Privacy Policy
Last updated
Ce document est publié uniquement en anglais, et c’est le texte anglais qui fait foi.
The short version
- Banxta does not ask for your name, your company’s name or any documents. It asks for your email address only if you choose to ask us about a human review of your application.
- Your answers to the check are kept in your browser and in the address of your result. We do not keep them on our servers unless you ask us about a human review, and there are no accounts.
- Anyone who has the link to your result can see your answers. Share it only with people you would show the answers to.
- We count visits with PostHog in a mode that stores nothing in your browser. We use no advertising cookies.
Who we are
Banxta is a free service that compares a company’s answers to seven questions with the published policies of business account providers, such as banks and electronic money institutions. It has two parts: this website, and the check, where you answer the questions and see your result. This policy covers both.
Banxta (“we”, “us”) is run by a private individual resident in Spain. We decide what personal data Banxta processes and why, which makes us the controller of that data.
For anything about this policy or your data, write to info@banxta.app.
What the check asks
The check asks seven questions about your company. Every answer is chosen from a list; there is no free-text field. The questions are:
- the country where the company is incorporated, or where you plan to incorporate it;
- what the business does, as a category;
- which licences the company holds, if any;
- where the owners with 25% or more live, and which citizenships they hold, as regions or countries;
- whether money will move to or from crypto exchanges;
- the expected annual volume through the account, as a range;
- the currencies you need.
Before the first question you choose your situation: planning ahead, applying now, or an account that was frozen or closed. After your result you can answer optional follow-up questions: where the directors live, whether you hold client money or pay out to third parties, where your customers are, whether they are businesses or consumers, and whether a provider has refused you before.
If you arrived through a link that carries a source label or a partner code, the check keeps that code with your answers, so we can tell which link people came from.
The check never asks for a person’s name, your company’s name or a document. It asks for contact details in one place only: the optional form on your result page for asking about a human review, described below. The answers describe a company in broad categories. Some of them, such as where the owners live, are about people, so we treat the answers as personal data wherever they could be linked to someone.
Where your answers go
In your browser, while you answer. The check keeps a draft in your browser’s local storage, under the name banxta.check.v1, and updates it after every change: your answers so far, the step you reached, any source or partner code, and the time. This lets you leave and come back. It stays on your device and is not sent to us. A draft that has not changed for 7 days is not used, and is deleted the next time you open the check. “Start over” clears your answers from it at once, and clearing your browser’s data for the site removes it.
To our server, when you finish. When you answer the last question, your browser sends the answers to our server, which works out your result and sends it back with a link to it. The server does not save the answers, and there are no user accounts. The one exception is a request for a human review, described below: it saves your answers only when you send it.
In your result link. The address of your result page contains your answers, encoded but not encrypted. Anyone who has the link can decode it, see your answers and open the same result. When you answer the follow-up questions, they are added to a new link. If you send the link by email or in a chat, those services see it too.
Each time a link is opened. Our server reads the answers from the link and works out the result again, using the provider information of that day, so the same link can show a different result later. The full report, at a similar address, works the same way. Result and report pages ask search engines not to index them.
If you ask about a human review
Your result page can offer a short form to ask us about a human review of your application. Human review is in pilot: sending the form does not start a review, and we do not promise one, a date or a price. It tells us that you would like us to get in touch about it. The form is optional, and the check works in full without it.
If you send it, we store:
- the email address you enter;
- the answers from your result link, as the categories you chose (your answers to the check, the situation you chose and any follow-up questions you answered), together with a link that opens the same result;
- the language of the page;
- the source label or partner code of the link you came from, if there was one;
- the time of the request, and where we are in handling it.
We store nothing else from the form. It has no free-text field, and it asks for no name, company name or document.
Where. Our server, not your browser, sends the request to a database run by Supabase, in the European Union (Frankfurt, Germany). Only we can read it.
Why, and on what basis. We use your email address and answers only to contact you about a review of your application. We also count requests, without the email addresses, to decide whether to offer reviews. We do not add you to a mailing list, send you marketing, or pass your details to any provider. The legal basis is your consent, which you give with the checkbox on the form. You can withdraw it at any time by writing to info@banxta.app, and we will delete your request. Withdrawing does not affect what we did before you withdrew.
How long. We keep a request, and any notice of it emailed to us, for 6 months after the request, or less if you ask us to delete it sooner.
A notice to us by email. If we switch it on, our server also emails us a notice of each request, with your email address, the language, any source or partner code and the link to your result. Resend, a US email delivery service, delivers that email to us and processes it for us for that purpose only.
Sending the form also records an analytics event, described under Analytics below. The event carries no email address and no part of your result link.
What we do not collect
- Names of people, and company names.
- Documents of any kind.
- Phone numbers.
- Email addresses, except the one you give us, with your consent, when you ask about a human review (see above). The option to email yourself a result is switched off. If we switch it on, we will need your email address to send the email. We will update this policy before that happens, to say who sends the email, why we hold the address and for how long.
- Payment details. Banxta is free during the pilot and takes no payments.
- Accounts or passwords. There are none.
Hosting
Both parts of Banxta are hosted by Vercel Inc. Like any web host, Vercel receives technical information about each request, such as your IP address, the address of the page, your browser’s user agent and the time, and keeps request logs to run and secure the service. For a result page, the address in those logs includes your encoded answers. Vercel processes this data for us as our hosting provider. The code that works out your result runs on Vercel’s servers in the United States.
Vercel keeps these logs for a limited period set by its own retention rules and our plan. Our own code writes no logs of your answers.
If you download your report as a PDF, our server opens your report page itself, in a browser it runs on Vercel for that one request, and sends you the file it prints. The file is made for that download and is not kept.
Analytics
We use PostHog, from PostHog’s EU Cloud in Frankfurt, Germany, to count visits and to see where people stop in the check. It runs on this website, and on the check when we switch it on there. We run it in PostHog’s cookieless mode, so it stores nothing in your browser: no cookies and no local storage.
With each page view and event, PostHog receives:
- the address of the page, and of the page you came from;
- your browser, operating system and device type, and your browser’s full user agent string;
- your screen size, browser language and time zone;
- the time.
PostHog’s servers also use your IP address and user agent, together with a random value that changes every day, to compute an identifier that counts one visitor within a day. PostHog’s documentation describes this as a one-way hash, says the daily value is deleted once that day’s events are processed, and says the IP address is removed before events are enriched, so no location is added to them. Because the daily value changes, the same visitor looks new each day, and we cannot recognise you from one day to the next.
Automatic capture of clicks and page text is off, and so are session recording, heatmaps and surveys. Besides page views and page leaves, our code can send only events from a fixed list: that a check started, that a question was answered, that a check was completed, that a result was viewed, that follow-up questions were answered, that the top match on a result was shown, that its preparation checklist, a provider’s sources or the full list of options was opened, that a provider’s own website was opened from a result or a report, your answer to “Was this useful?”, and that someone asked about a human review. They carry simple values: the step number, the situation you chose, the source label of the link you came from, how many providers are relevant to your answers and how many exclude them, a complexity rating, which follow-up questions you answered (not your answers to them), how many providers a result lists, a provider’s short name and its position in the list, how well a provider fits your answers, a reason chosen from a fixed list, where on the page a request for a human review was sent from, and where on the page a provider’s website was opened from. No event carries an email address, a name or free text.
On a result page the address itself contains your encoded answers. Before any event leaves your browser, on the check and on this website, that part of every address, including the address you came from, is replaced with a placeholder, so PostHog never receives your answers. Session recording is switched off.
PostHog keeps these events for the retention period of the PostHog plan we use, which on PostHog’s free plan is one year. Because they are not linked to you, we cannot pick out the events of one person.
Our code can also send page views to Plausible Analytics, another analytics service that uses no cookies. It is not switched on. We will update this policy before we switch it on.
Cookies and storage in your browser
Banxta uses one cookie and two browser storage entries. None of them is used for advertising, and none of them comes from another company.
bx_localeCookie, on this website and on the check- Holds the language of the last page you opened, for example “de”, and nothing else. When you come back to an address without a language in it, we use it to show you that language. It lasts one year. This website and the check each set their own, and they are not shared between the two.
banxta.check.v1Local storage, on the check only- Your draft, as described above. It stays on your device. A draft that has not changed for 7 days is not used, and is deleted the next time you open the check. “Start over” clears your answers from it at once, and clearing your browser’s data for the site removes it.
bx_locale_scrollSession storage, on this website and on the check- When you switch language, it remembers how far down the page you were, so the new page opens at the same place. It is read once and deleted straight away, and your browser discards session storage when you close the tab.
PostHog runs in cookieless mode and stores nothing in your browser.
Other services and links
Our fonts, images, flags and provider logos are served from our own servers, so opening a page does not send anything to a font service or to any provider. The only other service your browser contacts is PostHog, as described above.
If you write to us, your email reaches us through ImprovMX, an email forwarding service, into a mailbox hosted by Google (Gmail). We use your address and your message only to answer you.
If you ask about a human review, our server, not your browser, sends the request to Supabase and, if we have switched the notice on, to Resend, as described above.
Results and reports link to providers’ own pages: the published sources of the facts they quote and, for each provider that does not exclude you, the page on which it offers its business account. We add no tracking or referral parameters to these links and receive no payment for them. They open in a new tab, and they are set so that your browser does not pass the address of your result, which contains your answers, to the provider. If you follow one, you leave Banxta, and that provider’s own privacy policy applies.
Why we process this data
- Working out your result from your answers: this is necessary to provide the check you asked for.
- Hosting logs: our legitimate interest in running Banxta and keeping it secure.
- Analytics: our legitimate interest in knowing how many people use Banxta and where the check can be improved, using a method that stores nothing on your device and does not identify you.
- The language cookie and the two storage entries: our legitimate interest in showing you the language you chose and letting you leave the check and come back to it.
- A request for a human review, including the notice emailed to us: your consent, which you can withdraw at any time.
How long we keep it
- Your answers: we do not keep them, unless you ask about a human review. They exist in your browser’s draft, which the check stops using after 7 days without a change and deletes the next time you open it, and in any result link, for as long as someone keeps that link.
- A request for a human review, with your email address and answers: 6 months after the request, or less if you ask us to delete it sooner, or until you withdraw your consent, if that is sooner.
- Hosting logs: for the period Vercel keeps them, as described above.
- Email you send us: for as long as we need it to deal with your message, and then we delete it.
- Analytics events: the retention period of the PostHog plan we use, which on PostHog’s free plan is one year.
Where the data is processed
Vercel is a US company, and the code that works out your result runs in the United States. Where data leaves the UK or the European Economic Area this way, it relies on Vercel Inc.’s certification under the EU-U.S. Data Privacy Framework and its UK Extension. PostHog stores our analytics data in its EU Cloud in Frankfurt, Germany.
Requests for a human review are stored by Supabase in the European Union (Frankfurt, Germany). If we switch on the notice emailed to us, Resend, a US company, delivers it. Where your email address leaves the UK or the European Economic Area this way, it relies on Resend’s certification under the EU-U.S. Data Privacy Framework and its UK Extension, and on the standard contractual clauses in Resend’s data processing addendum.
Your rights
Depending on where you live, data protection law gives you rights over your personal data: to access it, to correct it, to have it deleted, to restrict or object to its use, and to receive a copy of it. In practice we hold very little that we could link to you:
- Your draft answers are only in your browser. Choose “Start over”, or clear your browser’s data for the site, to delete them.
- Your answers in a result link exist wherever that link is kept. We cannot recall a link you have shared.
- Analytics events are not linked to you, so we cannot find one person’s events.
- If you asked about a human review, we hold your email address and the answers from your result link. Write to info@banxta.app to see them, correct them, have them deleted or withdraw your consent.
If you think we hold personal data about you, or you want to use any of these rights, write to info@banxta.app. You also have the right to complain to a data protection authority: the Spanish Agencia Española de Protección de Datos (AEPD), in the country where we are based, or the one in the country where you live or work.
Children
Banxta is a service for businesses and is not meant for children.
Changes to this policy
We will update this page before we change what Banxta collects, and change the date at the top. Two changes we already know would need an update first: switching on the email option, and switching on Plausible Analytics.
Contact
Banxta, Spain.
Data protection requests: info@banxta.app.
Anything else: info@banxta.app.