Back

Privacy Policy

GDPR and Data Protection

This privacy policy has been updated to comply with GDPR, ISO 27001, SOC 2, CCPA, DPDPA, and other applicable data protection regulations.

Last updated: January 5, 2026

TellerWand Inc. ("TellerWand," "we," "us," or "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, mobile application, and services (collectively, the "Service").

1. Introduction

1.1 Scope

This Privacy Policy applies to:

  • All users of the TellerWand Service
  • Visitors to our website (https://tellerwand.com)
  • Users of our mobile application and Progressive Web App (PWA)
  • All data collected through our Service

1.2 Compliance

This Privacy Policy has been updated to comply with:

  • GDPR (General Data Protection Regulation) - European Union
  • CCPA (California Consumer Privacy Act) - California, United States
  • DPDPA (Digital Personal Data Protection Act) - India
  • ISO 27001 - Information Security Management
  • SOC 2 - Security, Availability, and Confidentiality
  • Other applicable data protection regulations

1.3 Acceptance

By using our Service, you consent to the collection, use, and disclosure of your information as described in this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use our Service.


2. Information We Collect

2.0 Data Minimization and Purpose Limitation

We follow the principles of data minimization and purpose limitation:

  • Data Minimization: We only collect information that is necessary for providing our Service
  • Purpose Limitation: We use your information only for the purposes stated in this Privacy Policy
  • Data Accuracy: You are responsible for ensuring the accuracy of information you provide
  • Storage Limitation: We retain data only for as long as necessary for the stated purposes

2.1 Information You Provide Directly

We collect information that you provide directly to us, including:

2.1.1 Account Information

  • Full name
  • Email address
  • Phone number (optional)
  • Password (encrypted)
  • Profile picture (optional)
  • Date of birth (optional)
  • Location (optional)

2.1.2 Financial Information

  • Investment details (mutual funds, stocks, PPF, EPF, NPS, real estate, gold, fixed deposits, bonds, etc.)
  • Transaction records (income and expenses)
  • Financial goals and targets
  • Asset valuations
  • Portfolio information
  • Bank account details (if provided for payment processing)
  • Payment method information (for subscription payments)

2.1.3 Family Information (Premium Feature)

  • Family member names and profiles
  • Family financial data
  • Family goals and planning information

2.1.4 Communication Information

  • Support requests and inquiries
  • Feedback and survey responses
  • Blog comments and submissions
  • Referral program information

2.2 Information Collected Automatically

We automatically collect certain information when you use our Service:

2.2.1 Device Information

  • Device type (mobile, tablet, desktop)
  • Operating system
  • Browser type and version
  • Device identifiers
  • IP address
  • Screen resolution
  • Language preferences

2.2.2 Usage Information

  • Pages visited and time spent
  • Features used and frequency
  • Click patterns and navigation paths
  • Search queries
  • Date and time of access
  • Session duration
  • Error logs and crash reports

2.2.3 Location Information

  • General location (country, city) based on IP address
  • Precise location (if you grant permission)
  • Time zone

2.2.4 Technical Information

  • Log files
  • Performance metrics
  • System configuration
  • Network information
  • Cookie and tracking data

2.3 Information from Third Parties

We may receive information about you from third-party sources:

2.3.1 Authentication Providers

  • Information from social login providers (Google, Apple, etc.)
  • OAuth provider data

2.3.2 Payment Processors

  • Payment transaction details
  • Billing information
  • Subscription status

2.3.3 Analytics Services

  • Aggregated usage statistics
  • User behavior insights

2.3.4 Referral Program

  • Referral link clicks
  • Referrer information
  • Conversion data

2.4 Cookies and Tracking Technologies

We use cookies, web beacons, and similar tracking technologies to collect information:

2.4.1 Types of Cookies

  • Essential Cookies: Required for Service functionality
  • Analytics Cookies: Help us understand how users interact with our Service
  • Preference Cookies: Remember your settings and preferences
  • Marketing Cookies: Used for advertising and referral tracking

2.4.2 Third-Party Cookies

  • Google Analytics
  • Cloudflare (security and performance)
  • Payment processors
  • Other service providers

2.5 Mobile App Permissions

If you use our mobile application, we may request the following permissions:

2.5.1 Camera Access

  • Purpose: To capture photos of receipts and financial documents
  • When Used: Only when you explicitly choose to take a photo
  • Storage: Photos are stored securely and can be deleted by you

2.5.2 Photo Library Access

  • Purpose: To access and share receipts, documents, and images
  • When Used: Only when you choose to select an image from your library
  • Storage: Images are processed and stored securely

2.5.3 Storage Permissions

  • Purpose: To save exported reports, documents, and cached data
  • When Used: For data export and offline functionality
  • Storage: Files are stored in app-specific directories

2.5.4 Network Permissions

  • Purpose: To connect to our servers and sync data
  • When Used: Required for Service functionality
  • Data: Only Service-related data is transmitted

2.6 Device Fingerprinting

We may collect device fingerprinting information for:

  • Fraud Prevention: Detecting and preventing fraudulent activities
  • Security: Identifying suspicious login attempts
  • Account Protection: Securing your account from unauthorized access

Device fingerprinting may include:

  • Device identifiers
  • Browser characteristics
  • Operating system information
  • Network information
  • Hardware characteristics

This information is used solely for security and fraud prevention purposes.

2.7 Public Information

Some information you provide may be publicly visible:

2.7.1 Blog Posts and Comments

  • Blog posts you publish are publicly accessible
  • Comments on blog posts are publicly visible
  • Your username or display name may be associated with public content

2.7.2 Shared Content

  • Content you choose to share publicly
  • Referral program participation (if made public)
  • Public profile information (if you enable public profile)

You can control what information is made public through your account settings.


3. How We Use Your Information

3.1 Service Provision

We use your information to:

  • Provide, maintain, and improve our Service
  • Process transactions and manage subscriptions
  • Authenticate and authorize access
  • Personalize your experience
  • Enable features and functionality
  • Process payments and billing
  • Send service-related communications

3.2 Communication

We use your information to:

  • Respond to your inquiries and support requests
  • Send important service updates and notifications
  • Provide customer support
  • Send marketing communications (with your consent)
  • Notify you about changes to our Service or policies

3.3 Analytics and Improvement

We use your information to:

  • Analyze usage patterns and trends
  • Improve Service performance and reliability
  • Develop new features and functionality
  • Conduct research and analytics
  • Monitor and prevent fraud and abuse
  • Debug and fix technical issues

3.4 Legal and Compliance

We use your information to:

  • Comply with legal obligations
  • Respond to legal requests and court orders
  • Enforce our Terms of Service
  • Protect our rights and property
  • Prevent fraud and security threats
  • Comply with regulatory requirements

3.5 Business Operations

We use your information to:

  • Manage our business operations
  • Process referrals and rewards
  • Conduct business analytics
  • Improve customer experience
  • Develop business strategies

3.6 AI and Machine Learning

We may use your information for AI and machine learning purposes:

3.6.1 Smart Recommendations

  • Provide personalized investment recommendations
  • Suggest financial goals based on your profile
  • Recommend expense categories and budgeting strategies

3.6.2 Automated Insights

  • Generate automated financial insights
  • Analyze spending patterns
  • Identify opportunities for savings and optimization

3.6.3 Fraud Detection

  • Detect fraudulent activities using automated systems
  • Assess risk scores for transactions and referrals
  • Prevent unauthorized access and abuse

3.6.4 Data Processing

  • AI/ML processing uses aggregated and anonymized data where possible
  • Personal information is processed securely and in accordance with this Privacy Policy
  • You can opt-out of certain AI features through account settings (where available)

3.7 Automated Decision-Making

We may use automated decision-making processes for:

3.7.1 Fraud Detection and Prevention

  • Automated risk assessment for transactions
  • Fraud scoring for referral program activities
  • Automated blocking of suspicious activities

3.7.2 Service Personalization

  • Automated content recommendations
  • Personalized feature suggestions
  • Automated categorization of transactions

3.7.3 Your Rights

  • You have the right to request human review of automated decisions
  • You can object to automated processing (where applicable)
  • Contact [email protected] to request review of automated decisions

4. How We Share Your Information

4.1 We Do NOT Sell Your Personal Information

TellerWand does NOT sell, rent, or trade your personal information to third parties for their marketing purposes.

4.2 Service Providers

We may share your information with trusted service providers who assist us in operating our Service:

4.2.1 Infrastructure Providers

  • Supabase: Database and authentication services
  • DigitalOcean: Cloud hosting and storage
  • Cloudflare: CDN and security services

4.2.2 Payment Processors

  • Cashfree: Payment processing and billing
  • Other payment gateway providers

4.2.3 Analytics Providers

  • Google Analytics: Usage analytics and insights
  • OpenReplay: Session replay and monitoring

4.2.4 Communication Services

  • Email service providers
  • Notification services
  • Customer support platforms

4.2.5 Security Services

  • Security monitoring and threat detection
  • Fraud prevention services

4.3 Legal Requirements

We may disclose your information if required by law or in response to:

  • Court orders or legal processes
  • Government requests
  • Regulatory investigations
  • Legal compliance requirements
  • Protection of rights and safety

4.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections.

4.5 With Your Consent

We may share your information with third parties when you explicitly consent to such sharing.

4.6 Aggregated and Anonymized Data

We may share aggregated, anonymized, or de-identified information that cannot be used to identify you individually for:

  • Research and analytics
  • Business intelligence
  • Industry reports
  • Marketing purposes

4.7 Family Features (Premium)

If you use Family Finance Management features:

  • Family members you invite can see shared financial information
  • You control what information is shared with family members
  • Family member data is subject to the same privacy protections

5. Data Security

5.1 Security Measures

We implement industry-standard security measures to protect your information:

5.1.1 Encryption

  • 256-bit AES encryption for data at rest
  • TLS/SSL encryption for data in transit
  • End-to-end encryption for sensitive financial data
  • Encrypted password storage (hashing with bcrypt)

5.1.2 Access Controls

  • Role-based access control (RBAC)
  • Multi-factor authentication (MFA) support
  • Regular access reviews and audits
  • Principle of least privilege

5.1.3 Infrastructure Security

  • Secure cloud infrastructure (DigitalOcean)
  • Regular security updates and patches
  • Network security and firewalls
  • DDoS protection (Cloudflare)
  • Intrusion detection and prevention

5.1.4 Data Protection

  • Regular security audits
  • Vulnerability assessments
  • Penetration testing
  • Security monitoring and logging
  • Incident response procedures

5.2 Security Certifications

We maintain compliance with:

  • ISO 27001: Information Security Management
  • SOC 2 Type II: Security, Availability, and Confidentiality
  • Industry best practices and standards

5.3 Your Responsibility

While we implement strong security measures, you are also responsible for:

  • Using a strong, unique password
  • Enabling multi-factor authentication (MFA)
  • Keeping your login credentials secure
  • Not sharing your account with others
  • Logging out from shared devices
  • Reporting suspicious activity immediately

5.4 Data Breach Notification

In the event of a data breach that may affect your personal information:

  • We will notify affected users within 72 hours (as required by GDPR)
  • We will notify relevant authorities as required by law
  • We will provide clear information about the breach and steps to protect yourself

6. Data Retention

6.1 Retention Periods

We retain your information for as long as necessary to:

  • Provide our Service to you
  • Comply with legal obligations
  • Resolve disputes
  • Enforce our agreements

6.2 Specific Retention Periods

6.2.1 Account Data

  • Active Accounts: Retained while your account is active
  • Deletion requests: 7-day grace period during which you may cancel in Settings or Account
  • After grace: Account is archived (soft-deleted) with up to 1 year recovery for support
  • Archived accounts: Personal identifiers are removed from active systems; recovery data is retained per our deletion policy

6.2.2 Financial Data

  • Transaction and payment records: Pseudonymized statutory ledger retained for 7 years (tax and legal compliance in India)
  • Investment data: Retained while your account is active; archived with soft-deleted accounts
  • After erasure: Financial identifiers are not retained in active product tables; ledger entries use provider payment IDs only (no email or name)

6.2.3 Communication Data

  • Support Requests: Retained for 3 years
  • Email Communications: Retained for 3 years
  • Blog Comments: Retained while the blog post exists

6.2.4 Log and Audit Data

  • Platform audit log (hot): 12 months in our primary database (Mumbai region)
  • Platform audit log (cold archive): Up to 3 years total in private encrypted object storage (India region)
  • After account erasure: Audit entries are pseudonymized (subject tokens; no plaintext email, name, or amounts)
  • Application error logs: Retained for up to 30 days
  • Security event logs: Retained for up to 1 year

6.3 Data Deletion

When you request account deletion:

  • You receive a 7-day grace period to cancel the request in Settings or Account
  • After grace, your account is soft-deleted (archived) with up to 1 year recovery for support
  • Statutory payment records are retained for 7 years in a pseudonymized ledger (provider order/payment IDs only)
  • Platform audit logs are retained for up to 3 years with pseudonymization after erasure
  • Aggregated, anonymized analytics may be retained where permitted by law

7. Your Rights and Choices

7.1 Access Rights

You have the right to:

  • Access: Request a copy of your personal information
  • Review: Review the personal information we hold about you
  • Export: Export your data in a machine-readable format

7.2 Correction Rights

You have the right to:

  • Update: Correct inaccurate or incomplete information
  • Modify: Update your personal information through account settings
  • Request Correction: Request correction of data we hold about you

7.3 Deletion Rights

You have the right to:

  • Delete Account: Request deletion of your account and personal information
  • Delete Specific Data: Request deletion of specific data points
  • Right to be Forgotten: Request erasure of your personal information (GDPR)

7.4 Data Portability

You have the right to:

  • Export Data: Receive your data in a structured, commonly used format
  • Transfer Data: Transfer your data to another service provider
  • Data Portability: Request transfer of your data (GDPR)

7.5 Opt-Out Rights

You have the right to:

  • Marketing Communications: Opt-out of marketing emails (unsubscribe link in emails)
  • Cookies: Manage cookie preferences through browser settings
  • Analytics: Opt-out of analytics tracking (where available)
  • Data Processing: Object to certain data processing activities

7.6 Restriction Rights

You have the right to:

  • Restrict Processing: Request restriction of data processing (GDPR)
  • Object to Processing: Object to processing of your personal information
  • Withdraw Consent: Withdraw consent for data processing (where applicable)
  • Object to Automated Decision-Making: Request human review of automated decisions (GDPR)

7.7 How to Exercise Your Rights

To exercise your rights, please:

  1. Email: Send a request to [email protected]
  2. Subject Line: Include "Privacy Request" and specify the right you wish to exercise
  3. Verification: We may require identity verification for security
  4. Response Time: We will respond within 30 days (or as required by applicable law)

7.8 Non-Discrimination

We will not discriminate against you for exercising your privacy rights.


8. Children's Privacy

8.1 Age Requirement

Our Service is not intended for children under the age of 18 (or the age of majority in your jurisdiction). We do not knowingly collect personal information from children.

8.2 Parental Consent

If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at [email protected].

8.3 Removal of Children's Data

If we become aware that we have collected personal information from a child without parental consent, we will:

  • Delete the information immediately
  • Terminate the child's account (if applicable)
  • Notify the parent or guardian (if contact information is available)

9. International Data Transfers

9.1 Data Storage Locations

Your information may be stored and processed in:

  • India: Primary data storage and processing
  • United States: Some service providers (Supabase, DigitalOcean, Cloudflare)
  • European Union: Some service providers (where applicable)

9.2 Transfer Safeguards

When transferring data internationally, we ensure:

  • Adequate Safeguards: Standard Contractual Clauses (SCCs) where required
  • Data Protection: Compliance with applicable data protection laws
  • Security Measures: Same security standards regardless of location
  • Legal Compliance: Adherence to GDPR, CCPA, and other applicable regulations

9.3 Your Consent

By using our Service, you consent to the transfer of your information to countries that may have different data protection laws than your country of residence.


10. Third-Party Services

10.1 Third-Party Links

Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of third parties. We encourage you to review their privacy policies.

10.2 Third-Party Integrations

We may integrate with third-party services for:

  • Payment processing
  • Analytics
  • Authentication
  • Communication
  • Storage

These third parties have their own privacy policies governing data collection and use.

10.3 Social Media

If you connect your account with social media services:

  • We may receive information from those services
  • Your use of social media features is subject to their privacy policies
  • You can disconnect social media accounts at any time

11. Cookies and Tracking Technologies

11.1 Types of Cookies We Use

11.1.1 Essential Cookies

  • Required for Service functionality
  • Cannot be disabled
  • Include authentication and security cookies

11.1.2 Analytics Cookies

  • Help us understand Service usage
  • Improve user experience
  • Can be disabled through browser settings

11.1.3 Preference Cookies

  • Remember your settings
  • Personalize your experience
  • Can be disabled through browser settings

11.1.4 Marketing Cookies

  • Used for advertising and referrals
  • Track campaign effectiveness
  • Can be disabled through browser settings

11.2 Managing Cookies

You can manage cookies through:

  • Browser Settings: Most browsers allow you to control cookies
  • Cookie Preferences: Manage preferences in account settings (where available)
  • Opt-Out Tools: Use industry opt-out tools for advertising cookies

11.3 Impact of Disabling Cookies

Disabling certain cookies may:

  • Affect Service functionality
  • Limit personalized features
  • Impact user experience

12. Do Not Track Signals

12.1 Browser Do Not Track

Some browsers include "Do Not Track" (DNT) features. We respect DNT signals and do not track users who have enabled DNT, except as required for Service functionality.

12.2 Limitations

DNT signals may not affect:

  • Essential Service functionality
  • Security and fraud prevention
  • Legal compliance requirements

13. California Privacy Rights (CCPA)

13.1 California Consumer Rights

If you are a California resident, you have additional rights under CCPA:

13.1.1 Right to Know

  • What personal information we collect
  • How we use your personal information
  • Categories of third parties with whom we share information

13.1.2 Right to Delete

  • Request deletion of your personal information
  • Subject to certain exceptions (legal compliance, etc.)

13.1.3 Right to Opt-Out

  • Opt-out of sale of personal information (we do not sell personal information)
  • Opt-out of sharing for cross-context behavioral advertising

13.1.4 Right to Non-Discrimination

  • We will not discriminate for exercising CCPA rights

13.2 Exercising CCPA Rights

To exercise your CCPA rights:

  • Email: [email protected]
  • Subject: "CCPA Privacy Request"
  • Include: Your name, email, and specific request

14. European Privacy Rights (GDPR)

14.1 GDPR Rights

If you are in the European Economic Area (EEA), you have additional rights under GDPR:

14.1.1 Right of Access

  • Obtain confirmation of data processing
  • Access your personal information
  • Receive a copy of your data

14.1.2 Right to Rectification

  • Correct inaccurate data
  • Complete incomplete data

14.1.3 Right to Erasure (Right to be Forgotten)

  • Request deletion of your personal information
  • Subject to legal retention requirements

14.1.4 Right to Restrict Processing

  • Request restriction of data processing
  • Under certain circumstances

14.1.5 Right to Data Portability

  • Receive your data in a structured format
  • Transfer data to another service

14.1.6 Right to Object

  • Object to processing of personal information
  • Object to direct marketing

14.1.7 Right to Withdraw Consent

  • Withdraw consent for data processing
  • Where processing is based on consent

14.1.8 Right to Object to Automated Decision-Making

  • Object to automated decision-making, including profiling
  • Request human intervention in automated decisions
  • Express your point of view and contest automated decisions

14.2 Legal Basis for Processing

We process your personal information based on:

  • Consent: When you provide explicit consent
  • Contract: To fulfill our contract with you
  • Legal Obligation: To comply with legal requirements
  • Legitimate Interests: For our legitimate business interests

14.3 Data Protection Officer

For GDPR-related inquiries, contact:


15. Indian Privacy Rights (DPDPA)

15.1 DPDPA Rights

If you are in India, you have rights under the Digital Personal Data Protection Act (DPDPA):

15.1.1 Right to Information

  • Know what personal data is being processed
  • Purpose of processing
  • Entities with whom data is shared

15.1.2 Right to Correction

  • Correct inaccurate personal data
  • Update incomplete data

15.1.3 Right to Erasure

  • Request deletion of personal data
  • Subject to legal retention requirements

15.1.4 Right to Grievance Redressal

  • File complaints about data processing
  • Seek resolution of privacy concerns

15.2 Exercising DPDPA Rights

You may exercise your DPDPA rights in the app or by email:

  • Access & portability: Settings → Privacy → Export My Data (MFA required)
  • Erasure: Settings or Account → Request Account Deletion (7-day grace, cancellable; MFA required)
  • Correction: Update your profile in Account settings
  • Policy acknowledgement: Material privacy policy updates require in-app acknowledgement (with MFA)
  • Email: [email protected] — Subject: "DPDPA Privacy Request"

Primary data processing is in India (Mumbai / ap-south-1). Platform audit logs are mandatory for security and compliance; regular administrators see masked identifiers; super administrators may access full audit detail under strict controls.


16. Marketing Communications

16.1 Opt-In Consent

We only send marketing communications with your explicit consent. You can opt-in when:

  • Creating an account
  • Subscribing to newsletters
  • Participating in promotions

16.2 Opt-Out

You can opt-out of marketing communications by:

  • Clicking "Unsubscribe" in marketing emails
  • Updating preferences in account settings
  • Contacting [email protected]

16.3 Service Communications

You cannot opt-out of:

  • Service-related notifications
  • Important account updates
  • Security alerts
  • Legal notices

17. Changes to This Privacy Policy

17.1 Policy Updates

We may update this Privacy Policy from time to time to:

  • Reflect changes in our practices
  • Comply with legal requirements
  • Improve clarity and transparency

17.2 Notification of Changes

We will notify you of material changes by:

  • Email: Sending an email to your registered email address
  • Website: Posting a notice on our Service
  • In-App: Displaying a notification in the application

17.3 Effective Date

The "Last Updated" date at the top of this Privacy Policy indicates when it was last revised.

17.4 Continued Use

Your continued use of our Service after changes become effective constitutes acceptance of the updated Privacy Policy.


18. Contact Information

18.1 Privacy Inquiries

For questions, concerns, or requests regarding this Privacy Policy or your personal information:

  • Email: [email protected]
  • Subject Line: "Privacy Inquiry" or "Privacy Request"
  • Response Time: We aim to respond within 30 days (or as required by applicable law)

18.2 Data Protection Officer

For GDPR-related inquiries:

18.3 General Contact

  • Website: https://tellerwand.com
  • Contact Page: https://tellerwand.com/contact-us
  • Support Hours: Monday to Friday, 9:00 AM to 6:00 PM IST

19. Additional Information

19.1 Data Controller

TellerWand Inc. is the data controller responsible for your personal information.

19.2 Data Processor

We may use third-party data processors who process data on our behalf under strict contractual obligations.

19.3 Supervisory Authority

If you are in the EEA and have concerns about our data processing, you have the right to lodge a complaint with your local data protection supervisory authority.

19.4 Governing Law

This Privacy Policy is governed by the laws of India, with jurisdiction in Bangalore, Karnataka, India.

19.5 Data Processing Agreements

We enter into Data Processing Agreements (DPAs) with all third-party service providers who process personal information on our behalf. These agreements ensure that:

  • Third parties process data only for specified purposes
  • Appropriate security measures are maintained
  • Data is not used for other purposes
  • Data is deleted when no longer needed

19.6 Research and Development

We may use aggregated, anonymized data for:

  • Research and development purposes
  • Improving our Service and features
  • Industry analysis and benchmarking
  • Academic research (with appropriate safeguards)

No personally identifiable information is used in research without your explicit consent.

19.7 Account Recovery and Data Access

During account recovery processes:

  • We may request additional verification information
  • Recovery data is used solely for account restoration
  • Recovery information is securely stored and deleted after successful recovery
  • We follow strict verification procedures to protect your account

20. Acceptance

By using our Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.


TellerWand Inc.
Last Updated: January 5, 2026
Version: 1.0

Note: This Privacy Policy is comprehensive and designed to comply with GDPR, CCPA, DPDPA, and other applicable data protection regulations. For specific legal advice, please consult with a qualified legal professional.