We built ServFin with privacy at its core. Your financial data stays on your device, so we never see it, store it, or have access to it.
Last updated: January 15, 2024
Your data never leaves your device. All reconciliation happens locally in your browser.
We don't store, transmit, or have access to your financial files or reconciliation data.
We use minimal analytics and never sell or share your personal information with third parties.
Bank-level encryption for authentication. Your account is protected with industry-standard security.
When you create an account, we collect your email address and password (securely hashed). If you subscribe to a paid plan, our payment processor (Stripe) handles your payment information, and we never see or store your full card details.
We collect basic analytics about how you use ServFin, including pages visited, features used, and session duration. This helps us improve our product and user experience.
Here's the important part: We do NOT collect, store, or transmit your financial files. When you upload Excel files for reconciliation, they are processed entirely in your browser using client-side JavaScript. The data never touches our servers.
We use your account information to provide access to ServFin, manage your subscription, and send important service-related communications.
Anonymous usage analytics help us understand which features are most valuable and where we can improve the user experience.
We may send you product updates, security alerts, and occasional marketing emails (which you can opt out of at any time).
All data transmitted between your browser and our servers is encrypted using TLS 1.3. Your password is hashed using bcrypt with a high cost factor.
Our application is hosted on Vercel's secure infrastructure with automatic security updates and DDoS protection.
We implement strict access controls internally. Only essential personnel have access to production systems, and all access is logged and audited.
We use Stripe for payment processing. Stripe is PCI-DSS Level 1 certified, the highest level of security certification. View Stripe's privacy policy at stripe.com/privacy.
Our authentication and database services are provided by Supabase, which maintains SOC 2 Type II compliance and provides enterprise-grade security.
We use privacy-focused analytics that don't use cookies and comply with GDPR, CCPA, and PECR requirements.
You can access all your account information through your dashboard. You can export your commission templates and calculation history at any time.
You can delete your account at any time through your settings. This will permanently remove all your data from our systems within 30 days.
You can update your account information at any time through your profile settings.
We're committed to transparency. If you have any questions about how we handle your data, please don't hesitate to reach out.