Data Security at Finmap
Finmap connects to your bank accounts, payment processors, and accounting tools to build your cash flow picture — which means the platform handles financial data that businesses are right to be careful about before connecting anything. This page explains how that data is handled.
Read-Only Bank and Account Connections
Connections to your bank, payment processor, or accounting software are read-only. Finmap reads transaction data to build your reports and forecasts; it cannot move money, initiate payments, or make changes to the connected accounts. Your funds and your login credentials stay with your bank or provider at all times — Finmap aggregates the data, it does not hold or control it.
Encryption, Hosting, and Subprocessors
Financial data is encrypted both in transit and at rest, and access within Finmap is limited to what's needed to operate the service. Finmap uses a limited set of infrastructure and service providers (subprocessors) to run the platform; a current list, along with details on data hosting and residency, is available on request — businesses with specific residency requirements should raise them before connecting live accounts.
Access Control
Within your own Finmap account, you control which team members can see which data through user roles and permissions. Access to customer data by Finmap's own staff is role-based and limited to what support and operations require.
GDPR, Backups, and Incident Response
Businesses operating under GDPR that need a Data Processing Agreement (DPA) should request one directly from Finmap's team. Backup and retention practices for customer data, and how Finmap handles and discloses security incidents that affect customer data, are available on request — including specific retention periods and incident-response timelines.
Questions Before You Connect
If you need specifics for a vendor security review or an internal compliance checklist before connecting your accounts, contact Finmap directly and they can walk through the hosting, encryption, and data-handling details relevant to your situation.