Privacy Policy
Your data, your business.
Last updated: July 2026 · Operated by Rafflexchange Inc.
Who we are
For the purposes of the Data Privacy Act, the Personal Information Controller (PIC) responsible for your personal data is Rafflexchange Inc. (“Rafflexchange”, “Monthcloser”, “we”, “us”), a company registered in the Republic of the Philippines and the operator of monthcloser.com. Contact us about any privacy matter at support@monthcloser.com.
Monthcloser does not look at your financial data. Here is exactly what that means.
The seven privacy commitments
These are the specific, named commitments that constitute Monthcloser's privacy stance. Each is backed by a technical or operational measure.
What we collect
Account and profile information
When you sign up, we store your email address, your name (optional), and a hashed password. We never see your password in plain text — it's hashed with a per-user salt before it touches our database. If you choose to complete your profile, we may also store optional details you provide, such as a phone number, employment type, or employer industry. These are entirely optional and used only to personalize your Monthcloser experience and improve the relevance of your benchmark comparisons.
Your monthly close data
To close a month, you upload your statements (PDF) and confirm them. We then store the structured result of that close:
- Bank transactions (date, description, amount, category, and the classification you confirm) from the statement you uploaded
- Credit-card line items from your statement
- Payslip earnings and deductions you confirmed during the close
- Financial account summaries (for example SSS, Pag-IBIG, PhilHealth, loans, insurance, or investment accounts) and their latest balances
- Your Financial Health Score and its four component scores for each closed month
- Your Close Reports
- Category rules you create to help us classify future merchants
- Milestone badges earned and your streak count
This data lives in a per-user space in our MongoDB Atlas database. No other user can see your data, and we don't share it with anyone outside what's strictly required to run the service (see “Who has access” below).
Your original documents are never stored
This is central to how Monthcloser works. When you upload a statement or payslip, the original file is processed entirely in memory and is never written to our disks or database. Once we extract the figures and you confirm them, the file is discarded. We keep only the structured result — not the source document. If a document is password-protected, the password you enter is used only to open the file during processing and is never stored or logged.
The Close Report™ and AI processing
You receive The Close Report™ — an automatic AI-generated monthly financial health report delivered after every close. We want to be fully transparent about how this works.
The Close Report and Ask AI use your verified closed-month data to generate these features automatically. If you prefer that your data is never processed by AI, contact us to disable Close Report and Ask AI generation — you keep full access to your monthly close either way. The two Ask AI questions available after each close use your data only to answer your specific question and are not retained beyond the session.
Enterprise program employees
If your employer provides Monthcloser as an employee benefit, your account is sponsored by your employer but your data remains entirely yours:
- Your employer cannot see your individual data. Any report your employer receives contains only anonymized group metrics for the cohort as a whole — no individual salary, balance, spending, or Financial Health Score.
- Your account belongs to you, not your employer. Your financial history, closed months, Close Reports, and score trajectory are yours permanently. If you leave the company, your account continues under an individual subscription.
- Your coach sees only what you share. A Monthcloser Certified Coach™ sees aggregated cohort information only; your individual data is visible to them solely if you explicitly grant Shared Close View access in the app, which you can revoke anytime.
Billing information
If you subscribe, payments are handled entirely by Stripe. We never see or store your full card number, CVV, or bank account details. From Stripe we receive and store:
- Your Stripe customer ID and subscription ID
- Payment status (paid / failed) and amount per invoice
- Plan code and subscription period dates
This is what powers the “Billing” tab in your account.
Logs and basic operations
Our server logs standard things like request paths, response status codes, and timestamps so we can keep the service healthy and secure. We don't run third-party analytics, ad pixels, or session recorders.
Why we process your data (legal bases)
Under the Data Privacy Act, we process your personal data only where we have a lawful basis to do so:
- Your consent — given when you sign up and when you upload and confirm documents for processing.
- Performance of a contract — to provide the Monthcloser service you signed up for, including closing your months and managing your subscription.
- Compliance with legal obligations — for example, retaining billing records required by tax and accounting laws.
- Our legitimate interests — to keep the service secure, prevent fraud and abuse, and improve reliability, balanced against your rights and freedoms.
If we introduce an anonymized benchmark dataset in the future, we would rely on your explicit opt-in consent, which you could withdraw at any time.
What we don't do
- We don't connect to your bank. No Plaid, no Open Banking, no read-only credentials. Your bank account stays your bank account.
- We don't sell your individual data. Ever — not your specific transactions, not your salary, not your Financial Health Score. We do not currently operate any data-licensing or benchmark product; if we ever offer anonymized aggregate benchmarks, it would be strictly opt-in and your individual data would never be sold.
- We don't track you across the web. No ad networks, no marketing pixels, no cross-site cookies.
- We don't use your data to train AI models. Under Anthropic's commercial API terms, data submitted through their API is not used to train their models.
- We don't share your data with your employer in individual form. Your employer receives only anonymized cohort metrics.
Who has access
Your data is processed by a small set of vetted infrastructure providers acting as our Personal Information Processors, each with a narrow, specific role and bound by their standard terms and applicable data-protection commitments:
| Provider | Role | Data processed |
|---|---|---|
| MongoDB Atlas | Database hosting | Account data, close records, and Close Reports (encrypted at rest at the storage layer) |
| Heroku | Application hosting | Runs the Monthcloser application servers |
| Anthropic | AI for the Close Report | Monthly close financial summary — per report only; under Anthropic's API terms, not used for training |
| Stripe | Payment processing | Billing records only — no financial health data |
The Monthcloser team accesses your data only to run the application that serves you and to help with a specific support request you raise — the latter only with your permission. Access is restricted by role and logged for security.
Employer-sponsored accounts
If your employer has entered into a service agreement with Rafflexchange Inc. to offer Monthcloser as an employee benefit, the following applies in addition to the rest of this policy.
Your employer's role. Your employer is a Personal Information Controller under the Data Privacy Act, sponsoring your participation in the program. That sponsorship covers the cost of your access and enables the program within your organization. It does not give your employer access to your personal data.
What your employer sees. Your employer — and no one at your employer — ever sees your individual closes, your Financial Health Score, your Close Report, your uploaded documents, or any figure attributable to you personally. The only information available to your employer is anonymized, aggregated cohort metrics for the group as a whole (for example, the cohort's average savings rate or the percentage of employees who completed a close this month), provided in a quarterly report. To prevent identification of any individual, we only report a metric if the cohort it describes has at least 10 participating employees; smaller cohorts are combined with a broader group or withheld until that threshold is met.
Access logging. Any access to your individual data by Monthcloser staff — which occurs only when strictly necessary to investigate a bug or respond to a support request — is logged. Such access never occurs without your consent for support matters.
AI and automated processing. Your Close Report and Financial Health Score are generated by automated systems from your verified closed data. No Monthcloser staff member reviews your data to produce these outputs. Aggregated cohort reports for your employer are similarly computed by automated systems from anonymized data and are not reviewed at the individual level.
When your employer's program ends. If your employer's service agreement with Rafflexchange Inc. ends — for any reason, including your own departure from the company — your account does not disappear. You will be notified and offered the option to continue on a personal subscription. Your complete close history, your Financial Health Score history, your Close Reports, and your Annual Forecast (if unlocked) remain yours permanently. Your employer has no role in that continuation and receives no data about it.
If you decline to continue. If you do not take up a personal subscription after your employer's program ends, your account enters read-only access. Your data is retained under the standard retention terms in this policy and is not shared with your employer or any third party. You may request deletion at any time by contacting support@monthcloser.com.
Your rights are unchanged. Employer sponsorship does not affect your rights under the Data Privacy Act. You retain the right to access, correct, object to, and request erasure of your personal data regardless of how your account was created or who is paying for it.
Where your data is processed
Some of our processors — including MongoDB Atlas, Heroku, and Anthropic — may store or process data on servers located outside the Philippines. Where personal data is transferred across borders, we take steps to ensure it remains protected to a standard consistent with the Data Privacy Act and applicable NPC issuances, and that our processors are bound by appropriate contractual and security safeguards.
For subscribers in Singapore, Australia, the United Kingdom, and the European Union, additional protections apply under the respective applicable privacy laws (PDPA, Privacy Act 1988, UK GDPR, and GDPR). Contact us if you have questions about the protections applicable to your jurisdiction.
How we protect your data
We apply organizational, physical, and technical security measures appropriate to the sensitivity of your financial data, including:
- Encryption in transit — all traffic between your browser and our servers is protected with TLS (HTTPS), with HTTP automatically upgraded to HTTPS.
- Encryption at rest — data is encrypted at rest at the storage layer by our database provider (MongoDB Atlas).
- Password protection — passwords are hashed with a per-user salt and never stored in plain text.
- Document minimization — original documents are never persisted; we keep only the structured figures you confirm.
- Access controls — data is partitioned per user and internal access is limited by role.
- Access logging — access to financial records is logged for security.
- AI processing — Close Report generation sends only a per-month financial summary to Anthropic over HTTPS and does not log your financial content.
How long we keep your data
| Data type | Retention period |
|---|---|
| Original documents (payslips, bank & CC statements) | Not retained. Discarded immediately after processing; never written to disk. |
| Account & close data (transactions, Financial Health Scores, Close Reports) | Kept while your account is active. Permanently deleted on account closure. |
| Billing records | Kept as long as required by applicable tax, accounting, and anti-fraud laws. Stripe retains billing records under its own policies. |
| Operational logs | Kept for a limited period for security and reliability, then rotated out. Financial content is never in operational logs. |
| Anonymized benchmark data (if introduced) | Would be retained only as anonymized aggregate statistics; the opt-in disclosure would explain that individual contributions cannot be removed from historical aggregates. |
| Access logs | Retained for security for a limited period, then rotated out. |
Your rights
Under the Data Privacy Act, you have the right to be informed, to access, to object, to rectify, to erasure or blocking, to data portability, and to be indemnified for damages. In practice, within Monthcloser you can:
- Access & export — view and download your monthly closes as CSV or similar
- Correct — edit any line, category, or rule directly in the app
- Delete — remove individual months, or request full account deletion
- Object — withdraw consent to specific processing by contacting us to disable Close Report generation
- Cancel — end your subscription anytime from Account → Subscription
To exercise any of these rights, contact us at support@monthcloser.com. You also have the right to lodge a complaint with the National Privacy Commission (NPC) if you believe your data privacy rights have been violated — see privacy.gov.ph.
Data breach notification
We maintain safeguards to prevent unauthorized access to your data. In the event of a personal data breach that may pose a real risk of serious harm, we will:
- Notify the National Privacy Commission within 72 hours of knowledge of the breach;
- Notify affected users within a reasonable time with specific information about what occurred and what data was involved; and
- Take immediate steps to contain the breach and prevent further unauthorized access.
Our database provider encrypts data at rest at the storage layer, which adds a layer of protection against certain forms of infrastructure compromise.
Cookies
We use one essential mechanism: a token stored in your browser's localStorage so you stay signed in. That's it. No tracking cookies, no third-party cookies, no consent banner drama because there's nothing tracking you.
Children
Monthcloser is intended for salaried professionals and is not designed for users under 18. We don't knowingly collect personal data from children. If you believe a minor has created an account, contact us at support@monthcloser.com and we will delete it promptly.
Changes to this policy
If we change how we handle data, we'll update this page and the “Last updated” date at the top. Significant changes — to the seven commitments, to what we collect, or to who has access — will be announced in-app with at least 30 days' notice before taking effect. We will never reduce the protections described in the seven commitments without explicit notice and the opportunity for you to export your data and close your account first.
Data Protection Officer & contact
Questions, deletion requests, access requests, or anything privacy-related — including matters for the attention of our Data Protection Officer — can be sent to support@monthcloser.com. We will respond within a reasonable period consistent with the Data Privacy Act. For complaints about how we have handled your personal data, you may also contact the National Privacy Commission directly at privacy.gov.ph.