Legal

Privacy Policy

Effective August 2026

Short version: we collect the minimum we need to move your pay early, we don't sell your data, and we keep sensitive info encrypted.

What we collect

From you: your name, date of birth, address, last 4 of SSN, and phone or email — for identity verification and account security. From Plaid: your bank account routing / masked number, balance, and transaction history — to detect your payday and prevent overdrafts. From Stripe: your debit card details for instant transfers and the membership charge. From your device: only what iOS or Android exposes to any app — locale, OS version, device model. We do not access your contacts, photos (unless you attach one during KYC), or location.

What we do with it

Identity data → identity verification (via Persona or Plaid IDV). Bank data → payday detection, advance limits, and money movement. Card data → membership billing and per-transfer fees. All of it → complying with Missouri EWA law and federal regulations (ECOA, BSA/AML).

What we never do

We don't sell your data. We don't share it with advertising networks. We don't report to credit bureaus. We don't use your data to train models beyond what runs our own risk decisions.

Third parties who see your data

Only the companies we need to run the product: Supabase (our database + auth), Plaid (bank connection), Stripe (card + subscription billing), Persona (identity verification), Twilio (text messages), Expo (push notifications), and Sentry (error reporting; PII stripped). Each has their own terms; we've vetted them for a fintech workload.

How long we keep it

As long as you're a customer plus the minimum retention required by law: transaction records for at least 5 years, BSA/AML records for at least 5 years after account close, and risk-decision records under ECOA for at least 25 months after each decision.

How we protect it

All data in transit is TLS 1.2+. Sensitive fields at rest (access tokens, PII) are encrypted with a per-installation key. Access to production data is limited to the small number of engineers who need it and is logged. Card details never touch our servers — Stripe handles them.

Your rights

You can view your data (request via help@wagevine.com), correct it in the app, or ask us to delete it — subject to the retention requirements above. You can turn off any notification category from Account → Reminders. You can cancel your membership or close your account in one tap.

Children

Wagevine is not for anyone under 18. If we learn we have data on a minor, we'll delete it.

Changes

If we change this policy in a material way, we'll notify you in the app before the change takes effect. Non-material edits — typos, clarifications — happen without notice.

Contact

Privacy questions: privacy@wagevine.com. Everything else: help@wagevine.com or (417) 555-0142.