Privacy Policy — Tallio

Version 1.6 | Effective: 28 August 2026

Tallio ("we", "us", "our") is a New Zealand-based web application that helps you analyse your bank spending using CSV exports. We are committed to protecting your privacy in accordance with the New Zealand Privacy Act 2020.

1. What We Collect

Data Source Purpose
Name, email address Your sign-in provider (Google or Microsoft) or the email address you use for a magic link Account identity, session management, billing
Display name You, if you edit it in the app How we show your name
Bank transaction data (dates, amounts, descriptions, bank, transaction type) CSV files you upload Spending analysis and categorisation
Upload metadata (filename, bank, transaction count) CSV files you upload Showing your imported files
Category overrides, custom categories, and renamed category labels Your in-app actions Personalised categorisation
Session cookie and anonymous account id Set when the app first talks to our API (including opening the site with JavaScript) Tie your data to this browser until you sign in or the session expires
Hashed IP address Magic-link sign-in request Rate-limiting sign-in emails. Stored with the unused link and deleted when that link is used or expires (within 15 minutes)
Stripe customer ID Stripe (on upgrade) Subscription management

We do not collect:

  • Bank login credentials
  • Credit or debit card numbers (Stripe handles all payment processing)
  • Location data or advertising identifiers. Cloudflare Turnstile may see browser and device signals on the sign-in screen (see Section 5); we do not store those signals ourselves.

We do not store the raw CSV file after it has been parsed.

2. Why We Collect It

We collect personal information solely to provide and improve the Spending Analytics service:

  • To parse, categorise, and display your transaction data
  • To maintain and improve the service, such as improving categorisation accuracy
  • To maintain your account and session
  • To process subscription payments via Stripe

Collaborative categorisation: When you correct a category, we may use that signal in aggregated form to improve shared categorisation rules for everyone. We only consider descriptions that many users categorise the same way, after filtering out transfers and other potentially identifying payment text (for example account numbers or “to:”/“from:” wording). We do not use transfer overrides to train shared rules. Aggregated mining records store pattern and count statistics only — not your user id.

3. How We Store and Protect It

  • All data is stored in Cloudflare, hosted on Cloudflare's global infrastructure
  • Connections are encrypted via HTTPS/TLS, and stored data is encrypted at rest by Cloudflare
  • Your transaction data is processed on our servers to provide categorisation, summaries, and insights, so it is not end-to-end encrypted. We may access it solely to operate and improve the service — for example, to diagnose a parsing problem or improve categorisation accuracy — and never for any other purpose
  • Session cookies are HttpOnly, Secure, and SameSite=Lax
  • Categorisation rules run server-side and are never exposed to the browser

Where your data is held: Cloudflare's infrastructure may store your data outside New Zealand. Cloudflare acts solely as our hosting provider and does not use your information for its own purposes; under the Privacy Act 2020 we remain responsible for it wherever it is stored.

4. How Long We Keep It

Account type Retention
Anonymous (no sign-in) Data is purged after 30 days of inactivity
Personal (signed in) Data is retained across sessions until you delete it or request deletion
Pro (paid) Data is retained for the life of your subscription. On cancellation, retention reverts to the Personal policy

You can wipe your spending data or ask us to close your account at any time (see Section 8).

5. Third Parties

We share personal information with the following third parties, and only as necessary to operate the service:

Third party Data shared Purpose
Google or Microsoft (OAuth) Email, name (received from the provider you sign in with) Authentication
Cloudflare Email The email address you enter for a magic-link sign-in, and that a sign-in was requested Sending the sign-in email
Cloudflare Turnstile Browser and device signals from the sign-in screen, plus the IP used to request a magic link Distinguishing humans from bots before sending a sign-in email
Google Fonts Your IP address (your browser requests the typeface) Loading the site fonts
Stripe Email, Stripe customer ID Payment processing
Cloudflare All data (as infrastructure host) Hosting, CDN, database

We do not sell, rent, or share your data with advertisers, data brokers, or any other third parties.

6. Cookies and local storage

We set one first-party session cookie (sid) to keep you signed in or to keep an anonymous session. We do not use analytics cookies or advertising cookies.

When you open sign-in, Cloudflare Turnstile may set its own cookies. When you start checkout, Stripe may set cookies needed to process payment. Your browser also requests fonts from Google; that is not a cookie we set.

Chart exclusions and date-range preferences may be stored in your browser's local storage, keyed to your account id. They stay on your device.

7. Your Rights Under the Privacy Act 2020

Under the New Zealand Privacy Act 2020, you have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your data

To exercise any of these rights, contact us at support@tallio.co.nz. You can also wipe spending data yourself (see Section 8).

8. Data Deletion

In the app: use Delete all my data (from your profile or the navigation menu). This permanently removes your transactions, category overrides, custom categories, renamed labels, and uploads. Your account, sign-in method, and Stripe customer record stay.

To close your account: contact us at support@tallio.co.nz with the email address associated with your account. We will delete your user record (which also removes remaining account data) and the Stripe customer association within 14 days.

9. Data Breaches

In the event of a privacy breach that is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and affected users as required by Part 6 of the Privacy Act 2020.

10. Children

This service is not directed at children under the age of 16. We do not knowingly collect personal information from children.

11. Changes to This Policy

We may update this policy from time to time. The current version and effective date are published on this page. Continued use of the service after changes constitutes acceptance.

12. Contact

If you have questions about this privacy policy or wish to make a complaint, contact us at:

Tallio
NZBN 9429053814333
support@tallio.co.nz

You may also contact the Office of the Privacy Commissioner: https://www.privacy.org.nz

Version History

Version Date Summary
1.6 28 August 2026 Aligned with recent product updates: in-app data wipe vs account closure, extra stored fields, Google Fonts, Turnstile/Stripe cookies, anonymous session on first API use
1.5 21 August 2026 Identified the operator and NZBN in Contact
1.4 17 August 2026 Disclosed Cloudflare Turnstile on magic-link sign-in
1.3 17 August 2026 Added magic-link email sign-in via Cloudflare Email
1.2 17 July 2026 Disclosed aggregated, filtered use of category corrections to improve shared rules; transfers and identifying payment text excluded
1.1 6 July 2026 Clarified that transaction data is server-readable (only share links are end-to-end encrypted), noted overseas hosting via Cloudflare, listed all sign-in providers
1.0 20 May 2026 Initial version