SpendWayEffective Date: 31 May 2026
At SpendWay, your privacy is fundamental to how we build and operate our platform. This Privacy Policy explains what information we collect, how we use it, what we share (and what we do not share), and your rights regarding your data.
This policy applies to all users of spendway.lk and the SpendWay applications. The Service is operated by Spendway Pvt Ltd, a company incorporated in Sri Lanka.
When you register for SpendWay, we collect:
For each account you create within SpendWay, you may provide:
You may enter or import transaction data through the following means:
Transaction data collected includes:
If you use the statement extraction feature, you may upload bank statements or similar financial documents. These are processed as described in Section 4 and are not stored in raw form beyond what is needed to complete the extraction.
We may collect technical information about how you use the Service, including:
This information is used to improve the Service, diagnose issues, and maintain security. It is not linked to your individual transaction or financial data.
We use your account and transaction data to:
We may use your email address to:
Aggregated and anonymised usage data may be used to understand how the Service is used and to improve its features and performance.
Spendway Pvt Ltd collects the following aggregated, anonymised platform metrics for internal analytics purposes:
These metrics are statistical in nature and cannot be used to identify any individual user.
SpendWay uses AI to help you generate expense reports. We are committed to sharing the minimum data necessary for this purpose.
When you generate an AI-assisted report, the following fields, and only these fields, are sent to the AI service:
Per account:
accountId: an internal database identifier assigned by SpendWay. This is not your bank account number, email address, or any information you have provided;accountType: the account type label you have set.Per transaction (array):
description, tags, category, amount, datetimeThe following are never sent to the AI:
When you upload a bank statement or other financial document, SpendWay provides document preparation tools and processes your submission as follows:
Step 1: Document preparation
Before submitting, you configure redaction areas, page rotation, and page exclusion using the in-app tools. You are responsible for correctly marking all content you wish to redact or exclude.
Step 2: Processing and text extraction
SpendWay applies your configuration (redactions, rotations, and page exclusions) and extracts text from the processed pages. This all occurs within our secure systems. No raw document content leaves our infrastructure.
Step 3: AI processing
Only the extracted text is sent to our AI service to identify and structure transactions. The AI returns a list of transactions, nothing more.
Step 4: Document handling
Documents are not retained beyond the extraction process. Extracted transaction data is stored in your SpendWay account and subject to the retention policy in Section 10.
If you enable the SMS sync feature, SpendWay monitors incoming SMS messages to identify and import transactions from supported banks. The following applies:
To be explicit, Spendway Pvt Ltd does not:
We use third-party AI services to power the expense report and statement extraction features. These providers receive only the minimum data described in Sections 3 and 4. They are contractually prohibited from using this data for any purpose other than delivering the requested AI functionality.
We use cloud hosting and infrastructure providers to operate the Service. These providers have access to data only as needed to run the platform and are bound by confidentiality obligations.
We may disclose information if required to do so by the laws of Sri Lanka, a court order, or a lawful request by a governmental authority, or where we believe in good faith that such disclosure is necessary to protect the rights, property, or safety of Spendway Pvt Ltd, our users, or the public.
In the event of a merger, acquisition, or sale of all or substantially all of Spendway Pvt Ltd's assets, your data may be transferred to the acquiring entity. We will notify you of any such transfer and any material changes to how your data is handled.
We implement industry-standard security measures to protect your data, including:
While we take security seriously, no system is completely immune to attack. You are encouraged to use a strong password and to contact us immediately at support@spendway.lk if you suspect your account has been compromised.
In the event of a data breach involving your personal data, Spendway Pvt Ltd will:
If you suspect that your account has been compromised or that your data may have been accessed without authorisation, please contact us immediately at security@spendway.lk.
This inbox is monitored exclusively for security and data breach-related reports. SpendWay is not obligated to respond to non-security matters sent to it. General support enquiries should be directed to support@spendway.lk, and data privacy requests to privacy@spendway.lk.
We retain your account and transaction data for a period of 2 years from the date the data was created or your account last active, whichever is later. After this period, data is deleted from our active systems.
If you delete your account before the 2-year period:
Under applicable Sri Lankan law and as a matter of our policy, you have the following rights regarding your personal data:
To exercise any of these rights, please contact us at privacy@spendway.lk.
SpendWay may use cookies and similar technologies for:
We do not use tracking cookies for advertising purposes. You can configure your browser to refuse cookies, though this may affect your ability to use certain features of the Service.
SpendWay is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at support@spendway.lk and we will take steps to remove it promptly.
SpendWay does not have a data-sharing relationship with any bank or financial institution. When you reference a bank within SpendWay (e.g. by selecting a bank logo to label an account), this is a cosmetic label within the app only. It does not cause any data to be sent to or received from that institution.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or via a notice in the app before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the revised policy.
This Privacy Policy is governed by the laws of the Democratic Socialist Republic of Sri Lanka.
If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact us:
Spendway Pvt Ltd