Privacy Policy

Effective date: February 22, 2026

At Maverick Finance ("we", "us", "our"), your privacy is fundamental to how we build and operate Maverick. This Privacy Policy explains what data we collect, how we use it, and how we protect it.

Information We Collect

We collect the minimum data necessary to provide the Service:

  • Account information — Email address and password (stored as a bcrypt hash; we never store your plaintext password)
  • Financial data — Budgets, categories, transactions, and other data you enter into the Service
  • Usage data — Session information and IP addresses, collected solely for security and abuse prevention

We do not collect data from third-party sources. All data in your account is provided directly by you.

How We Use Your Data

We use your data exclusively to:

  • Provide the Service — Store and display your budgets, transactions, and financial data
  • Send transactional emails — Account verification, password resets, and billing notifications
  • Maintain security — Monitor for unauthorized access, abuse, and security threats

What We Do NOT Do

We believe your financial data is deeply personal. We commit to the following:

  • We do not sell your data — Not to advertisers, data brokers, or anyone else
  • We do not share your data with third parties — Your data stays within Maverick
  • We do not serve behavioral advertising — There are no ads in Maverick
  • We do not use third-party tracking — No Google Analytics, no Facebook Pixel, no tracking scripts

Analytics

We use a self-hosted instance of Plausible Analytics on our marketing website. Plausible is privacy-focused by design:

  • No cookies are used
  • No personal data is collected
  • No cross-site or cross-device tracking
  • All data is aggregated and anonymous
  • Fully GDPR, CCPA, and PECR compliant

Plausible is not used within the Maverick application itself.

Cookies

Maverick uses a single session cookie for authentication:

  • Name: session_id
  • Purpose: Maintains your login session
  • Duration: Persistent until you log out
  • Type: Essential (required for the Service to function)

We do not use tracking cookies, advertising cookies, or any third-party cookies. For more details, see our Cookie Policy.

Data Storage

Your data is stored on self-hosted infrastructure that we operate and control:

  • Database: PostgreSQL with encryption at rest
  • Hosting: Self-managed servers (not shared cloud platforms)
  • Location: United States

We do not use third-party cloud databases or storage services for your personal data.

Data Retention

  • Active accounts — Your data is retained for as long as your account is active
  • Deleted accounts — Upon account deletion, your data is retained for 30 days (grace period), after which it is permanently and irreversibly deleted
  • Security logs — Session and access logs are retained for 90 days for security purposes

Data Portability

You can export all of your data at any time in JSON or CSV format directly from the Maverick application. We believe you should always be able to take your data with you.

Security

We implement the following measures to protect your data:

  • HTTPS everywhere — All data in transit is encrypted via TLS
  • Password hashing — Passwords are hashed with bcrypt
  • Rate limiting — Protection against brute-force and abuse
  • Audit logging — Security-relevant actions are logged for monitoring
  • Tenant isolation — Strict data separation between user accounts

If you discover a security vulnerability, please report it to [email protected].

Children's Privacy

Maverick is not intended for children under the age of 13. We do not knowingly collect personal information from children. If you believe a child under 13 has created an account, please contact us at [email protected] and we will promptly delete the account.

Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will provide at least 30 days' notice via email or a prominent notice within the Service. The effective date at the top of this page indicates when the policy was last updated.

Contact

If you have questions about this Privacy Policy or how we handle your data, contact us at [email protected].