionality (login sessions, security). Cannot be disabled.

Performance/Analytics Cookies:

Understand how users interact with the app. Can be disabled through settings.

We do NOT use advertising cookies, third-party tracking cookies, or social media cookies.

10.4 Mobile App Tracking

  • iOS: We comply with Apple's App Tracking Transparency (ATT) framework
  • Android: We comply with Google's advertising policies. We do NOT use advertising IDs for tracking.

11Third-Party Links and Integrations

Our Services may contain links to third-party websites, apps, or services. We do NOT control these third parties and are NOT responsible for their content, privacy practices, or security.

11.2 Third-Party Integrations

We integrate with trusted third parties to provide core functionality:

  • Plaid: Financial account linking
  • Stripe: Payment processing
  • Firebase: Authentication and notifications
  • Apple/Google: App distribution and subscriptions

12Payment Processing

12.1 Subscription Payments

Processed by: Stripe (web), Apple (iOS), Google (Android)

Important: We do NOT store full credit card numbers or CVV codes. Payment data is tokenized by processors.

12.2 ACH Payments (Bank-to-Credit Card)

When you use the "Pay Now" feature:

  1. You link bank account via Plaid
  2. You authorize payment in Ovr Finance
  3. We instruct Stripe to initiate ACH debit
  4. Stripe processes payment to your credit card issuer

Important: Ovr Finance does NOT hold or custody funds. We do NOT see your bank login credentials. Stripe is a licensed payment processor.

13App Store Privacy

13.3 App Permissions

iOS Permissions:

  • • Notifications: For payment reminders
  • • Biometric: For secure login (optional)
  • • Contacts: NOT requested
  • • Location: NOT requested

Android Permissions:

  • • Notifications: For payment reminders
  • • Biometric: For secure login (optional)
  • • Contacts: NOT requested
  • • Location: NOT requested

14Biometric Data

Biometric data is stored locally on your device, not on our servers. Apple and Google handle biometric processing. We only receive a success/failure signal when you authenticate.

14.2 State-Specific Biometric Laws

  • Illinois (BIPA): We do NOT collect, capture, or store biometric data ourselves
  • Texas and Washington: We comply with biometric privacy laws. No biometric data is sold or shared.

15International Data Protection & Compliance

Ovr Finance™ complies with major global data protection frameworks.

GDPR (EU/EEA)

Full compliance with all rights in Section 8

UK GDPR

UK GDPR mirrors EU GDPR with UK adaptations

CCPA/CPRA (California)

See Section 16.1 for detailed rights

PIPEDA (Canada)

Right to access, correct, withdraw consent

LGPD (Brazil)

Rights similar to GDPR

Privacy Act 1988 (Australia)

Australian Privacy Principles (APPs)

16State-Specific Privacy Rights (U.S.)

16.1 California Residents (CCPA/CPRA)

  • Right to Know: Request disclosure of categories and specific pieces of personal information collected
  • Right to Delete: Request deletion of personal information
  • Right to Correct: Request correction of inaccurate information
  • Right to Opt-Out of Sale/Sharing: We do NOT sell or share personal information
  • Right to Non-Discrimination: We will not discriminate for exercising CCPA rights

How to Exercise: Email privacy@ovrfinance.io with subject "CCPA Request - [Right Being Exercised]"

Other U.S. States

We comply with privacy laws in all U.S. states, including:

  • • Virginia (VCDPA)
  • • Colorado (CPA)
  • • Connecticut (CTDPA)
  • • Utah (UCPA)
  • • Montana, Oregon, Texas, and other emerging state laws

Email privacy@ovrfinance.io with your state in the subject line.

17Data Breach Notification

17.1 Our Commitment

In the unlikely event of a data breach, we will:

  1. Investigate immediately to determine scope and cause
  2. Contain the breach to prevent further unauthorized access
  3. Notify affected users within 72 hours (or sooner where required)
  4. Report to authorities as required
  5. Provide guidance on steps to protect yourself
  6. Implement measures to prevent recurrence

17.5 Reporting Security Issues

If you discover a security vulnerability, email security@ovrfinance.io with subject "Security Vulnerability Report". We appreciate responsible disclosure.

18Automated Decision-Making and AI

18.1 Use of AI and Algorithms

Ovr Finance™ uses AI and algorithms to:

  • • Calculate optimal debt payoff strategies
  • • Recommend payment amounts and timing
  • • Predict debt-free dates
  • • Personalize financial insights
  • • Detect anomalies or unusual spending patterns

18.2 Human Oversight

  • • AI recommendations are algorithmic outputs, not professional financial advice
  • • No AI decision has legal or similarly significant effects without human review
  • • You are NOT obligated to follow AI recommendations
  • • All final financial decisions are yours

18.6 No Profiling for Adverse Decisions

We do NOT use AI or profiling to deny services, charge different prices based on protected characteristics, or discriminate based on race, ethnicity, religion, gender, etc.

19Marketing and Communications

19.1 Types of Communications

Transactional (Cannot Opt-Out):

  • • Account notifications
  • • Security alerts
  • • Service updates
  • • Legal notices

Marketing (Can Opt-Out):

  • • New feature announcements
  • • Tips and educational content
  • • Special offers
  • • Surveys

19.2 How to Opt-Out of Marketing

  • Email: Click "Unsubscribe" at the bottom of any marketing email
  • SMS: Reply STOP to any marketing text
  • Push Notifications: Device settings or in-app Settings → Notifications

20Do Not Track Signals

We do NOT respond to Do Not Track signals because there is no industry standard for DNT implementation, and we do NOT track you across third-party websites or apps.

Global Privacy Control (GPC): We respect GPC signals for users in jurisdictions where recognized (California, Colorado, Connecticut). More info: globalprivacycontrol.org

21Limitation of Liability

While we implement robust security measures, we cannot guarantee absolute security. We are NOT liable for unauthorized access due to circumstances beyond our control, cyberattacks that bypass security measures, your own security lapses, or third-party breaches.

Liability Cap: Where liability cannot be excluded by law, our total aggregate liability is limited to the lesser of $100 USD or the total amount you paid to Ovr Finance in the 12 months prior to the claim.

21.6 No Waiver of Rights

Nothing in this section limits your rights under GDPR (EU/EEA), UK GDPR, CCPA/CPRA (California), or other applicable consumer protection laws.

22Updates to This Policy

We may update this Privacy Policy to reflect new features, legal changes, or improvements to our data practices.

For Material Changes:

  • • Email notification to your registered address
  • • In-app notification upon next login
  • • At least 30 days' advance notice

For Minor Changes:

  • • Updated "Effective Date" at top of Policy
  • • Notice on website

Previous versions available upon request: privacy@ovrfinance.io

23Contact Us

Privacy Questions

Email: privacy@ovrfinance.io

Response: 30 days

Security Issues

Email: security@ovrfinance.io

Response: 48 hours

General Support

Email: support@ovrfinance.io

Response: 2-3 business days

Mailing Address

JRM Creative Ventures LLC
Attn: Privacy Officer
111 Town Square Pl Ste 1238 PMB 877216
Jersey City, NJ 073