HAVEN LEGAL
Privacy Policy
1. Introduction
Haven is a personal budgeting application that helps users view accounts, transactions, bills, savings goals, and other financial information in one place. This Privacy Policy explains what information Haven collects, how it is used, when it is shared, and the choices available to users.
This policy applies to the Haven web application and its mobile web-app experience, including financial-account connections initiated through Plaid Link.
2. Information Haven collects
- Early-access application information, such as name, email address, pay schedule, current budgeting method, financial challenges, institutions a person hopes to connect, and willingness to provide beta feedback.
- Account information, such as name, email address, password hash, account preferences, and authenticated-session information.
- Financial information a user enters directly, including budgets, goals, bills, accounts, transactions, categories, and notes.
- Financial information a user authorizes Haven to receive through Plaid, including connected account names, balances, transactions, account type, and, when selected, investment or liability information.
- Technical and security information needed to operate and protect the service, including sign-in events, session information, device push-notification subscriptions, and security-related logs.
- Questions a user voluntarily sends to Haven Coach. Coach receives a summarized budget picture needed to respond; it is not given bank credentials or financial-account access tokens.
Haven does not receive or store a user’s online-banking username or password. Those credentials are entered directly into Plaid Link or the financial institution’s own sign-in experience.
3. How Haven uses information
- Review early-access applications, select private-beta participants, and communicate about application or invitation status.
- Provide budgeting, account-viewing, bill, savings-goal, and financial-planning features.
- Retrieve and display financial data a user has authorized through Plaid.
- Authenticate users, protect accounts, prevent misuse, and maintain service security.
- Send requested service communications, including account verification, password-reset, sign-in verification, and opted-in notifications.
- Respond to user questions through Haven Coach when that feature is used.
- Maintain, troubleshoot, and improve Haven.
Haven does not sell consumer financial information or use it for advertising based on a user’s financial activity.
4. How information is shared
Haven shares information only as needed to operate the service: with Plaid when a user connects a financial institution; cloud infrastructure and database providers that host Haven; transactional-email and push-notification providers; and the AI service used for Haven Coach when a user submits a Coach question. Haven may also disclose information when required by law, to protect Haven or its users, or as part of a business transfer if one occurs.
5. Data security
Haven uses reasonable administrative, technical, and organizational safeguards designed to protect information. These include HTTPS/TLS for data in transit, managed cloud storage protections, server-side access controls, multi-factor authentication for Haven production sign-in, and encryption of stored Plaid access tokens. No online service can guarantee absolute security.
6. Data retention and deletion
Haven retains information while an account is active and as needed to provide the service, meet legal obligations, resolve disputes, and enforce agreements. Early-access applications are retained for no longer than 12 months after their last update unless the applicant becomes a Haven member or asks Haven to delete the application sooner. Users can disconnect a financial institution from Haven to stop future retrieval from that connection. Users can also use Haven’s account-deletion control to request deletion of their Haven account and associated application data, subject to information Haven must retain for legal, security, or fraud-prevention purposes.
7. User choices and rights
Depending on where a user lives, they may have rights to access, correct, delete, or receive a copy of their personal information, or to limit certain processing. Users can update much of their budgeting information directly in Haven. For privacy questions or requests, contact Haven using the privacy contact method made available with the user’s Haven account.
8. Children’s privacy
Haven is not directed to children under 13 and does not knowingly collect personal information from children under 13.
9. Changes to this policy
Haven may update this Privacy Policy as its service or legal obligations change. The current version will be posted on this page with its updated date.
10. Plaid
Users who connect a financial institution through Plaid should also review the Plaid Privacy Policy. Plaid may process information as described in its own policy and in the consent screens shown during Plaid Link.
11. Contact
For questions about this Privacy Policy or a privacy request, email [email protected].
This policy describes Haven’s current practices and is not legal advice. Haven should obtain advice from a qualified privacy attorney before broad public launch or when legal requirements materially change.