Privacy Policy
Orla is a finance app, so we hold the line on data the way we hold the line on money: we collect what the product genuinely needs, we never sell it, and we tell you plainly where it goes. This page explains what that means in practice.
Who we are
Orla (“Orla”, “we”, “us”) is operated by Digital Flow PTE LTD, and provides the finance app at app.orla.finance and the site at orla.finance. For anything on this page, reach us at [email protected].
What we collect
We collect three kinds of data, and no more than we need for each.
- Account data: your email and display name, and the sign-in methods you set up (password hash, passkeys, linked Google or Ethereum wallet). We never store your password itself.
- Financial data you put in: the accounts, transactions, budgets, goals, invoices, documents and contacts you add or connect. This is your ledger, and it exists so the app can show it back to you.
- Technical and security data: the device, browser, IP address and timestamps behind sign-ins and account changes, kept so you and we can spot access that isn't yours.
- Identity data, only if you use virtual cards, and only in passing: the card issuer has to verify the person a card belongs to, so the form collects their full name, date of birth, home address, country and an identity document type and number. Orla does not keep it. It is encrypted while the application is in flight and erased as soon as the issuer has taken it on, whether the card was approved or refused. If you invite someone else to hold a card, that is their data and they enter it themselves.
- Blockchain addresses: the public addresses of the wallets you add or connect. Reading a balance or a history means asking a public blockchain about that address.
What we deliberately do not collect
Your self-custody wallet keys never reach us. Seeds are generated and encrypted in your browser; only the public address is stored, so we could not move your crypto even if we wanted to.
Usage analytics, meaning which sections and features you use to improve the product, never include your amounts, balances or contacts, and you can switch it off entirely in Settings.
Cookies on the site
The orla.finance site asks before it stores anything. Until you answer, Google Analytics runs with storage switched off: it sets no cookie and carries no identifier, and Orla's own counter records the page you are on with a random id that dies with the tab.
Answer yes and two things become possible, each separately:
- Traffic: how many people arrive, where from, and which pages they read. This is Google Analytics, and it uses cookies to tell a returning visit from a new one.
- Ads: which ad or search brought you here and whether it led anywhere, so we can stop paying for the ones that bring nobody. This uses Google's advertising cookies and signals, and it is the only part that involves advertising at all.
Changing your cookie answer
The signup button carries your answer across to app.orla.finance, so you are not asked twice on the way in. It carries the answer, never a name or an identifier. Inside the app, product analytics is a separate switch in Settings, and it is never advertising.
Change your mind at any time with the Cookies link at the bottom of any page on orla.finance. Sign-in and security cookies in the app are not part of this question: the app cannot work without them, so they are not optional.
How we use it
We use your data to run the service, and for nothing you would not expect:
- To operate the ledger and its features, and to sync balances from the accounts you connect.
- To secure your account, with sign-in checks, the security activity log, and alert emails when something sensitive changes.
- To send the messages the app produces (approvals, invoices, alerts) on the channels you chose.
- To improve the product in aggregate, unless you have turned usage analytics off.
Why we are allowed to
Where the GDPR or a similar law applies to you, this is the basis we rely on for each thing we do:
- To perform our contract with you: running the ledger, syncing the accounts you connect, issuing and servicing cards, and taking payment for a paid plan.
- To meet a legal obligation: identity checks and sanctions screening around cards and crypto, and keeping billing records.
- For our legitimate interests: keeping the service secure and available, preventing abuse, and diagnosing crashes. We weigh that against your interests, and it never extends to selling your data.
- With your consent: usage analytics, and any channel you switch on such as Telegram. You can withdraw consent at any time in Settings, and it will not affect what came before.
Where your data is processed
Orla is operated from Singapore, and the providers above are spread across Singapore, the European Union and the United States, so your data crosses borders to reach them.
Where a transfer leaves a country whose law restricts it, such as the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses or an adequacy decision covering that provider. Ask us at [email protected] and we will tell you which one applies to a given provider.
Who we share it with
We do not sell your data. We share it only with the service providers that make the product work, each handling a specific job and bound to use it only for that:
- Hosting and infrastructure: DigitalOcean (application and database) and Vercel (the marketing site).
- Email delivery: Resend, for verification, security and notification emails.
- Error monitoring: Sentry, for diagnosing crashes.
- AI assistant: Anthropic, which processes Copilot requests. Copilot sees your space through read-only tools.
- Payments: our subscription payment providers for card billing, and on-chain stablecoin transfers for crypto billing. Card numbers are entered in the provider's own form and never reach Orla.
- Virtual cards: our card issuing partner and the identity verification service it uses, when you use Orla's virtual cards. Issuing a card passes that holder's identity data to them so they can verify it; from that point the record is theirs, not ours.
- Compliance screening: AMLBot, which screens a destination blockchain address before you send to it. It receives the address, not your identity.
- Blockchain data: public nodes and explorers, which we query to read balances and history for the addresses you add. This includes Etherscan, Arbiscan, Blockscout, mempool.space, TronGrid and public RPC endpoints. A public blockchain address is, by design, public.
- Swaps: LI.FI, which routes an exchange between assets. It receives the addresses and amounts involved.
- Market data: CoinGecko and DeFiLlama, for prices and rates. We ask them what an asset is worth, not what you hold.
- Sign-in, if you choose it: Google, when you sign in with a Google account.
- Site measurement, if you allow it: Google Analytics and Google Ads, for visits to orla.finance and to the signup pages. They receive the pages you opened, your approximate location from your IP address, and the ad or search that sent you. They never receive your ledger, your balances or your contacts, and they see nothing at all inside the app.
- Connections you choose: the banks, exchanges and open-banking providers you link, and Telegram if you connect it.
Where connections are read-only
Bank and exchange connections are read-only by design. Bank links run in the provider's own secure window, so we never see your banking password. Exchange keys are stored encrypted, and on Binance, Bybit and OKX a key that carries trade or withdrawal rights is refused outright, because those exchanges let us check. Kraken and Coinbase do not expose that check, so there we ask you for a read-only key and cannot verify it for you.
How long we keep it
We keep your data while your account is open. Deleting your account erases your files and every sign-in method, and strips the identifying fields from the account record; what remains is an anonymised row that no longer points at a person, kept so shared ledgers other people still rely on do not break.
Two things have to be settled before we can erase: a shared space you solely own must be handed over or deleted, and any live card must be closed first, because a card is a live financial instrument at the issuer. The app tells you which one is blocking.
A card holder's identity data is not kept at all: it lives encrypted only while the application is with the issuer and is erased the moment that finishes, either way. The card issuer keeps its own verification record, under its own policy. The holder's name, email and phone stay only while the card exists, and are erased when it is closed.
Records we are required to keep, billing and compliance among them, are kept for as long as the applicable law requires and no longer.
Your choices
You are in control of the data we hold:
- See and edit most of your data directly in the app.
- Turn off usage analytics in Settings, at any time.
- Change what the site may measure with the Cookies link at the bottom of orla.finance, at any time.
- Choose which notifications reach you, and on which channels.
- Delete your account, which erases your personal data as described above. Where you have rights under laws such as the GDPR, the UK GDPR, Singapore's PDPA or the CCPA (access, correction, deletion, portability, and objecting to processing we base on legitimate interests), contact us at [email protected] and we will honour them.
- Complain to a regulator. If you are in the EEA or the UK you can complain to your national data protection authority; in Singapore, to the Personal Data Protection Commission. We would rather you told us first at [email protected], but that choice is yours.
Security
The measures behind this policy are described on our Security page: encrypted secrets, hashed passwords, passkeys and two-factor sign-in, browser-held wallet keys, and read-only connections.
Changes
If we change this policy in a way that affects you, we will update the date above and, for material changes, tell you in the app or by email.