Last Updated: [DATE]
Rainy Day LLC ("Rainy Day," "we," "us," or "our"), a [YOUR STATE] limited liability company, is committed to protecting your privacy and the security of your personal information. This Privacy and Security Policy ("Policy") describes how we collect, use, share, and protect your information when you use the Rainy Day mobile application (the "App") and related services (collectively, the "Services").
By using the Services, you agree to the collection and use of information in accordance with this Policy.
| Category | Data Elements | Purpose |
|---|---|---|
| Account Information | Full legal name, email address, phone number, date of birth, password | Account creation, identity verification, communications |
| Profile Information | Profile photo, city, state, zip code | Community features, Discover search, personalization |
| Identity Verification (KYC) | Full legal name, date of birth, last four digits of SSN, physical address | Regulatory compliance (BSA/AML) — transmitted directly to Dwolla for verification; Rainy Day does not store your SSN (see Section 3) |
| Financial Information | Bank account details (via Plaid), transaction history within Communities | Facilitating ACH payments, dues tracking, disbursement processing |
| Community Content | Messages, event details, disbursement descriptions, proposal text, vote records | Providing community features |
| Communications | Emails and messages you send to us | Customer support, issue resolution |
| Category | Data Elements | Purpose |
|---|---|---|
| Device Information | Device type, operating system, device identifiers, IP address | Security, fraud prevention, trusted device verification |
| Location Information | Approximate location (from IP address or zip code), GPS (if permitted) | Discover nearby communities, profile location |
| Usage Data | App interactions, feature usage, timestamps | Service improvement, debugging |
| Push Notification Tokens | Firebase Cloud Messaging tokens | Delivering notifications |
| Source | Data Elements | Purpose |
|---|---|---|
| Plaid | Bank account name, account type, account/routing numbers, account holder name | Linking bank accounts for ACH transfers |
| Dwolla | Transaction status, transfer IDs, verification status | Processing and tracking payments |
| Apple / Google Sign-In | Name, email address (if using social sign-in) | Account authentication |
Rainy Day collects and stores only the minimum amount of personal information necessary to provide the Services, prevent fraud, and comply with applicable law. We do not collect data for advertising, profiling, or any purpose unrelated to operating the platform. Every data element we collect serves a specific, documented purpose as described below.
We use your information for the following purposes:
Rainy Day will never sell, rent, lease, or trade your personal information to any third party, for any reason, at any time. We will never willingly provide your private information to any external source except as specifically described in this section. We share your information only when it is necessary to provide the Services, process payments, comply with the law, or prevent fraud.
When identity verification is required to create a payment account (Dwolla FBO/Wallet), your SSN (or last four digits) is collected through the App and transmitted directly to Dwolla for verification. Rainy Day does not store your SSN on our servers, in our database, or in any Rainy Day system. Once transmitted to Dwolla, your SSN is held and processed solely by Dwolla and its identity verification partners in accordance with Dwolla's Privacy Policy. SSN collection is required by federal law (Bank Secrecy Act / USA PATRIOT Act) to verify the identity of individuals using financial services and to prevent money laundering, terrorist financing, and fraud.
| Provider | Data Shared | Purpose |
|---|---|---|
| Dwolla, Inc. | Name, DOB, SSN (last 4), address, bank account info, transaction data | Payment processing, identity verification, regulatory compliance |
| Plaid Inc. | Bank credentials (via Plaid Link — we never see these), account info | Bank account connectivity |
| Google / Firebase | Account data, messages, usage data | Cloud infrastructure, authentication, push notifications, analytics |
| SendGrid (Twilio) | Email address, name | Transactional emails (welcome, verification, notifications) |
| Twilio | Phone number | SMS verification, community invitations |
When you use the payment features of the Services, your information is processed by Dwolla. Dwolla may share your information with the following parties for their operational and compliance purposes:
Dwolla does not sell your personal information for advertising or marketing purposes. For complete details on how Dwolla collects, uses, and shares your data, please review Dwolla's Privacy Policy and Dwolla's Terms of Service.
When you link a bank account through the App, your bank account data is accessed through Plaid. Plaid may share your information with the following parties for their operational purposes:
Plaid does not sell your personal information for advertising or marketing purposes. You can review and revoke Plaid's access to your data at any time through Plaid Portal. For complete details, please review Plaid's End User Privacy Policy.
Once your information is shared with Dwolla, Plaid, or their respective partners, that information is subject to their privacy policies, not ours. Rainy Day does not control how Dwolla, Plaid, or their partners use, store, or share your information beyond what is described in their respective policies. We strongly encourage you to review their privacy policies before using the payment features of the Services.
Rainy Day takes the security of your data seriously. If we discover that any third party has attempted to gain unauthorized access to, scrape, harvest, or illegally obtain private information from our platform about our users, their Communities, or their members, we will pursue all available legal remedies and prosecute to the fullest extent of the law. This includes unauthorized access to financial data, member information, community records, and any other data stored within our systems.
We may disclose your information if required by law, regulation, legal process, or governmental request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others, or to detect and prevent fraud. We will make reasonable efforts to notify you of such disclosures unless prohibited by law.
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction. We will notify you of any such transfer and any changes to this Policy at least thirty (30) days in advance.
| Data Type | Retention Period |
|---|---|
| Account information | Retained while your account is active; deleted upon account deletion |
| Transaction records | Retained for seven (7) years after the transaction date for regulatory compliance |
| Community messages | Subject to each Community's message retention settings (configurable by Leaders) |
| Identity verification data | Retained by Dwolla in accordance with their retention policy |
| Bank account tokens | Deleted when you unlink your bank account or delete your account |
| Device and login data | Retained for security purposes for up to two (2) years |
You may delete your account at any time through the App (Settings > Delete Account). Upon deletion:
You may also request data deletion by contacting support@joinrainyday.com.
You may access your personal information through the App (Profile tab). You may request a copy of your data by contacting support@joinrainyday.com.
You may update your profile information at any time through the App.
You may delete your account and personal data as described in Section 5.
You may manage push notification preferences through the App and your device settings. You may opt out of non-essential emails by contacting support@joinrainyday.com. You cannot opt out of transactional notifications (payment confirmations, security alerts).
You may disable location services for the App through your device settings. This may limit the Discover Communities feature.
You may review and revoke Plaid's access to your financial data through Plaid Portal (https://my.plaid.com).
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
To exercise these rights, contact us at support@joinrainyday.com or through the App. We will verify your identity before processing your request. We will respond within forty-five (45) days.
Categories of Personal Information Collected (per CCPA):
Residents of Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws may have similar rights to those described in Section 7. To exercise your rights, contact support@joinrainyday.com.
The Services are not directed to children under the age of 18. We do not knowingly collect personal information from children under 18. If we learn that we have collected information from a child under 18, we will delete it promptly. If you believe a child has provided us with personal information, contact support@joinrainyday.com.
We implement industry-standard security measures to protect your personal information:
In the event of a data breach affecting your personal information, we will notify you and applicable regulatory authorities in accordance with applicable law, including within seventy-two (72) hours where required.
The Rainy Day mobile App does not use cookies. We use Firebase Analytics for basic usage metrics (app opens, feature usage). We do not use third-party advertising trackers. We do not build advertising profiles based on your activity.
Your use of the Services involves third-party services that have their own privacy policies and terms of service. By using the payment and bank-linking features of the Services, you are also subject to the terms and privacy policies of Dwolla and Plaid. We encourage you to review all of the following before using the Services:
Financial Service Providers (apply when you link a bank account or make/receive payments):
Infrastructure and Authentication Providers:
Rainy Day is not responsible for the privacy practices of these third-party services. Their handling of your data is governed by their respective policies, not ours. If you have questions about how a third-party service uses your data, please contact that service directly.
The Services are intended for use within the United States. If you access the Services from outside the United States, your information will be transferred to and processed in the United States. By using the Services, you consent to this transfer.
We may update this Policy from time to time. We will notify you of material changes via email or in-app notification at least thirty (30) days before the changes take effect. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.
If you have questions about this Privacy and Security Policy, your personal data, or wish to exercise your privacy rights, contact us at:
Rainy Day LLC
Email: support@joinrainyday.com
Website: https://joinrainyday.com
For privacy-specific inquiries: privacy@joinrainyday.com