Last Updated and Effective Date: July 7, 2025
This Privacy Policy (the "Policy") describes the privacy practices of CashmApp: Finance GPS and its affiliates and subsidiaries (collectively, "CashmApp," "we," "our," or "us"). This Policy applies to the CashmApp mobile application (the "App"), our websites, APIs, and any other related services (collectively, the "Services"). By accessing or using our Services, you expressly consent to our collection, storage, use, and disclosure of your personal information as described in this Policy.
We take the protection of your personal data very seriously. This Policy has been drafted to comply with applicable data protection laws, including but not limited to the General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the United Kingdom General Data Protection Regulation ("UK GDPR"), the California Consumer Privacy Act of 2018 ("CCPA") as amended by the California Privacy Rights Act of 2020 ("CPRA"), the Personal Information Protection and Electronic Documents Act ("PIPEDA"), and other applicable federal, state, and international data protection and privacy statutes.
"Personal Data" or "Personal Information" means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
"Processing" means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
"Data Controller" means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data. For the purposes of this Policy, CashmApp is the Data Controller.
We may collect, use, store, and transfer different kinds of Personal Data about you which we have grouped together as follows:
We use different methods to collect data from and about you, including through:
Direct interactions: You may give us your Identity, Contact, and Financial Data by filling in forms or by corresponding with us by post, phone, email, or otherwise. This includes Personal Data you provide when you create an account, subscribe to our premium services, interact with the AI financial coach, or request support.
Automated technologies or interactions: As you interact with our App, we may automatically collect Technical and Usage Data about your equipment, browsing actions, and patterns. We collect this Personal Data by using cookies, server logs, mobile analytics SDKs, and other similar technologies.
Third parties or publicly available sources: We may receive Personal Data about you from various third parties, such as authentication providers (Google, Apple, Firebase) and analytics providers (Firebase Crashlytics).
Under the GDPR and UK GDPR, we must have a lawful basis to process your Personal Data. We rely on the following bases:
We will only use your Personal Data when the law allows us to. Most commonly, we will use your Personal Data in the following circumstances:
CashmApp integrates third-party Artificial Intelligence capabilities provided by Google Gemini AI (Google LLC / Google Cloud Platform) to deliver personalized financial guidance, automated budget calculations, and smart route suggestions (the "Ollie AI Feature").
In compliance with Apple App Store Review Guidelines 5.1.1(i) and 5.1.2(i):
We may share your Personal Data with the parties set out below for the purposes described in this Policy:
We require all third parties to respect the security of your Personal Data and to treat it in accordance with the law. We do not allow our third-party service providers to use your Personal Data for their own purposes.
Your information, including Personal Data, may be transferred to — and maintained on — computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction. If you are located in the European Economic Area (EEA) or the UK, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented: (a) transferring to countries deemed to provide an adequate level of protection; or (b) utilizing specific contracts approved by the European Commission (Standard Contractual Clauses).
We have put in place appropriate, industry-standard security measures to prevent your Personal Data from being accidentally lost, used, or accessed in an unauthorized way, altered, or disclosed. This includes the use of encryption (such as TLS for data in transit and AES-256 for data at rest), secure Keychain/SharedPreferences storage on the device, and secure cloud infrastructure. In addition, we limit access to your Personal Data to those employees, agents, contractors, and other third parties who have a business need to know. They will only process your Personal Data on our instructions, and they are subject to a duty of confidentiality. We have put in place procedures to deal with any suspected Personal Data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
We will only retain your Personal Data for as long as reasonably necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements. We may retain your Personal Data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you. When you delete your account, your data is permanently expunged from our active production databases within thirty (30) days, subject to residual copies on encrypted backups which are overwritten in the ordinary course of business.
Depending on your location and applicable law (e.g., GDPR, CCPA/CPRA), you may have the following rights under data protection laws in relation to your Personal Data:
To exercise any of the rights set out above, please contact us. You will not have to pay a fee to access your Personal Data; however, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.
If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with specific rights regarding your Personal Information. You have the right to request that we disclose certain information to you about our collection and use of your Personal Information over the past 12 months. You have the right to request the deletion of your Personal Information. We do not and will not sell your Personal Information. We do not share your Personal Information for cross-context behavioral advertising. We will not discriminate against you for exercising any of your CCPA rights.
Our Services are not intended for use by children under the age of 13 (or under 16 in certain jurisdictions in the EEA). We do not knowingly collect, solicit, or maintain Personal Data from anyone under the age of 13 or knowingly allow such persons to register for our Services. If you are under 13, please do not send any Personal Data about yourself to us. In the event that we learn that we have collected Personal Data from a child under age 13 without verification of parental consent, we will delete that information as quickly as possible.
We keep our Privacy Policy under regular review. We reserve the right to modify this Policy at any time, so please review it frequently. Changes and clarifications will take effect immediately upon their posting on the website or within the App. If we make material changes to this Policy, we will notify you here, by email, or by means of a notice on our homepage, so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we use and/or disclose it.
If you have any questions about this Privacy Policy or our privacy practices, please contact our Data Protection Officer (DPO) in the following ways:
Contact: CashmApp Support Team