Privacy Policy

Version 1.0 · Last updated 11 June 2026 · Effective [effective date]

This document is a comprehensive draft prepared to current UK data-protection requirements. It should be reviewed by your legal adviser and tailored to your live operations (and the highlighted fields completed) before publication.

This Privacy Policy explains how Ravn Technologies Ltd ("Ravn", "we", "us", "our") collects, uses, shares, stores and protects your personal data, and your rights in relation to it. It applies to our website (getravn.co.uk), our mobile application, and related services (together, the "Service").

We are the controller of your personal data and are responsible for it. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).

Contents

  1. Who we are & how to contact us
  2. Personal data we collect
  3. How we collect it
  4. How & why we use it (lawful bases)
  5. Open Banking
  6. Automated processing & profiling
  7. Marketing
  8. Who we share data with
  9. International transfers
  10. How long we keep it
  11. Security
  12. Data breaches
  13. Your rights
  14. Children
  15. Complaints
  16. Changes

1. Who we are & how to contact us

2. The personal data we collect

CategoryExamples
Identity & contactName, email, date of birth, UK mobile number, postcode/address.
Account & credentialsPassword (hashed), account settings, preferences, marketing choices.
Financial & transactional (via Open Banking, with consent)Account names, balances, transactions, recurring payments, detected bills and providers, assets/liabilities you add.
Usage & technicalDevice type, operating system, app version, IP address, identifiers, in-app activity, diagnostics/crash logs.
CommunicationsSupport messages, feedback, and records of contact with us.
PaymentSubscription status and history. Card details are handled by our payment processor; we do not store full card numbers.

We do not intentionally collect special category data (e.g. health, ethnicity). Bank transaction data may incidentally reveal such information; we process it only to provide the Service and apply additional care.

3. How we collect it

4. How & why we use your data — and our lawful basis

PurposeLawful basis
Provide the Service: find bills, forecast safe-to-spend, show net worth, coach negotiations, enable switchingPerformance of a contract
Access your bank account informationExplicit consent
Take payment and manage your subscriptionPerformance of a contract
Security, fraud prevention, debugging, and improving the ServiceLegitimate interests
Send service/transactional messages (e.g. alerts, renewals)Performance of a contract / legitimate interests
Send marketing emailsConsent (opt-out any time)
Comply with legal, tax and regulatory obligationsLegal obligation

Where we rely on legitimate interests, we have balanced those interests against your rights; contact us for our assessment.

5. Open Banking

If you choose to connect a bank account, we access your account information on a strictly read-only basis through an FCA-authorised Open Banking (Account Information Service) provider ([provider, e.g. TrueLayer / GoCardless]). We cannot move money from your accounts. You provide explicit consent at the point of connection; consent lasts up to 90 days and is then refreshed; and you may withdraw consent at any time in the app, via the provider, or with your bank. We use this data solely to find and analyse your bills, forecast what is safe to spend, and present your net worth. We do not sell it. See our separate Open Banking Consent Notice.

6. Automated processing & profiling

To deliver features such as bill detection, the "safe-to-spend" forecast and your Ravn Score, we analyse your transaction and account data automatically (a form of profiling). These outputs are informational tools to help you decide — they are not solely-automated decisions producing legal or similarly significant effects, and we do not use them to deny you a product or take action without your involvement. You can contact us to query how a result was produced.

7. Marketing

We will only send you marketing where you have consented, and you can opt out at any time via the unsubscribe link or by emailing us. We treat service messages (security, renewals, important changes) separately — these are not marketing and are necessary to provide the Service. We comply with PECR for electronic marketing.

8. Who we share your data with

We share personal data only with processors and partners that help us operate Ravn, under written contracts requiring appropriate protection. We never sell your data. Recipients include:

RecipientPurpose
Open Banking provider [name]Bank connectivity (AIS)
Cloud hosting & database [e.g. Supabase / AWS, region]Hosting and storage
Payment processor [Stripe]Subscription billing
Email provider [e.g. Resend]Service & marketing emails
Switching partner [e.g. Switchcraft]Provider switching (only when you choose to switch)
Analytics/error tooling [if any]Diagnostics and improvement
Professional advisers, authorities, acquirersLegal/regulatory compliance or corporate transactions

9. International transfers

Where personal data is processed outside the UK, we ensure an adequate level of protection using UK adequacy regulations or appropriate safeguards (such as the UK International Data Transfer Agreement / Addendum to the EU SCCs). For details of where your data is processed, contact us.

10. How long we keep it

DataRetention
Waitlist emailUntil launch + [e.g. 12 months], or until you unsubscribe.
Account dataFor the life of your account, then deleted/anonymised within [e.g. 30 days] of closure.
Bank-derived dataDeleted when you disconnect the account or close your account (subject to limited legal/audit retention).
Transaction/billing recordsUp to 6 years for tax/accounting/legal purposes.

11. How we keep it safe

We use encryption in transit and at rest, strict access controls, read-only bank access, and regular review of our security practices. While no system is perfectly secure, we take measures appropriate to the risk.

12. Data breaches

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours where required, and will inform you without undue delay where the risk is high.

13. Your rights

Under UK data-protection law you have the right to: be informed; access your data; rectify inaccurate data; erase ("be forgotten"); restrict processing; data portability; object to processing (including direct marketing); rights regarding automated decision-making; and to withdraw consent at any time (without affecting prior processing).

To exercise any right, email privacy@getravn.co.uk. We may need to verify your identity. We respond within one month (extendable by two months for complex requests, with notice). Exercising your rights is free unless a request is manifestly unfounded or excessive.

14. Children

The Service is intended for UK residents aged 18 or over. We do not knowingly collect data from anyone under 18; if you believe a child has provided data, contact us and we will delete it.

15. Complaints

If you have a concern, please contact us first at privacy@getravn.co.uk — see our Complaints Procedure. You also have the right to complain to the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow SK9 5AF — ico.org.uk, 0303 123 1113.

16. Changes to this policy

We may update this policy from time to time. We will post the updated version here with a new version number and date, and notify you of material changes in-app or by email. Your continued use of the Service after changes take effect constitutes acceptance.

Terms of Service · Cookie Policy · Open Banking Consent · Complaints