Privacy Policy

Last updated: June 11, 2026 · Beta

Layne ("we", "us") is a spend-management platform. A dedicated virtual card is issued for each vendor you add, and your SaaS spend is tracked on your behalf. This policy describes what we collect and how we use it.

What we collect

  • Account data: name, email, and the cardholder details required by our card issuer (legal name, date of birth, billing address). Identity verification is performed by Stripe; we never see or store your full card numbers, bank credentials, or government IDs.
  • Spend data: transactions made on the cards issued for your account, budgets, and vendor connections you configure.
  • Vendor usage data: when you connect a vendor API key, we access that vendor in read-only mode to retrieve billing/usage information. Keys are stored encrypted and are never used to make changes to your vendor accounts.

Demo/sandbox data is synthetic and shared; don't put real data in the sandbox.

How we use it

To provide the service: provisioning a dedicated card per vendor, enforcing budgets, displaying spend analytics, and sending the alerts you enable. We do not sell your data. We share it only with the processors that make the service work (Stripe for payments and the card program, Supabase for hosting, Resend for email).

Your choices

You can export your data anytime from Settings → Data Export, disconnect any vendor (which deletes its stored key), and request account closure from Settings. On closure we cancel your cards and delete your data, subject to records we must retain for financial compliance.

Contact

Questions about this policy: reach us through your account's support channel.

Privacy Policy · Layne