Privacy Policy

Effective and Last Updated: August 25, 2026

This Privacy Policy explains how In Flow LLC, doing business as CardPlan ("CardPlan," "we," "us," or "our"), collects, uses, discloses, and protects personal information when you use the CardPlan website, application, calculators, reports, embedded tools, and related services (collectively, the "Service").

CardPlan provides consumer-directed software for organizing credit-card information and comparing estimated utilization, payment-allocation, and timing scenarios. CardPlan does not currently obtain consumer credit reports, provide credit scores, make lending or eligibility decisions, move money on a user’s behalf, dispute credit-report information on a user’s behalf, or negotiate debts with creditors. CardPlan’s calculations and scenarios are informational estimates and do not guarantee any credit-score, credit-reporting, approval, lending, or other financial outcome.

Privacy at a glance

  • We collect information reasonably needed to operate, secure, support, measure, and improve the features you use.
  • You may enter credit-card information manually or choose to connect eligible U.S. credit-card accounts through a financial connectivity provider.
  • When you connect an eligible credit-card account, CardPlan uses a financial connectivity provider to obtain the account information you authorize for CardPlan’s connected features. Depending on the financial institution and data availability, this may include balances, credit limits or available credit, APR information, minimum payments, payment due dates, statement information, institution or account identifiers, and connection metadata.
  • CardPlan does not currently request detailed purchase or merchant transaction history through its financial connectivity provider.
  • CardPlan does not receive financial-institution usernames or passwords that you enter into a provider-controlled authentication experience.
  • CardPlan does not currently sell personal information or connected financial-account information and does not currently use or share that information for cross-context behavioral advertising.
  • CardPlan does not use connected financial information to make lending, insurance, housing, employment, or other eligibility decisions, create a consumer report, or move money.
  • Disconnecting a financial-account connection stops future CardPlan updates through that connection. It does not automatically delete information already saved in CardPlan.

1. Scope and Eligibility

This Policy applies to personal information CardPlan processes through the Service. It does not govern the privacy practices of financial institutions, financial connectivity providers, payment processors, publishers, analytics providers, or other third parties that operate under their own privacy policies.

The Service is currently intended for individuals located in the United States who are at least 18 years old. By using the Service, you acknowledge the practices described in this Policy.

2. Information We Collect

A. Account and authentication information

We may collect your email address, internal account identifiers, authentication and session information, one-time login-code records, security events, preferences, goals, settings, and communications you send to us.

B. Information you enter into CardPlan

You may manually provide information about credit cards, financial goals, and planning preferences, including card nickname or issuer; current balance; credit limit; minimum payment; available payment amount; payment due date; statement closing date; APR; promotional APR and expiration date; last statement information; financial goals; target utilization; planned payments; corrections; confirmations; and notes.

Do not enter a full card number, security code, bank password, Social Security number, or other information that CardPlan does not request.

C. Public calculators and temporary handoffs

Some CardPlan calculators can be used without creating an account. Ordinary calculator computations may be processed to return a result without being saved as a permanent CardPlan account record. If you choose to continue from a calculator into another CardPlan flow, CardPlan may create a temporary server-side handoff containing the calculator inputs and results needed to continue that flow, which may include card nicknames, balances, credit limits, APRs, payment amounts, or target information. Temporary handoffs are intended to expire after the applicable handoff period and are not intended to become permanent account records unless you continue into a feature that saves the information.

D. Connected credit-card data

When you choose to connect an eligible credit-card account, CardPlan uses a financial connectivity provider. CardPlan’s current connected-account integration is limited to eligible U.S. credit-card accounts and related credit-card liability information.

Depending on the financial institution, account, and data availability, CardPlan may receive or process current or available balance; credit limit or available credit; APR information; minimum payment amount; payment due date; last statement date and related statement information when available; financial institution and account names, identifiers, types, or status information; and connection, refresh, authorization, and other technical metadata needed to establish, maintain, troubleshoot, reconnect, or discontinue the connection.

CardPlan does not currently request detailed purchase or merchant transaction history through the connected-account service.

CardPlan does not receive financial-institution usernames or passwords that you enter into a provider-controlled authentication experience. Financial connectivity providers and participating financial institutions process connection information under their own terms and privacy practices.

The availability, completeness, and freshness of connected information vary by financial institution and may be delayed, unavailable, incomplete, or require reauthorization.

E. Payment and subscription information

If you purchase a report, subscription, or other paid service, a payment processor processes payment information. CardPlan may maintain limited billing and subscription information such as billing or customer email, processor customer identifiers, checkout-session identifiers, subscription identifiers, plan or price identifiers, subscription status, billing-period and cancellation information, payment status, amount and currency, and payment, invoice, charge, refund, or reconciliation identifiers. CardPlan does not directly store your full payment-card number or card security code.

F. Publisher and embedded-tool information

CardPlan may offer calculators or other tools through approved third-party publishers. CardPlan may collect publisher contact information, organization or website information, authorized domain, applicable terms acceptance, publisher identifiers, release or connection status, and attribution information. An embedded CardPlan-controlled calculator may receive the information a visitor submits inside the CardPlan experience. CardPlan’s embed architecture is intended not to send the visitor’s financial inputs to the publisher’s parent page. A publisher’s own website, cookies, analytics, and tracking remain subject to that publisher’s practices.

G. Analytics, attribution, device, usage, and technical information

CardPlan and its service providers may automatically collect technical and usage data such as IP address or a hashed representation of an IP address, browser type, device type, operating system, referring page, pages viewed, timestamps, session or authentication events, error logs, performance data, security signals, first-touch UTM attribution, publisher attribution, subscription or conversion events, and similar operational information.

CardPlan may use first-party analytics and analytics providers. CardPlan’s first-party analytics are designed to exclude credentials and sensitive financial input values from analytics-event properties. CardPlan may also use cookies or similar technologies as described below.

H. Support, feedback, research, and communications

We collect the information you provide when you ask for support, report a problem, respond to a survey, participate in product research, submit a privacy request, or otherwise communicate with us.

3. Sources of Information

We collect personal information directly from you when you create an account, enter information, use calculators, connect an account, purchase a product, contact us, or otherwise use the Service; from financial connectivity providers and participating financial institutions when you authorize a connected credit-card account; from payment or billing providers in connection with purchases, subscriptions, refunds, and billing administration; from approved publishers, referral sources, or attribution links when you arrive through those channels; from service providers that support hosting, databases, authentication, security, email delivery, monitoring, analytics, and customer support; and automatically from your browser, device, and use of the Service.

4. How We Use Personal Information

We use personal information to provide, operate, maintain, secure, and improve the Service; authenticate users and maintain account security; connect eligible credit-card accounts and retrieve, refresh, organize, and use the financial information you authorize for CardPlan’s connected-account features; calculate utilization, organize account information, generate scenarios and reports, save plans, and provide reminders or progress views; process purchases, subscriptions, refunds, and billing administration; send login codes, receipts, connection notices, security alerts, service messages, and other communications; respond to questions and support requests; troubleshoot problems and prevent abuse or fraud; maintain connection status and limited connection history; diagnose connection failures; support reconnection and disconnection; measure the reliability and use of connected-account features; monitor performance and debug errors; conduct internal research and product analytics; create aggregated or deidentified information that does not reasonably identify an individual; comply with law; enforce agreements; protect rights and safety; and establish or defend legal claims.

CardPlan does not currently use connected financial-account information to underwrite you, determine creditworthiness, make lending or insurance decisions, determine eligibility for employment or housing, provide a consumer report, or move money to or from your accounts.

5. How We Disclose Personal Information

Service providers. We may disclose information to vendors that provide hosting, databases, authentication, email delivery, payment processing, financial connectivity, security, monitoring, analytics, customer support, and related operational services, to the extent reasonably necessary for those services.

Financial connectivity providers and financial institutions. CardPlan uses financial connectivity services to provide connected credit-card functionality. When you choose to connect an account, the connectivity provider and participating financial institution process information required to establish and maintain the connection and make authorized information available to CardPlan. These providers and institutions operate under their own privacy notices and terms.

Payment providers. CardPlan uses payment services to process subscriptions, purchases, billing events, refunds, and payment administration.

Parties you direct or authorize. We disclose information when you instruct us to do so or intentionally use a feature that sends information to another party.

Legal and safety recipients. We may disclose information when we reasonably believe disclosure is required by law, legal process, or regulatory request, or is reasonably necessary to protect CardPlan, our users, or others from fraud, abuse, security threats, or harm.

Business transaction recipients. Information may be disclosed as part of due diligence or a merger, financing, acquisition, reorganization, bankruptcy, change in operating entity, or sale of all or part of the business, subject to applicable confidentiality and legal requirements.

6. Sale, Advertising, and Materially Different Future Uses

CardPlan does not currently sell personal information.

CardPlan does not currently use or share personal information or connected financial-account information for cross-context behavioral advertising.

CardPlan does not currently provide user financial profiles to data brokers.

If CardPlan materially changes these practices, we will update applicable disclosures before the new practice begins and provide any notice, consent, opt-out mechanism, or other right required by applicable law. This Policy does not authorize CardPlan to make a materially different use of previously collected personal information where additional notice or consent is required.

7. Connected Financial Accounts

Connecting an eligible credit-card account is optional. CardPlan uses a financial connectivity provider to provide connected-account functionality for eligible U.S. credit-card accounts.

When you choose to connect an account, the financial connectivity provider presents its connection experience and obtains the authorizations applicable to that connection. CardPlan uses authorized credit-card liability and related account information to support connected CardPlan features.

CardPlan may receive information such as balances, credit limits or available credit, APR information, minimum payments, payment due dates, statement information, financial-institution and account identifiers, account status, and connection metadata when available.

CardPlan does not currently request detailed purchase or merchant transaction history through its financial connectivity provider.

CardPlan does not receive financial-institution usernames or passwords that you enter into a provider-controlled authentication experience.

Connected data may be delayed, incomplete, unavailable, or require reauthorization. CardPlan does not control the availability, accuracy, refresh frequency, or continued support of a financial institution or account through a third-party connectivity provider.

You may disconnect an eligible financial-account connection using available CardPlan controls. When a connection is disconnected, CardPlan stops requesting future updates through that connection and removes or invalidates the provider connection credential used for continued access.

Disconnecting is not the same as deleting CardPlan data. A CardPlan card created from or associated with a financial-account connection may remain in CardPlan as a manually maintained card after disconnection. Information previously saved to that card does not automatically disappear solely because the financial connection is disconnected.

CardPlan may retain limited information about a past connection—such as provider or institution identifiers, connection status, dates, and operational events—as reasonably necessary for account history, customer support, security, troubleshooting, service reliability, internal product analytics, legal obligations, and dispute resolution, subject to the retention practices described below.

Financial connectivity providers process information under their own privacy policies and terms. Review the provider’s disclosures and the privacy practices of your financial institution before connecting an account.

8. Cookies and Similar Technologies

CardPlan may use cookies, local storage, and similar technologies for authentication, session management, security, temporary workflows, preferences, attribution, performance, and analytics. These may include authentication or session cookies, report or temporary-workflow cookies, first-touch attribution cookies, publisher attribution cookies, and analytics technologies provided by service providers.

Some attribution cookies may remain for approximately 90 days, authentication cookies may remain for approximately 30 days, and temporary workflow cookies may expire sooner, depending on the feature and configuration. You may be able to control non-essential cookies through browser settings or available consent controls, but disabling essential cookies may prevent parts of the Service from functioning.

The Service does not generally respond to browser “Do Not Track” signals. Where applicable law requires CardPlan to recognize a legally valid opt-out preference signal for a data practice to which that signal applies, CardPlan will handle the signal as required by law.

9. Data Retention

We retain personal information for as long as reasonably necessary for the purposes described in this Policy, taking into account the sensitivity of the information, the nature of the Service, user choices, security needs, legal and contractual obligations, dispute-resolution needs, and whether information is still needed to provide a requested feature.

Account and profile information. Generally retained while your account is active and for a limited period afterward as needed to complete account closure, prevent fraud, maintain records, resolve disputes, or comply with law.

Manual card details, saved plans, reports, and generated outputs. Generally retained while needed to provide account history and requested features or until you delete the information or request account deletion, subject to legal, security, billing, backup, and operational exceptions.

Connected credit-card data and connection records. Generally retained while needed to provide connected-account and CardPlan planning features. Disconnecting a financial-account connection stops future updates through that connection but does not automatically delete information already saved in CardPlan. A previously connected CardPlan card may remain as a manual card. CardPlan may retain limited past-connection and operational metadata for account history, customer support, security, troubleshooting, service reliability, internal analytics, legal obligations, and dispute resolution.

Financial-connectivity webhook and connection operational records. CardPlan may retain limited event metadata needed to verify webhook processing, prevent duplicate processing, investigate failures, monitor connection health, and maintain security. CardPlan’s webhook-event records are designed not to retain raw webhook bodies, provider verification tokens, access tokens, secrets, or complete financial payloads.

Temporary calculator handoffs. Intended to remain available only for the applicable temporary handoff period and to be removed or rendered unusable under CardPlan’s retention process after that period, unless the information has separately become part of an account or another retained feature at your direction.

Payment and subscription records. Retained as needed for billing, tax, accounting, fraud prevention, chargebacks, disputes, reconciliation, and legal compliance.

Security, access, technical, and analytics logs. Retained for an operational period appropriate to troubleshooting, security monitoring, abuse prevention, product reliability, analytics, or an investigation or legal obligation.

Transactional email records and support communications. Retained as needed to document delivery or service events, resolve requests, maintain service history, troubleshoot, prevent duplicate communications, address disputes, and comply with legal obligations.

Deletion from active systems may not immediately remove information from backups or narrowly retained legal, security, billing, fraud-prevention, audit, or dispute records. Backup copies are not intended for ordinary product use and are removed or overwritten according to applicable backup lifecycles unless preservation is required.

10. Data Security

We use administrative and technical safeguards designed to reduce the risk of unauthorized access, use, alteration, loss, or disclosure of personal information. Safeguards may include authentication and authorization controls, restricted handling of provider credentials and secrets, encryption in transit, rate limiting, data minimization, logging, monitoring, and security procedures appropriate to the Service.

No system, network, method of transmission, or method of electronic storage can be guaranteed to be completely secure. You are responsible for maintaining the security of your email account, devices, and access to CardPlan.

11. Your Choices and Controls

You may review and update manual card information through available CardPlan controls; disconnect a connected financial account to stop future CardPlan updates through that connection; understand that disconnecting does not automatically delete previously saved CardPlan card information or all historical connection metadata; request access, correction, deletion, or a copy of personal information by contacting us; manage subscription billing using available billing controls; unsubscribe from non-essential marketing emails using the link in the message; and control non-essential cookies through browser settings or available consent controls.

Account deletion, card deletion, financial-account disconnection, and subscription cancellation are separate actions unless CardPlan expressly states otherwise.

12. U.S. State Privacy Rights

Depending on where you live and whether a particular privacy law applies to CardPlan, you may have rights to confirm whether we process your personal information; access certain personal information; request correction; request deletion subject to exceptions; receive a portable copy of certain information; opt out of sale, sharing for cross-context behavioral advertising, or targeted advertising where those practices and rights apply; limit certain uses or disclosures of sensitive personal information where applicable; appeal certain privacy-request decisions; and exercise privacy rights without unlawful discrimination.

CardPlan does not currently sell personal information or share personal information for cross-context behavioral advertising.

To submit a privacy request, email privacy@getcardplan.com with the subject “Privacy Request” and describe the request. We may verify your identity by asking you to confirm control of your CardPlan email address or provide other information reasonably necessary to protect your account. An authorized agent may submit a request where permitted by law, but we may require proof of authorization and direct identity verification.

13. California Notice at Collection

The categories below summarize personal information CardPlan may collect, the principal purposes for which it is used, categories of recipients to which it may be disclosed for business purposes, and general retention criteria. CardPlan does not currently sell these categories of personal information or share them for cross-context behavioral advertising.

Identifiers and account data. Examples include email address, user ID, session identifiers, and IP address or hashed IP information. Purposes include creating and securing accounts, authentication, communication, and fraud prevention. Recipients may include hosting, authentication, email, security, and support providers. Retention depends on account lifecycle, security, legal, and dispute-resolution needs.

Financial and commercial information. Examples include manually entered or provider-supplied balances, credit limits or available credit, APR information, minimum payments, payment due dates, statement information, planned payment amounts, and subscription or billing status. Purposes include providing calculations, connected-account features, scenarios, saved plans, subscriptions, troubleshooting, security, and support. Recipients may include financial connectivity providers and participating financial institutions for connectivity, payment providers for billing, and hosting, database, security, or operational service providers. Retention depends on requested feature history, account lifecycle, connection lifecycle, billing, security, fraud-prevention, legal, and dispute needs.

Connection and technical information. Examples include provider or account identifiers, institution identifiers, connection status, refresh, reconnection or disconnection status, and operational or webhook-event metadata. Purposes include establishing and maintaining connections, supporting reconnection or disconnection, security, troubleshooting, reliability measurement, and internal product analytics. Recipients may include financial connectivity providers and hosting, database, security, or operational providers as applicable. Retention depends on connection history, troubleshooting, security, analytics, legal, and dispute needs.

Internet or electronic activity. Examples include browser, device, pages viewed, timestamps, logs, error events, analytics events, attribution information, and security events. Purposes include operating, securing, troubleshooting, measuring, and improving the Service. Recipients may include hosting, monitoring, analytics, and security providers. Retention depends on operational, analytics, troubleshooting, security, and legal needs.

Inferences and generated outputs. Examples include utilization calculations, payment scenarios, progress classifications, saved-plan outputs, and report outputs. Purposes include providing the Service and improving user-requested features. Recipients may include hosting or database providers and parties you direct. Retention depends on account lifecycle, user-selected history, feature needs, and deletion choices.

Communications and support data. Examples include messages, feedback, support requests, survey responses, and privacy requests. Purposes include responding to users, troubleshooting, improving the Service, documenting requests, and resolving disputes. Recipients may include email, support, hosting, and security providers. Retention depends on resolution of the request, service history, legal requirements, and dispute needs.

California residents may exercise applicable rights using the process in Section 12. Whether particular information constitutes “sensitive personal information” under California law depends on the statutory definition and the specific information CardPlan processes; CardPlan does not use this Policy to characterize all financial information as statutory sensitive personal information.

14. Children’s Privacy

CardPlan is not directed to children under 18, and we do not knowingly collect personal information from anyone under 18. If we learn that an ineligible minor has provided personal information, we may close the account and delete information as appropriate and legally permitted.

15. External Services and Links

The Service may link to or integrate with services operated by other companies or organizations. CardPlan does not control those parties’ privacy or security practices. Review their policies before providing information or using their services.

16. Processing Locations

CardPlan is operated from the United States and is currently intended for U.S. users. CardPlan and its service providers may process information in the United States and other locations where they operate, subject to applicable contractual obligations and law.

17. Changes to This Policy

We may update this Policy as CardPlan changes or as legal requirements evolve. We will post the updated Policy and revise the “Last Updated” date. If a change materially affects how we use previously collected information, we will provide additional notice or obtain consent when required by law.

18. Contact Us

Questions, privacy requests, or complaints may be sent to:

In Flow LLC, doing business as CardPlan
Email: privacy@getcardplan.com
Website: https://getcardplan.com