1. Introduction
This Privacy Policy explains how CapitalMap (“CapitalMap”, “we”, “us”, or “our”) collects, uses, stores, processes, and shares information when you use our website and related services (the “Service”).
CapitalMap is a personal wealth tracking and visualisation tool. It is designed to help you organise and view financial information that you choose to enter or connect. It is not a bank, broker, custodian, payment service, credit rating agency, or registered investment adviser.
By accessing or using the Service, you acknowledge that you have read this Privacy Policy. If you do not agree, do not use the Service.
2. Important summary (read this first)
- Your detailed financial balances and portfolio records are intended to live primarily in your own Google Spreadsheet (your “Vault”), which you create through the Service.
- To display and update that information in the CapitalMap interface, our servers access your Vault with your authorisation (via Google OAuth) and may temporarily process that data. This is not “zero-knowledge” cryptography: when you use the Service, authorised processing of Vault contents is required for the product to function.
- We store limited account and connection metadata (for example identity information and spreadsheet identifiers) needed to operate authentication and Vault access. We do not intend to maintain a permanent multi-tenant database of your balances as our system of record.
- Figures shown in CapitalMap depend on data you enter and on Google Sheets / third-party availability. We do not guarantee accuracy, completeness, or fitness for any financial decision.
- CapitalMap is in an initial / early-access phase. Bugs, sync issues, downtime, or incorrect displays may occur. Do not treat the Service as a sole source of truth for financial decisions. See our Terms of Service (Early access section).
3. Information we collect
3.1 Account and identity information
When you sign in with Google, we receive information from Google’s authentication services such as your Google account identifier, email address, and display name / profile photo (if provided by Google). We use this to create and maintain your CapitalMap session and account.
3.2 Vault connection information
To connect your Spreadsheet Vault we store information such as your spreadsheet identifier (and related connection metadata) and OAuth credentials or tokens needed to access Google Sheets on your behalf. Tokens may be stored securely on our systems (for example encrypted at rest where configured) and used only to provide the Service.
3.3 Financial and portfolio content
Content you place in your Vault (assets, liabilities, expenses, goals, snapshots, events, notes, labels, amounts, and similar fields) is processed by the Service when you sync, view, create, edit, or delete records. Processing includes reading and writing via the Google Sheets API and generating on-screen calculations (for example totals, allocations, and progress indicators).
Your browser may also cache a local copy of synced Vault data (for example in IndexedDB) to improve performance. Clearing site data, logging out, or using device controls may remove that cache.
You may also use CapitalMap as a guest without signing in. In that mode, assets, liabilities, goals, and related records you enter are stored only in your browser (IndexedDB) on that device. We do not receive a copy of those records until you sign in and choose to import them into your Google Spreadsheet Vault. Guest data is lost if you clear site data, use another browser or device, or decline import after sign-in.
3.4 Usage, device, and analytics information
We use Google Analytics (GA4) to understand product usage (for example page views and feature events such as create/update/delete of record types). We configure analytics to avoid intentionally sending personal identifiers such as email addresses, names, sheet URLs, monetary amounts, or free-form search text. Analytics may still collect standard technical data via Google’s systems (for example approximate location derived from IP, device/browser type, and event timestamps), subject to Google’s policies.
3.5 Support communications
If you email us, we process the content of your message and contact details to respond. Please avoid sending passwords, full account numbers, or unnecessary sensitive financial documents.
3.6 Information we do not intentionally collect
We do not ask for government ID numbers, bank login credentials, or card CVV as part of standard product use. Do not submit such information through the Service.
4. How we use information
We use information to:
- Authenticate you and maintain sessions;
- Let guests store tracker records locally in the browser until they import a Vault;
- Connect to, read from, and write to your authorised Google Spreadsheet Vault;
- Display dashboards, charts, lists, and calculations you request;
- Provide onboarding, settings, sync, and support;
- Monitor reliability, security, abuse, and product improvement via analytics;
- Comply with law and enforce our Terms of Service;
- Communicate service-related notices (for example security or material policy changes).
We do not sell your personal information. We do not use your Vault balances to train public AI models or to provide advice tailored as a regulated financial service.
5. Legal bases / purposes (where applicable)
Depending on your location, we process information because it is necessary to perform our contract with you (providing the Service), because we have legitimate interests in running a secure and useful product, because you have given consent (for example Google OAuth scopes), and/or to comply with legal obligations. Where consent is required, you may withdraw it by disconnecting Google access, deleting your Vault connection, or stopping use of the Service, subject to residual technical and legal retention needs.
6. Sharing and third parties
We share information only as needed to operate the Service, including with:
- Google — Authentication, Google Sheets API access, and Google Analytics. Your use of Google products is also governed by Google’s terms and privacy policies.
- Infrastructure providers — Hosting, databases, and related cloud services used to run CapitalMap (for example authentication and metadata storage).
- Professional advisers or authorities — If required by law, legal process, or to protect rights, safety, and security.
- Business transfers — If we undergo a merger, acquisition, or asset sale, information may transfer as part of that transaction under appropriate confidentiality.
We do not control Google’s independent processing of data in your Google Account or Spreadsheet. You remain responsible for Google Account security and Spreadsheet sharing settings.
7. Retention
Account and connection metadata are retained while your account is active and for a reasonable period afterward for security, dispute resolution, and legal compliance. Temporary processing artefacts, logs, and caches may exist for short operational periods. Local browser caches persist until cleared. Analytics data is retained according to our analytics provider’s settings and policies.
Because your Vault is a Google Spreadsheet you control, deleting CapitalMap account metadata does not automatically delete the Spreadsheet in your Google Drive. You must manage or delete that file in Google if desired.
8. Security
We implement reasonable technical and organisational measures appropriate to the nature of the Service (for example encrypted transport, access controls, and session cookies). No method of transmission or storage is 100% secure. You are responsible for protecting your Google Account, devices, and Spreadsheet permissions.
9. Your choices and rights
- Revoke CapitalMap’s Google access from your Google Account permissions.
- Disconnect or replace your Vault connection within the Service (where available).
- Log out and clear browser site data / local caches.
- Request account-related assistance by emailing capitalmapin@zohomail.in.
Depending on applicable law (including, where relevant, India’s Digital Personal Data Protection Act, 2023, and other privacy laws), you may have rights to access, correction, erasure, or withdrawal of consent. We will respond to verifiable requests as required by law. We may need to verify your identity and may retain information where legally permitted or required.
10. Children
The Service is not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has provided information, contact us and we will take appropriate steps.
11. International processing
We and our processors may process information in India and other countries where our service providers operate. By using the Service you understand that information may be transferred to jurisdictions with different data-protection rules.
12. Changes
We may update this Privacy Policy from time to time. The “Last updated” date will change when we do. Material changes may be highlighted in the Service or by other reasonable notice. Continued use after the effective date constitutes acceptance of the updated Policy.
13. Contact
Privacy questions: capitalmapin@zohomail.in
See also our Terms of Service.
This document is provided for transparency and risk allocation. It is not a substitute for personalised legal advice. CapitalMap may update practices; if a conflict arises between marketing slogans and this Policy, this Policy and the Terms of Service control.