These documents are provided in good faith for an early-access product and should be reviewed by a qualified solicitor before commercial launch.
1.Introduction and data controller
SaveMyBudget is a service operated by IK Ventures Ltd, a company registered in England and Wales, Company Number 09477473, with a trading address at 843 Finchley Road, London, NW11 8NA (“we”, “us”, “our”).
This policy explains what personal data we handle, why, and what rights you have. We handle personal data in accordance with the UK GDPR and the Data Protection Act 2018. You can get in touch about anything in this policy via our contact form.
2.Our two distinct roles
We act in two different capacities, and it matters which one applies to you:
- Controller. For visitors to savemybudget.io, waitlist signups and people who email us, we decide why and how the data is used. This policy governs that processing.
- Processor. For click telemetry collected by our tag on our customers' own websites, our customer is the controller and we act on their documented instructions under a data processing agreement. If you visited a customer's website, their privacy notice governs that data; we process it only to detect invalid clicks and support refund claims for that customer.
3.What we collect
(a) Website and waitlist data (we are controller)
- Your work email address (required to join the waitlist).
- Your monthly Google Ads spend band, used to prioritise onboarding.
- Your website URL, if you choose to provide it.
- Standard technical data generated by visiting our site: IP address, user-agent, and request timestamps in server logs.
(b) Click telemetry on customer websites (we are processor)
When a customer installs our JavaScript tag on their landing pages, we record the following for each ad click:
- The Google click identifier attached to the visit (gclid, gbraid or wbraid).
- The IP address and user-agent string of the request, recorded server-side.
- A device fingerprint derived from canvas, WebGL, font and screen signals.
- Browser automation markers indicating headless browsers or scripted drivers.
- Interaction metadata: counts and timings of mouse movements, scrolls, touches, clicks and keydown events, plus dwell time on the page.
We also process click, campaign and cost data pulled from the customer's Google Ads account so we can reconcile it against our own telemetry.
4.What our tag does not do
This is a deliberate, auditable guarantee about the design of our tag:
- It never reads page content.
- It never reads the values typed into form fields.
- It never records which keys are pressed — only that a keydown occurred, and when.
- It never reads passwords, card numbers or payment details.
- It cannot modify the host website; it is asynchronous, error-contained and read-only with respect to the page.
5.Google user data and Limited Use
Where a customer connects their Google Ads account to SaveMyBudget via OAuth, the data we access is used solely to detect invalid clicks, prepare and file refund claims, and report results back to that same customer. We never sell Google user data, never use it for advertising, and never use it to train generalised or third-party models.
SaveMyBudget's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6.Legal bases for processing
- Legitimate interests — for fraud prevention, detection and network security. UK GDPR expressly recognises processing strictly necessary for fraud prevention as a legitimate interest. You have the right to object to processing based on legitimate interests (see section 11).
- Consent — for marketing emails and waitlist updates. You can withdraw consent at any time, without affecting processing carried out before withdrawal.
- Contract — where processing is necessary to deliver the service a customer has signed up for.
7.Cross-customer threat intelligence
Threat signals derived from traffic we observe — offending IP addresses, subnets, device fingerprints and ASNs — are pooled in aggregated, pseudonymised form so that a fraudster caught in one account can be blocked for every account.
Client business data never crosses customer boundaries. Campaign names, keywords, spend, conversions, claim outcomes and any other commercial information stay with the customer they belong to. Only abuse signals are shared, and they are not attributed to the customer whose traffic revealed them.
8.Sharing and sub-processors
We do not sell personal data. We share it only with:
- Cloudflare — edge network, request handling and DDoS protection.
- Neon — managed Postgres database hosting.
- Fly.io — application and worker hosting.
- MaxMind — IP intelligence and geolocation lookups.
- Our email delivery provider — transactional and waitlist emails.
- Google — when we submit and correspond about invalid-click refund claims on a customer's behalf.
- Professional advisers and authorities, where we are legally required to disclose.
9.Where your data is held and international transfers
Our infrastructure is EU/UK-hosted: Cloudflare edge, Postgres in London and workers in London. Where a sub-processor requires a transfer outside the UK, we rely on UK adequacy regulations or, where none applies, the International Data Transfer Addendum to the EU Standard Contractual Clauses together with appropriate supplementary measures.
10.Retention
- Raw click telemetry including IP address and user-agent: 90 days. This aligns with Google's 60-day claim window plus a buffer for adjudication.
- Aggregates, detection outputs and threat signals: retained longer in pseudonymised form to keep detection effective.
- Waitlist data: retained until you withdraw or ask us to delete it.
- Records we must keep for accounting or legal reasons: retained for the statutory period.
11.Your rights
Under UK GDPR you have the right to:
- Be informed about how your data is used.
- Access a copy of the personal data we hold about you.
- Have inaccurate data rectified.
- Have your data erased, where the conditions are met.
- Restrict processing in certain circumstances.
- Data portability for data you provided to us.
- Object to processing based on legitimate interests, including profiling.
- Withdraw consent at any time, where consent is the legal basis.
- Not be subject to solely automated decisions producing legal or similarly significant effects.
To exercise any right, get in touch via our contact form, selecting “Privacy / data request”. If your data was collected on a customer's website, we will pass your request to that customer as controller and support them in responding.
12.Security
We use encryption in transit, access controls scoped to least privilege, isolated per-customer data boundaries, audit logging and regular dependency review. No system is perfectly secure, but we design for containment: our tag cannot alter the host page, and our services fail safe rather than fail open.
13.Cookies
Our landing page uses only essential cookies needed to serve and secure the site. We do not run advertising or cross-site tracking cookies on savemybudget.io.
The fraud detection tag itself relies on server-side logging and stores nothing on the visitor's device — no cookies, no local storage, no persistent identifiers written to the browser.
14.Changes to this policy
We may update this policy as the product develops. The “last updated” date at the top of this page always reflects the current version, and we will notify customers of material changes.
15.Contact and complaints
IK Ventures Ltd, 843 Finchley Road, London, NW11 8NA. The quickest way to reach us is our contact form.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk. We would appreciate the chance to resolve it with you first.