Back to home

Privacy Policy

Last updated: April 22, 2026

This Privacy Policy explains how oewang ("oewang", "we", "our", or "us") collects, uses, stores, and protects personal data when you use our product and website.

oewang is built to help people track daily finances, including transactions, wallets, receipts, invoices, documents, and AI-assisted workflows. Privacy and workspace data isolation are core design principles in the product.

Data We Collect

  • Account data: name, email, profile details, authentication provider information.
  • Workspace data: workspace name, membership, role, and settings.
  • Financial data you provide: transactions, wallets, categories, contacts, debts, invoices, and related records.
  • Files you upload: receipts, invoice files, and other documents stored in vault features.
  • Integration data: data required to operate connected services (for example messaging or email integrations you enable).
  • Technical and security data: request metadata, audit records, operational logs, and abuse prevention signals.

How We Use Data

  • Deliver and maintain the product.
  • Authenticate users and protect accounts/workspaces.
  • Process financial workflows and generate reports/insights.
  • Provide support and troubleshoot service issues.
  • Improve reliability, security, and product quality.
  • Meet legal, tax, audit, and compliance obligations.

Workspace Access and Visibility

oewang enforces workspace-scoped access controls. Authenticated requests are validated against active workspace membership, and access is limited by role and permission.

Users can only access data they own or data available inside workspaces where they are active members. Access is revoked when membership is removed.

Legal Bases (GDPR)

For users in the EEA/UK, we process personal data based on one or more of the following:

  • Contract necessity: to provide the oewang service.
  • Legitimate interests: security, fraud prevention, reliability.
  • Legal obligations: accounting, tax, and regulatory duties.
  • Consent: where required for optional processing activities.

Third-Party Processors and Integrations

We use third-party service providers to operate the product (for example authentication/database infrastructure, payment processing, cloud storage, messaging channels, and AI providers). These providers process data on our behalf under contractual controls.

If you connect optional integrations, data is processed as required to deliver that integration's functionality. We do not sell your personal data.

Google API Data

If you connect Google services, oewang's use of data received from Google APIs follows the Google API Services User Data Policy, including Limited Use requirements.

Data obtained from Google Workspace APIs (including Gmail data) is not used to train generalized AI/ML models.

International Data Transfers

Your data may be processed in countries outside your place of residence. Where required, we apply appropriate transfer safeguards under applicable law.

Data Retention

We keep personal data for as long as needed to provide the service, maintain security, and comply with legal obligations. Retention periods vary by data type and legal requirements.

When retention is no longer required, we delete or anonymize data according to our internal controls.

Security

We apply technical and organizational security measures, including encryption in transit, encrypted storage where supported, authenticated access control, role-based authorization, and audit logging.

No system is 100% secure, but we continuously review and improve our controls.

Your Privacy Rights

Privacy rights vary by region. Depending on where you live, you may have rights to access, correct, export, restrict, erase, or object to certain uses of your personal data.

Indonesia (UU PDP)

For users in Indonesia, we process personal data in line with Indonesia's Personal Data Protection Law (UU PDP). Subject to legal conditions, you may request access, correction, deletion, restriction, and other rights recognized by applicable Indonesian law.

EEA / UK (GDPR)

For users in the EEA/UK, GDPR-related rights may include access, rectification, erasure, restriction, portability, objection, and complaint rights with a supervisory authority, subject to legal limitations.

United States (State Privacy Laws)

For users in certain US states, you may have rights to know, access, correct, delete, and request a portable copy of personal data, and where applicable, rights to opt out of specific processing uses defined by state law.

oewang supports a structured privacy request workflow. Requests are tracked through lifecycle states (received, in progress, completed, rejected) and may require identity verification.

Where required by law, we aim to respond within applicable statutory deadlines (typically within 30 days, subject to complexity and legal allowances).

Children's Privacy

oewang is not intended for children under 18, and we do not knowingly collect personal data from children under 18.

Changes to This Policy

We may update this Privacy Policy from time to time. Material updates will be posted on this page with a revised "Last updated" date.

Contact

For privacy questions or requests, contact us at support@oewang.com.