Legal
Privacy Policy
Last updated 17 August 2026
This policy explains what Springrock Ventures LLC (“Springrock”, “we”, “us”) collects when you use springrock.ai or our products — Finvo, Statify and The Dolla Bin — why we collect it, and what you can do about it. Springrock Ventures LLC is the data controller.
This website
springrock.ai is a static informational site. It sets no cookies, runs no JavaScript, and carries no analytics or advertising trackers. Our web server keeps standard access logs — IP address, timestamp, requested page, referrer and user agent — for security and troubleshooting, and deletes them on a rolling basis.
What we collect in the products
Account information
An email address, and a name where you provide one. Depending on the product, you may sign in with a password, a magic link sent to your email, or a third-party account such as Google or GitHub. When you sign in with a third party, we receive your email address and basic profile information — never your password with that provider.
Content you create
Whatever you put into the product: in Finvo, your invoices, clients, expenses, templates and reports; in The Dolla Bin, your listings, images, offers, messages, crates and wants lists; in Statify, the metrics synced from the accounts you connect.
Data from accounts you connect (Statify)
Statify only connects to a third-party service when you explicitly authorise it, using that provider's official authorisation flow. Depending on what you connect, that can include activity and repository statistics, listening history, fitness and health metrics such as sleep, recovery and weight, and business metrics such as revenue, orders and traffic. Access tokens are stored encrypted. You can disconnect any integration at any time from your settings, which stops further syncing.
Health and financial data is sensitive. We use it only to display your own statistics back to you and to produce the reports you have asked for. We do not sell it, and we do not use it for advertising.
Payment information
Subscription payments are processed by Stripe, Inc. Card details go directly to Stripe and we never see or store them. We retain a customer and subscription identifier, your plan, and billing status so we know what you are entitled to.
Technical and usage data
Server logs, error reports and basic usage events, used to keep the products running, diagnose faults and prevent abuse.
Why we process it
- To provide the service you signed up for — performance of our contract with you.
- To take payment and manage subscriptions — contract and legal obligation.
- To communicate with you about your account, security and material changes — contract and legitimate interests.
- To keep the service secure and working, including fraud and abuse prevention — legitimate interests.
- To meet legal and tax obligations.
- With your consent, for anything else — for example connecting an integration, or receiving optional product email. You can withdraw consent at any time.
We do not sell your data
Springrock does not sell or rent personal information, and does not share it for cross-context behavioural advertising.
Who else processes your data
We share data only with service providers that help us run the products, under contracts limiting them to that purpose:
| Provider | Purpose |
|---|---|
| Stripe, Inc. | Subscription payments and billing; marketplace payments and seller payouts on The Dolla Bin |
| Resend | Transactional email — receipts, magic links, notifications |
| Cloudflare R2 / object storage | Storage of uploaded files and images |
| OVH | Hosting of the servers we operate |
| Services you connect (Statify) | Only those you authorise yourself |
We may also disclose information if legally required, or to protect our rights, users or the security of the service. If our business is ever transferred, personal data may transfer with it and we will tell you first.
Where your data lives
Our application servers and databases run on dedicated hardware that we operate ourselves in a data centre in Portland, Oregon, United States. Our processors, including Stripe, are also principally located in the United States.
If you are in the EEA or the UK, this means your personal data is transferred to and processed in the United States. We rely on the European Commission's Standard Contractual Clauses, and the equivalent UK addendum, as the safeguard for those transfers, together with the technical measures described under Security below.
Security
Traffic is encrypted in transit with TLS. Databases sit on a private network with no direct route from the internet. Third-party access tokens are encrypted at rest, passwords are stored hashed, access to production systems is restricted, and we take regular encrypted backups. No system is perfectly secure, but we treat it as our job to keep yours safe, and we will notify you and any relevant regulator promptly if a breach affects your data.
How long we keep it
We keep your account data while your account is open. If you delete your account, we delete or anonymise your personal data within 30 days, except records we must keep for legal, tax or accounting reasons — typically invoice and payment records for up to seven years. Backups age out on their own retention schedule.
Your rights
Wherever you live, you can ask us to:
- access the personal data we hold about you, or receive a copy of it;
- correct anything that is wrong;
- delete your account and its data;
- export your content in a portable format;
- restrict or object to certain processing, or withdraw consent;
- opt out of non-essential email — every marketing message has an unsubscribe link, and we will still send essential account and billing notices.
If you are in the EEA or UK, these rights arise under the GDPR, and you may complain to your local supervisory authority. If you are a California resident, the CCPA/CPRA gives you rights to know, delete, correct and opt out of sale or sharing — we do not sell or share your data — and we will not discriminate against you for exercising them.
To exercise any of this, email support@springrock.ai from the address on your account. We respond within 30 days.
Children
Our products are not intended for anyone under 18, and we do not knowingly collect their personal data. If you believe a child has given us information, contact us and we will delete it.
Changes to this policy
We may update this policy. The date at the top always reflects the current version, and we will notify account holders by email before a material change takes effect.
Contact
Springrock Ventures LLC
2108 North Street, Ste N, Sacramento, CA 95816, USA
support@springrock.ai