CrosswindFinance Privacy Policy
Effective Date: September 17, 2026
CrosswindFinance respects your privacy and is committed to protecting the information entrusted to us. This Privacy Policy explains what information CrosswindFinance collects, how we use it, when it may be shared, and the choices available to you when you use the CrosswindFinance website and application.
For purposes of this policy, "CrosswindFinance," "we," "us," and "our" refer to the CrosswindFinance service. "Customer" or "organization" refers to an organization that establishes a CrosswindFinance account, and "user" refers to an individual who accesses CrosswindFinance on behalf of an organization.
1. Information We Collect
Account and Identity Information
When you create or use a CrosswindFinance account, we may collect information such as:
- Your name
- Email address
- Account credentials
- Organization membership and role
- Email confirmation and account-security information
- Multi-factor authentication and passkey information where those features are used
Passwords are handled through the application's authentication system and are not stored as readable plain-text passwords.
Organization Information
We collect information supplied when creating or managing an organization, including:
- Organization name
- Organization URL or subdomain
- Organization membership
- User roles and permissions
- Uploaded logos, favicons, and other organization branding
- Subscription plan and account status
Financial and Business Information
CrosswindFinance is designed to store information that customers provide for budgeting, accounting, and financial-management purposes. This may include:
- Budgets and budget categories
- Financial account names and balances
- Income and expense transactions
- Transaction dates and amounts
- Vendors and payees
- Memos and reference numbers
- Funds and classifications
- Reconciliation information
- Imported financial records
- QuickBooks or other accounting data imported by the user
- CSV or other supported data files
- Receipts, invoices, and other transaction attachments
- Reports and information derived from customer financial data
The information stored in CrosswindFinance depends on what the customer chooses to enter, upload, or import.
Payment and Subscription Information
Paid subscriptions are processed using Stripe.
CrosswindFinance may store information needed to maintain your subscription, including Stripe customer, subscription, and price identifiers and subscription status.
Payment-card information submitted during Stripe checkout is processed by Stripe. CrosswindFinance does not store your complete payment-card number or card security code in its application database.
Invitations and Communications
When an organization invites another person to CrosswindFinance, we may collect the invitee's:
- Email address
- Assigned organization role
- Invitation status
- Invitation creation, expiration, and acceptance information
We also maintain information necessary to send account confirmations, password resets, invitations, application notifications, and other service-related email.
Technical and Security Information
When you use CrosswindFinance, our systems and hosting providers may automatically process technical information necessary to operate and secure the service, including:
- IP address
- Request and access information
- Authentication and session information
- Security and rate-limiting information
- Application errors and diagnostic information
- Browser or device information made available through ordinary web requests
We use this information primarily to provide, protect, troubleshoot, and improve the service.
2. How We Use Information
We use information collected through CrosswindFinance to:
- Create and administer user accounts
- Create and operate customer organizations
- Authenticate users
- Enforce organization roles and permissions
- Provide budgeting, transaction, accounting, reconciliation, reporting, and related features
- Import and process information submitted by users
- Store files and attachments requested by customers
- Process subscriptions and maintain billing status
- Send account confirmations, invitations, password resets, security notices, and service communications
- Provide customer support
- Maintain application security
- Detect or prevent fraud, abuse, unauthorized access, and other security threats
- Diagnose application problems
- Maintain and improve CrosswindFinance
- Comply with legal obligations and enforce our agreements
We do not use customer financial records for the purpose of selling those records to advertisers or data brokers.
3. Customer Data and Organization Access
Information entered into an organization's CrosswindFinance workspace belongs to that organization's account and is accessible only according to the organization's assigned user roles and permissions.
Organization administrators control which users they invite and what level of access those users receive.
CrosswindFinance uses tenant-based data isolation so that users of one organization are not intended to have access to another organization's financial information.
Users should not share account credentials or provide access to individuals who are not authorized to view their organization's information.
4. How We Share Information
We do not sell customer financial records.
We may disclose information in the following circumstances.
Service Providers
We use third-party service providers to operate CrosswindFinance. These providers may process information only as necessary to provide services to us, including:
- Cloud application and database hosting
- Payment processing
- Email delivery
- Domain, network, security, and infrastructure services
For example, CrosswindFinance uses Microsoft Azure infrastructure for production hosting and Stripe for subscription billing.
Within Your Organization
Information stored in your organization's workspace may be visible to other authorized users of that organization based on their assigned roles and permissions.
Legal and Security Requirements
We may disclose information when we reasonably believe disclosure is necessary to:
- Comply with applicable law, regulation, court order, subpoena, or other legal process
- Protect the rights, property, or safety of CrosswindFinance, our customers, users, or others
- Investigate fraud, security incidents, abuse, or unauthorized activity
- Enforce our agreements or policies
Business Transfers
If CrosswindFinance or substantially all of its assets are involved in a merger, acquisition, financing, reorganization, or sale, information associated with the service may be transferred as part of that transaction, subject to applicable law.
5. Cookies and Similar Technologies
CrosswindFinance uses cookies and related browser technologies necessary to operate the application.
These may be used for purposes such as:
- Maintaining authenticated sessions
- Protecting account security
- Supporting authentication and multi-factor authentication
- Preventing unauthorized requests
- Remembering application or interface preferences
Disabling essential cookies may prevent portions of CrosswindFinance from functioning correctly.
If we later introduce additional analytics, advertising, or other non-essential tracking technologies, we may update this Privacy Policy and provide additional choices where required.
6. Data Storage and Security
CrosswindFinance takes reasonable administrative, technical, and organizational measures designed to protect information against unauthorized access, alteration, disclosure, or destruction.
These measures include technologies and practices such as authenticated access, role-based authorization, organization-level data isolation, secure HTTPS communications, account lockout and rate-limiting protections, and restricted access to production systems.
No internet service or electronic storage system can be guaranteed to be completely secure. Users are responsible for maintaining the confidentiality of their login credentials and for notifying us if they believe their account has been compromised.
7. Data Retention
We retain information for as long as reasonably necessary to:
- Provide the CrosswindFinance service
- Maintain customer accounts
- Meet contractual obligations
- Resolve disputes
- Maintain security and audit information
- Comply with applicable legal, tax, accounting, or regulatory requirements
Information may remain temporarily in backups or disaster-recovery systems after it has been removed from active systems.
We may retain limited information when necessary to document transactions, enforce agreements, prevent fraud or abuse, or comply with legal obligations.
8. Accessing, Correcting, Exporting, or Deleting Information
CrosswindFinance provides account-management functionality that allows users to review certain personal account information.
Users may also have options to download or delete personal account information.
An organization's financial and business information may belong to the customer organization rather than an individual user. Requests involving organization data may therefore need to be made by an authorized organization owner or administrator.
You may contact us to request assistance with:
- Accessing personal information
- Correcting inaccurate personal information
- Obtaining a copy of personal information
- Deleting personal information
- Questions concerning retention of your information
Some information may need to be retained when required by law or for legitimate security, accounting, contractual, or operational purposes.
9. Data Submitted by Organizations
Customers are responsible for determining what information they enter, upload, import, or otherwise provide to CrosswindFinance.
Customers should ensure they have the authority to provide information concerning their employees, members, vendors, donors, customers, or other individuals.
CrosswindFinance processes organization data for the purpose of providing the service requested by the customer.
10. Sensitive Information
CrosswindFinance may contain financial information that customers consider sensitive.
Users should avoid entering highly sensitive personal information that is not necessary for the use of CrosswindFinance, such as Social Security numbers, complete payment-card numbers, authentication credentials for other services, medical information, or other information unrelated to the application's intended financial-management functions.
11. Children's Privacy
CrosswindFinance is intended for use by businesses and organizations and is not designed for children under 13.
We do not knowingly solicit personal information directly from children under 13. If we learn that such information has been provided directly by a child without appropriate authorization, we will take reasonable steps to remove it.
12. Third-Party Services
CrosswindFinance may interact with or provide links to third-party services.
Those services operate under their own terms and privacy policies. CrosswindFinance is not responsible for the privacy practices of third-party websites or services that we do not control.
Stripe's handling of payment information, for example, is governed by Stripe's own privacy practices.
13. Changes to This Privacy Policy
We may update this Privacy Policy as CrosswindFinance changes or as legal or operational requirements evolve.
When we make material changes, we will update the effective date above and may provide additional notice through the application or by email when appropriate.
Continued use of CrosswindFinance after an updated policy becomes effective is subject to the updated policy, to the extent permitted by applicable law.
14. Contact Us
Questions or requests concerning this Privacy Policy or the handling of personal information may be sent to:
CrosswindFinance
Email: privacy@crosswindfinance.com
Website: https://crosswindfinance.com
