CashboxCashbox
Privacy

Privacy policy

This policy explains the information Cashbox collects to run the product, how we use it, who we share it with, and the choices you have.

Last updated: April 21, 2026

Who this applies to

This policy applies to visitors to the Cashbox website (cashbox.events) and to organisations and users of the Cashbox application.

When you use Cashbox through your employer or production company, that organisation is the data controller for the event, expense, revenue, and supporting-document data your team enters. Cashbox acts as a data processor on their behalf.

For the website itself and for your personal account record (name, email, login), Cashbox is the controller.

Information we collect

Account and authentication data: name, email address, profile photo (if provided), hashed credentials or federated sign-in identifiers (e.g. Google), organisation membership, role, and preferred language.

Organisation configuration: organisation name, tax ID, default currency, locale, categories, approval thresholds, tax-rate catalog, and invited members.

Financial product data entered by your team: events, budgets, expenses (including supplier, amounts, dates, tax lines, FX snapshots), revenue lines, approvals, notes, and the associated audit history.

Uploaded files: invoice and receipt attachments, CSV imports, and optional screenshots attached to support or bug reports. Files are stored in Firebase Storage under your organisation.

Billing data: plan, subscription status, billing email, VAT number, and invoice history. Payment-card details are handled by Stripe and never stored on Cashbox servers.

Communications: the contents of messages you send through our contact form, support form, bug reports, and direct email.

Technical data: IP address, browser, device type, approximate location derived from IP, timestamps, and standard server logs used for security, abuse prevention, and debugging.

How we use information

To operate the service: authenticate users, render your organisation's data, run approvals, compute aggregates, send transactional emails (invitations, approvals, password resets), and keep a tamper-evident audit trail.

To provide support: respond to contact, support, and bug-report submissions, and to troubleshoot issues you report.

To bill and manage subscriptions: enforce plan limits (active events, users, storage), process payments through Stripe, and issue receipts.

To keep the service safe: detect abuse, prevent fraud, rate-limit submissions, and protect other customers.

To improve the product: understand aggregate usage patterns and reliability. We do not sell personal information or use your organisation's financial data to train external models.

Legal bases (EEA / UK)

Performance of a contract: providing the service to the organisation and user that signed up.

Legitimate interests: securing the service, preventing abuse, responding to enquiries, and improving reliability, balanced against your rights.

Legal obligations: meeting accounting, tax, and other statutory requirements (for example, retaining invoice data).

Consent: when you choose to send us optional information, such as a screenshot attached to a bug report.

Subprocessors

We share data with a small set of infrastructure and service providers strictly to run Cashbox:

Google Cloud / Firebase — authentication, Firestore database, Cloud Storage, and hosting (data region: EU where available).

Stripe — subscription billing and payments; handles your payment-card details under its own PCI-compliant environment.

Resend — delivery of transactional and notification emails sent from the product.

Google Analytics — website analytics on our public pages, loaded only with your consent; IP addresses are anonymised.

We maintain written data-processing agreements with each subprocessor and only share the minimum data needed for that service. International transfers are covered by Standard Contractual Clauses where applicable.

Sharing within your organisation

Data entered into an organisation (events, expenses, revenue, attachments, audit entries) is visible to other members of that organisation according to their assigned role.

Organisation owners and admins can see team membership, invitations, role changes, and the full financial record. Owners can export or delete their organisation's data at any time.

Disclosures

We do not sell personal information, and we do not share it with third parties for their own advertising.

We may disclose information if required by law, in response to valid legal process, or when reasonably necessary to protect the service, our users, or our legal rights.

Retention

Account and organisation data is retained for as long as the organisation is active. If a subscription is cancelled, data is retained for a short grace period to allow export, after which it is deleted or anonymised on request.

Invoice, tax, and accounting data may be retained for longer periods where required by Estonian and EU law (typically up to 7 years for accounting records).

Server logs and security data are kept for a limited period appropriate to their purpose.

Security

Data is transmitted over TLS and stored on managed infrastructure with encryption at rest. Access controls are role-based and enforced both in the application and at the database layer via security rules.

Every write to financial data is recorded in an audit log including the actor, timestamp, and change. No system is perfectly secure — if you believe your account has been compromised, contact us immediately.

Your rights

Under the GDPR and similar laws, you may request access to, correction of, or deletion of your personal data; object to or restrict certain processing; and request a portable copy of your data.

Owners can export their organisation's financial data directly from the product. For personal-account requests, write to hello@cashbox.events with enough detail for us to identify the record.

If you believe we have not handled your request appropriately, you may lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or with the supervisory authority of your EU member state of residence.

Cookies

Cashbox uses a small number of strictly necessary cookies to keep you signed in, protect against cross-site request forgery, and remember your language preference. These are required for the service to work and are not optional.

With your consent, we also use Google Analytics 4 to understand how visitors find and use our public website. It is loaded only after you accept in the cookie banner — if you decline, or ignore the banner, no analytics script is loaded and no analytics cookie is set.

If you accept, we also store the campaign parameters (such as utm_source or gclid) from the link that first brought you to the site, so we can tell which marketing produced a signup. If you decline, these are discarded and never leave your browser.

You can change your choice at any time by clearing this site's data in your browser, which makes the banner appear again. We ask again at least every six months regardless.

Children

Cashbox is a business product and is not directed to children under 16. If you believe a minor has created an account, contact us and we will remove it.

Changes

We may update this policy as the product evolves. Material changes will be highlighted on the page and, where appropriate, notified to organisation owners by email.

The "last updated" date at the top of this page always reflects the current version.

Contact

For privacy questions, data-subject requests, or subprocessor details, contact hello@cashbox.events.