Privacy & Data Protection

SplitWish Privacy Policy

Effective Date: September 9, 2026 • Version 2.0.0 • SplitWish. by SG Infotech (Solution Gateway Infotech)

Summary of Our Core Privacy Principles

  • ✓Zero Ad Tracking: We never sell, rent, or monetize your personal or financial data to third-party advertisers.
  • ✓Bank-Grade Encryption: All communications use TLS 1.3 in transit and AES-256 encrypted database storage at rest.
  • ✓No Card Data Stored: Subscriptions are processed securely by Apple App Store and Google Play via RevenueCat.
  • ✓Full User Control: Delete your account, groups, receipts, and personal data at any time with one click in the app.

1. Introduction & Controller Information

SplitWish. and SG Infotech ("Solution Gateway Infotech", "we", "us", or "our") provide the SplitWish mobile application (available on iOS and Android), backend APIs, and web services. This Privacy Policy explains how we collect, store, process, synchronize, and protect your information when you access or use our applications and platform services.

For the purposes of the EU General Data Protection Regulation (GDPR), UK GDPR, and applicable global privacy laws, SplitWish. acts as the Data Controller for your account and personal profile information.

2. Information We Collect

To provide real-time collaborative shopping, itemized bill splitting, multi-currency debt calculation, and settlement tracking, we collect the following categories of information:

A. Account & Profile Data

  • Identity Details: Full name, verified email address, optional profile avatar image, and default currency setting (e.g., USD, EUR, GBP, INR).
  • Authentication Credentials: Passwords stored strictly as secure one-way salted cryptographic hashes. For OAuth sign-ins (Google / Apple Sign-In), we store authentication provider IDs and public profile tokens.
  • Phone Number Hash: Optional phone numbers are stored as one-way cryptographic hashes for privacy-preserving contact matching and group invites without storing raw plaintext phone numbers.

B. Groups & Social Collaboration Data

  • Group Metadata: Group title, type (e.g., apartment, roommates, trip, couple, family, project), description, and custom group avatar.
  • Memberships & Roles: Member rosters, membership roles (Owner, Admin, Member), and unique alphanumeric group invitation codes.

C. Expenses, Splits & Settlement Data

  • Transaction Records: Expense title, amount, currency, category, payer ID, creator ID, split type (simple equal split vs. advanced itemized breakdown), and timestamp.
  • Itemized Shares: Individual line-item names, quantities, unit prices, and user assignments.
  • Debt Simplification Graphs: Calculated net balances between debtors and creditors within groups.
  • Settlement Proofs: Payment confirmation records, settlement currency, notes, and optional payment proof photos.
  • Audit History: Immutable edit changelogs tracking modifications to shared expenses to ensure transparency among group members.

D. Collaborative Shopping List Data

  • List Items: Item names, quantities, units, estimated/actual prices, locked/checked status, and assigning members.
  • Real-Time Presence: Active in-store shopping session indicators broadcast across group members.
  • Historical Item Catalog: Aggregate purchase frequency and price history for smart autofill within your private group.

E. Media & Receipt Uploads

  • Photos of physical itemized receipts, store bills, avatars, and payment receipts uploaded to our secure, private encrypted cloud storage.

F. Device Tokens & Diagnostic Data

  • Push Notification Tokens: Standard mobile device push tokens used to deliver transactional alerts and group updates.
  • Security Audit Logs: IP addresses and user agents recorded in administrative audit logs during security-critical operations (bans, password resets, session revocation).
  • Diagnostic Telemetry: Anonymized crash logs and performance metrics captured to maintain application stability.

3. How We Use Your Information

We process your information exclusively for the following legitimate purposes:

  • Service Delivery: Synchronizing live shopping checklists in real time, calculating multi-currency debts, and itemizing receipts.
  • Offline Sync: Caching data securely on your local device to allow full offline app usage, followed by bi-directional background synchronization upon reconnection.
  • Push Notifications: Notifying you when group members add expenses, start live shopping runs, assign items, or record settlements.
  • Subscription Management: Managing SplitWish Premium subscription status ($2.99/mo) and feature entitlements via RevenueCat.
  • Fraud Prevention & Security: Detecting suspicious account activity, enforcing account safety, and preventing spam.

4. Third-Party Service Providers & Data Processors

We partner with select, industry-leading infrastructure providers to operate SplitWish. All third parties are contractually bound under Data Processing Agreements (DPAs) to process data strictly on our behalf:

ProcessorPurposeData Handled
RevenueCatIn-app subscription verification & status managementAnonymous App User ID, subscription entitlement status
Apple App Store & Google Play StoreIn-app purchase & payment processingSubscription billing (SplitWish never sees or stores card details)
Device Push Notification ServicesTransactional mobile push notificationsEncrypted device push tokens, notification payloads

5. Data Retention & Account Deletion

We retain your personal data for as long as your SplitWish account remains active. You maintain complete sovereignty over your data:

  • In-App Account Deletion: You can permanently delete your account at any time under Settings → Account → Delete Account.
  • Automated Cascading Purge: When an account is deleted, our secure databases execute an immediate cascading deletion of your personal records, active sessions, push notification tokens, and private uploaded receipts.
  • Shared Group Continuity: Group balance history remains consistent for remaining group members with your profile anonymized as "Former Member" to prevent disruption to existing financial calculations.

6. Your Rights Under GDPR & CCPA/CPRA

Regardless of your geographic location, SplitWish provides standard global privacy rights:

  • Right of Access: Request a full copy of all personal data held about you.
  • Right to Rectification: Update inaccurate account or profile data directly within the application.
  • Right to Erasure ("Right to be Forgotten"): Request full deletion of your profile and personal media.
  • Right to Data Portability: Export your expenses and group split records to CSV / Excel spreadsheet formats.
  • Right to Opt-Out of Automated Processing: We do not engage in automated profiling or automated credit decisions.

7. Data Security Architecture

We enforce strict technical and organizational safeguards to protect your information:

  • Transport Encryption: All HTTP API calls and real-time collaboration connections are strictly encrypted via TLS 1.3.
  • Database Protection: Production databases are hosted in isolated virtual private networks with automated daily encrypted backups and AES-256 storage encryption.
  • Session Security: Ephemeral authentication tokens paired with real-time revocation blacklists for immediate sign-out and session eviction upon password changes.

8. Children's Privacy

SplitWish is not directed to individuals under the age of 13 (or 16 in the European Economic Area). We do not knowingly collect personal information from children. If we discover that a child has registered an account, we will take immediate steps to delete the account and associated data.

9. Contact & Data Protection Officer

If you have any questions, privacy inquiries, or wish to exercise your legal data rights, please contact our Privacy Engineering Team:

SplitWish Data Protection Office

SG Infotech (Solution Gateway Infotech)

Email: privacy@splitwish.app / legal@sginfotech.com

Support: support@splitwish.app