Privacy Policy
Last updated: 28 August 2026 · Version: 2026-08-v1
PlixoPay ("we", "us", or "our") is the commercial name for a group expense-splitting application. The Service at plixopay.com (the "Service") is operated in Spain by Edgar Adrian Padilla Raza, acting as a self-employed individual (autónomo). This Privacy Policy explains how we collect, use, and protect your personal data when you use the Service. It applies to all users in Spain and the European Union and has been written to comply with the EU General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679.
If you have any questions, contact us at hola@plixopay.com.
1. Data Controller
The data controller responsible for your personal data is:
Edgar Adrian Padilla Raza, operating the PlixoPay service as a self-employed individual (autónomo)Commercial/product name: PlixoPay
NIF: 60142016Y
Address: Basses de Sant Pere 10, 08003 Barcelona, Spain
Email: hola@plixopay.com
See our Legal Notice for full provider details.
2. Data We Collect
We collect the following categories of personal data:
2.1 Account Information
- Full name — used to identify you within groups and to other members.
- Email address — used for authentication, transactional emails (invitations, settlement confirmations), and account recovery.
- Password — stored as a one-way bcrypt hash; we never store plaintext passwords.
2.2 Payment Information
- IBAN / bank account details — collected when you add a payout method. Stored securely and used solely to process settlements.
- Stripe payment method tokens — when you add a card or bank account through Stripe, Stripe stores the underlying payment credentials. We store only a reference token (Stripe Customer ID / Payment Method ID). We never receive or store raw card numbers.
- Stripe Connected Account data — if you receive Stripe-processed settlements through PlixoPay, Stripe may require a Connected Account in your name, which involves identity and payout verification data handled directly by Stripe. We store a reference identifier (Stripe Connected Account ID) only.
- Transaction metadata — amounts, currency, timestamps, party identifiers, and the fee/rate version applied, related to expenses and settlements within the Service.
2.3 Usage Data
- IP address and basic request logs (retained for up to 30 days for security purposes).
- Session identifiers (stored in an encrypted cookie, not used for tracking).
2.4 Data You Share With Others
Your name is visible to other members of any group or event you participate in. Your email address is not shared with other users.
3. How We Use Your Data
| Purpose | Legal Basis (GDPR Art. 6) |
|---|---|
| Providing and operating the Service (creating accounts, groups, expenses) | Art. 6(1)(b) — Performance of a contract |
| Processing payments and settlements via Stripe | Art. 6(1)(b) — Performance of a contract |
| Sending transactional emails (invitations, receipts, confirmations) via Resend | Art. 6(1)(b) — Performance of a contract |
| Security, fraud prevention, and abuse detection | Art. 6(1)(f) — Legitimate interests |
| Compliance with legal obligations (e.g., anti-money-laundering, tax records) | Art. 6(1)(c) — Legal obligation |
We do not sell your personal data to third parties, use it for advertising, or engage in automated profiling that produces legal or similarly significant effects.
4. Third-Party Processors
We share data with the following sub-processors solely to operate the Service. Each processor is bound by a Data Processing Agreement (DPA) and may only use your data on our instructions:
Stripe, Inc.
Payment processing, card tokenisation, and money transfers. Data transferred to the US under Standard Contractual Clauses (SCCs) in accordance with GDPR Chapter V.
Resend, Inc.
Transactional email delivery. Your name and email address are transmitted to Resend solely to deliver emails triggered by your actions (e.g., invitations, confirmations). Data transferred under SCCs.
Neon
Database hosting for the Service's primary datastore (account, group, expense, and transaction records), hosted in an EU region.
Render
Application hosting for the Service's backend and frontend.
We may also disclose your data to competent authorities when required by applicable law, court order, or regulatory requirement.
5. Data Retention
- Account data — retained for as long as your account is active plus 2 years after deletion, to comply with financial record-keeping obligations.
- Payment & transaction records — retained for 7 years as required by Spanish tax law (Ley General Tributaria).
- Server logs — retained for up to 30 days and then permanently deleted.
6. Your Rights Under GDPR
Under the GDPR you have the following rights with respect to your personal data. To exercise any of these rights, email us at hola@plixopay.com with the subject line "GDPR Request". We will respond within 30 days.
Right of Access (Art. 15)
You may request a copy of all personal data we hold about you.
Right to Rectification (Art. 16)
You may correct inaccurate data at any time via your account settings or by contacting us.
Right to Erasure / "Right to be Forgotten" (Art. 17)
You may request deletion of your account and associated personal data. We will delete or anonymise your data unless we are legally required to retain it (e.g., for tax or anti-fraud obligations).
Right to Data Portability (Art. 20)
You may request an export of your personal data in a machine-readable format (JSON or CSV).
Right to Restriction of Processing (Art. 18)
You may ask us to restrict processing of your data in certain circumstances, for example while a rectification request is being assessed.
Right to Object (Art. 21)
You may object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds.
Right to Lodge a Complaint
You have the right to lodge a complaint with the Spanish data protection authority: Agencia Española de Protección de Datos (AEPD) — www.aepd.es.
7. Cookies and Local Storage
We use a single session cookie (connect.sid) for authentication. This cookie is essential to the Service and does not track you across other websites. We do not use advertising cookies, analytics cookies, or any form of cross-site tracking.
We also use browser localStorage to store lightweight application preferences (e.g., onboarding state). No personal data is stored in localStorage.
8. Security
We implement appropriate technical and organisational measures to protect your data, including HTTPS encryption in transit, bcrypt password hashing, and least-privilege database access controls. Payment data is handled by PCI-DSS-compliant processors (Stripe) and never stored on our servers in raw form.
9. Children's Privacy
The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us immediately at hola@plixopay.com.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via email or a prominent notice in the app at least 30 days before they take effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
11. Governing Law
This Privacy Policy is governed by Spanish law and, where applicable, EU law including the GDPR. Any disputes arising from this policy shall be subject to the exclusive jurisdiction of the courts of Spain.
Contact
For any privacy-related requests or questions, contact our data protection point of contact at: