Privacy Policy
Last updated: April 10, 2026
1. Introduction
Gravitiy, Inc. ("the Company," "we," "us," or "our") operates gravitiy.com (the "Service"), an AI-powered finance-operations platform that automates transaction reconciliation and generates rolling cash-flow forecasts for finance teams at growing businesses. This Privacy Policy explains what information we collect through the Service, how we use it, and the choices you have. It applies to information we collect when you visit gravitiy.com, register for early access, connect your financial data sources, or communicate with us directly.
The Company is based at 1120 Avenue of the Americas, 4th Floor, New York, NY 10018, and can be reached at [email protected].
2. Information We Collect
2.1 Information You Provide
When you apply for early access, create an account, or contact us, we collect:
- Contact details (name, business email address, phone number, company name, and role);
- Information about your finance team and current close process, submitted during onboarding or in contact forms;
- The content of any messages and support requests you send us.
2.2 Financial Transaction Data You Submit
The core function of the Service requires connecting Gravitiy to your financial data sources. When you do, we receive and process:
- Bank transaction records (dates, amounts, counterparty names, and account identifiers), delivered via Plaid, direct bank API connection, or CSV upload;
- Ledger and ERP data (journal entries, account balances, vendor names, and transaction codes) from your connected QuickBooks, Xero, or NetSuite instance;
- Reconciled and unreconciled transaction states as computed by the Service.
We access your financial accounts through OAuth authorization only. We do not store your banking login credentials. We process transaction content solely to match transactions against ledger entries, flag exceptions, and build your cash-flow forecast. We do not use your financial transaction data to train machine learning models without your explicit written consent.
2.3 Information Collected Automatically
When you visit gravitiy.com or interact with the dashboard, we automatically collect limited technical information:
- IP address and approximate location (city and region level);
- Browser type, operating system, and device class;
- Pages visited, feature interactions, and session duration;
- Cookie and similar session identifiers (see Section 5).
2.4 We Do Not Knowingly Collect Children's Data
gravitiy.com is a business finance tool not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact [email protected] and we will delete it.
3. How We Use Information
We use the information we collect to:
- Perform automated reconciliation matching on the transaction records you submit;
- Generate and update your rolling cash-flow forecast and flag projected shortfalls;
- Surface unmatched exceptions in your review queue and deliver variance analysis;
- Operate, maintain, and improve the Service, including refining matching logic using anonymized and aggregated reconciliation patterns (not your identifiable transaction records);
- Respond to inquiries, provide onboarding support, and communicate service updates;
- Send product communications where you have consented or where permitted by applicable law;
- Detect, investigate, and prevent unauthorized access or abuse;
- Comply with legal obligations.
We do not sell personal information for monetary value. Where applicable state law treats certain advertising arrangements as a "sale" or "share," see your state's section below.
4. Sharing of Information
We share personal information only with:
- Cloud infrastructure and hosting providers that store and process Service data on our behalf under contractual data-handling terms;
- Third-party integration partners (Plaid, QuickBooks/Intuit, Xero, Oracle NetSuite) to the extent necessary to establish and maintain your connected data sources;
- Analytics and error-monitoring tools we use to operate and improve the Service;
- Authorities, when required by law, court order, or to protect the rights, safety, or property of the Company or others;
- A successor entity in the event of a merger, acquisition, or asset sale, subject to this Policy.
We do not sell your personal information or your financial transaction data to third parties.
5. Cookies and Tracking
We use cookies and similar technologies to manage your session, store preferences, and measure how the Service is used. For details and your choices, see our Cookie Policy.
6. Data Retention
We retain financial transaction records and reconciliation state for the duration of your active subscription plus 90 days after cancellation, to support data export and final reporting. Contact and account information is retained for as long as your account is active or as needed to deliver support. Inactive marketing-list contacts are purged after 24 months. Server access logs are retained 90 days, then aggregated and anonymized.
If your business is subject to recordkeeping obligations under applicable financial regulations, you remain responsible for maintaining required records independently of the Service.
7. Security
We use administrative, technical, and physical safeguards to protect the financial and personal information we process, including TLS encryption in transit, encrypted storage at rest, OAuth-only access to financial integrations, restricted-access databases, and least-privilege access controls. No system is perfectly secure; we cannot guarantee absolute security.
8. Your General Rights
Depending on your jurisdiction, you may have rights including access, correction, deletion, and the ability to limit certain processing. To make a request, email [email protected]. We will respond within the timeframe required by applicable law.
9. New York Residents
New York does not currently have a comprehensive consumer privacy statute. As a matter of policy, the Company extends the following baseline rights to all U.S. residents regardless of state of residence.
9.1 Baseline Rights
- Right to Know: request the categories of personal information we have collected about you.
- Right to Delete: request deletion of personal information you have provided.
- Right to Correct: request correction of inaccurate personal information.
- Right to Opt Out of Marketing: unsubscribe from marketing emails or opt out via the link in each marketing message.
9.2 How to Exercise
Email [email protected] with a description of your request and enough detail for us to verify your identity. We respond within 45 days.
9.3 Sector-Specific Rights
If you are protected by federal sector laws (such as the Gramm-Leach-Bliley Act for financial institutions or other applicable federal statutes), those laws may give you additional rights with respect to data covered by them. Finance teams using the Service who are subject to federal recordkeeping or data-protection obligations remain responsible for compliance with those obligations independently of this Policy.
9.4 California Visitors
If you are a California resident, you may also exercise the rights granted under the California Consumer Privacy Act ("CCPA") and California Privacy Rights Act ("CPRA"), including the right to know, the right to delete, the right to correct, and the right to opt out of sale or sharing. We do not sell personal information and do not "share" personal information for cross-context behavioral advertising.
To submit a CCPA/CPRA request, email [email protected] with the subject line "California Privacy Request."
10. Changes to This Policy
We may update this Policy from time to time. Material changes will be reflected by a new "Last updated" date and, where appropriate, a notice on the Service.
11. Contact
Questions, requests, or complaints can be sent to:
Gravitiy, Inc.1120 Avenue of the Americas, 4th Floor
New York, NY 10018
Email: [email protected]
Phone: +1 (212) 554-0224