Privacy Policy

Version 1.0 · Effective 14 September 2026

1. Who we are

CFO-Flow provides 13-week cashflow forecasting for small and mid-sized businesses. The service is operated by CFO WHITELABEL LIMITED ("we", "us"), of 3 Loudon Terrace, Glasgow, G12 9AQ.

This policy explains what information we collect when you use CFO-Flow, why we collect it, who we share it with, how long we keep it, and the choices you have. It applies to every account on the platform, whichever organisation the account belongs to.

Questions or requests about this policy, or about your data, go to security@cfowhitelabel.co.uk

2. What we collect

  • Account information. Your name, work email address, and password. Passwords are stored hashed by our authentication provider and never in plain text.
  • Bank transaction data, via Plaid. For the accounts you choose to connect: transaction descriptions, amounts, dates, and merchant category, together with the identifiers Plaid uses to refer to those accounts and transactions.
  • Spreadsheet access, via Google or Microsoft. If you connect a Google Sheets or Microsoft Excel workbook, the access needed to read and write that specific file, granted through Google's or Microsoft's own consent screen.
  • Usage and error data. Sync history, sign-in timestamps, a record that you acknowledged this policy and when, and error reports, associated with your account and organisation but not with the content of your transactions.

What we deliberately do not receive. We request transaction data from Plaid and nothing else. We do not receive your account numbers, your routing numbers, your balances, or your identity details from Plaid, because we do not enable the Plaid products that provide them. We never receive your online banking credentials at all — Plaid handles that exchange directly with your bank, and we never see it.

3. Why we collect it

We use this information to operate the product you signed up for: reconciling your bank transactions, classifying them, and building the rolling 13-week cashflow forecast in your spreadsheet.

We also use account and usage data to authenticate you, secure your account, provide customer support, and send you service notifications — a failed sync, a bank connection that needs re-authorising, a billing update.

We do not sell your data, and we do not use your financial data to train AI models.

4. Who is responsible for your information, and our lawful basis

Two organisations have a part in this. Your own organisation decides that its bank transactions should be brought into CFO-Flow and turned into a forecast, and we carry that out on its instructions. For that information your organisation is responsible — it is the data controller and we act as its processor. Questions about why it is held, and requests to see or delete it, are answered by your organisation, and we help them answer.

For everything else — your account and sign-in, our security and audit records, and our billing records — we decide, and so we are responsible. The list below gives our reason for each.

Data protection law says we need a valid reason — a "lawful basis" — before we use anyone's personal information, and that you are entitled to be told which reason applies to which activity. It matters because it decides what you can do about it: where we rely on our legitimate interests, you can object.

  • Setting up and running your account. Necessary to provide the service you have signed up for, or our legitimate interest in delivering that service where our contract is with your organisation rather than with you personally.
  • Reconciling and classifying your bank transactions, and building your forecast. Carried out on your organisation's instructions, as its processor. Your organisation is responsible for this information, and for the basis it relies on.
  • Customer support and service notifications. The same lawful basis as setting up and running your account, above.
  • Security monitoring, audit logs, policy acknowledgements, and error reports. Our legitimate interest in keeping the platform and your account secure.
  • AI-assisted transaction categorisation, where your organisation has switched this on. Carried out on your organisation's instructions, where it has switched this on and supplied its own provider key. Personal identifiers are removed from the description on a best-effort basis first. Counterparty business names are deliberately retained, because they are what makes a category suggestion possible.
  • Billing. Necessary to perform our contract with you, and, for retained billing records, our legal obligation to keep tax and accounting records.

Where the basis above is our legitimate interests, you can object to that use of your information — see Section 8.

5. Who we share it with

We share data only with the providers that make the product work. Each acts under its own agreement with us and, for regulated financial data, its own compliance obligations.

  • Plaid — the bank connection itself, for linking your bank account and retrieving transactions.
  • Google and Microsoft — read and write access to the specific workbook you connect, for writing your forecast into your own spreadsheet.
  • Nango — the spreadsheet connection only, for issuing and refreshing the spreadsheet access tokens. Your transaction data passes directly between our servers and Google or Microsoft, never through Nango.
  • Google Gemini — the transaction description only, with personal identifiers removed on a best-effort basis before it is sent and counterparty business names deliberately retained, to suggest a category for a transaction. Optional — see below.
  • Stripe — what it needs to bill you, for billing and payment processing. It never receives your bank transaction data.
  • Supabase — your account and financial data, encrypted at rest. Our database and authentication provider.
  • Vercel — application hosting. No durable store of your data.
  • Resend — your email address and the content of service emails, for confirmations, invitations, and notifications.
  • Sentry — error reports, configured to exclude the content of your financial data, for error monitoring.

AI classification is optional and off unless you turn it on. If your organisation enables it and supplies its own Google Gemini API key, we send the transaction description to Google to get a suggested category back. Personal identifiers are removed from the description on a best-effort basis first; counterparty business names are deliberately retained, because they are what makes a category suggestion possible. Nothing else about you or your organisation goes with it. If you do not enable this, no transaction data is sent to Google for classification.

We do not sell your personal data. We only share data with the service providers identified above to run CFO-Flow, or where we are required to do so by law.

6. How we protect it

  • Every account requires a second authentication factor before any bank data is reachable.
  • Your data is encrypted in transit and at rest.
  • Bank access tokens and other credentials are held in a dedicated secrets vault, never in plain text, and are never logged or included in an email.
  • Each organisation's data is isolated from every other organisation's, enforced both in our application code and independently at the database level, so that no single mistake exposes another organisation's data.
  • Administrative action taken inside the product against an organisation's data is restricted to named administrators and written to an append-only audit log that cannot be edited or erased through the application. A small number of named administrators also hold direct infrastructure access to the database and hosting platform, which is necessary to operate and recover the service; that access is recorded in our access register, is held by the fewest people possible, and is reviewed on a defined cycle.

7. How long we keep it, and how we delete it

We retain your data for as long as your account is active. Our full internal schedule is set out in our Data Retention and Disposal Policy, which is available on request; the summary is:

  • Bank transaction data — for the life of your account. Deleted when your organisation is deleted.
  • Bank access tokens — for the life of the bank connection. Revoked at Plaid and purged when you disconnect or delete.
  • Account and user records — for the life of your account.
  • Billing records — kept after deletion, in de-identified form, for as long as tax and financial recordkeeping law requires.
  • Administrative audit records — kept after deletion, in de-identified form, so that a record of who did what to an account survives the account.
  • Error reports — a limited period set by our error monitoring provider. They exclude the content of your financial data.

Cancelling is not deleting. If your subscription is cancelled, your organisation's data is locked rather than deleted, so a returning customer loses nothing. Deletion happens only as a separate, deliberate step, and only when you ask for it.

What deletion actually does. When you ask us to delete an organisation, we remove its transaction data, its account and user records, and its stored credentials, and we disconnect the bank link at Plaid so that we no longer have access to it. The sign-in accounts of its members are deleted too, so the login stops working — unless the person also belongs to another organisation here, in which case their account stays for that one. Your spreadsheet is your own file and stays with you — we give up our access to it rather than deleting your workbook. We keep a de-identified record of billing history and of administrative actions, as described above; neither names you or retains your bank transaction data. Deleted data may persist briefly in encrypted backups until those backups expire on their normal cycle, after which it is unrecoverable.

To request deletion of your account or your organisation's data, contact security@cfowhitelabel.co.uk

8. Your choices and your rights

  • You can disconnect a linked bank account or spreadsheet at any time from within the product, without deleting your account.
  • You can request a copy of the data we hold about you or your organisation.
  • You can request that we correct data we hold about you.
  • You can object to any use of your information that relies on our legitimate interests — Section 4 says which uses those are. For your bank transaction data, that request goes to your own organisation, and we will help them answer it.
  • You can request that we delete your account and associated data, subject to what we are legally required to retain (for example, billing records).
  • You can ask us any question about how your data is handled.
  • You can complain to a supervisory authority if you are unhappy with how we have handled your information.

Send any of the above to security@cfowhitelabel.co.uk. We will acknowledge your request within 10 business days and complete it within one calendar month of receiving it, or tell you if the law allows us longer and why we need it. If we need to check who you are before we can act, the month runs from when you give us what we need for that. We will not charge you for making a request, and we will not treat you differently for having made one.

You also have the right to lodge a complaint with a supervisory authority in the EEA member state where you work or normally live, or where the alleged infringement occurred; a list is at edpb.europa.eu. The supervisory authority in the UK is the Information Commissioner's Office, at ico.org.uk/make-a-complaint or on 0303 123 1113. We would ask that you raise it with us first at security@cfowhitelabel.co.uk, so that we have the chance to put it right.

9. Children

CFO-Flow is a business tool. It is not directed at, and not knowingly used by, anyone under 18. We do not knowingly collect personal information from children.

10. International transfers

Our providers are listed in Section 5. Some of them, notably our OAuth broker, are hosted in the United States. Where your data is transferred outside the country you are in, we rely on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses, as incorporated into our providers' data processing agreements.

11. Changes to this policy

If we make a material change to how we collect, use, or share your data, we will notify account owners by email and update the effective date at the top of this document. We review this policy at least annually, and on any material change to what we collect, how we use it, or who we share it with — the annual review happens even when nothing has changed.

12. How to contact us

For any question or request about this policy or your data: security@cfowhitelabel.co.uk

CFO WHITELABEL LIMITED, 3 Loudon Terrace, Glasgow, G12 9AQ.