Privacy Policy

What we collect, where it lives, and what we never do with it.

Effective July 21, 2026Basel Systems, Inc.

Baselhelps a business find the rewards it's leaving on the table by analyzing its own card transactions. That means we handle financial data, so we've built the product to limit what it collects and give you direct controls over ongoing connections. This policy explains exactly what we collect, why, where it is stored, and the choices you have.

The short version: Basel never receives your bank login credentials, never moves money, and cannot open cards. With your consent, Basel keeps a read-only Plaid connection active so it can refresh transaction history and send monitoring alerts. Transaction records and reports are stored in your authenticated workspace. The Plaid access token is sealed before database storage using a separate server-side encryption key. You can disconnect Plaid or delete your Basel data from Profile.

01

Who this covers

This Privacy Policy describes how Basel Systems, Inc. (“Basel,” “we,” “us”) handles information in connection with the Baselwebsite and application (the “Service”). Basel is a business tool intended for use by companies and their authorized personnel, not by consumers for personal, family, or household purposes.

By using the Service you agree to this policy and to our Terms of Service. If you do not agree, do not use the Service.

02

What we collect

We keep collection deliberately narrow. The categories are:

Account information
The email address and name you provide when creating an account, plus the plan you select. Supabase Auth stores the account record and one-way password hash; Basel does not store the plain-text password.
Financial transaction data
When you connect a card or upload a statement, we process transaction records — merchant name, date, amount, account reference, and available category information — to categorize spend, compute your report, and monitor changes.
Connection metadata
The name and last four digits of a connected account and the institution name, used to label your connection in the app.
A pseudonymous identifier
Your Basel account UUID is sent to Plaid as the “client user id.” It is an opaque identifier, not your name or email, and it is not used for advertising or cross-site tracking.
Technical & usage data
Standard information your browser and our hosting provider generate on any web request (such as IP address, timestamps, and error logs) for security and reliability. We do not use advertising trackers or sell this data.

We do not collect your bank or QuickBooks login credentials — those go directly to Plaid or Intuit and never to us (see Connected accounts).

03

How we collect it

  • You provide it. You provide your name and email when creating an account; Supabase Auth processes the password and authentication emails. You also provide any statement CSV you choose to upload. The raw CSV file is parsed in your browser and is not uploaded; the resulting transaction records are saved to your authenticated workspace.
  • Through Plaid, at your direction. If you connect a bank or card account, Plaid authenticates you and returns transactions to Basel for initial import and ongoing read-only monitoring until you disconnect. See Connected accounts below.
  • Through QuickBooks, at your direction. If you connect a QuickBooks Online company, Intuit authenticates you and returns recent credit-card expense records to Basel for a one-time import.
  • Automatically. Technical data generated by your browser and our infrastructure when you load the Service.
  • Sample data.The “sample business” is synthetic data we generate; it contains no real person or company's information.
04

How we use it

We use the information above only to operate the Service:

  • To categorize transactions and compute your Leakage Report, action plan, and monthly scoreboard.
  • To detect recurring charges routed to the wrong card and cards approaching a tracked rewards cap.
  • To send monitoring and monthly recap emails you have enabled.
  • To maintain your account and remember your settings.
  • To secure the Service, prevent abuse, debug, and keep it reliable.
  • To comply with law and enforce our Terms.

We do not use your financial transaction data for advertising, and we do not sell it. Our recommendations are computed bounty-blind: affiliate incentives play no part in the analysis, and when a recommended card would pay us a referral fee we disclose that on the recommendation itself.

05

Where your data lives

This is the part most privacy policies gloss over, so we'll be specific:

  • Your workspace is stored in Supabase.Transaction records, reports, monitoring snapshots, alerts, and preferences are stored in database rows associated with your authenticated user and workspace. Row-level access controls prevent ordinary browser clients from accessing another user's workspace.
  • Plaid access tokens are sealed at the application layer.To support ongoing monitoring, Basel retains the Plaid access token in encrypted form. It is sealed with AES-256-GCM before database storage, and the encryption key is held separately in the application's server environment. The token is never returned to the browser.
  • Uploaded CSVs never leave your browser. Parsing happens locally; the file itself is not uploaded. The transaction records produced by parsing are stored in your workspace when you save the import.
  • QuickBooks remains a one-time import. The Intuit access token is used during the import request and is not retained for ongoing monitoring.

Application and database administrators with privileged production access may technically access stored records where necessary to operate, secure, debug, or comply with law. Access should be limited operationally and protected with administrative MFA.

06

Connecting accounts through Plaid or QuickBooks

When you choose to connect a bank or card account, we use Plaid Inc. to facilitate the connection. Plaid Link opens in your browser and collects your credentials directly; your credentials go to Plaid, never to Basel. Plaid then provides Basel with the transaction data needed to run your analysis.

Plaid's handling of your information is governed by Plaid's own policies. Please review the Plaid End User Privacy Policy. Before we surface Plaid Link, we ask you to confirm your consent to Basel accessing your transaction data on a read-only basis for the purpose of this analysis. You can revoke a connection at any time through your bank or through Plaid Portal.

Basel keeps the Plaid Item active to receive transaction updates and run the monitoring you requested. You can disconnect it from your Basel Profile, your bank, or Plaid Portal. Basel's disconnect control asks Plaid to remove the Item and stops future synchronization while retaining existing reports unless you delete them. When you choose to connect QuickBooks Online, we use Intuit's OAuth flow to facilitate a one-time import. Intuit collects your QuickBooks credentials directly; your credentials go to Intuit, never to Basel.Intuit then provides Basel with the credit-card expense data needed to run your analysis. Intuit's handling of your information is governed by the Intuit Global Privacy Statement.

07

How we share information

We do not sell your personal information. We share it only in these limited cases:

  • Service providers. Vendors that host and operate the Service on our behalf (for example, our cloud hosting provider, database and authentication provider, Plaid, Intuit, and email delivery provider) process data only as needed to provide their service and under contract.
  • With your direction. When you connect an account, you direct us to receive your data from Plaid or Intuit.
  • Legal & safety. Where required by law, to respond to lawful requests, or to protect the rights, safety, and security of Basel, our users, or the public.
  • Business transfers. In connection with a merger, acquisition, or sale of assets, subject to this policy.

We do not share your transaction data with card issuers, and we are not compensated for steering you toward any card. Referral relationships, where they exist, are disclosed on the recommendation and never influence the math.

08

How long we keep it

  • Workspace data, including transaction records, reports, monitoring snapshots, alerts, and preferences, persists until you use the deletion control or ask us to delete it, subject to legal, fraud-prevention, backup, or dispute-retention obligations.
  • Your authenticated session persists in browser cookies until you sign out, delete site data, or the session expires.
  • The sealed Plaid access tokenis retained while monitoring is active. Disconnecting Plaid revokes the Plaid Item and deletes the sealed token from Basel's active connection record. If Plaid is temporarily unavailable, the encrypted token is kept only in a service-only revocation queue until Plaid confirms removal, with retry backoff. QuickBooks tokens are not retained after the one-time import.
  • Technical logs are kept only as long as needed for security and reliability, then deleted or aggregated.

If we hold any information about you on our servers, we will delete it on request as described below, except where we must retain it to comply with a legal obligation, resolve disputes, or enforce our agreements.

09

Your rights and choices

Depending on where you are located (for example, under the California Consumer Privacy Act as amended, or comparable state laws), you may have the right to access, correct, delete, or receive a copy of your personal information, and to be free from discrimination for exercising these rights.

You can exercise the principal connection and deletion choices from Profile:

  • Delete workspace data. Open your profile and use “Delete workspace data” to revoke connected Plaid Items and erase transaction, report, alert, and preference data associated with your signed-in user. The control also clears Basel data stored in that browser and signs you out; your login and billing account remain until separately deleted or cancelled.
  • Access & portability. Your report and its underlying figures are visible in the app, and the report can be exported to PDF.
  • Revoke a connection. Disconnect from Basel Profile, your bank, QuickBooks, or Plaid Portal.

To exercise any right with respect to information we may hold, or to ask a question about your data, email [email protected]. We will verify your request and respond within the timeframe required by applicable law. You may use an authorized agent where the law permits.

10

How we protect it

We encrypt data in transit, keep provider credentials server-side, seal retained Plaid access tokens with authenticated encryption before database storage, and enforce ownership checks on workspace routes. For the full picture, see our Security & Trust page. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

11

Children

The Service is a business product and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us and we will delete it.

12

Changes to this policy

We may update this policy from time to time. When we make material changes we will update the effective date at the top and, where appropriate, provide additional notice. Continued use of the Service after an update means you accept the revised policy.

13

Contact us

Questions about this policy or your data? Email [email protected]. You can also write to Basel Systems, Inc..