This policy explains how the operator providing services under the Finero name (“Finero”, “we”, “us”) processes personal information through getfinero.com (the “Website”), the Finero platform, payment pages, integrations and related support (the “Service”). Contact us at privacy@getfinero.com.
Finero provides accounts-receivable software for businesses. It connects business systems, manages invoice and payment workflows, and sends related communications. Personal information means information relating to an identified or identifiable person, including business information that identifies a contact, account user or individual payer.
Who this policy applies to
This policy covers Website visitors, prospective customers, people who contact us, account users and invited colleagues, and the contacts, invoice recipients and payers whose information a business customer processes through Finero.
Finero’s role: controller and processor
We act as a controller for purposes we determine, such as handling enquiries, managing our customer relationships and accounts, authenticating users, operating and measuring the Website, supporting and securing the Service, and keeping our business and legal records. Where applicable law uses different terms, our responsibilities follow the actual processing involved.
For customer-controlled invoice, contact, payment, integration and workflow information, we generally act as a processor on the business customer’s behalf. The customer determines the business purpose, connected systems, authorised users and instructions. It is responsible for the accuracy and lawful provision of that information and for required notices and permissions. We use it to carry out the customer’s instructions and provide the Service, subject to applicable law. This allocation does not remove Finero’s own legal responsibilities.
If your information comes from a business using Finero, contact that business first about its processing. We assist as required by our role and applicable law. This policy is a privacy notice, not a substitute for a data-processing agreement where one is required.
Information we process
The information involved depends on the features and connections used.
Website, accounts and business contacts
- Enquiries and support. Names, work email addresses, companies, ERP and payment-provider details, invoice-volume ranges, submitted notes, messages and material you provide for support. Demo requests also include the submission time, page URL and campaign parameters present in the link.
- Accounts and access. Email addresses, names and profile information, sign-in and verification information, account-approval status, workspace details, invitations, memberships, roles and permissions. Sign-in uses email verification codes or an available third-party sign-in provider. That provider supplies the identity and basic profile information used for authentication.
- Authorisation and business records. Records of legal notices and acceptance, including user, document version, time, source, IP address and browser information where available; API and agent permissions and usage; and business contact, subscription, billing and correspondence records where applicable to our relationship.
- Technical and usage information. IP addresses, browser and device information, URLs, referral and campaign information, session identifiers, language, approximate location, request times, access and activity records, connection health, and error information. Website form rate-limiting uses an IP-derived hash; hosting providers can separately process connection information. Cookies and Website analytics are described below.
Customer-controlled business information
- Contacts and invoices. Customer and contact names, recipient email addresses, business identifiers, invoice and installment references, amounts, currencies, dates, balances, payment and collection status, dispute or exclusion indicators, and related source records supplied by connected systems. Source records and customer-entered text may contain additional personal information supplied by the customer or its systems.
- Payments. Payment-link, checkout-session and transaction references, amounts, currencies, statuses, timestamps and failure information. Provider responses may also include payer contact or billing information. Payment credentials are entered into provider-operated checkout, which may be hosted by the provider or embedded within Finero. Finero does not collect or store full card numbers through those checkout fields. Finero provides the software workflow; the payment provider processes the payment under its own arrangements.
- Connections and communications. Integration settings and authorisation credentials, connected-mailbox identity and permissions, message recipients and content, sender and reply-to details, schedules, delivery attempts, provider message references, and workflow and synchronisation history.
Provide only information needed for the relevant task. Do not put passwords, full card numbers or unrelated sensitive personal information into notes, messages or support material.
Where information comes from
Information comes directly from you; from a business customer, its administrators and authorised users; from connected ERP, accounting, payment, email and identity services; from applications or agents authorised to use Finero; and automatically from use of the Website and Service. A customer may supply your information even if you have no Finero account.
Why we process information and our legal bases
For information we control, we use the following bases where applicable law requires them:
- Providing and administering the Service. To respond to enquiries, establish accounts, authenticate users, deliver support and manage subscriptions and billing: performance of a contract with you or steps you request before a contract, or our legitimate interests in serving the business you represent.
- Operating and protecting our business. To maintain and improve the Website and Service, understand usage, investigate errors and misuse, manage business relationships and establish or defend claims: legitimate interests, where permitted and balanced against your rights.
- Legal requirements. To keep required records and respond to binding legal requests: compliance with applicable legal obligations.
- Consent where required. Activities requiring consent, including non-exempt device tracking or certain marketing communications, require a separate valid choice. Reading this policy or acknowledging a notice is not that consent. You may withdraw consent without affecting earlier lawful processing.
For information processed on a customer’s behalf, the customer determines the lawful basis. Finero uses that information to sync business records, manage payment links and status, send or schedule communications, carry out authorised automation, and return payment information to connected systems under the customer’s instructions.
Do you have to provide information?
You generally choose whether to provide information. Unless we identify a legal requirement, providing it is not legally compulsory. Without the details needed for an enquiry, account, connection or workflow, we may be unable to respond or provide that feature. Customers determine what information they require from their own contacts and payers.
Cookies and similar technologies
The Website stores your cookie-category choices in your browser. Optional experience and marketing technologies remain disabled unless you accept the relevant category. The Website does not currently load optional analytics or marketing cookies, so accepting an optional category does not by itself place one on your device. Connection requests still expose an IP address and basic request information to the infrastructure needed to deliver and protect the Website.
The platform uses browser storage for authentication sessions, pending sign-in, invitation and agent-authorisation steps, and interface preferences. Third-party sign-in and payment components may use their own cookies or similar technologies under their providers’ notices. Externally loaded resources, such as fonts, also send connection information to their delivery providers.
Browser settings can block or clear cookies and local storage, although this can affect sign-in or other features and does not remove information already received. The Website’s Cookie Settings lets you review and change optional categories. For privacy requests, contact privacy@getfinero.com.
Connected email accounts
When an administrator connects a Google mailbox, Finero accesses its account identifier, email address and display name, records the granted permissions, and stores an encrypted authorisation credential to send messages on the customer’s behalf. Finero sends the message content and recipient details to the mailbox provider and records delivery information. This connection requests sending access, not access to read your inbox, contacts or mailbox history.
You can disconnect the mailbox in Finero or revoke access through your Google account. Disconnecting removes Finero’s stored mailbox authorisation. It does not erase messages already delivered or the related business and delivery records. Contact privacy@getfinero.com for requests concerning retained personal information.
Finero’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Such information is not used for advertising, sale, creditworthiness assessment or general-purpose AI model training. The sharing purposes elsewhere in this policy remain subject to these restrictions.
Automation and AI-connected applications
Customer-configured workflows process invoice, contact and payment information to determine collection eligibility, generate payment links, schedule or send messages, update payment status and perform related operational actions. Their results depend on the source information and configuration, and may affect communications or payment options presented to a customer’s contacts.
If you authorise an external AI assistant or other application through Finero’s API or agent connection, it can receive the business information exposed by the authorised features and request permitted actions, such as creating payment links or changing email schedules. Information returned to that application is processed in its environment under its own arrangements. The customer controls its choice of application and permissions. Revoking access stops subsequent authorised access through that connection; it does not recall information already shared or completed actions.
These features do not replace the customer’s responsibility to check data, configure workflows appropriately, and assess any legal requirements for decisions affecting individuals. Contact the relevant business about an invoice or collection decision, or contact us to exercise any applicable privacy rights concerning our processing.
How information is shared
- The customer and its authorised recipients. Workspace users can access information according to their permissions; administrators manage membership and connections. Selected recipients receive customer-directed communications. A person holding a payment link may see the invoice and payment information made available through that link.
- Customer-selected services. Connected ERP, accounting, payment, email and agent services receive the information needed for their role in the enabled workflow. Independent providers process information under their own terms and privacy practices; customers control which services they connect.
- Providers supporting Finero. Hosting, database, authentication, storage, content-delivery, security, diagnostics, analytics and communications providers process information to support the Service. Business email, contact and support management, document, accounting and other administration tools may process the information relevant to those business purposes. Providers may change; their permitted use must remain consistent with the purpose, customer instructions where applicable, and applicable data-protection requirements.
- Personnel and professional advisers. Authorised personnel, including founders, officers, employees and contractors, and relevant affiliates or advisers may access information needed to operate, support or protect Finero, subject to applicable access and confidentiality requirements.
- Legal requirements and business transactions. Information may be disclosed where legally required or permitted to investigate misuse, protect rights or safety, or establish or defend claims; or as necessary in a financing, reorganisation, merger or sale, subject to applicable confidentiality, purpose and consent restrictions.
A provider’s independent processing is distinct from work it performs on Finero’s behalf. Using a provider does not remove obligations that applicable law places on Finero. This notice does not authorise unrelated use of customer-controlled information or override a required processing agreement.
International processing
The Service uses infrastructure and providers in different countries. Information may be stored or accessed outside your country, where Finero, a customer or a relevant provider operates, and local protections may differ. Processing locations depend on the service and connections involved; this policy does not promise storage in a particular country.
Cross-border processing remains subject to applicable transfer requirements. This notice is not consent to an otherwise unlawful transfer. Contact privacy@getfinero.com for information about processing locations and any transfer arrangements relevant to your data.
How long information is kept
Retention depends on the type of information, the purpose for which it was collected, the customer relationship and instructions, and applicable legal requirements. We retain account, enquiry and business records to administer the relationship and resolve outstanding matters; customer records to provide the Service; and relevant transaction, security and legal evidence for record-keeping, investigating incidents and resolving claims. These needs can continue after an account or connection closes.
There is no single retention period for all records. Expiry of a sign-in code, invitation or payment link does not mean its associated records are deleted. Removing an invoice from an ERP, disconnecting a service or revoking access does not automatically erase information already held in Finero, delivered emails or copies held by independent providers. Historical records and any backups can have separate lifecycles.
You can request deletion using the contact details below. We assess requests against the applicable customer instructions, legal rights and retention requirements. We do not promise an automatic deletion date or immediate removal from every backup or independent third-party system.
How we protect information
Finero uses technical and organisational measures intended to protect personal information, including authenticated access, workspace-based permissions and encryption of stored connection credentials. Controls depend on the system and processing involved. No service, transmission or storage method is completely secure; this policy is not a guarantee against unauthorised access or loss and does not limit legally required protections.
Your privacy rights
Depending on applicable law, you may have rights to access or obtain a copy of personal information, correct it, request deletion, restrict or object to processing, receive portable data, withdraw consent, or challenge qualifying automated decisions. Conditions and exceptions apply. Where direct marketing is involved, you may object or ask us to stop. Other locally applicable rights, including an available right to appeal a privacy decision, remain unaffected by this policy.
Contact privacy@getfinero.com for information we control. For customer-controlled records, contact the business that provided them; if you contact us, we may direct or forward your request to that business. We may need information to verify identity and authority without disclosing another person’s data. We respond and assist as required by applicable law. You may also complain to the relevant data-protection authority, including Israel’s Privacy Protection Authority where applicable.
Children
Finero is a B2B service intended for organisations and their authorised adult users, not a service directed to children. Customers should not provide children’s information unless necessary and lawfully authorised. Contact us if you believe a child has provided personal information directly to Finero.
Changes to this policy
We may update this policy to reflect changes in the Service, our practices or legal requirements. We update the date and revision above and provide additional notice or obtain consent where required. Publishing an update does not by itself authorise a new use that requires consent.
Contact us
For privacy questions, requests or concerns about Finero’s processing, contact privacy@getfinero.com. Include enough information to identify the relevant account or business, but do not send passwords, sign-in codes or full payment-card details.