Privacy Policy

Version 1.0 · Last updated 10 October 2026

This policy explains how the operator providing services under the Finero name (“Finero”, “we”, “us”) processes personal information through getfinero.com (the “Website”), the Finero platform, payment pages, integrations and related support (the “Service”). Contact us at privacy@getfinero.com.

Finero provides accounts-receivable software for businesses. It connects business systems, manages invoice and payment workflows, and sends related communications. Personal information means information relating to an identified or identifiable person, including business information that identifies a contact, account user or individual payer.

Who this policy applies to

This policy covers Website visitors, prospective customers, people who contact us, account users and invited colleagues, and the contacts, invoice recipients and payers whose information a business customer processes through Finero.

Finero’s role: controller and processor

We act as a controller for purposes we determine, such as handling enquiries, managing our customer relationships and accounts, authenticating users, operating and measuring the Website, supporting and securing the Service, and keeping our business and legal records. Where applicable law uses different terms, our responsibilities follow the actual processing involved.

For customer-controlled invoice, contact, payment, integration and workflow information, we generally act as a processor on the business customer’s behalf. The customer determines the business purpose, connected systems, authorised users and instructions. It is responsible for the accuracy and lawful provision of that information and for required notices and permissions. We use it to carry out the customer’s instructions and provide the Service, subject to applicable law. This allocation does not remove Finero’s own legal responsibilities.

If your information comes from a business using Finero, contact that business first about its processing. We assist as required by our role and applicable law. This policy is a privacy notice, not a substitute for a data-processing agreement where one is required.

Information we process

The information involved depends on the features and connections used.

Website, accounts and business contacts

Customer-controlled business information

Provide only information needed for the relevant task. Do not put passwords, full card numbers or unrelated sensitive personal information into notes, messages or support material.

Where information comes from

Information comes directly from you; from a business customer, its administrators and authorised users; from connected ERP, accounting, payment, email and identity services; from applications or agents authorised to use Finero; and automatically from use of the Website and Service. A customer may supply your information even if you have no Finero account.

Why we process information and our legal bases

For information we control, we use the following bases where applicable law requires them:

For information processed on a customer’s behalf, the customer determines the lawful basis. Finero uses that information to sync business records, manage payment links and status, send or schedule communications, carry out authorised automation, and return payment information to connected systems under the customer’s instructions.

Do you have to provide information?

You generally choose whether to provide information. Unless we identify a legal requirement, providing it is not legally compulsory. Without the details needed for an enquiry, account, connection or workflow, we may be unable to respond or provide that feature. Customers determine what information they require from their own contacts and payers.

Cookies and similar technologies

The Website stores your cookie-category choices in your browser. Our hosting and security providers set a few cookies to deliver and protect the Website. If you accept the Experience category, our hosting provider’s website analytics also sets a session cookie to count visits and pages viewed. The Cookie Policy lists each one. Optional experience and marketing technologies remain disabled unless you accept the relevant category. Connection requests also expose an IP address and basic request information to the infrastructure needed to deliver and protect the Website.

The platform uses browser storage for authentication sessions, pending sign-in, invitation and agent-authorisation steps, and interface preferences. Third-party sign-in and payment components may use their own cookies or similar technologies under their providers’ notices.

Browser settings can block or clear cookies and local storage, although this can affect sign-in or other features and does not remove information already received. The Website’s Cookie Settings lets you review and change optional categories. For privacy requests, contact privacy@getfinero.com.

Connected email accounts

When an administrator connects a Google mailbox, Finero accesses its account identifier, email address and display name, records the granted permissions, and stores an encrypted authorisation credential to send messages on the customer’s behalf. Finero sends the message content and recipient details to the mailbox provider and records delivery information. This connection requests sending access, not access to read your inbox, contacts or mailbox history.

You can disconnect the mailbox in Finero or revoke access through your Google account. Disconnecting removes Finero’s stored mailbox authorisation. It does not erase messages already delivered or the related business and delivery records. Contact privacy@getfinero.com for requests concerning retained personal information.

Finero’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Such information is not used for advertising, sale, creditworthiness assessment or general-purpose AI model training. The sharing purposes elsewhere in this policy remain subject to these restrictions.

Automation and AI-connected applications

Customer-configured workflows process invoice, contact and payment information to determine collection eligibility, generate payment links, schedule or send messages, update payment status and perform related operational actions. Their results depend on the source information and configuration, and may affect communications or payment options presented to a customer’s contacts.

If you authorise an external AI assistant or other application through Finero’s API or agent connection, it can receive the business information exposed by the authorised features and request permitted actions, such as creating payment links or changing email schedules. Information returned to that application is processed in its environment under its own arrangements. The customer controls its choice of application and permissions. Revoking access stops subsequent authorised access through that connection; it does not recall information already shared or completed actions.

These features do not replace the customer’s responsibility to check data, configure workflows appropriately, and assess any legal requirements for decisions affecting individuals. Contact the relevant business about an invoice or collection decision, or contact us to exercise any applicable privacy rights concerning our processing.

How information is shared

A provider’s independent processing is distinct from work it performs on Finero’s behalf. Using a provider does not remove obligations that applicable law places on Finero. This notice does not authorise unrelated use of customer-controlled information or override a required processing agreement. We do not sell personal information or share it for cross-context behavioural advertising.

International processing

The Service uses infrastructure and providers in different countries. Information may be stored or accessed outside your country, where Finero, a customer or a relevant provider operates, and local protections may differ. Processing locations depend on the service and connections involved; this policy does not promise storage in a particular country. For information Finero processes on a customer’s behalf, the hosting location and transfer terms of the Data Processing Agreement apply.

Cross-border processing remains subject to applicable transfer requirements. This notice is not consent to an otherwise unlawful transfer. Contact privacy@getfinero.com for information about processing locations and any transfer arrangements relevant to your data.

How long information is kept

Retention depends on the type of information, the purpose for which it was collected, the customer relationship and instructions, and applicable legal requirements. We retain account, enquiry and business records to administer the relationship and resolve outstanding matters; customer records to provide the Service; and relevant transaction, security and legal evidence for record-keeping, investigating incidents and resolving claims. These needs can continue after an account or connection closes.

There is no single retention period for all records. Expiry of a sign-in code, invitation or payment link does not mean its associated records are deleted. Removing an invoice from an ERP, disconnecting a service or revoking access does not automatically erase information already held in Finero, delivered emails or copies held by independent providers. Historical records and any backups can have separate lifecycles.

You can request deletion using the contact details below. We assess requests against the applicable customer instructions, legal rights and retention requirements. We do not promise an automatic deletion date or immediate removal from every backup or independent third-party system. For information Finero processes on a customer’s behalf, the return and deletion terms of the Data Processing Agreement apply when that customer’s agreement ends.

How we protect information

Finero uses technical and organisational measures intended to protect personal information, including authenticated access, workspace-based permissions and encryption of stored connection credentials. Controls depend on the system and processing involved. No service, transmission or storage method is completely secure; this policy is not a guarantee against unauthorised access or loss and does not limit legally required protections.

Your privacy rights

Depending on applicable law, you may have rights to access or obtain a copy of personal information, correct it, request deletion, restrict or object to processing, receive portable data, withdraw consent, or challenge qualifying automated decisions. Conditions and exceptions apply. Where direct marketing is involved, you may object or ask us to stop. Other locally applicable rights, including an available right to appeal a privacy decision, remain unaffected by this policy.

Contact privacy@getfinero.com for information we control. For customer-controlled records, contact the business that provided them; if you contact us, we may direct or forward your request to that business. We may need information to verify identity and authority without disclosing another person’s data. We respond and assist as required by applicable law. You may also complain to the relevant data-protection authority, including Israel’s Privacy Protection Authority where applicable.

Children

Finero is a B2B service intended for organisations and their authorised adult users, not a service directed to children. Customers should not provide children’s information unless necessary and lawfully authorised. Contact us if you believe a child has provided personal information directly to Finero.

Changes to this policy

We may update this policy to reflect changes in the Service, our practices or legal requirements. We update the date and revision above and provide additional notice or obtain consent where required. Publishing an update does not by itself authorise a new use that requires consent.

Contact us

For privacy questions, requests or concerns about Finero’s processing, contact privacy@getfinero.com. Include enough information to identify the relevant account or business, but do not send passwords, sign-in codes or full payment-card details.