Privacy policy

Effective: May 2026. Applies to UK users.
UK GDPR
Summary

Baanka collects the minimum data needed to run savings groups. We use your data to provide the service, keep groups safe, and meet basic legal obligations.


What we collect

Account data: name, email address, and role.

Group data: group name, contribution amount, and schedule.

Activity data: payments, payouts, and join requests.

Usage data (with your consent): pages visited, features used, and anonymised session recordings.


Why we use it

Lawful basis under UK GDPR:

To provide the service (contract).

To keep groups safe and prevent misuse (legitimate interests).

To understand how the product is used during private beta (consent — analytics cookies only).


Who can see what

We default to least-privilege access. Members see limited information about other members. Organisers can view member emails for invitations and admin tasks.


Analytics and cookies

With your consent, we use PostHog to collect anonymised usage data — which pages you visit, which features you use, and session recordings with all inputs masked. This helps us improve Baanka during private beta.

Data collected: an anonymous user ID, your role (organiser or member), and usage events. No name, email, or financial data is sent to PostHog.

Processor: PostHog Inc., stored on EU servers (eu.i.posthog.com). Data does not leave the EU.

Lawful basis: your explicit consent, given via the banner shown on first login.

Your preference is stored locally in your browser under the key baanka_analytics_consent. It is never sent to our servers.

To withdraw consent, clear your browser's localStorage for baanka.co.uk — the consent banner will reappear on your next visit and you can decline.


Your rights

Access: export your data at any time.

Deletion: request account removal via support.

Correction: update your details through the support form.


To exercise any of these rights, use the support form or email support@baanka.app.


Data portability

As Baanka develops, we intend to give you the option to share your activity record — contributions, completed cycles, trust score — with third parties such as lenders, credit unions, or other platforms. Any such sharing will require your explicit consent at the time of sharing. We will never share your data with third parties without your active permission.


Retention

We retain data only as long as needed to operate your groups and meet legal or security requirements.