Vision Financial, Inc., a Delaware corporation ("Vision Finance," "we," "our," or "us"), operates the Vision platform at visionfinance.app. This Privacy Policy explains how we collect, use, store, and protect your information when you use our service.
When you connect your financial accounts through Plaid, we access:
We do not collect or store your bank login credentials. All credential exchange is handled securely by Plaid.
We use Firebase Authentication as our authentication provider. When you create an account, Firebase collects your email address and password hash. We do not store passwords directly — all authentication data is managed by Google's Firebase infrastructure.
We may collect anonymous usage analytics to improve the platform, including pages visited and feature usage patterns.
Your data is used exclusively to:
We do not sell, rent, or share your personal financial data with third parties for marketing purposes.
We use Plaid Inc. ("Plaid") to securely connect to your financial institutions and retrieve your financial data on your behalf. When you link an account through Vision Finance, you authorize Plaid to connect to your selected institution and transmit your account balances, transaction history, investment holdings, and liability information to Vision Finance.
By using Vision Finance, you grant Vision Finance and Plaid the right, power, and authority to act on your behalf to access and transmit your personal and financial information from the relevant financial institution. You agree to your personal and financial information being transferred, stored, and processed by Plaid in accordance with the Plaid End User Privacy Policy.
Vision Finance does not receive or store your bank login credentials — Plaid handles all credential exchange. You can revoke Plaid's access to any linked institution at any time by disconnecting it in Settings. Plaid is SOC 2 Type II certified and PCI DSS compliant.
We use Google Firebase for user authentication, including email/password sign-in. Firebase processes your email address and password hash. Firebase's use of your data is governed by Google's Privacy Policy. Firebase is SOC 2 and ISO 27001 certified.
Our application is hosted on Vercel (SOC 2 Type II certified) with DNS and security managed by Cloudflare (SOC 2 Type II, ISO 27001 certified). Cached portfolio snapshots, Plaid access tokens (encrypted), and rate-limit counters live in Upstash Redis (SOC 2 Type II certified).
We use MarketStack to fetch end-of-day stock prices for the holdings drill-down chart. We send only the ticker symbol you're viewing — never your account balance, holdings list, or any personally identifiable information. Governed by MarketStack's Privacy Policy.
We use Stripe to process subscription payments. Stripe collects and stores your payment card information directly — Vision never sees your full card number. Stripe is PCI DSS Level 1 certified. Stripe's use of your data is governed by their Privacy Policy.
We use Sentry to capture application errors and crashes so we can diagnose bugs quickly. Sentry events may include the URL you were on, the browser you used, and a stack trace. We configure Sentry to drop common network errors and do not intentionally capture PII in error reports. Governed by Sentry's Privacy Policy.
We use PostHog to understand how our product is used — which features are adopted, where users get stuck, and what to improve. PostHog records page views, button clicks, and custom events tied to your anonymized user ID. We do not send PostHog your bank account data, balances, or transaction details. Autocaptured events strip elements tagged with data-ph-no-capture or class="ph-no-capture". Governed by PostHog's Privacy Policy. You can opt out by contacting support@visionfinance.app.
We use Resend to send monthly report emails and Loops for onboarding / waitlist emails. These providers see the email address we send to and the contents of the email. We use no third-party tracking pixels in marketing emails.
We implement industry-standard security measures to protect your data:
We retain your data only as long as necessary to provide our services. The following retention schedule applies:
When data reaches the end of its retention period or you request deletion:
You may request full account deletion at any time by contacting support@visionfinance.app. Upon receiving your request, we will:
You have the right to:
To exercise any of these rights, contact us at support@visionfinance.app.
We use cookies and local storage for the following purposes:
We do not use third-party tracking cookies or advertising cookies.
Vision Finance is not intended for users under the age of 18. We do not knowingly collect data from minors.
If you are located in the European Economic Area or the United Kingdom, you have the following rights under the General Data Protection Regulation:
Our legal basis for processing is (a) contract performance — we need your data to deliver the service you signed up for, (b) legitimate interest for fraud prevention and service security, and (c) consent for any optional analytics or marketing communications.
We do not transfer data outside the US/EU without standard contractual clauses where required.
California residents have the following rights under the California Consumer Privacy Act and California Privacy Rights Act:
To exercise these rights, use the in-app controls in Settings or email support@visionfinance.app. We will verify your request by confirming ownership of the email address on file and respond within 45 days.
We retain your data as long as your account is active, plus the following periods after account deletion:
We may update this Privacy Policy from time to time. Material changes will be announced in-app and by email at least 7 days before taking effect. Continued use of the service after changes constitutes acceptance of the updated policy.
For questions, data requests, or to exercise any rights under this policy, contact us at:
Vision Financial, Inc. (a Delaware corporation)
support@visionfinance.app