FINSTAT.AI - PRIVACY POLICY
Effective Date: July 25, 2026 Version: 1.4 Organization: FINSTAT INC. Product: FinStat.ai Website: https://www.finstat.ai
TABLE OF CONTENTS
- Introduction
- Key Definitions
- Information We Collect
- How We Use Your Information
- AI Processing and Third-Party Services
- Data Sharing and Disclosure
- Data Security
- Data Retention
- Your Privacy Rights
- GDPR - European Privacy Rights
- CCPA - California Privacy Rights
- Cookies and Tracking Technologies
- International Data Transfers
- Children's Privacy
- Changes to This Policy
- Contact Us
1. INTRODUCTION
Welcome to FinStat.ai (the "Product" or "Services"), operated by FINSTAT INC. ("FinStat," "we," "us," or "our").
This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you:
- Visit our website at https://www.finstat.ai
- Use our artificial intelligence-powered financial accounting, Chart of Accounts mapping, and financial reporting software
- Interact with our customer support, marketing, or other services
Your privacy is important to us. We are committed to protecting your personal information and being transparent about our data practices. This Privacy Policy is designed to help you understand:
- What information we collect and why
- How we use and share that information
- Your rights and choices regarding your information
- How we protect your data
By using our Products or Services, you agree to the collection, use, and disclosure of your information as described in this Privacy Policy. If you do not agree, please do not use our Products or Services.
Important Notice About AI Processing
Our Products utilize artificial intelligence (AI) and machine learning technologies provided by third-party services, including OpenAI and Anthropic, to analyze and categorize financial transactions. When you upload documents or transaction data to our Products, that data may be processed by these AI services. We have configured these integrations to protect your data (see Section 5 for details).
2. KEY DEFINITIONS
"Personal Data" or "Personal Information" means any information relating to an identified or identifiable individual.
"Processing" means any operation performed on personal data, including collection, storage, use, disclosure, or deletion.
"Licensee" means an organization or individual that has subscribed to our Products under a License Agreement.
"Authorized User" means an individual authorized by a Licensee to access and use the Products.
"AI Services" means third-party artificial intelligence and machine learning services we use to provide transaction categorization and document processing, including OpenAI (ChatGPT, GPT-4), Anthropic (Claude), and xAI (Grok).
"Controller" means the entity that determines the purposes and means of processing personal data (typically the Licensee for account data).
"Processor" means the entity that processes personal data on behalf of the Controller (FinStat acts as a processor for Licensee data).
"Sub-processor" means a third-party service provider engaged by FinStat to process personal data (e.g., AI Services, cloud infrastructure providers).
3. INFORMATION WE COLLECT
We collect several categories of information when you use our Products and Services:
3.1 Information You Provide Directly
(a) Account and Identity Data
- Full name
- Email address
- Username and password
- Company or organization name
- Job title or role
- Phone number (optional)
- Billing address
(b) Financial and Payment Data
- Bank account information (for transaction imports via bank connections)
- Payment card details (processed by Stripe; we do not store full card numbers)
- Transaction history and payment records
- Accounting and bookkeeping data
- Tax identification numbers (when provided for tax reporting features)
(c) Documents and Files
- Receipts, invoices, and financial documents you upload
- Bank statements and credit card statements
- Tax forms and supporting documentation
- Any other files you choose to upload to the Products
(d) Communications Data
- Messages you send to our support team
- Survey responses and feedback
- Email correspondence
- Chat transcripts with customer support
(e) Preferences and Profile Data
- Account settings and preferences
- Categorization rules and customizations
- Chart of Accounts (COA) structures and configurations
- COA mapping rules and automation settings
- Financial report templates and custom report configurations
- Notification preferences
- Product feedback and feature requests
3.2 Information We Collect Automatically
(a) Usage and Analytics Data
- Pages viewed and features used
- Time spent on different sections
- Clicks, navigation paths, and user interactions
- Search queries within the Products
- Errors, crashes, and performance metrics
(b) Technical and Device Data
- IP address
- Browser type and version
- Operating system
- Device type (desktop, mobile, tablet)
- Screen resolution
- Language settings
- Time zone
- Cookies and similar tracking identifiers
(c) Authentication and Security Data
- Login timestamps and frequency
- Authentication methods used (email/password, OAuth, SSO)
- Access logs and security events
- Device fingerprints for fraud prevention
3.3 Information from Third-Party Sources
(a) Bank and Financial Institutions
- Transaction data imported from connected bank accounts or credit cards
- Account balances and financial institution information
(b) OAuth and SSO Providers
- Profile information from Google, Microsoft, or other authentication providers (if you use social login)
- Email address and basic profile data
(c) Payment Processors
- Payment confirmation and receipt information from Stripe
3.4 Information We Do NOT Collect
We do not knowingly collect:
- Special Categories of Personal Data under GDPR (e.g., race, ethnicity, political opinions, religious beliefs, health data, genetic data, biometric data for identification, sexual orientation)
- Information about criminal convictions or offenses
- Personal data of children under 13 years of age (or applicable age in your jurisdiction)
- Social Security Numbers (unless you explicitly provide them in uploaded documents for legitimate accounting/tax purposes)
4. HOW WE USE YOUR INFORMATION
We process your personal information for the following purposes:
4.1 To Provide and Maintain the Products
Lawful Basis: Performance of contract, legitimate interests
- Create and manage your account
- Authenticate your identity and authorize access
- Process and categorize financial transactions using AI
- Perform optical character recognition (OCR) on uploaded documents
- Map transactions to Chart of Accounts based on user-approved rules
- Store and organize your financial data
- Generate Financial Reports (income statements, balance sheets, cash flow statements, custom reports) based on user-configured settings
- Provide reports, summaries, and insights
- Sync data with connected bank accounts
- Provide customer support and respond to inquiries
4.2 To Improve and Develop the Products
Lawful Basis: Legitimate interests, consent (where required)
- Analyze usage patterns to improve features and user experience
- Conduct research and development on new features
- Test and optimize AI categorization models (using anonymized data only)
- Debug errors and fix technical issues
- Monitor and improve system performance and reliability
4.3 For Security and Fraud Prevention
Lawful Basis: Legitimate interests, legal obligations
- Detect, prevent, and respond to security incidents
- Protect against unauthorized access, fraud, or abuse
- Monitor for suspicious activity or policy violations
- Enforce our Terms of Service and other policies
- Comply with legal obligations and law enforcement requests
4.4 For Communication and Marketing
Lawful Basis: Consent, legitimate interests, performance of contract
- Send transactional emails (account notifications, password resets, receipts)
- Provide product updates and feature announcements
- Send marketing communications about our Products (only with your consent)
- Conduct surveys and request feedback
- Respond to customer support inquiries
You can opt out of marketing communications at any time by clicking "unsubscribe" in emails or contacting us at support@finstat.ai.
4.5 For Legal and Compliance Purposes
Lawful Basis: Legal obligations, legitimate interests
- Comply with applicable laws, regulations, and legal processes
- Respond to subpoenas, court orders, or government requests
- Enforce our rights and protect our property
- Comply with tax, accounting, and financial regulations
- Maintain records required by law
4.6 For Business Operations
Lawful Basis: Legitimate interests
- Process payments and manage billing
- Conduct internal audits and quality assurance
- Analyze business performance and trends
- Prepare financial statements and reports
- Manage business relationships with partners and vendors
5. AI PROCESSING AND THIRD-PARTY SERVICES
5.1 Artificial Intelligence Services
Our Products use third-party AI services to analyze and categorize your financial data. This is a core feature of how FinStat.ai works.
(a) AI Providers We Use:
- OpenAI (ChatGPT, GPT-4, and related models) - https://openai.com/policies/privacy-policy
- Anthropic (Claude and related models) - https://www.anthropic.com/legal/privacy
- xAI (Grok and related models) - https://x.ai/legal/privacy-policy
- Other AI/ML providers as needed for optimization and feature development
(b) What Data Is Processed by AI Services: When you use our transaction categorization, Chart of Accounts mapping, or financial report generation features, the following data may be sent to AI Services:
- Transaction descriptions, amounts, dates, and merchant names
- Text extracted from uploaded receipts, invoices, and financial documents via OCR
- Context about your Chart of Accounts structure, account types, and categorization preferences (to improve accuracy)
- Historical transaction categorizations and COA mappings (to identify patterns and improve suggestions)
(c) How We Protect Your Data with AI Services:
- API Configuration: We use API settings designed to prevent AI providers from training their models on your data (where such options are available)
- Data Minimization: We only send the minimum data necessary for categorization
- No Permanent Storage: AI Services process data transiently; they do not permanently store your financial data in their systems (per their policies)
- Encryption: All data transmitted to AI Services is encrypted in transit using TLS/SSL
(d) AI Provider Data Policies: While we take steps to protect your data, please note that data sent to AI Services is subject to those providers' privacy policies and terms. We recommend reviewing:
- OpenAI Privacy Policy: https://openai.com/policies/privacy-policy
- Anthropic Privacy Policy: https://www.anthropic.com/legal/privacy
- xAI Privacy Policy: https://x.ai/legal/privacy-policy
(e) AI Provider Security and Compliance Certifications: All AI Services integrated with our Products maintain industry-leading security and compliance certifications:
- OpenAI: SOC 2 Type II certified, ISO 27001/27017/27018/27701 certified, GDPR and CCPA compliant
- Anthropic (Claude): SOC 2 Type I/II certified, ISO 27001:2022 and ISO/IEC 42001:2023 (AI Management System) certified, HIPAA compliant, GDPR and CCPA compliant with dedicated EU data residency
- xAI (Grok): SOC 2 Type 2 certified, GDPR and CCPA compliant
These third-party certifications provide additional assurance that AI Services handling your data maintain:
- Enterprise-grade security controls
- Regular independent security audits
- Compliance with international data protection standards
- Robust encryption standards (TLS 1.2+ in transit, AES-256 at rest)
For more information about AI provider security practices, see:
- OpenAI Trust Portal: https://trust.openai.com/
- Anthropic Trust Center: https://trust.anthropic.com/
- xAI Security: https://x.ai/security
5.2 Other Third-Party Services
Our Products integrate with the following third-party services:
| Service | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|
| WorkOS | Authentication and user management | Name, email, authentication credentials | https://workos.com/legal/privacy |
| Stripe | Payment processing | Name, email, payment card details, billing address | https://stripe.com/privacy |
| VULTR | Cloud infrastructure hosting | All data stored on our platform | https://www.vultr.com/legal/privacy/ |
| Filestack | File upload and management | Uploaded document files | https://www.filestack.com/privacy/ |
| Zendesk | Customer support ticketing | Name, email, support inquiries | https://www.zendesk.com/company/agreements-and-terms/privacy-notice/ |
All third-party services are carefully vetted for security and privacy compliance. We require that they:
- Maintain appropriate security measures
- Process data only as instructed by us
- Comply with applicable data protection laws (GDPR, CCPA, etc.)
- Use data solely to provide services to us, not for their own purposes
(f) FinStat's Own Model Improvement (Document Structure Only): To improve accuracy for all users, FinStat may use documents you upload to train and improve FinStat's own document-recognition and data-extraction systems — specifically, by learning the structure and format of financial documents (for example, how a particular bank's statement is laid out). FinStat does not sell your data, does not use your or your clients' personal or account information (such as names, account numbers, or login credentials) to train models, and does not expose that personal or account information to anyone outside FinStat other than the service providers listed in this Policy that are needed to operate the Services.
5.3 Data Processing Agreements
For Licensees subject to GDPR, we have Data Processing Agreements (DPAs) in place with key sub-processors, including AI Services, to ensure GDPR-compliant processing. A list of current sub-processors is available at https://www.finstat.ai/subprocessors.
5.4 Beta / Pre-Release Use
If you participate in a pre-release or "beta" version of the Services as an invited Beta Partner, your use is additionally governed by the Beta Program Terms in Section 25 of our Terms of Service. As with our generally available Services, data you upload during the Beta — including your clients' data — is used to provide and improve the Services (including learning the structure and format of financial documents, as described in Section 5(f) above), and is not sold. FinStat does not use your or your clients' personal or account information to train models and does not expose it outside FinStat except to the service providers needed to operate the Services. You may request deletion of your Beta data at any time (see Section 8, Data Retention, and Section 9, Your Privacy Rights). As a Beta Partner, you remain responsible for obtaining any client consent your professional or contractual obligations require before uploading client data, and you may anonymize client data before uploading.
6. DATA SHARING AND DISCLOSURE
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
We share your information only in the following limited circumstances:
6.1 With Service Providers and Sub-Processors
We share personal information with third-party service providers who perform services on our behalf, including:
- AI Services (OpenAI, Anthropic) for transaction categorization
- Cloud hosting providers (VULTR) for infrastructure
- Payment processors (Stripe) for billing
- Authentication services (WorkOS) for login and security
- Support platforms (Zendesk) for customer service
All service providers are contractually obligated to:
- Use data only for the specific services they provide to us
- Maintain appropriate security and confidentiality measures
- Comply with applicable data protection laws
- Not use data for their own business purposes or marketing
6.2 With Your Consent or at Your Direction
We may share your information when you explicitly direct us to do so, such as:
- Integrating with third-party accounting software (e.g., QuickBooks, Xero) at your request
- Sharing reports or data exports with individuals you specify
- Connecting your bank accounts via third-party aggregation services
6.3 For Legal and Compliance Reasons
We may disclose personal information when required by law or when we believe disclosure is necessary to:
- Comply with legal process (subpoenas, court orders, search warrants)
- Respond to government or regulatory requests
- Enforce our Terms of Service or other agreements
- Protect the rights, property, or safety of FinStat, our users, or the public
- Detect, prevent, or investigate fraud, security issues, or illegal activity
We will notify you of legal requests for your data unless prohibited by law.
6.4 In Business Transactions
If FinStat is involved in a merger, acquisition, asset sale, financing, bankruptcy, or other business transaction, your personal information may be transferred or disclosed as part of that transaction. We will provide notice before your information is transferred and becomes subject to a different privacy policy.
6.5 With Professional Advisors
We may share personal information with professional advisors, including:
- Lawyers (for legal advice and representation)
- Accountants and auditors (for financial review)
- Insurance providers (for risk management)
- Business consultants (for strategic planning)
These advisors are bound by confidentiality obligations and may use data only for the purposes of advising FinStat.
6.6 Aggregated and Anonymized Data
We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you. For example:
- Industry benchmarks and trends (e.g., "Average transaction volume for restaurants")
- Usage statistics (e.g., "80% of users categorize transactions within 24 hours")
- Product performance metrics
This data does not identify you personally and is not subject to this Privacy Policy.
7. DATA SECURITY
7.1 Security Measures
We implement industry-standard administrative, technical, and physical safeguards to protect your personal information, including:
(a) Administrative Safeguards:
- Security policies and procedures
- Employee training on data protection and privacy
- Background checks for employees with access to sensitive data
- Confidentiality agreements with employees and contractors
- Regular security audits and risk assessments
(b) Technical Safeguards:
- Encryption: All data transmitted to and from our servers is encrypted using TLS/SSL (Transport Layer Security), with certificates issued by a publicly trusted Certificate Authority. Data at rest is encrypted using AES-256 encryption.
- Access Controls: Role-based access controls (RBAC) limit data access to authorized personnel only
- Authentication: Multi-factor authentication (MFA) available for user accounts; required for administrative access
- Firewall Protection: Network firewalls and intrusion detection/prevention systems
- Vulnerability Management: Regular security scans and penetration testing
- Secure Development: Code reviews, security testing, and secure coding practices
(c) Physical Safeguards:
- Data hosted in SOC 2 Type 2 certified data centers (VULTR)
- Physical access controls and surveillance at data center facilities
- Redundant power, cooling, and network connectivity
7.2 Payment Security
We use Stripe, a PCI-DSS Level 1 certified payment processor, to handle all payment transactions. We do not store full credit card numbers on our servers. Stripe handles payment card data securely and in compliance with PCI-DSS requirements.
7.3 Security Incident Response
In the event of a data breach or security incident that affects your personal information, we will:
- Investigate the incident promptly
- Take steps to contain and remediate the breach
- Notify affected individuals within 72 hours (or as required by applicable law)
- Notify relevant supervisory authorities (e.g., data protection authorities under GDPR)
- Provide information about the incident, affected data, and steps you can take to protect yourself
7.4 Your Role in Security
While we implement robust security measures, you also play a role in protecting your data:
- Use strong, unique passwords for your account
- Enable multi-factor authentication (MFA) if available
- Do not share your login credentials with others
- Log out of your account when using shared or public devices
- Report suspicious activity or security concerns to security@finstat.ai
7.5 Limitations
No system is 100% secure. Despite our efforts, we cannot guarantee absolute security of your data. Unauthorized access, hacking, data loss, or other breaches may occur. By using our Products, you acknowledge and accept these risks.
8. DATA RETENTION
8.1 How Long We Retain Your Data
We retain your personal information for as long as necessary to:
- Provide the Products and Services to you
- Comply with legal obligations (e.g., tax, accounting, and financial recordkeeping requirements)
- Resolve disputes and enforce our agreements
- Maintain business records and analytics
Specific retention periods:
| Data Type | Retention Period | Reason |
|---|---|---|
| Account and profile data | Duration of account + 7 years after closure | Legal and tax compliance |
| Transaction and financial data | Duration of account + 7 years after closure | IRS and accounting regulations |
| Uploaded documents | Duration of account + 30 days after deletion request | User access and legal requirements |
| Support communications | 3 years | Customer service and dispute resolution |
| Usage and analytics data | 2 years (anonymized after 90 days) | Product improvement |
| Marketing data | Until consent is withdrawn or 2 years of inactivity | Marketing compliance (GDPR, CAN-SPAM) |
| Security logs | 1 year | Fraud prevention and security |
8.2 Data Deletion Upon Account Closure
When you close your account or request deletion of your data:
- We will delete or anonymize your personal information within 30 days, except where we are required to retain data for legal, tax, or regulatory purposes
- You have 30 days after account closure to export your data before it is deleted
- We may retain anonymized, aggregated data for analytics and product improvement
8.3 Legal and Regulatory Retention
We may retain certain data for longer periods when required by law, including:
- Tax records: 7 years (IRS requirement for business records)
- Financial statements: 7 years (generally accepted accounting principles)
- Legal holds: Indefinitely during pending or threatened litigation
- Regulatory requirements: As specified by applicable regulations (e.g., SOX, SEC rules for certain businesses)
8.4 Data Deletion Requests
You may request deletion of your personal data at any time by contacting us at privacy@finstat.ai. We will honor your request within 30 days, subject to legal retention requirements. See Section 9 for details on exercising your rights.
9. YOUR PRIVACY RIGHTS
You have the following rights regarding your personal information:
9.1 Right to Access
You have the right to request access to the personal information we hold about you. You can:
- View and download your data through your account dashboard
- Request a copy of your data by contacting us at privacy@finstat.ai
We will provide your data in a structured, commonly used, and machine-readable format (e.g., CSV, JSON) within 30 days.
9.2 Right to Rectification (Correction)
If your personal information is inaccurate or incomplete, you have the right to:
- Update your account information directly in your account settings
- Contact us at privacy@finstat.ai to request corrections
We will update your information within 30 days of your request.
9.3 Right to Erasure (Deletion)
You have the right to request deletion of your personal information in certain circumstances, including:
- The data is no longer necessary for the purposes for which it was collected
- You withdraw consent (where processing is based on consent)
- You object to processing based on legitimate interests
- The data has been unlawfully processed
- Deletion is required by law
To request deletion, contact us at privacy@finstat.ai. We will comply within 30 days, except where retention is required by law.
9.4 Right to Restriction of Processing
You have the right to request that we restrict processing of your personal information in certain circumstances, such as:
- You contest the accuracy of the data (restriction applies while we verify)
- Processing is unlawful but you prefer restriction over deletion
- We no longer need the data, but you need it for legal claims
9.5 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another service provider. This right applies when:
- Processing is based on consent or contract performance
- Processing is carried out by automated means
You can export your data directly from your account dashboard or request a data export at privacy@finstat.ai.
9.6 Right to Object
You have the right to object to processing of your personal information when processing is based on legitimate interests or for direct marketing purposes.
To object, contact us at privacy@finstat.ai. For marketing objections, click "unsubscribe" in any marketing email.
9.7 Right to Withdraw Consent
Where processing is based on your consent, you have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing conducted before withdrawal.
9.8 Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority if you believe we have violated your privacy rights. In the United States, you may contact:
- Federal Trade Commission (FTC): https://www.ftc.gov/
- Your state Attorney General's office
For EU/EEA residents, contact your local data protection authority: https://www.edpb.europa.eu/about-edpb/about-edpb/members_en
9.9 How to Exercise Your Rights
To exercise any of the rights above:
- Email us: privacy@finstat.ai
- Include: Your name, email address, account information (if applicable), and a description of your request
- Verification: We may ask for proof of identity to verify your request (to prevent unauthorized access)
We will respond to your request within 30 days. If your request is complex or we receive multiple requests, we may extend the response time by an additional 60 days (we will notify you of any extension).
10. GDPR - EUROPEAN PRIVACY RIGHTS
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR).
10.1 Legal Basis for Processing
We process your personal data under the following lawful bases:
| Processing Activity | Legal Basis |
|---|---|
| Providing the Products and Services | Performance of contract (our Terms of Service) |
| Processing financial data and transactions | Performance of contract |
| Sending transactional emails | Performance of contract |
| Improving and developing the Products | Legitimate interests (product improvement) |
| Security and fraud prevention | Legitimate interests (security and safety) |
| Usage analytics (in-product) | Legitimate interests (business operations) |
| Marketing communications | Consent (you can opt out anytime) |
| Compliance with legal obligations | Legal obligation (tax, accounting, law enforcement) |
10.2 International Data Transfers
Our servers and AI Services are primarily located in the United States. If you are located in the EEA, UK, or Switzerland, your personal data will be transferred to the US, which has not received an "adequacy decision" from the European Commission.
To protect your data, we rely on the following safeguards:
- Standard Contractual Clauses (SCCs): We use European Commission-approved Standard Contractual Clauses with our sub-processors
- Data Processing Agreements (DPAs): We have DPAs with AI Services and other sub-processors
- Additional Security Measures: Encryption, access controls, and security audits
A copy of our Standard Contractual Clauses is available upon request at privacy@finstat.ai.
10.3 Controller vs. Processor Roles
- When you are an individual user: FinStat is the data controller for your account, profile, and usage data
- When you are an Authorized User of a Licensee account: The Licensee (your organization) is typically the data controller and FinStat is the data processor
If you have questions about how your organization (Licensee) handles your data, please contact your organization's privacy or HR team.
10.4 Data Protection Officer
For GDPR-related inquiries, you may contact our Data Protection Officer (DPO) at:
- Email: dpo@finstat.ai
- Address: FINSTAT INC., Data Protection Officer, c/o REPUBLIC REGISTERED AGENT LLC, 898 South State Street, Ste 310, Orem, Utah 84097, USA
11. CCPA - CALIFORNIA PRIVACY RIGHTS
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA).
11.1 Categories of Personal Information We Collect
Under CCPA, we collect the following categories of personal information (refer to Section 3 for details):
| CCPA Category | Examples from Our Collection |
|---|---|
| Identifiers | Name, email, IP address, username |
| Financial Information | Bank account details, payment card information, transaction data |
| Commercial Information | Subscription history, purchase records, payment history |
| Internet or Electronic Activity | Browsing history, usage data, clicks, interactions |
| Geolocation Data | IP-based approximate location (city/state level) |
| Professional Information | Job title, company name (if provided) |
| Inferences | Preferences, categorization patterns, product usage insights |
We do not collect sensitive personal information such as Social Security numbers, driver's license numbers, precise geolocation, race, ethnicity, health data, or sexual orientation (except to the extent contained in documents you voluntarily upload).
11.2 Sources of Personal Information
We collect personal information from:
- Directly from you (account registration, uploads, communications)
- Automatically (cookies, usage tracking, device data)
- Third parties (bank connections, authentication providers, payment processors)
11.3 Purposes for Collecting Personal Information
See Section 4 for detailed purposes. In summary:
- Provide and maintain the Products
- Process transactions and billing
- Improve and develop features
- Security and fraud prevention
- Marketing and communications (with consent)
- Legal compliance
11.4 Personal Information We Disclose
We disclose personal information to the following categories of third parties (see Section 6 for details):
- Service providers and sub-processors (AI Services, hosting, payment, support)
- Professional advisors (legal, accounting)
- Government and legal entities (when required by law)
- Business transaction parties (in case of merger or acquisition)
11.5 We Do Not "Sell" or "Share" Personal Information
FinStat does not sell or share your personal information for monetary consideration or cross-context behavioral advertising.
We may share anonymized, aggregated data that cannot identify you, but this is not considered a "sale" under CCPA.
11.6 Your CCPA Rights
California residents have the following rights:
(a) Right to Know: Request disclosure of:
- Categories of personal information collected
- Sources of personal information
- Purposes for collection and disclosure
- Categories of third parties with whom we share data
- Specific pieces of personal information we hold about you
(b) Right to Delete: Request deletion of your personal information (subject to legal exceptions)
(c) Right to Correct: Request correction of inaccurate personal information
(d) Right to Opt Out of Sales/Sharing: Not applicable (we do not sell or share personal information)
(e) Right to Limit Use of Sensitive Personal Information: Not applicable (we do not use sensitive personal information for purposes beyond CCPA-permitted uses)
(f) Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights
11.7 How to Exercise Your CCPA Rights
To exercise your rights:
- Email us: privacy@finstat.ai
- Call us (toll-free): 1-800-614-1423
- Include: Your name, email, account information (if applicable), and request details
Verification: We will verify your identity before fulfilling your request (to prevent unauthorized access). We may ask for:
- Email confirmation
- Account login verification
- Government-issued ID (in limited cases for sensitive requests)
Response Time: We will respond within 45 days. For complex requests, we may extend by an additional 45 days (with notice).
Authorized Agents: You may designate an authorized agent to make requests on your behalf. The agent must provide proof of authorization (e.g., power of attorney).
11.8 California "Shine the Light" Law
Under California Civil Code Section 1798.83, California residents may request information about our disclosure of personal information to third parties for direct marketing purposes. We do not share personal information with third parties for their direct marketing purposes.
12. COOKIES AND TRACKING TECHNOLOGIES
12.1 What Are Cookies?
Cookies are small text files stored on your device when you visit a website. They help websites remember your preferences, authenticate your identity, and track usage for analytics.
12.2 Types of Cookies We Use
| Cookie Type | Purpose | Duration | Can You Disable? |
|---|---|---|---|
| Necessary Cookies | Essential for login, security, and site functionality (e.g., session management, authentication) | Session or up to 1 year | No (site won't work properly without them) |
| Functionality Cookies | Remember your preferences (e.g., language, theme, account settings) | Up to 1 year | Yes (but may affect user experience) |
First-Party Analytics Cookie (_fs_vid) |
Anonymous visitor identifier for product research, security, fraud prevention (including free-trial abuse detection), quality assurance, and marketing attribution (including UTM parameters). Stored in FinStat's own database; not shared with advertising networks | Up to 2 years | Yes (via browser cookie controls; site remains usable) |
We DO NOT use:
- Third-party analytics cookies: We do not use third-party analytics services (for example Google Analytics, Matomo Cloud, or similar) or advertising pixels on our website
- Advertising/Targeting Cookies: We do not track you for behavioral advertising or share website analytics data with ad networks
During beta we operate a first-party attribution warehouse that may record IP address, user-agent, approximate IP-based location, pages viewed, UTM parameters, and (after sign-in) a link from the visitor cookie to your authenticated account for security and research purposes. See also Section 3 (Information We Collect) and Section 4 (How We Use Your Information).
12.3 Third-Party Cookies
Our website and Products may include cookies from third-party services:
- Stripe: Fraud detection and payment processing (https://stripe.com/privacy)
- WorkOS: Authentication and user management (https://workos.com/legal/privacy)
12.4 How to Manage Cookies
(a) Browser Settings: Most browsers allow you to:
- Block all cookies
- Accept only first-party cookies (block third-party)
- Delete cookies after each session
- View and delete existing cookies
Instructions for popular browsers:
- Chrome: Settings > Privacy and Security > Cookies
- Firefox: Settings > Privacy & Security > Cookies and Site Data
- Safari: Preferences > Privacy > Cookies and website data
- Edge: Settings > Cookies and site permissions
(b) Cookie Consent Manager: When you first visit our website, you may see a cookie consent banner. You can:
- Accept all cookies
- Accept only necessary cookies
- Customize your preferences
You can update your cookie preferences at any time by clicking the "Cookie Settings" link in the footer of our website.
Note: Disabling necessary cookies may affect site functionality (e.g., you may not be able to log in).
12.5 Do Not Track (DNT)
Some browsers offer a "Do Not Track" (DNT) signal. We do not currently respond to DNT signals, as there is no industry-wide standard for how to interpret them. However, you can control cookies and tracking through browser settings as described above.
13. INTERNATIONAL DATA TRANSFERS
13.1 Where Your Data Is Stored
Our primary data storage and processing facilities are located in the United States. When you use our Products, your personal information may be transferred to, stored in, and processed in the US.
Additionally, our sub-processors (AI Services, cloud hosting, etc.) may store or process data in other countries, including:
- United States (primary location for OpenAI, Anthropic, VULTR)
- European Union (if we expand infrastructure to EU data centers)
13.2 Safeguards for International Transfers
We implement appropriate safeguards to protect your data when it is transferred internationally:
(a) For EEA, UK, and Switzerland residents:
- Standard Contractual Clauses (SCCs): European Commission-approved data transfer agreements with sub-processors
- Data Processing Agreements (DPAs): Contracts requiring GDPR-compliant processing
- Adequacy Decisions: When transferring to countries with EU adequacy decisions (e.g., UK under the UK-EU Trade and Cooperation Agreement)
(b) For all users:
- Encryption: All data transmitted internationally is encrypted using TLS/SSL
- Access Controls: Strict access controls limit who can access data
- Compliance: Sub-processors contractually obligated to comply with applicable data protection laws
13.3 Questions About International Transfers
If you have questions or concerns about how your data is transferred internationally, contact us at privacy@finstat.ai.
14. CHILDREN'S PRIVACY
14.1 Age Restriction
Our Products and Services are not intended for children under 13 years of age (or the applicable age of consent in your jurisdiction, such as 16 in the EU).
We do not knowingly collect personal information from children. If you are under 13 (or the applicable age in your jurisdiction), do not use our Products or provide any personal information to us.
14.2 Parental Notice and Consent
If we discover that we have collected personal information from a child without parental consent, we will:
- Delete the information as soon as possible
- Terminate the child's account (if applicable)
- Notify the parent (if contact information is available)
14.3 Parents and Guardians
If you believe your child has provided personal information to us without your consent, please contact us immediately at privacy@finstat.ai. We will investigate and take appropriate action.
15. CHANGES TO THIS PRIVACY POLICY
15.1 Updates
We may update this Privacy Policy from time to time to reflect:
- Changes to our Products or Services
- Changes in applicable laws or regulations
- Improvements to our data practices
- New features or technologies
When we make changes, we will:
- Update the "Effective Date" at the top of this policy
- Post the revised policy on our website at https://www.finstat.ai/privacy
- Notify you of material changes via email or a prominent notice on our website
15.2 Material Changes
For material changes that significantly affect your rights or how we process your data, we will:
- Provide 30 days' advance notice before the changes take effect
- Offer you the opportunity to review the changes and make choices about your data
- If required by law, obtain your consent before applying changes to your existing data
Material changes may include:
- New categories of personal data collected
- New purposes for processing data
- Sharing data with new categories of third parties
- Significant changes to data retention periods
- Changes to your privacy rights
15.3 Acceptance of Changes
By continuing to use our Products or Services after changes take effect, you agree to the revised Privacy Policy. If you do not agree to the changes, you may:
- Stop using the Products
- Close your account
- Contact us to exercise your deletion rights (see Section 9)
15.4 Prior Versions
We will maintain prior versions of this Privacy Policy for reference. You can request previous versions by contacting us at privacy@finstat.ai.
16. CONTACT US
16.1 Privacy Inquiries
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, contact us:
Email: privacy@finstat.ai Data Protection Officer: dpo@finstat.ai Support: support@finstat.ai Phone (toll-free): 1-800-614-1423
Mailing Address: FINSTAT INC. Attn: Privacy Team c/o REPUBLIC REGISTERED AGENT LLC 898 South State Street, Suite 310 Orem, Utah 84097 United States of America
16.2 Response Time
We aim to respond to all privacy inquiries within 30 days. For complex requests or GDPR/CCPA data requests, we may extend the response time by an additional 30-60 days (we will notify you of any extension).
16.3 Complaints and Disputes
If you have a complaint about our privacy practices:
- Contact us first: We want to resolve your concerns directly
- Supervisory Authority: If you are not satisfied with our response, you may lodge a complaint with a data protection authority (see Section 9.8 or 10.5)
16.4 Business Inquiries
For business-related inquiries (partnerships, vendor relationships, media requests), contact:
General Inquiries: info@finstat.ai Business Development: business@finstat.ai Media/Press: press@finstat.ai
APPENDIX: SUMMARY OF KEY POINTS
This summary provides a quick overview of our privacy practices. For complete details, please read the full Privacy Policy above.
| Topic | Key Points |
|---|---|
| What We Collect | Name, email, financial data, uploaded documents, COA structures, report configurations, usage data, device/technical data |
| How We Use It | Provide Products, AI categorization, COA mapping, financial report generation, improve features, security, support, legal compliance |
| AI Processing | We use OpenAI, Anthropic, and xAI (Grok) AI services to categorize transactions, map to Chart of Accounts, and generate financial reports. Data is encrypted and not used to train third-party models. AI providers maintain SOC 2, ISO, GDPR, and CCPA certifications. |
| Data Sharing | We share data with service providers (AI, hosting, payment) but DO NOT sell your data. |
| Your Rights | Access, correct, delete, export, object to processing, withdraw consent |
| GDPR (EU) | Legal basis: contract performance, legitimate interests, consent. Standard Contractual Clauses for US transfers. |
| CCPA (California) | Right to know, delete, correct. We do NOT sell or share personal information. |
| Security | Encryption, access controls, SOC 2 certified hosting, PCI-DSS payment processing |
| Retention | Account data: 7 years after closure (tax/legal compliance). Marketing: until opt-out or 2 years inactivity. |
| Cookies | Necessary (required), Functionality (preferences). NO third-party analytics or advertising cookies. |
| Children | Not intended for users under 13. We do not knowingly collect children's data. |
| Changes | We will notify you of material changes with 30 days' notice. |
| Contact | privacy@finstat.ai or 1-800-614-1423 |
Thank you for trusting FinStat.ai with your financial data. Your privacy is our priority.
END OF PRIVACY POLICY
Document Version: 1.3 Effective Date: July 11, 2026 Organization: FINSTAT INC.