— Legal

Privacy Policy

Last updated: June 27, 2026

1. Who We Are

Fizzy ("we", "us", "our") is a personal net worth tracking tool available at fizzymoney.com. The data controller is Le Duc Hieu, an individual operator based in the Netherlands. To exercise any of your rights or ask questions about how we handle your personal data, contact us at leduchieu642@proton.me.

2. Data We Collect

We collect only what is necessary to provide the Service:

  • Account data: your name, email address, and a hashed (bcrypt) password when you register.
  • Financial data you enter: account names, institution names, account categories, monthly balance amounts, exchange rates, and financial goals — all manually entered by you. We do not connect to banks or receive data from financial institutions.
  • Server logs: IP address, browser type, pages visited, and timestamps, collected automatically for security and debugging purposes. We do not use third-party analytics trackers. Server logs are retained for a maximum of 90 days, after which they are automatically deleted.
  • Payment data: handled entirely by Paddle. We receive a confirmation of payment status but never see or store your card number or bank details.

3. How We Use Your Data

We use your data to:

  • Create and manage your account and authenticate your sessions
  • Store and display the financial data you enter
  • Calculate net worth, category totals, and projections
  • Process your subscription via Paddle and manage access to Pro features
  • Send transactional emails (password reset, subscription confirmation) — no marketing emails without your explicit consent
  • Maintain security and prevent fraud
  • Comply with legal obligations

We do not sell, rent, or trade your data to any third party for marketing or advertising purposes.

4. Legal Basis for Processing (GDPR)

If you are in the European Economic Area, our legal bases are:

  • Contract performance — to provide the Service you signed up for (Art. 6(1)(b) GDPR).
  • Legitimate interests — for security logging and fraud prevention, where our interests are not overridden by your rights (Art. 6(1)(f) GDPR). You have the right to object to processing on this basis; see Section 9.
  • Legal obligation — where required by applicable law (Art. 6(1)(c) GDPR).

5. Third-Party Services

We share data with the following processors only as necessary to operate the Service:

  • Supabase — cloud database hosting (PostgreSQL). Your account and financial data is stored on Supabase-managed infrastructure. Supabase is SOC 2 Type II compliant and provides a Data Processing Agreement. Data is stored in the AWS us-east-1 region by default; if you require EEA data residency, contact us before registering.
  • Paddle (Paddle.com Market Limited) — payment processing and subscription management. Paddle acts as Merchant of Record and processes payment data under their own Privacy Policy. We receive only a subscription status signal.

We do not use advertising networks, social media pixels, or behavioural tracking SDKs.

6. Cookies

Fizzy uses only a session cookie to keep you logged in. No tracking cookies, advertising cookies, or third-party analytics cookies are used. You can delete this cookie by logging out or clearing your browser storage; doing so will end your session.

7. Data Retention

We retain your personal data for as long as your account is active. If you delete your account, we will delete your personal data and financial entries within 30 days, except where we are required to retain records for legal or tax compliance purposes (typically up to 7 years for transaction records held by Paddle as MoR).

Server logs (including IP addresses) are retained for a maximum of 90 days and then automatically purged.

8. Security

We take reasonable technical measures to protect your data including:

  • Passwords stored as bcrypt hashes (never in plain text)
  • All data transmitted over HTTPS/TLS
  • Database access restricted to the application layer
  • Row-level security enforced: your data is queryable only by your own user ID

No system is 100% secure. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach (as required by GDPR Article 33), and will notify affected users without undue delay where the breach is likely to result in a high risk to those users.

9. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate data (most data can be updated directly in the app).
  • Erasure — request deletion of your account and associated data.
  • Portability — receive your financial entries as a CSV export (available in History → Export CSV).
  • Object to processing — object to processing based on legitimate interests (Art. 21 GDPR). We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, or where processing is necessary for legal claims.
  • Restrict processing — in certain circumstances, request that we limit how we use your data.

To exercise any right, email leduchieu642@proton.me with the subject line "Data Request". We will respond within one month. You also have the right to lodge a complaint with the data protection authority in your country of residence. For EU users, a directory of national supervisory authorities is available at edpb.europa.eu.

10. Children

Fizzy is not intended for users under 18 years of age. We do not knowingly collect data from minors. If we become aware that a minor has created an account, we will delete it promptly.

11. International Transfers

Your data may be processed on servers located outside your country of residence. Where data is transferred outside the EEA, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or adequacy decisions. Supabase provides SCCs as part of their Data Processing Agreement. Paddle maintains their own transfer mechanisms described in their privacy policy.

12. Changes to This Policy

We may update this policy from time to time. We will notify you by email or in-app notice at least 14 days before material changes take effect. The "Last updated" date at the top of this page indicates when the most recent revision was made.

13. Contact

For privacy-related questions, data requests, or concerns: leduchieu642@proton.me