
Last updated: June 6, 2026
Naviio, Inc. ("Naviio," "we," "us") operates the Naviio financial intelligence platform. This Privacy Policy explains what data we collect, how we use it, and your rights regarding your information.
We collect information you provide directly and data retrieved through integrations you authorize:
Account data: Email address, name, and hashed password when you register.
Financial data (via connected integrations):
Bank transactions, account balances, and account metadata via Plaid
Profit & loss, balance sheet, and expense data via QuickBooks or Xero
Revenue, MRR/ARR, and subscription metrics via Stripe
Payroll totals via Gusto or ADP
Advertising performance metrics (spend, impressions, clicks, conversions) via Meta Ads or Google Ads, used solely to reconcile your ad charges and display your own campaign performance
Usage data: Pages visited, features used, and error logs for improving the product.
We do not collect full bank account numbers, routing numbers, credit card numbers, or online banking credentials. Plaid handles all bank authentication — we never see your bank username or password.
We use your data exclusively to provide the Naviio service:
Displaying your financial dashboard, reports, and forecasts
Generating AI-powered insights and alerts
Authenticating your account and maintaining your session
Sending transactional emails (account confirmations, alert notifications)
Improving product reliability and fixing errors
We do not sell your data. We do not use your financial data for advertising, credit decisioning, or any purpose other than providing you the Naviio service.
We share data only with the following service providers, strictly as needed to operate the platform:
AWS — cloud infrastructure and database hosting
Plaid — bank data aggregation (governed by Plaid's Privacy Policy)
Anthropic — AI analysis (receives aggregated financial summaries only; no raw transactions or PII)
SendGrid — transactional email delivery
Vercel — application hosting
We do not share your financial data with other customers, data brokers, advertisers, or any third party not listed above. All vendors are contractually bound to use your data only to provide their service to Naviio.
We implement industry-standard security measures to protect your data:
All data is encrypted at rest using AES-256 via AWS KMS
All data in transit is encrypted using TLS 1.2 or higher
OAuth tokens are encrypted at the application layer before storage
Multi-factor authentication is required for all access to production systems
Access to customer data is limited to named personnel with a documented business need
No method of transmission or storage is 100% secure. If you believe your account has been compromised, contact us immediately at hello@naviio.com.
We retain your financial data for up to 25 months from the date of collection to enable historical analysis. Authentication logs are retained for 90 days. When you delete your account, we permanently delete all your financial data within 30 days and revoke all connected integration tokens immediately.
You may request deletion of your data at any time. See Section 7 for how to exercise this right.
Naviio uses Plaid to connect to your bank accounts. By connecting a bank account, you agree to Plaid's End User Privacy Policy (plaid.com/legal/end-user-privacy-policy/).
Plaid data accessed through our platform is:
Used only to display your financial information back to you
Never shared with other customers or third parties for marketing or analytics
Revoked via Plaid's API immediately upon disconnection or account deletion
Stored in compliance with Plaid's Developer Policy
You have the right to:
Access your personal data by logging into your account or emailing hello@naviio.com
Correct inaccurate data through your account settings
Delete your account and all associated data at any time (Settings → Account → Delete Account, or email us)
Export your data in a portable format upon request
Opt out of non-essential communications
California residents may have additional rights under the CCPA. To submit a request, email hello@naviio.com with "CCPA Request" in the subject line.
We use a single session cookie ("markup_session") to maintain your authenticated session. We do not use third-party tracking cookies, advertising cookies, or analytics cookies. You may delete this cookie at any time, which will log you out of the platform.
Naviio is intended for business use by adults. We do not knowingly collect personal information from anyone under the age of 18. If you believe we have inadvertently collected such information, contact us immediately.
We may update this Privacy Policy periodically. When we make material changes, we will notify you by email or via an in-app notice at least 30 days before the change takes effect. Continued use of the platform after the effective date constitutes acceptance of the updated policy.
For privacy-related questions or to exercise your rights:
Naviio, Inc.
Email: hello@naviio.com
Fairfield, CT