Bank Connections & Open Banking
Consumer Information Page — last updated March 19, 2026
In plain English
- Loots connects to your bank read-only — we can never move money or make payments.
- We use your transaction data to detect bills, track subscriptions, and give you spending insights.
- Your bank credentials are never stored or seen by Loots.
- You can disconnect at any time from Settings → Accounts.
- Connections are made through Akahu, a New Zealand open finance platform regulated under the Credit Contracts and Consumer Finance Act.
What data we access
When you connect a bank account, Loots requests read-only access to the following data via Akahu:
Transaction history
Dates, amounts, descriptions, and merchant names for your transactions. Used to detect bills and subscriptions.
Account balances
Current and available balances for linked accounts. Used to show your financial overview.
Account names and numbers
The name and last 4 digits of linked accounts. Used to identify which accounts are connected.
What we cannot do: We have no ability to initiate payments, move money, create payees, or make changes to your bank accounts in any way. Akahu enforces read-only access at the API level.
How we use your data
Your financial data is used exclusively to power Loots features. It is never sold or shared with third parties for advertising or marketing.
Bill & subscription detection
We analyse recurring transactions to identify bills (power, internet, insurance, streaming, etc.) and alert you to price increases.
Spending insights
Weekly digest, spending personality, and anomaly detection — all generated locally from your transaction history using AI.
Budget suggestions
We compare your spending against similar profiles to surface potential savings.
Switch suggestions
When we detect an overpriced bill, we surface NZ providers who may offer a better deal.
Powered by Akahu
Loots connects to your bank accounts through Akahu, a New Zealand open finance platform. Akahu acts as the secure intermediary between Loots and your bank — your bank credentials go directly to Akahu, and Loots never sees them.
Akahu uses OAuth 2.0 to authorise access. You log in to your bank directly on the bank's own website or Akahu's secure connection flow. Loots receives only the access token, not your username or password.
Learn more about Akahu's privacy practices and open finance platform at akahu.nz.
Your controls
Disconnect at any time
Go to Settings → Accounts and click Disconnect next to any connected account. Your access token is revoked immediately with Akahu — Loots loses access to new transaction data instantly.
Delete your account
You can delete your Loots account from Settings → Account. This immediately revokes all bank connection tokens and permanently deletes all your data.
Export your data
Download a copy of all your data (transactions, bills, and more) from Settings → Account → Export Data.