Who we are
Funance is operated by Troy Popovic, an Australian individual based in Melbourne, Victoria. For the purposes of the Privacy Act 1988 (Cth) and the Australian Privacy Principles, Funance is the entity collecting and managing your data.
Contact: hello@funance.com.au
What information we collect
Account information
- Email address (for account creation and magic-link login)
- Display name (optional)
- Authentication session tokens (managed by Supabase)
Newsletter subscription (no account required)
If you enter your email address into a newsletter form on this site without creating an account, we store that address separately from any account data, along with:
- The page the address was submitted from, and the date and time
- A one-way hash of your IP address and your browser’s user-agent string — kept as a record that consent was given, and to limit abuse of the form. We do not store the IP address itself
- Whether and when you confirmed the subscription, and whether and when you unsubscribed
We use double opt-in: submitting the form sends you a confirmation email, and you receive nothing further unless you click the link in it. A newsletter subscription is not an account, holds no financial data, and can be ended with the unsubscribe link in any email we send you.
Financial data you enter
- Income, expenses, debts, assets, savings goals, subscriptions
- Names you give to budget categories or partners
- Property values, super balances, novated lease details
- Birth years (used for retirement projections only)
This data is what we exist to help you manage. It is encrypted in transit (TLS 1.3) and at rest in our database.
Payment information
Payments are processed by Stripe. We never see or store your full credit card number. We retain only the Stripe customer ID and subscription status, which is enough for us to know whether your account is active.
Technical information
- IP address (used for rate limiting and abuse prevention; not stored long-term)
- Browser user-agent string (for debugging)
- Sync activity logs (timestamp + payload size only, not contents)
- Sign-in timestamps, and how long each dashboard visit lasts
Usage measurement
While the dashboard is open in a visible tab, your browser sends us a timestamp roughly every 30 seconds. We store the start and end of each visit so we can see how long people spend in the app and whether new features get used. This is first-party only — it never leaves our own database, and it records when you were in the app, never what you were looking at or typing.
We also record the time of your most recent sign-in, so we can tell active accounts from dormant ones.
What we do NOT collect
- We do not use third-party analytics that profile you (e.g. Google Analytics, Facebook Pixel). The only measurement on this site is our own, described under Cookies below, and it never leaves our database
- We do not sell your data to anyone, ever
- We do not share your data with advertisers or data brokers
- We do not access bank accounts via Open Banking or screen scraping — all data you see in Funance is data you entered yourself
How we use your information
- Provide the service: store and sync your financial data across your devices
- Authenticate you: verify your identity at login via magic-link email
- Process payments: via Stripe, for subscription billing
- Send essential emails: account confirmation, payment receipts, password resets, security alerts. You cannot opt out of these as they are required for the service to function.
- Send product updates: occasional email about new features, changes and new articles. Creating an account subscribes you to these — you are told so on the sign-in screen — and so does confirming a newsletter signup. Every one carries a one-click unsubscribe link, and opting out never affects the essential emails above or your access to the service.
- Improve the product: we may look at aggregated usage patterns (e.g. which tabs are most-used) but never at individual user data without your consent
- Provide support: if you contact us, we may temporarily access your account to diagnose the issue. We log such access.
Where your data is stored
Funance uses several service providers to deliver the product. Each is selected for security and reliability. Some of these providers store or process data outside Australia.
Application data (Supabase)
Your financial data, account profile, and session information are stored with Supabase in their Sydney region (ap-southeast-2) — physically located in Australia.
Payment processing (Stripe)
Stripe processes payment information per their own privacy practices. Stripe processes payment data in the United States. View Stripe's privacy policy.
Transactional email (Resend)
Email delivery (magic links, payment receipts, trial-ending notices) is handled by Resend, which processes email metadata (your email address, the message subject, and timestamps) on AWS infrastructure in the United States. The body content of the emails passes through this infrastructure during delivery but is not retained beyond Resend's standard logging period.
Hosting (Vercel)
The Funance website and API are deployed on Vercel. Static page content is served via Vercel's global CDN (which has nodes worldwide), and our API functions execute in Vercel's Sydney region (syd1).
Cross-border disclosure (APP 8)
Some of the service providers above are located outside Australia. Under Australian Privacy Principle 8, we are required to disclose this to you and to take reasonable steps to ensure overseas recipients comply with the APPs.
By using Funance, you consent to your personal information being disclosed to the following overseas recipients:
- Stripe (United States) — for payment processing
- Resend (United States) — for transactional email delivery
- Vercel (United States, with Sydney edge nodes) — for hosting and content delivery
You acknowledge that, by giving this consent, APP 8 will not apply to these disclosures. This means that if an overseas recipient handles your information in a way that would breach the APPs, Funance will not be accountable under Section 16C of the Privacy Act for that breach. You may withdraw this consent at any time by deleting your account, which will stop further data being sent to these providers.
We choose providers we consider to have substantially similar privacy and security standards to the APPs. All data in transit is encrypted with TLS 1.3.
Your rights
Under Australian privacy law, you have the right to:
- Access your data — there's an export button in the app, or email us
- Correct your data — you can edit anything in the app at any time
- Delete your data — there's a delete-account button in the app, which removes all data and cancels any active subscription. Email us if you can't access your account.
- Object to specific uses — contact us
- Lodge a complaint — with the Office of the Australian Information Commissioner (oaic.gov.au)
How long we keep your data
- Active accounts: as long as the account exists
- Deleted accounts: all financial data and profile information removed immediately on deletion request
- Payment records: retained by Stripe per their policies (typically 7 years for tax compliance)
- Server logs: 30 days, then deleted
- Website funnel records: 12 months, then deleted
Cookies
We use two first-party cookies and nothing else. There are no third-party cookies, no advertising cookies, and no tag manager or vendor script of any kind on this site.
- Authentication: keeps you logged in.
- Visitor ID (from 19 September 2026): a random identifier, valid for 90 days, used only to measure our own signup funnel — see below. It is not derived from your IP address, your device or anything else about you, it is unreadable by any script on the page, and it means nothing to anyone but us.
How we measure our own website
We want to know whether people who arrive from a search engine find what they were looking for, and whether the interactive demo is worth having. To answer that we record, against the random visitor ID above: the page you first arrived on, whether you opened the demo (and how far you got through its guided tour) or used one of the calculators, and the domain that referred you — google.com, for example.
We do not store the full referring web address, because it can contain another site’s query parameters. We do not store your IP address in this record at all. We do not follow you across other websites, because we have nothing on any other website to follow you with.
If you later create an account, that visitor ID is linked to it, so we can tell that a particular landing page produced a signup. If you never create an account the record stays anonymous and is deleted within 12 months.
Blocking cookies, or using a browser that clears them, means we simply do not measure you. Nothing about the site stops working.
Children
Funance is not intended for users under 18. We do not knowingly collect data from minors. If you believe a child has used Funance, please contact us so we can delete the account.
Security
We take security seriously. Specifically:
- All data in transit is encrypted with TLS 1.3
- Authentication is passwordless (magic-link); we never store passwords
- Database access is restricted by Row Level Security policies
- Application secrets are stored in encrypted environment variables, never in code
- We will notify you within 72 hours of any breach affecting your data, in line with the Notifiable Data Breaches scheme
Changes to this policy
We may update this policy occasionally. Material changes will be communicated by email at least 14 days before they take effect. Minor changes (e.g. typo corrections) may be made silently. The "last updated" date at the top of this page reflects the most recent change.
5 September 2026 — website measurement
We added the Cookies section describing first-party measurement of our own website: a random visitor ID, stored in a cookie for 90 days, used to work out which pages bring people to Funance and whether the interactive demo is worth keeping.
This is a material change, so it takes effect on 19 September 2026, fourteen days after this notice. No measurement data is recorded before that date. There is no third party involved at any point, your IP address is not stored in these records, and if you never create an account the record stays anonymous and is deleted within 12 months.
The previous version of this page said we used no tracking cookies at all. That was true when it was written, and this change is the reason it no longer will be — which is why you are getting an email about it rather than a silent edit.