Cash Flow Frog logo

Privacy Policy

Privacy Notice
Last updated: July 29, 2026
Prior versions of this Privacy Notice can be found at https://cashflowfrog.com/privacy-policy/.

About this Privacy Notice

This Privacy Notice is meant to give you information about what personal data we collect about you, how we use it, why we use it, and how you control the data processing.

Table of Contents

  1. The Basics: Who We Are, Our Role, and Definitions
  2. Personal Data we Collect as a Processor
  3. Personal Data We Collect as a Controller, How We Use it, and Why
    1. Website Visitors
    2. Users
    3. Visitors to Our Social Media Pages
  4. Our Marketing Activities
  5. Sharing the Personal Data We Collect
  6. International Transfers
  7. Security
  8. Your Rights - How to Control Our Use of Your Personal Data
  9. Data Retention
  10. Cookies and Similar Technologies
  11. Third-Party Services
  12. Minors
  13. Changes to the Privacy Notice

  14. The Basics

    1. Who We Are

      1. We, FinBoard Ltd. (d/b/a “Cash Flow Frog”) offer cloud-based cash flow forecasting and monitoring services on a software-as-a-service basis through our online platform ("Platform"). We also maintain an informational website at www.cashflowfrog.com, which provides information about our company and the Platform but is not used to deliver our services (the “Website”). References in this Privacy Notice to “Services” mean the Platform and any related tools, features, or integrations or services we make available from time to time. Our offices are located at Sapir 7, Herzliya Israel .

      2. If you have questions about our company or your privacy, or want to exercise your rights, you can contact us at contact@cashflowfrog.com.

    2. Our Role: Controller and Processor. Certain data protection laws, including the laws in the EU, differentiate between a party that determines why and how personal data is processed (called a "controller") and a party that processes personal data solely on the controller's behalf and according to the controller's instructions (called a "processor"). We are the controller in respect of the processing described in this Privacy Notice. That said, in respect of the cash flow and financial data that we process in order to provide you with our Services (including data collected from your connected accounting software, banking platforms, and other third-party integrations), we serve as a processor on behalf of our customer (being the business entity that has entered into an agreement with us for receiving the Services, a “Customer” and "Customer Agreement" respectively). Please see the section below on Personal Data We Collect as a Processor for more information.

    3. Definitions and Recommendations

    1. When we refer to “Services", we mean our Platform and any related tools, features, or integrations we make available from time to time.
    1. When we refer to "personal data", we mean information that is defined as personal data under law. This includes information that identifies you directly or indirectly, including unique identifiers like IP addresses or cookie IDs.
    1. When we refer to "you", we mean visitors to our Website, and any user of our Services, as applicable and indicated in this Privacy Notice.
    1. This Privacy Notice is meant to be read together with our Terms of Service available at https://cashflowfrog.com/terms-conditions/ (the “Terms of Service”), and, where applicable, the Customer Agreement between us and your organization. In general, we recommend that you routinely review this Privacy Notice and your preferences on our Platform and/or Website (as applicable).
    1. A Note on Legal Bases. Certain jurisdictions only allow the processing of personal data where a legal basis has been established. Under the EU's General Data Protection Regulation ("GDPR"), the possible legal bases include (but are not limited to): your consent, the processing is necessary to perform a contract with you, the processing is necessary to fulfill our legal obligations, or a company has a legitimate business interest to process your personal data. Where we are a controller, we only collect and process data where we have established a legal basis. Below you can find more details about specific legal bases. You are not required under law to provide us with the Personal Data described in this Privacy Notice. However, if you do not agree to provide the same, we will not be able to provide you with some or all of our services.
  15. Personal Data We Collect as a Processor. When a Customer connects its accounting software (such as QuickBooks, Xero, Sage Intacct, Zoho Books, FreshBooks, Odoo, Zapier or other supported platforms), banking accounts (via Plaid or similar services), or third-party services via MCP (Model Context Protocol) integrations (including AI chatbot features) to our Services, we extract and process financial, business, and other data on the Customer’s behalf, including invoices, transaction records, client and vendor details, employee information, bank account transaction data, and data processed through MCP integrations. This data may contain personal data about the Customer’s clients, vendors, employees, and other business contacts. In that case, we serve as a processor and the Customer serves as the controller. We process that data on the Customer’s behalf and according to its instructions, as set out in the applicable Customer Agreement (including any data processing addendum thereto), in order to provide the Customer with Services. We may share this data with the relevant Customer or its authorized users, in the scope of providing the Services. To learn more about our processing activities in this capacity or to exercise your privacy rights regarding them, please contact the applicable Customer directly.

  16. Personal Data We Collect as a Controller, How We Use It, and Why. Below is a description of the types of personal data we collect, how we use it, and the reason why we consider each use lawful. You have no legal obligation to provide us with personal data, but if you do not provide us with certain information, we may not be able to provide you with the associated services.

    1. Website Visitors. Our Website is an informational site that provides information about our company and the Platform. When you visit our Website, we may collect the following types of data about you.
    1. Contact Form Information – When you send us a message through the contact form on our Website, we collect any data you provide, such as your name, email address, and the content of your message.

      How We Use this Data: To respond to your message or inquiry. We also add this information to our customer relationship management (CRM) tool and our promotional email lists.

    Legal Basis: When we process this data to respond to your inquiry, the applicable legal basis depends on the nature of your inquiry. Where your inquiry relates to engaging or purchasing our Services (for example, a request for a demo, a pricing inquiry, or a request to enter into a contract), we process your personal data on the basis that such processing is necessary in order to take steps at your request prior to entering into a contract. Where your inquiry is of a general nature and does not relate to the engagement of our Services, we process your personal data on the basis of our legitimate interests in receiving, managing, and responding to inquiries directed to us. We send you newsletters and promotional communications in compliance with applicable law. When we send you such communications, we do so based on our legitimate interests to maintain a relationship with our customer base.

    1. Activity and System Data (Including Cookies) – When you visit our Website, we automatically collect certain data about your computer or mobile device. Some of this data is collected through essential means (such as server logs and necessary cookies) and includes your IP address, device ID, and basic usage data. In addition, we may collect further data through non-essential cookies (such as analytics and advertising cookies), including browsing history (e.g. the other sites you've visited before ours), detailed usage data, metadata, and your activity on our Website (e.g. what pages you visited, for how long, and what links you clicked on). For more information about the cookies we use and how to adjust your preferences, see the Cookies and Similar Technologies section below.

      How We Use this Data: We mainly use this data to generate aggregated analytics data about the use of our Website so we can maintain and improve the Website and develop new products or services. We also use this data to provide and maintain the Website, prevent fraud and protect the security of our Website. In addition, we use analytics data for company and business management purposes, including customer retention, analyzing usage patterns and predicting customer needs, identifying market and customer trends and preferences, and creating lookalike audiences that allow us to identify new potential customers. Some cookies may be used for retargeting purposes - to provide you with advertising for our products and services, based on your preferences and interests. One of the tools we use to collect and analyze this data is "Google Analytics". For more information about how Google collects information and how you can control such use, see: www.google.com/policies/privacy/partners/.

      Legal Basis: We process data collected through essential means (such as server logs and necessary cookies) for two purposes, each with its own legal basis. To the extent such processing is necessary for the provision and maintenance of the Website to you, we do so on the basis that such processing is necessary for the performance of a contract with you, or to take steps at your request prior to entering into a contract. To the extent such processing relates to the development and improvement of our products and services and the prevention of fraud, we do so on the basis of our legitimate interests to maintain our assets. We process data collected through non-essential cookies (such as analytics and advertising cookies) based on your consent. You may withdraw your consent at any time by adjusting your cookie preferences. Additional information regarding Our Marketing Activities is provided below.

    1. Users. If you are a registered user of our Services, we collect the following information from and about you.

      1. Registration Data – In order to access our Platform, you must first create an account. When creating an account, you will be asked to provide your name and email address. If you access our Platform using a third-party login service (such as Google or Microsoft), we also receive personal data about you from that service, such as: your name, email, and phone number.

      How We Use this Data: We use your registration information to allow you to access our Platform, save your preferences, protect the security of our Platform, prevent fraud, and address any issues that arise. We use your contact details to communicate with you about our Platform. We also use your contact details to send you informational newsletters and marketing materials about our products and services. For more information about our marketing activities and how you can control your preferences, see the section on Our Marketing Activities below.

      Legal Basis: When we process your registration data to provide you with our Services, we do so to perform a contract with you, in this case our Terms of Service (and, where applicable, the Customer Agreement). When we process your registration data to maintain our Platform, including to prevent fraud, protect the security of and/or address issues with our Platform, we do so on the basis of our legitimate interest to maintain our assets. When we use your contact details to send you newsletters and marketing materials, we do so based on your consent. You may withdraw your consent at any time by emailing us at contact@cashflowfrog.com.

      1. Payment Data – If you purchase a subscription for our Services, your payment is processed by our third-party payment processor. We receive general transaction data (such as the date, amount, and subscription plan) and a tokenized reference from our payment processor that allows us to identify and manage your transactions. We do not directly store your full credit card number or payment credentials.

    How We Use this Data: To process your payment, manage your subscription, and to prevent fraud.

    Legal Basis: We process your payment data to perform a contract with you, specifically our Terms of Service and/or the Customer Agreement (if applicable). When we process your payment data to prevent fraud, we do so based on our legitimate interest to protect ourselves and our customers.

    1. Activity and System Data (Cookies) – We collect data about your device and your activity, as described more fully above in Section 3.1.2, when you use our Platform.
    1. Visitors to Our Social Media Pages
    1. Visitors' Interactions - When you engage with our social media outlets, such as when you post on our social media pages, like, share, comment on our posts, answer surveys, or similar activities, we collect the personal data you provide, such as the content of your post and the information available to us through your profile or account. The social media companies we use may also provide us with aggregate and analytical information about activity relating to us.

    How we use this data: We may use this information to engage with you or respond to your posts and comments and to analyze the effectiveness of our social media efforts and to improve how we manage them, and for marketing purposes.

    Legal Basis: When we process your personal data to engage with you or respond to your posts and comments, we do so on the basis of our legitimate interest to engage with and serve our audiences in an effective manner. When we process your personal data to improve our social media outlets or for marketing purposes, we do so based on our legitimate interest to effectively market our products and services, improve our Services, and develop new ones.

    1. Enforcement and Protection of Rights. We may use any of the personal data described in this Privacy Notice where we believe it is necessary to enforce our rights, protect our property or safety (or that of third parties), investigate potential violations of our Terms of Service or Customer Agreement, prevent fraud or other illegal activity, or as otherwise required by law.
  17. Our Marketing Activities. As described above, we may use personal data we collect for advertising and marketing purposes. We try to limit the marketing material we send to a reasonable and proportionate level. Below we describe how you can control the marketing material you receive from us.

    1. Email Marketing and Services Communications

      1. We use your contact details to send you informational newsletters and other marketing material about our products and services. We do so in accordance with applicable law. You can opt out of receiving marketing communications at any time by following the “unsubscribe” link in any message we send you, or by emailing us at contact@cashflowfrog.com.
      1. If you are a registered user, you can change your preferences within your account to reflect how you would like us to communicate with you.
    1. Note that if you are a registered user, we may need to contact you about administrative or service-related issues as part of the services we provide to you. This is not marketing communication and you will continue to receive these messages even if you opt-out of marketing emails.
  18. Sharing the Personal Data We Collect. We share your personal data as follows:

    1. Affiliates. We share your personal data with our affiliated company, Cash Flow Frog US, LLC, where this is necessary to provide you with our products and services (including payment processing) and so that we can manage our business, such as to keep updated records of our users.
    1. Customers. If you use our Services in connection with a company that is our customer, that customer may have access to information about your use of our Services. For example, a user with an administrator account may be able to see your data.

    2. Service Providers. Below is a list of the types of service providers we use, the service each provides, and the types of data shared with each. All service providers have agreed to confidentiality restrictions and have undertaken to use your personal data solely as we direct.

Type of Service Description Personal Data Shared
Cloud Computing and Database Hosting We use service providers that offer cloud computing and database hosting services. They offer us space on their servers for us to store our files and programs, including your personal data. All personal data that we collect from you is stored on third party servers.
Customer Relationship Management (CRM) We use external CRM tools to help us keep track of our customers and information related to them, including their personal data. your name, company, position, email address, and phone number.
Email Marketing We use an independent vendor to send out marketing emails on our behalf. your name and email address.
Payment Processors When you make a payment through our Services, the transaction is processed by a third-party payment processor. the details of your credit card number and other transaction data.
Analytics Providers We use a service provider to assist us with analytics services for our Website and Platform. Data collected automatically through our site, including IP addresses and cookie information.
Error Monitoring We use a service provider to monitor and report errors and issues within our Platform. Technical data, usage data, and error logs which may include personal data.
Customer Communication We use a service provider for in-Platform customer communication, support, and engagement. Your name, email address, and communications content.
  1. Data Controllers. We also share your personal data with certain third parties who act as independent controllers of your personal data. Such parties process your personal data in accordance with their respective privacy notices. This includes the third parties listed below in Section 10.4 who place cookies on our Website and Platform. For further details regarding our arrangement with such controllers, please contact us at contact@cashflowfrog.com.

Controller Description
Plaid Inc. We use Plaid Inc. (“Plaid”) to obtain your data from financial institutions. When a Customer chooses to connect bank accounts through our Platform, the Customer engages Plaid to access and transmit personal and financial information from the relevant financial institution(s). Such data processing by Plaid is permitted and instructed by the Customer. Plaid acts as an independent data controller in respect of the personal data it collects and processes through its services. Your personal data will be transferred, stored, and processed by Plaid in accordance with Plaid’s End User Privacy Policy, available at: https://plaid.com/legal/#end-user-privacy-policy.
Meta Platforms, Inc. See further details in Section 10.4 below.
Google LLC See further details in Section 10.4 below.
Microsoft Corporation See further details in Section 10.4 below.
  1. Change of Ownership. If we are looking to sell our company, liquidate assets, or merge with another, we may share your personal data with other interested parties as part of negotiations toward that transaction. In such case, or where we do sell our company, your personal data shall continue to be subject to the provisions of this Privacy Notice.

  2. Law Enforcement Related Disclosure. We may share your personal data with government agencies or other relevant parties, such as a law office or independent auditor: (i) if we believe that such disclosure is appropriate to protect our rights, property or safety (including the enforcement of the Terms of Service, the Customer Agreement and this Privacy Notice) or those of a third party; (ii) if required by law or court order; or (iii) as is necessary to comply with any legal and/or regulatory obligations, such as audit requirements.

  1. International Transfers. Some of our service providers are located in countries other than your own. When we transfer your personal data internationally, we will do so safely and securely and in accordance with applicable law.

    1. If you are located in the EU, when we share your personal data with third parties based outside of the European Economic Area ("EEA"), we will ensure that they sign agreements that require them to comply with applicable law, keep your data secure at similar levels to the level described in this Privacy Notice, and make sure that your data protection rights are protected. We will also implement the following safeguards:

      1. When we transfer your personal data to Israel, we rely on the decision by the European Commission that says that Israel is considered to provide an adequate level of data protection.
      1. When we transfer your personal data to entities in the US that are covered under the Data Privacy Framework, we rely on the decision by the European Commission that says that these entities are considered to provide an adequate level of data protection.
    1. Where we transfer your personal data to other countries, we (i) take additional security measures to protect the data and (ii) use specific contracts approved by the European Commission, known as the Standard Contractual Clauses, to give your personal data the same protection it has in the EEA.
    1. Please contact us at contact@cashflowfrog.com if you would like further information on the specific mechanism used by us when transferring your Personal Data out of the EEA.
  2. Security. The security of your personal data is our highest priority. We work hard to make sure that your personal data will be held securely and that it will not be shared or lost accidentally. However, it is impossible to guarantee absolute security. The security of your data also depends on the security of the devices you use and the way in which you protect your user IDs and passwords. The measures we take include:

    1. Technical Measures. The electronic safeguards we employ to protect your personal data include secure servers, firewalls, and antivirus protections. We encrypt data in transit and at rest using secure encryption protocols.

    2. Access Control. We limit access to your personal data only to authorized personnel who have a need to know, including management, account managers, customer support staff, and software developers. We review these permissions regularly and revoke an employee's access immediately after his/her termination.

    3. Internal Policies. We maintain and regularly review and update our privacy related and information security policies.

    4. Personnel. We require employees to sign non-disclosure agreements according to applicable law and industry customary practice.

    5. Standards and Certifications. We have been certified as compliant with ISO 27001 (Information Security Management).

    6. Database Backup. Our databases are backed up and verified regularly. Backups are encrypted and stored within the production environment to preserve their confidentiality and integrity.

  3. Your Rights - How to Control Our Use of Your Personal Data. Depending on which laws apply, you have certain legal rights over your data. Below is some general information about rights that may apply to you, but we recommend checking the law or consulting with a lawyer to understand what applies in your specific case. To exercise your rights, please contact us at contact@cashflowfrog.com. We may ask for reasonable evidence to verify your identity before we can comply with any request.

    1. Right of Access. You may have a right to know what personal data we collect about you. We may charge you with a fee to provide you with this information, if permitted by law. If we are unable to provide you with all the information you request, we will do our best to explain why. See Article 15 of the GDPR for more details, if your personal data is subject to GDPR.
    1. Right to Correct Personal Data. You may request that we update, complete, correct or delete inaccurate, incomplete, or outdated Personal Data. See Article 16 of the GDPR for more details, if your personal data is subject to GDPR.
    1. Deletion of Personal Data ("Right to Be Forgotten"). If you are located in the EU, you may have the right to request that we delete your personal data. Note that we cannot restore information once it has been deleted. Even after you ask us to delete your personal data, we may be allowed to keep certain data for specific purposes under applicable law. See Article 17 of the GDPR for more details, if your personal data is subject to GDPR.
    1. Right to Restrict Processing. If you are located in the EU, you may have the right to ask us to stop processing your personal data. See Article 18 of the GDPR for more details, if your personal data is subject to GDPR.
    1. Right to Data Portability. If you are located in the EU, you may have the right to request that we provide you with a copy of the personal data you provided to us in a structured, commonly-used, and machine-readable format. See Article 20 of the GDPR for more details, if your personal data is subject to GDPR.
    1. Right to Object. If you are located in the EU, you may have the right to object to certain processing activities. See Article 21 of the GDPR for more details, if your personal data is subject to GDPR.
    1. Withdrawal of Consent. If we are processing your data based on your consent, you are always free to withdraw your consent, however, this won't affect processing we have done from before you withdrew your consent.
    1. Right to Lodge a Complaint with Your Local Data Protection Authority. If you are located in the EU, you have the right to submit a complaint to the relevant data protection authority if you have any concerns about how we are processing your personal data, though we ask that as a courtesy you please attempt to resolve any issues with us first.
    1. Your Rights Under Israeli law. If you are subject to Israeli law, you may request to access any personal data you have provided to us and request that such personal data be corrected, updated, or deleted, including in accordance with Articles 13 through 14 of the Israeli Privacy Protection Law, 1981. You may exercise such rights by emailing us at contact@cashflowfrog.com. You may have the right to delete your personal data subject to and in accordance with Article 3 of the Israeli Privacy Protection Regulations (Provisions Regarding Information Transferred to Israel from the European Economic Area), 2023.
  4. Data Retention.

    1. We retain your personal data for as long as necessary to fulfill each of the purposes we described above. Once the data is no longer needed, we delete it.
    1. When deciding how long to store personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized access, the purposes for which the personal data was collected, as well as applicable legal requirements. Please note that we may delete information from our systems without notifying you first. Retention by any of our service providers or subcontractors may vary in accordance with each business's retention policy.

    2. In some circumstances, we may store your personal data for an extended term if required to do so by law (e.g. to fulfill tax or audit requirements), or to keep accurate records of our interactions in case there is a prospect of litigation relating to your personal data. In such cases, we will maintain the same security measures as described above.

    1. Please contact us at contact@cashflowfrog.com if you would like details about the retention periods for each type of personal data we process.
  5. Cookies and Similar Technologies. We use cookies and similar technologies on our Website and our Platform.

    1. What are Cookies? A cookie is a small piece of text that is sent to your browser by a website you visit. This piece of text acts as a sort of tag, letting the website know that it's you (really, your device) that's visiting. There are other technologies that act similarly, like web beacons, pixel tags, and Device IDs for apps, but for simplicity's sake we'll refer to them all as "cookies”.

    2. First-Party / Third-Party Cookies. Websites and platforms providers can place their own cookies (called "first-party cookies") but can also place cookies from other providers or sites (called "third-party cookies"). If your browser holds both first and third-party cookies for a given website, both the website and the third party are notified when you visit the site. We may place both first and third-party cookies on our Website and Platform.

  6. How We Use Cookies. While the specific names and types of cookies we use may change from time to time, they generally fall into one of the categories listed below.

Cookie Type Function
Necessary These cookies allow the Website and Platform to work correctly. They enable your access to the Website and Platform, move around, and access different services, features, and tools. These cookies cannot be disabled. These cookies also help us identify and prevent security risks. They may be used to store your session information to prevent others from changing your password without your login information.
Functionality These cookies remember your settings, preferences, and other choices you make (like placing an item in a shopping cart) in order to help personalize and streamline your experience.
Performance/Analytics These cookies collect analytical information to help us understand how you use our Website and Platform, for example whether you have viewed messages, clicked on links, and how long you spent on each page. This helps us improve our Website and Platform to better suit your needs.
Advertising These cookies help advertisers show you ads. When we place advertising cookies, they help us track the efficiency of our advertising campaigns. Advertising cookies may track your browsing habits and activity when visiting our Website and Platform and sites of third parties and help us serve ads that are relevant and meaningful to you and your interests.
  1. Third Party Cookies. In addition to our first-party cookies, we place cookies from the third parties listed below who serve as independent data controllers of your personal data and who process such data in accordance with their respective privacy notices:

  1. Google Analytics (Performance/Analytics) www.google.com/policies/privacy/partners/

    b. Meta / Facebook (Advertising). For further details, please see www.facebook.com/privacy/policy/.

    c. Google Tag Manager / Google Ads (Advertising). For further details, please see www.google.com/policies/privacy/.

    d. Microsoft Bing (Advertising/Retargeting). For further details, please see privacy.microsoft.com.

    e. DoubleClick by Google (Advertising/Retargeting). For further details, please see policies.google.com/technologies/ads.

    f. Intercom (Customer support chat). For further details, please see https://www.intercom.com/legal/privacy.

    1. How to Adjust Your Preferences. Most web browsers are initially configured to accept cookies, but you can change the settings so your browser refuses all cookies or certain types of cookies. In addition, you are free to delete any existing cookies at any time. Please note that some features of the services may not function properly when cookies are disabled or removed. For example, if you delete cookies that store your account information or preferences, you will be required to input these each time you visit.
  2. Third-Party Services. You may have access to third-party services through our Services. Please note that all use of third-party services is at your own risk and subject to such third party's terms and privacy policies. We do not take any responsibility for the performance of other services.

  3. Minors. We do not knowingly collect or transfer personal data from or about minors under the age of sixteen (16). If you become aware that an individual under the age of sixteen (16) has registered or has provided us with personal data without parental permission, please notify us immediately.

  4. Changes to the Privacy Notice. We may update this Privacy Notice from time to time to keep it up to date with legal requirements and the way we operate our business. We will place any updates on this webpage. Please come back to this page every now and then to make sure you are familiar with the latest version.

Back to top

FAQ

Trusted by thousands of business owners

Start Free Trial Now