
Pre-production notice
Privacy at Bank Spree
Last updated September 9, 2026. This notice describes Bank Spree’s current architecture and planned handling of provider-backed financial data. It will be finalized with a monitored privacy contact and jurisdiction-specific retention schedule before public launch.
Information Bank Spree handles
Bank Spree stores account identity information, the bonus offers and Sprees you choose to track, normalized financial-account metadata, normalized transaction activity needed to evaluate requirements and detect rewards, confirmed earnings history, billing enrollment state, and payment outcomes. Bank Spree does not collect or store online-banking usernames, passwords, or full payment-card numbers.
Why the information is used
Information is used to authenticate you, connect accounts with your consent, track frozen promotional requirements, explain progress, identify and verify reward payments, provide billing, secure the service, and meet legal obligations. Bank Spree does not use AI to decide financial qualification.
Providers and disclosure
Bank Spree uses contracted infrastructure, financial-data, email-delivery, and payment providers only to operate the service. Plaid supports connected financial data and Stripe processes billing and stores payment credentials. Provider access is limited to the data and purpose required. Bank Spree does not sell personal or financial information. A financial institution remains responsible for qualification and payout decisions.
Retention and deletion
Bank Spree minimizes stored financial data and retains it only while needed to provide the service, maintain user-requested history, secure the platform, or satisfy legal requirements. Before production financial connectivity launches, the retention schedule and disconnect/account-deletion workflows will be finalized, tested, and published. Users may request access, correction, disconnection, or deletion through the production privacy contact.
Security
Bank Spree uses encrypted transport, managed encryption at rest, server-only provider credentials, least-privilege access, row-level owner isolation, immutable financial-history controls, dependency review, and tested authorization boundaries. No internet service can guarantee absolute security.
Your choices
Connecting a financial account is optional and requires an explicit consent flow. Users can decline connection, review tracked activity, disconnect a provider connection, and exercise applicable privacy rights. Production account deletion will revoke provider access before deleting or retaining data according to the published schedule.
Contact and changes
The monitored security/privacy contact and public production URL are pre-launch requirements. Material changes to collection, use, or retention will be reflected here before they take effect.