Privacy Policy

1. Introduction

DataChimp Labs (“DataChimp Labs,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you use our applications, websites, and related services (collectively, the “Services”).

This Policy applies to end users of DataChimp Labs applications. Individual applications may publish an application-specific privacy addendum that supplements this Policy with additional detail about that application’s data flows. In the event of a conflict, the application-specific addendum controls for that application.

Certain DataChimp Labs applications integrate with Plaid Inc. (“Plaid”) to enable users to connect their financial accounts. Sections 2.3, 4, and 10 describe the Plaid integration in additional detail.

2. Information We Collect

2.1 Information You Provide Directly

When you create an account or use the Services, you may provide us with:

  • Account information (name, email address, password credentials).
  • Profile information (mailing address, phone number, date of birth where required by law, employer or occupation where relevant to the Service).
  • Communications you send us (support requests, feedback, survey responses).
  • Payment and billing information, where applicable — processed through a PCI-DSS compliant payment processor; we do not store full payment card numbers.

2.2 Information Collected Automatically

When you interact with the Services, we automatically collect certain information, including:

  • Device information (operating system, browser type and version, device identifiers, screen resolution).
  • Network information (IP address, general geographic location derived from IP, mobile network carrier).
  • Usage information (pages viewed, features used, time and duration of sessions, referring URLs, click events).
  • Cookies, pixels, local storage, and similar technologies — see Section 11 — Cookies & Tracking.

2.3 Financial Account Information via Plaid

Where a DataChimp Labs application offers you the ability to connect a financial account, we use Plaid Inc. to securely retrieve information about your financial accounts. The connection is initiated through the Plaid Link consent interface, which is presented to you in-app.

When you connect an account through Plaid Link, you authorize your financial institution to share the following categories of information with us via Plaid’s API:

  • Account identifiers — account numbers (typically masked), routing numbers where necessary for the feature, and internal Plaid identifiers.
  • Account balances — current and available balances.
  • Transaction history — transaction dates, amounts, descriptions, merchant names, and categorization metadata.
  • Account holder information — name, email, phone number, and address as held by the financial institution on the connected account.
  • Institution information — the name and identifiers of the financial institution the account is held with.

The specific data categories retrieved depend on the features you enable and the permissions you grant on the Plaid Link consent screen. You can revoke access to any connected account at any time — see Section 7 — Your Rights.

Plaid’s own privacy policy. Plaid acts as our service provider for the Plaid Link connection. Plaid’s collection and use of your information is also governed by Plaid’s End User Privacy Policy, available at https://plaid.com/legal/#end-user-privacy-policy. We recommend that you review Plaid’s policy in addition to this Policy.

3. How We Use Information

We use the information described above for the following purposes:

  • Service delivery — to provide, personalize, and improve the Services, including displaying your financial data, calculating derived metrics, and delivering the features you have requested.
  • Account management — to create and manage your account, authenticate you, and communicate with you about the Services.
  • Security and fraud prevention — to detect, investigate, and prevent unauthorized access, account takeover, fraudulent transactions, and abuse.
  • Compliance and legal obligations — to comply with applicable law, respond to lawful requests, enforce our terms, and protect the rights, property, or safety of DataChimp Labs, our users, and others.
  • Product improvement and analytics — to understand how the Services are used and improve them, using aggregated or de-identified data where possible.
  • Communications — to send you transactional messages (required for service delivery) and, with your consent where required, marketing communications you can opt out of at any time.

Where we rely on consent as a legal basis (for example, for optional analytics or marketing), you may withdraw consent at any time without affecting the lawfulness of prior processing.

4. How We Share Information

We do not sell your personal information. We disclose personal information only in the following circumstances:

  • Service providers. We share information with vendors that process data on our behalf under written contracts that require appropriate confidentiality and security, and that restrict use to the purposes we specify. Categories include:
    • Plaid Inc. — connecting your financial accounts via Plaid Link.
    • Amazon Web Services (AWS) — cloud infrastructure hosting.
    • Communications providers — transactional email and messaging.
    • Monitoring and analytics providers — application performance monitoring and product analytics.
    • Support tools — helpdesk and customer communication platforms.
  • Legal and regulatory disclosures. We may disclose information when required by law, subpoena, court order, or other valid legal process, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others, to investigate fraud, or to respond to a government request.
  • Business transactions. If DataChimp Labs is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to standard confidentiality protections and notice to affected users where required.
  • With your consent or at your direction. We share information with third parties when you direct us to (for example, connecting a third-party integration).

No sale of personal data. DataChimp Labs does not sell personal information as “sale” is defined under the California Consumer Privacy Act (CCPA) as amended by the CPRA, nor do we share personal information for cross-context behavioral advertising as those terms are defined under California law.

5. Data Retention

We retain personal information only as long as necessary for the purposes for which it was collected, or as required by applicable law, whichever is longer:

Category Retention
Account & profile information For the life of your account plus a reasonable period thereafter for legal and audit purposes.
Financial account information (Plaid) Retained while the account connection is active; deleted or de-identified after disconnection, subject to statutory retention (e.g., anti-money-laundering, tax, audit).
Transaction history Retained per the feature enabled and applicable regulatory minimums.
Usage and analytics data Retained in identifiable form for a limited period, then aggregated or de-identified.
Communications & support records Retained as long as necessary to service your account and for legal compliance.
Backups Rotated on a defined schedule; deletion requests are honored on active systems and applied to backups on next rotation.

When retention periods end, we delete or de-identify the information in a secure manner.

6. Data Security

DataChimp Labs implements administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. These safeguards are described in the DataChimp Labs Information Security Policy and include:

  • Encryption in transit (TLS 1.2+) and at rest (AWS KMS-managed keys).
  • Role-based access control with least-privilege enforcement and MFA on administrative access.
  • Continuous monitoring, centralized logging, and alerting.
  • Secure software development lifecycle (code review, SAST, SCA, secret scanning, container scanning).
  • Regular vulnerability assessments and remediation with defined SLAs.
  • Personnel training and background screening where legally permissible.

No security program can guarantee absolute security. We work to continuously improve our program and address emerging threats.

7. Your Rights

Depending on where you reside, you may have some or all of the following rights regarding your personal information:

7.1 GDPR / UK GDPR Rights (EEA, UK, Switzerland)

  • Right of access — to obtain a copy of the personal data we hold about you.
  • Right to rectification — to correct inaccurate or incomplete data.
  • Right to erasure (“right to be forgotten”) — to have your personal data deleted, subject to legal retention obligations.
  • Right to restriction of processing — to limit how we process your data in certain circumstances.
  • Right to data portability — to receive your data in a machine-readable format and transmit it to another controller.
  • Right to object — to object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent — where processing is based on consent.
  • Right to lodge a complaint — with your local data protection supervisory authority.

7.2 CCPA / CPRA Rights (California)

  • Right to know what personal information we collect, use, disclose, and (if applicable) sell or share.
  • Right to delete personal information we have collected, subject to legal exceptions.
  • Right to correct inaccurate personal information.
  • Right to opt out of sale or sharing of personal information — DataChimp Labs does not sell or share personal information as defined under California law.
  • Right to limit use and disclosure of sensitive personal information.
  • Right to non-discrimination for exercising your rights.

7.3 HIPAA Rights (where PHI applies)

Where DataChimp Labs handles Protected Health Information (“PHI”) on behalf of a covered entity, DataChimp Labs acts as a Business Associate. Individual rights with respect to PHI (access, amendment, accounting of disclosures, restrictions) are exercised through the covered entity that provided the PHI. DataChimp Labs will support the covered entity in fulfilling those rights as required by the applicable Business Associate Agreement and 45 CFR Part 164.

7.4 Other Jurisdictions

Users in other jurisdictions may have additional or analogous rights under local law. Where applicable, we will honor those rights.

7.5 How to Exercise Your Rights

To exercise any of these rights, contact us at privacy@datachimplabs.com or use any in-application “manage my data” controls provided. We will verify your identity before acting on a request. We will respond within the time frame required by applicable law (generally 30 days under GDPR, extendable by 60 days for complex requests; 45 days under CCPA, extendable by 45 days).

You will not be discriminated against for exercising a privacy right.

To disconnect a financial account connected via Plaid Link at any time, use the in-application “connected accounts” controls or contact support. Disconnection stops future data retrieval; historical data is retained under the retention schedule in Section 5 unless you also request deletion.

8. International Data Transfers

DataChimp Labs is based in the United States, and personal information may be processed in the United States and other countries where we or our service providers operate. These countries may have data protection laws that differ from those in your country of residence.

When we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on lawful transfer mechanisms including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, together with any supplementary measures required by applicable guidance.
  • Adequacy decisions where the European Commission has determined the destination country provides an adequate level of protection.
  • UK International Data Transfer Agreement / Addendum for transfers from the United Kingdom.

Copies of the transfer safeguards are available on request to privacy@datachimplabs.com.

9. Children’s Privacy

The Services are not directed to children. We do not knowingly collect personal information from children under 13 years of age (or under 16 in jurisdictions where local law sets a higher age of digital consent) without verifiable parental consent. If we learn that we have collected personal information from a child without the required consent, we will delete it promptly. Parents or guardians who believe their child has provided us with personal information should contact privacy@datachimplabs.com.

The Services may contain links to, or integrate with, third-party websites and services. This Policy does not apply to those third parties. Their handling of your information is governed by their own privacy policies.

Plaid in particular is a third-party service provider that we use to connect financial accounts. When you use Plaid Link within a DataChimp Labs application, you are also subject to Plaid’s End User Privacy Policy at https://plaid.com/legal/#end-user-privacy-policy. We encourage you to review it.

11. Cookies & Tracking

We and our service providers use cookies, local storage, pixels, and similar technologies to:

  • Keep you signed in and remember your preferences (strictly necessary and functional).
  • Understand how the Services are used and improve them (analytics).
  • Diagnose errors and secure the Services (security).

We do not use cookies for cross-context behavioral advertising. Where required by law, we present a cookie banner allowing you to accept or reject non-essential cookies. You can also manage cookies through your browser settings; note that disabling strictly necessary cookies may prevent the Services from functioning.

12. Changes to This Policy

We may update this Policy from time to time. When we do, we will revise the version and effective_date in the front-matter above and, for material changes, provide notice through the Services or by email. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.

13. Contact Us

If you have questions or concerns about this Policy or our privacy practices, or wish to exercise a privacy right, contact us at:

If you are in the EEA or UK, you may also contact our Data Protection Officer at the email above.

14. Jurisdiction-Specific Disclosures

14.1 European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR)

  • Controller. For the DataChimp Labs Services, DataChimp Labs is the controller of personal data described in this Policy. Where DataChimp Labs processes personal data on behalf of a business customer under a written agreement, DataChimp Labs acts as a processor and that customer is the controller.
  • Legal bases. We process personal data under one or more of the following legal bases: performance of a contract (delivering the Services), legitimate interests (securing the Services, preventing fraud, improving the Services), consent (where required, including for certain cookies and marketing), and compliance with legal obligations.
  • Automated decision-making. We do not make decisions producing legal or similarly significant effects concerning you based solely on automated processing without a lawful basis and appropriate safeguards.
  • Supervisory authority. You have the right to lodge a complaint with your local supervisory authority.

14.2 California (CCPA / CPRA)

  • Categories of personal information collected in the past 12 months: identifiers; commercial information; internet/electronic activity; geolocation (approximate); professional or employment-related information (where provided); financial information (via Plaid where you have connected an account); inferences drawn from the above.
  • Sources: directly from you; automatically from your device; from service providers including Plaid; from third parties you direct to share information with us.
  • Purposes: the purposes described in Section 3.
  • Disclosure for a business purpose: to the categories of service providers described in Section 4, under contractual restrictions.
  • Sale/Share: we do not sell personal information or share it for cross-context behavioral advertising.
  • Sensitive personal information: we only use sensitive personal information (which may include financial account information) for the business purposes permitted by CPRA § 1798.121; we do not use it to infer characteristics about you beyond providing the Service you requested.
  • Retention: as described in Section 5.
  • Authorized agents. You may designate an authorized agent to make a request on your behalf; we will verify the agent’s authorization and your identity before acting.

14.3 Other US States

Where applicable, we honor rights granted under state privacy laws including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and other state privacy laws as they come into effect. Requests may be submitted through the channels described in Section 7.5.


This Privacy Policy is a corporate baseline for DataChimp Labs applications. Application-specific addenda published alongside individual products may add product-specific disclosures.


Copyright © 2026 DataChimp Labs. Public Trust Center.