Coast
PricingSecurityFAQ Sign in Start free →

Privacy Policy

Effective date: July 9, 2026

This policy explains how Union Street Ventures, Inc., doing business as Coast ("Coast", "we", "us"), collects, uses, and protects personal information when you use coastflow.io (the "Service"). The short version: we collect the minimum needed to deliver cash reports you configure, we never see your banking credentials, we do not sell your data, and we do not use your financial data for advertising.

1. Information we collect

Account information. Your email address, organization name, and authentication data (login sessions, two-factor enrollment status, trusted-device records — stored as one-way hashes, never raw tokens).

Financial account information (via Plaid or manual entry). When you connect a financial institution through Plaid, we receive account names, account types, masked account numbers, and balances only — we do not collect transaction histories, and your banking username/password go directly to Plaid and are never sent to or stored by Coast. You can also enter balances manually. See the Plaid End User Privacy Policy for how Plaid processes your data.

Report & delivery configuration. Your message templates, schedules, and recipients (Slack channel selections, email addresses, phone numbers you add).

Usage & log data. IP address, browser type, pages viewed, and security events (logins, admin actions) kept in audit logs to operate and secure the Service.

Payment information. Handled by Stripe — we store your Stripe customer reference and subscription status, never card numbers.

Cookies. We use strictly necessary, first-party cookies only: your session, your trusted-device token, and security state. No advertising or cross-site tracking cookies, and no third-party analytics scripts on the app.

2. How we use information

  • Provide the Service: retrieve balances, compute reports, deliver them to the channels you chose.
  • Secure the Service: authentication, fraud and abuse prevention, audit logging.
  • Operate the business: billing, support, service announcements.
  • Improve the Service: aggregate, de-identified usage statistics.

We do not sell personal information, "share" it for cross-context behavioral advertising (as defined by the CPRA), or use Customer Data to train machine learning models.

3. Legal bases (GDPR)

Where the GDPR applies, we process personal data: to perform our contract with you (providing the Service); for our legitimate interests (securing and improving the Service, which do not override your rights); to comply with legal obligations; and with your consent where we ask for it (e.g. connecting a financial account).

4. Who we share data with (sub-processors)

We share personal data only with service providers who process it on our instructions under contractual confidentiality and security obligations:

ProviderPurposeLocation
SupabaseDatabase hosting & authenticationUnited States
RenderApplication hostingUnited States
PlaidRead-only financial account connectivityUnited States
StripePayments & subscription billingUnited States
ResendTransactional & report email deliveryUnited States
Twilio/TelnyxSMS report delivery (if you enable SMS)United States
SlackReport delivery to workspaces you connectUnited States

We may also disclose information if required by law or to protect the rights, safety, and security of Coast, our customers, or the public — and, with notice, in a merger or acquisition. We have no other categories of third-party recipients.

5. Data retention & deletion

We keep Customer Data while your account is active. When you delete your account (or 30 days after a terminated subscription), Customer Data is permanently deleted from production systems; encrypted backups age out on a fixed schedule thereafter. Financial connection tokens are revoked at Plaid on disconnection. Audit and billing records may be retained longer where the law requires. To request deletion at any time, email support@coastflow.io from your account email — we honor verified requests within 30 days.

6. Security

All traffic is encrypted in transit (TLS 1.2+); data is encrypted at rest; provider access tokens are additionally encrypted at the application layer; tenant data is isolated with database-enforced row-level security; two-factor authentication is available on every account; and administrative access is logged. Details: coastflow.io/security. No method of transmission or storage is 100% secure, but we treat the safety of financial data as our first engineering priority. If we learn of a breach affecting your personal data, we will notify you without undue delay consistent with applicable law.

7. International transfers

We are based in the United States and process data there. Where we receive personal data from the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses with our sub-processors (or their equivalent approved mechanisms).

8. Your rights

Everyone: you can access, correct, export, or delete your data in the app or by emailing support@coastflow.io.

EEA/UK (GDPR): you additionally have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your supervisory authority.

California (CCPA/CPRA): you have the right to know, delete, correct, and opt out of sale/sharing (we do not sell or share), and the right not to be discriminated against for exercising your rights. We honor Global Privacy Control signals for the browser you send them from. Authorized agents may submit requests with proof of authorization.

We verify requests via your account email and respond within the time required by the applicable law (generally 30–45 days).

9. Children

The Service is for business use and not directed to anyone under 18; we do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.

10. Changes to this policy

We may update this policy; material changes will be announced by email or in-app at least 14 days before they take effect. The current version is always at coastflow.io/privacy.

11. Contact

Privacy questions or requests: support@coastflow.io
Union Street Ventures, Inc. · Indiana, United States

© Coast · PricingSecurityFAQTermsPrivacyDPA
Questions? support@coastflow.io