Last updated: 7 September 2026
Spenflo ("we", "us") is the data controller for the personal data described in this policy. Spenflo is operated by a UK sole trader — registered trading details available on request.
Contact: info@spenflo.com
Account data — the email address and password (stored as a salted hash, never in plain text) you sign up with; your company name; login timestamps and session data; IP address (used for rate-limiting against abuse).
Cloud billing data — once you connect a cloud provider, we ingest cost and usage data from your AWS/GCP/Azure billing APIs: service names, resource identifiers, tags, cost amounts, and usage quantities. This describes your infrastructure and spend, not your staff. A cloud resource tag or name occasionally contains a person's name — we don't do anything with this beyond displaying it back to you as part of your own cost breakdown.
Cloud credentials — the IAM role, service account, or access key you provide to grant read-only billing access, encrypted at rest and never logged or displayed in plain text after initial submission.
Payment data — handled entirely by Stripe. We never receive or store your card number; we hold only a Stripe customer/subscription reference.
Analytics — Vercel Web Analytics counts page views and visits across the site so we know whether anyone's using it. It's cookieless, doesn't track you across other sites, and doesn't build an advertising profile. No other analytics or tracking scripts are used.
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel | Application hosting | US |
| Neon | Database (Postgres) | US (EU region available) |
| Stripe | Payment processing | US |
| Resend | Transactional email | US |
We do not sell your data, and do not share it with anyone else except where required by law.
Vercel and Neon are US-headquartered. Where personal data is transferred outside the UK/EEA, we rely on the UK International Data Transfer Addendum / EU Standard Contractual Clauses that these providers have in place.
While your account is active: for as long as you have a Spenflo account.
On disconnecting a cloud provider: that provider's cost history and recommendations are deleted immediately, not just the credential.
On account deletion: everything is deleted — users, sessions, connections, cost data, recommendations, budgets, alert channels — immediately and irreversibly, self-service from your account settings.
Under UK GDPR, you have the right to access, correct, delete, or export your data, and to object to certain processing.
We use one cookie: a session cookie that keeps you logged in. It's strictly necessary for the Service to function and isn't a tracking or advertising cookie. Our analytics is cookieless — it doesn't set anything on your device.
Spenflo is a B2B product for business use and is not directed at, or knowingly used by, children.
We'll update the date at the top of this page when this policy changes, and notify you of material changes via email or an in-app notice.
If you're unhappy with how we've handled your data, you also have the right to complain to the UK Information Commissioner's Office (ICO): ico.org.uk.