Spendbase is built by Digital It Up. We take your privacy seriously and collect only what we need to run the service.
When you create an account we collect your email address and, optionally, your full name. When you use Spendbase we store the data you enter: workspace names, subscription records, expense entries, project details, and team member email addresses. We also collect standard server logs (IP address, browser type, pages visited) for security and debugging purposes.
We use your data solely to provide, maintain, and improve the Spendbase service. This includes: powering your dashboards and reports, sending renewal and budget alert emails you configure, sending transactional emails (password reset, team invitations), and diagnosing bugs. We do not sell, rent, or share your data with third parties for marketing purposes.
Your data is stored in Supabase (Postgres) hosted on AWS infrastructure. All data is encrypted at rest and in transit (TLS 1.2+). Database access uses Row Level Security — users can only read data belonging to their workspaces. Receipt and attachment files are stored in Supabase Storage with workspace-scoped access policies.
Spendbase does not store any payment card information. All payment processing is handled by Razorpay, which is PCI DSS compliant. We store only your Razorpay subscription ID and billing status to manage your plan.
We use a single session cookie (workspace_id) to keep you signed in to your active workspace. This is a first-party, HTTP-only, secure cookie. We do not use third-party advertising cookies. We use PostHog for product analytics (page views, feature usage) — you can opt out by enabling Do Not Track in your browser.
Spendbase uses the following third-party services: • Supabase — database, auth, and file storage • Razorpay — payment processing • Resend — transactional email delivery • PostHog — product analytics (anonymised) Each service has its own privacy policy and data processing agreement.
Your data is retained for as long as your account is active. When you delete your account, all workspaces you own — including subscriptions, expenses, projects, and team records — are permanently deleted within 30 days. Billing records may be retained for up to 7 years as required by applicable tax law.
You have the right to: access a copy of your personal data, correct inaccurate information, delete your account and associated data, and withdraw consent at any time. To exercise these rights, email us at info@digitalitup.in. We will respond within 30 days.
Spendbase is intended for business use and is not directed at children under 18. We do not knowingly collect personal information from minors.
We may update this policy from time to time. We will notify workspace owners by email at least 14 days before any material changes take effect. Continued use of the service after changes constitutes acceptance of the updated policy.
Questions about this policy? Email info@digitalitup.in or contact us via digitalitup.in.