Spendbase
Get started
Last updated: 30 April 2026

Privacy Policy

Spendbase is built by Digital It Up. We take your privacy seriously and collect only what we need to run the service.

1. Information we collect

When you create an account we collect your email address and, optionally, your full name. When you use Spendbase we store the data you enter: workspace names, subscription records, expense entries, project details, and team member email addresses. We also collect standard server logs (IP address, browser type, pages visited) for security and debugging purposes.

2. How we use your information

We use your data solely to provide, maintain, and improve the Spendbase service. This includes: powering your dashboards and reports, sending renewal and budget alert emails you configure, sending transactional emails (password reset, team invitations), and diagnosing bugs. We do not sell, rent, or share your data with third parties for marketing purposes.

3. Data storage and security

Your data is stored in Supabase (Postgres) hosted on AWS infrastructure. All data is encrypted at rest and in transit (TLS 1.2+). Database access uses Row Level Security — users can only read data belonging to their workspaces. Receipt and attachment files are stored in Supabase Storage with workspace-scoped access policies.

4. Payment data

Spendbase does not store any payment card information. All payment processing is handled by Razorpay, which is PCI DSS compliant. We store only your Razorpay subscription ID and billing status to manage your plan.

5. Cookies

We use a single session cookie (workspace_id) to keep you signed in to your active workspace. This is a first-party, HTTP-only, secure cookie. We do not use third-party advertising cookies. We use PostHog for product analytics (page views, feature usage) — you can opt out by enabling Do Not Track in your browser.

6. Third-party services

Spendbase uses the following third-party services: • Supabase — database, auth, and file storage • Razorpay — payment processing • Resend — transactional email delivery • PostHog — product analytics (anonymised) Each service has its own privacy policy and data processing agreement.

7. Data retention

Your data is retained for as long as your account is active. When you delete your account, all workspaces you own — including subscriptions, expenses, projects, and team records — are permanently deleted within 30 days. Billing records may be retained for up to 7 years as required by applicable tax law.

8. Your rights

You have the right to: access a copy of your personal data, correct inaccurate information, delete your account and associated data, and withdraw consent at any time. To exercise these rights, email us at info@digitalitup.in. We will respond within 30 days.

9. Children

Spendbase is intended for business use and is not directed at children under 18. We do not knowingly collect personal information from minors.

10. Changes to this policy

We may update this policy from time to time. We will notify workspace owners by email at least 14 days before any material changes take effect. Continued use of the service after changes constitutes acceptance of the updated policy.

11. Contact

Questions about this policy? Email info@digitalitup.in or contact us via digitalitup.in.