How We Collect, Use, and Protect Your Information
Data Jackson, LLC ("Data Jackson," "we," "us," or "our") operates the Financial Coach application and related financial technology services that connect to financial institutions via Plaid, Inc.'s financial data network. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our services.
We are committed to protecting your privacy and handling your financial data with the care it deserves. Please read this policy carefully. By using our services, you agree to the collection and use of information as described herein.
When you connect a financial account through Plaid, we receive financial data from your linked institutions. See Section 5 for full details on how we handle Plaid-sourced data. This may include:
| Purpose | Data Used | Basis |
|---|---|---|
| Provide financial coaching and analysis features | Financial transactions, account balances, goals | Contract performance / Consent |
| Personalize your experience and recommendations | Transaction history, preferences, goals | Consent |
| Authenticate your identity and secure your account | Email, password hash, device info | Contract performance / Legitimate interest |
| Communicate service updates and notifications | Email address | Legitimate interest / Consent |
| Improve and develop our services | Aggregated, de-identified usage data only | Legitimate interest |
| Security monitoring and fraud prevention | Usage logs, IP address, device info | Legitimate interest / Legal obligation |
| Comply with legal obligations | As required by applicable law | Legal obligation |
We do not sell your personal information or financial data. We do not use your financial data for advertising purposes.
We process your personal information based on the following legal grounds:
Our application uses Plaid, Inc. to connect to your financial institutions. When you use Plaid Link within our application, Plaid's own privacy policy also applies to the data Plaid collects on our behalf.
/item/remove API in the same operation (see Section 7).The CFPB's Section 1033 open-banking / personal financial data rights rule remains subject to ongoing rulemaking and legal challenge as of this policy's last review. We are monitoring its status and will update this policy and our data-sharing practices as the rule's requirements are finalized; this policy does not make a compliance claim regarding Section 1033 either way.
We do not sell, rent, or trade your personal or financial information. We share data only in the following limited circumstances:
| Recipient | Purpose | Safeguards |
|---|---|---|
| Plaid, Inc. | Financial institution connectivity to retrieve your authorized account data | Data Processing Agreement; SOC 2 Type II certified |
| Cloud infrastructure providers (AWS, GCP) | Hosting and data storage for the application | Data Processing Agreement; encrypted storage; SOC 2 / ISO 27001 certified |
| Authentication service providers | Secure user identity and MFA management | Industry-standard authentication protocols; DPA in place |
| Legal authorities | When required by law, court order, or to protect safety | Disclosed only as legally required; narrowly scoped |
Any third-party service provider receiving your data is contractually bound to process it only for the stated purpose and to maintain appropriate security controls.
| Data Type | Retention Period | Deletion Method |
|---|---|---|
| Financial transaction data (from Plaid) | Deleted immediately on account deletion; backup copies purged within 90 days | Immediate database deletion; cryptographic erasure on backup rotation |
| Account information (name, email) | Deleted immediately on deletion request | Secure deletion from all systems |
| Usage logs (security and audit) | 12 months rolling | Automated log expiration |
| Financial goals and preferences | Deleted immediately on account deletion | Secure deletion |
| Backup copies | 90 days maximum after primary deletion | Overwritten in next backup cycle |
When you request account deletion, we verify your identity and then delete all primary data — including revoking any linked Plaid access — immediately, not on a 30-day delay. Backup copies are purged on the next backup rotation cycle, within 90 days. We will confirm completion upon request.
We implement a comprehensive security program to protect your information (detailed in our Information Security Policy ISP-2026-001). Key safeguards include:
No method of transmission over the Internet or electronic storage is 100% secure. We maintain commercially reasonable security measures appropriate for the sensitivity of the data we process.
You have the following rights regarding your personal information:
| Right | Description | How to Exercise |
|---|---|---|
| Access | Request a copy of the personal data we hold about you | Email us at brandon@datajackson.com |
| Correction | Request correction of inaccurate or incomplete data | Update in-app or contact us |
| Deletion | Request deletion of your personal data | Account deletion in-app or email us |
| Portability | Receive a copy of your data in a machine-readable format | Email us at brandon@datajackson.com |
| Withdraw Consent | Withdraw consent for processing where consent is the basis | Disconnect accounts in-app; contact us for full withdrawal |
| Restriction | Request restriction of processing in certain circumstances | Email us at brandon@datajackson.com |
| Object | Object to processing based on legitimate interest | Email us at brandon@datajackson.com |
We respond to all privacy rights requests within 30 days. Complex requests may require an extension, which we will communicate to you promptly.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
To exercise California rights, submit a verifiable consumer request to: brandon@datajackson.com or via the in-app privacy settings. We respond to verified requests within 45 days (extendable once by an additional 45 days with notice).
In the past 12 months, we have collected the following CCPA categories:
We use essential cookies and similar technologies to operate the application (session management, authentication). We do not use third-party advertising cookies or cross-site tracking technologies.
Essential cookies cannot be disabled as they are necessary for the application to function. You may clear cookies through your browser settings, which will log you out of the application.
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have inadvertently collected personal information from a child under 18, we will delete it promptly. If you believe we have collected information from a child, please contact us immediately at brandon@datajackson.com.
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:
Your continued use of our services after a policy update constitutes acceptance of the revised policy. For significant changes, we may seek fresh consent.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
For privacy rights requests, you may also submit a request through the privacy settings within the application. We respond to all requests within 30 days.