Privacy Policy
We value your privacy and are committed to protecting your data.
Last updated: July 7, 2026
"Your financial data is yours, not ours. We simply provide the secure connection between your bank and your tools."
Penny's privacy shortcut
Our Privacy Promise
BankSync acts as a secure proxy between your financial institutions and the tools you use. We do not persistently store full banking datasets unless needed for a feature you enable, such as BankSync Tables or another managed destination, or for support, security, compliance, backups, or legal requirements. Your data is retrieved through financial data providers and delivered to the destinations you choose, such as Google Sheets™, Notion, Airtable, Excel, APIs, webhooks, or future destinations.
How We Work
BankSync uses secure integrations with regulated open banking providers to connect to your financial institutions, depending on your region. When you use our service:
Secure Authentication
Your bank login credentials are handled by your financial institution or the relevant open banking provider, not stored by BankSync
Zero Credential Storage
We never see, store, or have access to your banking passwords
Data Flow, Not Storage
Your transaction data is processed transiently unless storage is needed for a feature you enable, support, security, compliance, or legal requirements
Direct Delivery
The data is securely sent to your chosen destination, such as Google Sheets, Notion, Airtable, Excel, an API, or a webhook
Data We Collect
While we do not persistently store full banking datasets by default, we do collect and store:
Your name, email, and contact details
Your payment history and subscription plan
Information about which services you've connected to
Aggregated or de-identified usage, reliability, security, and product metrics
Data you choose to store in BankSync-managed features, including future BankSync Tables or similar hosted destinations
This information is stored securely and used to provide, support, secure, maintain, analyse, and improve our service.
Data Sharing and Transfers
We do not sell your personal data or banking data, and we do not share identifiable banking data for third-party advertising, data brokerage, or another party's independent commercial exploitation. We disclose data only in the following limited circumstances:
Service Providers
We share data only with trusted service providers who help us operate our service or with providers and destinations you authorise:
For BankSync-appointed service providers and subprocessors, we seek written confidentiality, security, no-training, data-use, and incident-notification obligations. Independent providers, customer-selected destinations, and providers acting under their own terms or legal obligations control their own privacy and security practices.
- •Plaid Technologies, Inc.: For US and Canadian bank connections (we do not receive or store your bank login credentials)
- •Salt Edge Limited (FCA FRN 822499): For UK Open Banking connections under FCA authorisation
- •Fiskil Pty Ltd (CDR Registration ADRBNK000246): For Australian CDR connections
- •SnapTrade: For US and Canadian investment portfolio data
- •Google LLC: For Google Sheets™ integration (only when you explicitly connect your Google account)
- •Notion Labs, Inc.: For Notion integration (only when you explicitly connect your Notion account)
- •Airtable, Inc.: For Airtable integration (only when you explicitly connect your Airtable account)
- •Stripe, Inc.: For payment processing (we do not store payment card details)
Customer Destinations
When you connect or select any current or future third-party app, workspace, spreadsheet, database, storage location, AI tool, API, webhook, export, email address, or similar destination, including Google Sheets, Google Drive, Notion, Airtable, Microsoft Excel, Microsoft 365, and Slack, you instruct us to deliver data to that destination. After delivery, that destination is controlled by your account, settings, users, permissions, sharing links, automations, retention choices, AI settings, model-training settings, and the destination provider's own terms and privacy practices.
BankSync-Managed Destinations
BankSync-managed destinations, including any future BankSync Tables feature, are protected as part of BankSync-controlled systems while the data remains there. You control what you store, which users you invite, what permissions you grant, which API keys or automations you enable, and where data is exported or synced next.
Independent Third-Party Providers
Banks, brokerages, data holders, open banking providers, financial data aggregators, Plaid, Fiskil, Salt Edge, SnapTrade, destination providers, identity providers, app marketplaces, AI providers, and infrastructure providers may process data under their own terms, legal obligations, account relationships, and security controls. Their independent processing, outages, compromises, retention, deletion, product-improvement settings, AI use, model-training settings, sale, or sharing are not controlled by BankSync except where they process data solely on our behalf under our written instructions.
Legal Requirements
We may disclose your data if required by law, court order, or to protect our rights and the safety of our users.
Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of the business transaction.
Important: Within systems BankSync controls, we do not sell your banking data, use it for advertising or data brokerage, or use customer banking data to train artificial-intelligence or machine-learning models. Customer-selected destinations and independent providers may have their own terms, privacy settings, AI settings, training settings, security obligations, and legal obligations, and their independent acts or incidents sit outside the BankSync Boundary.
Data Protection Mechanisms
We implement comprehensive security measures to protect your sensitive data:
All data is encrypted using TLS 1.3 during transmission
All stored data is encrypted using AES-256 encryption
Strict role-based access controls and multi-factor authentication
Regular security audits and penetration testing
Banking Data Protection: Banking data is processed through secure, transient systems and delivered to your chosen destination. We retain it only where needed for a feature you enable, support, security, compliance, or legal requirements.
Your Choices
You have control over your data:
Bank disconnection: You can disconnect your bank accounts at any time
Account deletion: You can delete your BankSync account and all associated data
Data requests: You can request a copy of the data we hold about you
To exercise these options, please visit your account settings or contact our support team.
Contact Us
If you have any questions about our privacy policy or how we handle your data, please contact us:
Open Banking & Regulatory Disclosures
BankSync operates under multiple regulated open banking frameworks depending on your region. We partner with licensed providers; we do not hold banking licences or data-access accreditations directly.
United States & Canada: Connections facilitated through Plaid Technologies, Inc. (CFPB-registered data aggregator).
United Kingdom: Connections facilitated through Salt Edge Limited, a Registered Account Information Service Provider authorised by the Financial Conduct Authority (FCA FRN 822499). BankSync does not hold its own FCA authorisation.
Australia: CDR connections are facilitated through Fiskil Pty Ltd (CDR Registration ADRBNK000246). BankSync operates as a CDR Representative of Fiskil under CDR Rule 1.10AA. BankSync does not hold its own CDR accreditation.
For full regulatory disclosures, see our Compliance page.
Last updated: July 7, 2026
BankSync is a trading name of Flagbase Pty Ltd (ABN 49 686 408 668), serving customers globally.