Privacy
What this application holds
This notice explains what Augustine Equity collects, why, who else sees it, how it is protected, how long it is kept, and the rights you have over it. Each section leads with a plain-language summary and then gives the detail — nothing is hidden behind a click.
The short version: your data is used to run the Service and nothing else. It is not sold, not shared for advertising, and not used to train any model.
- Last updated
- 9 August 2026
- Effective
- 9 August 2026
- Provider
- Augustine Realty Company, Greensboro, North Carolina, USA
Who we are and what this notice covers
In short: Augustine Realty Company is the controller of the data described here.
Augustine Equity is operated by Augustine Realty Company, Greensboro, North Carolina, USA (“Augustine,” “we,” “us”), which is the controller of the personal information described in this notice.
This notice covers the Augustine Equity application, website and related services. It does not cover the practices of the third parties the Service connects to — your bank, Plaid, Google, Stripe — each of which has its own privacy policy. This notice forms part of our Terms of Service.
Privacy questions, requests and complaints go to augustinerealtycompany@gmail.com.
What we collect
In short: Account details, what you enter, documents you upload, and — only if you connect one — bank data through Plaid.
Your account. Name, email address, a bcrypt hash of your password if you set one, your role, and your household membership. If you sign in with Google we receive your name, email address and profile image from Google — never your Google password.
What you enter. Properties, valuations, loans, assets, budgets, goals, contacts, reminders and notes you record, and documents you upload.
Bank data, through Plaid. When you connect an institution, we use Plaid to retrieve account names, types, the last four digits of account numbers, balances, and transaction history — date, amount, description, merchant and category. You enter your bank credentials on Plaid’s screen, at your own bank. We never see them, and we never store them. The connection is read-only: we request only Plaid’s transactions product and not the products that would let us initiate a payment or transfer, so this application cannot move money.
Mailbox data, only if you enable it. If you connect a mailbox for email triage, we access only the messages needed for that feature and only while the connection is active.
Technical and security data. Server and security logs containing IP address, timestamps, user agent, and the actions taken in the application — used to keep the Service running and to investigate abuse.
Payment data. Paid plans are billed through Stripe, which holds your card details. We receive only the subscription status and the last four digits and brand of the card — never the full number.
Why we collect it, and the legal bases
In short: To run the Service you asked for. Never for advertising, resale or model training.
We use this information to compute one thing — everything owned, everything owed and the difference — to keep a dated history of that figure, to provide the documents, reminders, triage and assistant features, to bill paid plans, to secure the Service and investigate abuse, to support you, and to comply with law.
Your data is not sold, not rented, not shared for advertising or cross-context behavioural advertising, and not used to train any machine-learning model, ours or a third party’s. There is no advertising tracker and no third-party analytics script in this application.
Where the GDPR or UK GDPR applies, our legal bases are: contract (providing the Service you signed up for), consent (bank and mailbox connections, which you can withdraw at any time), legal obligation (tax and accounting records), and legitimate interests (securing the Service, preventing fraud and abuse, and improving reliability) — balanced against your rights.
Consent, and how to withdraw it
In short: Bank data is retrieved only after you tick the box, and stops the moment you revoke.
Bank data is only ever retrieved after you tick the consent box on the connect screen and complete Plaid’s own authorisation.
You can withdraw that consent at any time with the Forget control on the connections list. That deletes the stored access token immediately and stops all further retrieval. To also remove the balances and transaction history already retrieved, email us and we will delete them. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
Who else sees it
In short: A short list of sub-processors, plus legal compulsion. Nobody else.
Only the sub-processors that make the application run:
- Plaid — bank connections and transaction data
- Cloudflare — hosting, TLS, storage and edge security
- Neon — the application database
- Google — sign-in, and mailbox access if you enable it
- Stripe — payment processing for paid plans
- Resend — verification and notification email
Each holds only what it needs and is bound to use it only to provide its service to us.
Household members. People in your household can see the records shared with the household, as controlled by the household owner.
Legal and corporate disclosures. We disclose data to others only where the law requires it — a valid subpoena, court order or lawful request — or where necessary to establish, exercise or defend legal claims or to protect the rights and safety of users or the public. If the business is merged, acquired or its assets sold, data may transfer as part of that transaction, subject to this notice.
How it is protected
In short: TLS everywhere, encrypted bank tokens, hashed passwords, role-based access — but no system is perfectly secure.
Every connection uses TLS 1.2 or higher. Bank access tokens are encrypted with AES-256-GCM before they are written to the database, with the key held in a separate secret store. Passwords are stored only as bcrypt hashes. Access is role-based and reviewed quarterly. Data is scoped per household and that isolation is enforced by automated tests.
Full detail is in our Information Security Policy, Access Control Policy and Vulnerability Management Policy.
No method of transmission or storage is completely secure, and we cannot and do not guarantee absolute security. You are responsible for keeping your credentials confidential and for the security of the devices you use. Tell us immediately at augustinerealtycompany@gmail.com if you suspect unauthorised access.
Breach notification. If a breach affects your personal information, we will notify you and any regulator without undue delay and within the timeframes required by applicable law.
How long we keep it
In short: Tokens die on revocation; financial history is kept seven years; accounts are deleted within 30 days of a request.
Retention periods, and how data is disposed of, are set out in our Data Retention and Disposal Policy. In short:
- bank access tokens are deleted as soon as a connection is revoked;
- transaction and balance history is kept for seven years, to support tax and lending records;
- account records are deleted within 30 days of a deletion request;
- security logs are kept for a limited period for abuse investigation, and backups age out on their own schedule after deletion.
We keep information longer only where law requires it or where it is necessary to establish, exercise or defend a legal claim.
Your rights, wherever you are
In short: Access, correct, delete, port, object — email us and we respond within 30 days.
Email augustinerealtycompany@gmail.com to see what we hold about you, to correct it, to have it deleted, or to obtain a portable copy. We respond within 30 days. We may need to verify your identity before acting, and we will never discriminate against you for exercising a privacy right.
California (CCPA/CPRA)
California residents have the rights to know, access, delete, correct, and to opt out of sale or sharing and of certain profiling, plus the right to limit use of sensitive personal information. We do not sell or share personal information, and we have not done so in the preceding twelve months, including the personal information of anyone under 16. Financial account information is sensitive personal information and is used only to provide the Service. You may use an authorised agent to make a request.
EEA and UK (GDPR)
You have the rights of access, rectification, erasure, restriction, portability, and objection to processing based on legitimate interests, and the right to withdraw consent at any time. You may lodge a complaint with your supervisory authority or the UK ICO. We make no automated decision with legal or similarly significant effect about you.
Other US states
Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas and others) have equivalent rights of access, correction, deletion, portability and opt-out, and a right to appeal a refused request by replying to our response.
International transfers, and children
In short: Data is processed in the United States. Nobody under 18 may use the Service.
Where data is processed.The Service is operated from the United States and your information is stored and processed there and in the regions our sub-processors use. If you are in the EEA or UK, transfers rely on the European Commission’s Standard Contractual Clauses or another lawful transfer mechanism, together with the technical measures described above. US law may permit government access on terms that differ from your home jurisdiction.
Children. The Service is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, email us and we will delete it.
Changes to this notice
In short: Material changes are announced in the application before they take effect.
We may update this notice as the product changes. The “last updated” date above is revised whenever we do, and material changes are announced in the application before they take effect. Continued use after the effective date means you accept the updated notice. Prior versions are available on request.
Privacy questions and requests go to augustinerealtycompany@gmail.com. See also the Terms of Service and our published Information Security, Access Control, Vulnerability Management and Data Retention policies.