Skip to main content

The Short Version

  • โœ… We never see your bank password
  • โœ… We canโ€™t make transfers or payments (read-only access)
  • โœ… Your data is encrypted (AES-256)
  • โœ… We use industry-standard open banking protocols
  • โœ… You can delete everything anytime

How Bank Connections Work

1. You Log In Directly to Your Bank

When you connect a bank, youโ€™re redirected to your bankโ€™s official website. You enter your credentials thereโ€”not on Lunch Flow. We never see or store your password.

2. You Authorize Read-Only Access

Your bank asks: โ€œDo you want to give Lunch Flow read-only access to your transactions?โ€ You click โ€œYesโ€ and specify which accounts. We can only read. We cannot:
  • Make transfers
  • Make payments
  • Change account settings
  • Access your full account number (only last 4 digits)

3. Your Bank Sends Us Your Transaction Data

Using secure open banking APIs, your bank sends us:
  • Transaction dates and amounts
  • Merchant names
  • Account balances
  • Transaction categories (if available)
We donโ€™t get:
  • Your login credentials
  • Your PIN
  • Security questions/answers
  • Full account numbers

Open Banking Compliance

PSD2 (Europe)

For European banks, we use providers that are PSD2 compliant, which means:
  • Regulated by financial authorities
  • Regular security audits
  • Strict data protection standards
  • Consumer protection built-in

Other Regions

We use established, regulated open banking providers in each region:
  • North America: MX/Finicity (regulated financial services provider)
  • Pacific Asia: Finverse (licensed aggregator)
  • New Zealand: Akahu (certified open banking provider)

Your Control

You Can Always:

  • โœ… See exactly what data we have
  • โœ… Disconnect any bank anytime
  • โœ… Delete specific connections
  • โœ… Export all your data
  • โœ… Delete your entire account (and all data)

Questions About Security?

If you have specific security questions or concerns: ๐Ÿ“ง Email: hello@lunchflow.app Weโ€™re happy to provide more technical details or discuss your specific use case.