Privacy Notice
Sylvadi Design Inc. (“Sylvadi,” “we,” “us”) is an Ontario corporation that operates Expense Pools from Canada. This notice explains how we handle personal information when you use expensepools.com, the Expense Pools iOS app, and related support and transactional email.
1. Information we collect
- Account and profile information: name, username, verified email address, optional nickname and profile image, language and display preferences, and records showing acceptance of legal documents.
- Authentication and device information: password hashes, session and recovery-token hashes, passkey public credentials and related device information, signed-in device name, platform, app version, and session dates. Passwords, passkey private keys, and raw biometric data are not available to us.
- Shared-expense information: pool and group names, descriptions, roles, participant and guest names, currencies, transactions, dates, payers, splits, balances, settlement requests, confirmations, rollover records, invitations, and activity needed to maintain the shared ledger.
- Security and operational information: request action and status, Cloudflare request identifier, one-way hashed IP address used to group security events, rate-limit records, abuse reports, and diagnostic errors. Cloudflare Turnstile may process browser, device, network, and interaction signals to distinguish people from automated abuse.
- Optional website analytics: only after you accept analytics, Google Analytics may receive a page path that excludes query strings, unapproved URL fragments, verification or recovery credentials, along with browser, device, approximate location, session, and interaction information generated by the Google tag. We do not send names, email addresses, pool names, transaction descriptions, or numeric user identifiers as analytics properties.
- Communications: information included in support requests and transactional email delivery events.
Expense Pools does not collect bank-account or payment-card details and does not move money. On supported Apple devices, Face ID or Touch ID can unlock locally stored credentials. The biometric comparison occurs through the operating system; Expense Pools does not receive or store your face or fingerprint data.
2. Why we use information
- Create and secure accounts, verify email addresses, maintain sessions, recover accounts, and provide passkeys and local biometric unlock.
- Create pools and groups, deliver invitations, calculate shared expenses and balances, and provide exports, settlements, and rollover records.
- Detect abuse, enforce rate limits and access controls, investigate incidents, and keep security and audit records.
- Send requested transactional messages and respond to support, privacy, and security requests.
- Maintain, troubleshoot, and improve service reliability and meet legal obligations.
- With your consent, measure aggregate website use so we can understand which pages are useful and improve navigation and reliability.
We limit collection and use to purposes a reasonable person would consider appropriate for operating and protecting the service. We will seek additional consent before using personal information for a materially different purpose when the law requires it.
3. Pools, invitations, and guests
Pool and group information is visible to the members who need it to understand and manage the shared ledger. Email invitations grant no access until the recipient accepts using the matching verified email address. An owner or administrator may create a guest participant without an account. Other members may see that guest’s display name, avatar, transactions, splits, and balance.
Do not add another person’s information unless you are authorized to do so. If you receive an unexpected or abusive invitation, ignore or report it or contact help@sylvadi.com.
4. When we disclose information
We disclose information to other pool or group members as described above; to a successor owner when ownership is transferred; when you direct us to export or share it; and when required by law or necessary to protect users, the public, or the service.
We use Cloudflare to provide hosting, database, content delivery, bot and abuse protection, operational logging, and transactional-email infrastructure. Apple provides App Store and TestFlight distribution and operating-system services used by the iOS app, including passkeys and local biometric authentication. If you accept optional website analytics, Google processes analytics information for us through Google Analytics. These providers process information under their own terms and/or as service providers to us. We do not sell personal information and do not use analytics for third-party behavioural advertising or ad personalization.
5. Processing outside Canada
Our service providers may process or store information in Canada, the United States, or other countries where they operate. Information processed outside your province or country may be subject to the laws of that jurisdiction and lawful access by its authorities. We assess providers and use contractual and technical safeguards appropriate to the information and service.
6. Retention and deletion
- Account and active shared-ledger information is kept while needed to provide the service.
- Verification, recovery, invitation, session, and rate-limit records expire, are revoked, or are periodically removed according to their security purpose.
- Security, audit, legal-acceptance, and support records are kept only as long as reasonably needed for security, compliance, dispute handling, and legal obligations. Records of qualifying privacy breaches are kept for at least the period required by law.
- Provider-managed backup or recovery copies may remain until their normal rotation completes and are not used for ordinary product activity.
You can prepare an account export and request account deletion in the Account area. Deletion revokes sessions, removes or de-identifies direct account information, disables memberships, and transfers or closes resources that require an owner. Because pool records belong to a shared ledger, transactions and related history needed by other members may remain with your participant identity de-identified. We may also retain information when required by law or to establish, exercise, or defend legal claims.
7. Security
We use access controls, expiring sessions, hashed passwords and security tokens, rate limits, audit records, step-up authentication for sensitive actions, and HTTPS encryption in transit. Passkey private keys remain under the control of your device or credential provider. No service can guarantee absolute security. Report suspected vulnerabilities to help@sylvadi.com.
8. Your privacy choices
Depending on where you live, you may request access to or correction of personal information, ask how it has been used or disclosed, withdraw consent subject to legal and service limitations, obtain an export, or request deletion. You may also challenge our compliance. We may need to verify your identity before completing a request. Optional website analytics stays disabled until you accept it, and you can withdraw that choice at any time from our Cookies & Storage notice. Use the in-app controls or contact our Privacy Officer at contact@sylvadi.com.
9. Children
Expense Pools is not directed to children under 15. A person under 15 must not create or independently manage an account. If you believe a child has provided personal information without valid parental or guardian involvement and consent, contact our Privacy Officer so we can review and take appropriate action.
10. Changes
We will post a new version date when this notice changes. We will provide additional notice or request renewed consent before a material change when required by law.
11. Contact and complaints
Privacy Officer
Sylvadi Design Inc.
148 Byng Ave
North York, Ontario M2N 4K7
Canada
contact@sylvadi.com
Please include enough information for us to understand your request, but do not email passwords, session tokens, or unnecessary financial records. General product support remains available at help@sylvadi.com. You may also complain to the privacy regulator with jurisdiction over you, including the Office of the Privacy Commissioner of Canada where applicable.