Trust & Privacy

How we handle your data

This page is maintained by Abundantia Advisory, the team behind Pocket CFO™, to answer common security and privacy questions about this app. It describes the current practices in place. It is not an independent certification or audit.

What we collect

  • Lead details you submit on the free tool form: name, email, business type, revenue range, and the answers you choose in the quiz.
  • Account details if you create one: email address and authentication identifiers from your chosen sign-in method.
  • Workbook inputs you enter inside the app: expenses, offers, goals, and pricing assumptions.
  • Marketing attribution: UTM tags, referrer, and ad click IDs (e.g. gclid, fbclid) carried in the URL when you arrive.
  • Standard logs: IP address, user agent, and timestamps captured by our infrastructure providers for security and reliability.

How we use it

  • Deliver the revenue planning tool and your saved workbook.
  • Send transactional emails (sign-in, receipts, account notices).
  • Send marketing emails about Pocket CFO™ and related Abundantia Advisory offers. You can unsubscribe at any time using the link in any marketing email.
  • Measure marketing performance and improve the product.

Security controls in place

  • Encryption in transit for all traffic to the app and to our backend providers (HTTPS / TLS).
  • Row-level access controls on the database: signed-in users can only read and write their own workbook data; lead records are not readable by other users.
  • Admin access to lead and user data is restricted to named Abundantia Advisory staff with a dedicated admin role.
  • Payments are processed by Stripe. We never see or store your full card number; only a Stripe customer reference and the subscription status are kept in our database.
  • Secrets and API keys are stored server-side and are never exposed to the browser.

Subprocessors

We rely on the following providers to run the service. Each handles a limited slice of your data on our behalf:

  • Supabase — database, authentication, file storage.
  • Cloudflare — application hosting and edge runtime.
  • Stripe — payment processing and billing.
  • Resend — transactional and marketing email delivery.
  • Analytics & ads — where enabled, Google Analytics, PostHog, Meta Ads, and Google Ads receive event data tied to your browser session for measurement and attribution.

Retention & deletion

We keep lead and account records while your relationship with us is active. To request a copy of your data, correction, or deletion, email hello@thepocketcfo.io. We respond within 30 days.

Cookies & tracking

We use first-party cookies to keep you signed in and to remember your workbook session. Third-party cookies from the analytics and ad providers above may be set when those features are enabled. You can block them in your browser settings or via your operating system's ad-tracking controls.

Reporting a security issue

If you believe you have found a vulnerability or a data exposure, please email security@thepocketcfo.io with the details. We take reports seriously and will acknowledge receipt within two business days.

What this page is not

This page describes app-owner practices and platform features currently in use. It is not a SOC 2, ISO 27001, GDPR, HIPAA, or PCI certification, and it is not an independent audit. For contractual data-processing terms, contact us directly.

Last updated: August 14, 2026