Security by limited authority
Read-only access
Connected access is limited to account information. Banqa does not initiate transfers, payments or withdrawals.
Explicit consent
A bank connection begins only after you choose it and authorise access in the regulated provider or bank flow.
Data minimisation
Banqa aims to collect the information required for budgeting, support, security and legal compliance—nothing for advertising resale.
User control
You can disconnect bank access, remove optional Android permission and request account deletion.
Bank authentication and finAPI
Banqa intends to use finAPI’s PSD2 licence and Web Form as an unlicensed customer. Bank authentication takes place in the regulated provider or bank-controlled flow. Do not send bank passwords, PINs, TANs or authentication codes to Banqa support.
The provider identifies itself and supplies its own legal and privacy information before processing credentials or consent. Banqa receives only the account information and connection metadata permitted by the authorised flow.
Consent may expire or require renewed strong customer authentication. Banks and providers can restrict or interrupt access for security or regulatory reasons. Banqa treats those interruptions as connection failures, not permission to bypass safeguards.
Protecting stored and transmitted data
Banqa’s production security programme is designed around:
- HTTPS/TLS for website, app and service communications.
- Encryption and access restrictions appropriate to financial and authentication data.
- Separation of secrets from source code and routine operational output.
- Least-privilege access, controlled administrative paths and periodic access review.
- Logging and monitoring focused on authentication, abnormal access and service integrity.
- Backups, recovery procedures and deletion through defined retention cycles.
- Dependency review, patch management and security testing before material releases.
Encryption is a security control, not a claim that Banqa is technically unable to access every item it must process. Banqa will not describe the service as “zero access” unless that architecture has been independently implemented and verified.
Android notification detection
The optional Android feature requires operating-system permission. Its design goal is to identify supported spending notifications on the user’s device and create only the expense data the feature needs, rather than upload a general notification history. Permission can be revoked in Android settings.
Notification parsing can be wrong. Users should review detected amounts and merchants. iOS does not provide equivalent notification access, so this feature is not offered there.
Operational controls
Provider review
Providers handling hosting, email, AI, subscription or financial information are assessed for purpose, access, location and contractual safeguards.
Change control
Security-sensitive changes are reviewed, tested and deployed through controlled paths with secrets kept outside public files.
Availability
Monitoring, backups and recovery procedures are maintained in proportion to service risk. Connected data may still be delayed by banks or providers.
People
Production access is limited to authorised people with a business need and is removed when no longer required.
Incident handling
Banqa’s incident process is intended to identify, contain, investigate, recover and document security events. Where a breach creates a legal notification duty, Banqa will notify the relevant authority and affected users within the required timeframe. Events involving regulated account access will also be coordinated with the contracted provider.
Support may temporarily disconnect a bank integration, revoke sessions or restrict an account where reasonably necessary to protect users or investigate abuse.
Report a security concern
Email support@banqa.app with the subject Security report. Include the affected URL or feature, reproduction steps and the potential impact. Do not include real bank credentials or another person’s financial data.
Banqa does not currently operate a public bug-bounty programme. Good-faith reports will be acknowledged and triaged; do not exploit data, disrupt the service or publish an issue before there has been a reasonable opportunity to address it.