Privacy Policy

Our Privacy Policy

Our Privacy Policy

Our Privacy Policy

Last Updated: April 6, 2025

Article 1 (Purpose)

Article 1 (Purpose)

This Privacy Policy explains how Finola (the “Company”) collects, uses, and safeguards personal information of Members to comply with applicable U.S. laws and regulations.

Article 2 (Information Collected and Methods of Collection)

Article 2 (Information Collected and Methods of Collection)

  1. Types of Information Collected

    1. During sign-up: Email address, password, name (or nickname), mobile phone number, etc.

    2. During payment: Payment-related information (payment method, card issuer, transaction history, etc.)

    3. Automatically generated information: IP address, cookies, access logs, device information, etc.

    4. Additional information for events or promotions: Name, contact details, address, or other marketing-related data (subject to separate consent)

  2. Methods of Collection

    1. Information provided directly by the user during registration, payment, or inquiries

    2. Automated collection via cookies or other technical tools during service usage

    3. Information provided by partners, with the Member’s consent

Article 3 (Purpose of Using Personal Information)

Article 3 (Purpose of Using Personal Information)

  1. Member Management: Confirming membership intent, verifying identity, maintaining and managing membership, preventing service misuse

  2. Service Provision: Snack purchasing, blog/content creation, payment processing, customer support

  3. Marketing and Advertising: Providing information about events and promotions, conducting surveys (subject to separate consent)

  4. Statistical Analysis and Service Improvement: Analyzing usage patterns, enhancing service quality, developing new features

Article 4 (Retention and Use Period)

Article 4 (Retention and Use Period)

  1. In principle, the Company will destroy personal information without delay once the purpose of its collection and use is fulfilled.

  2. However, if certain information must be retained in compliance with applicable laws (e.g., U.S. tax codes, consumer protection laws), the Company will retain such information for the legally mandated period before destruction.

Article 5 (Destruction Procedures and Methods)

Article 5 (Destruction Procedures and Methods)

  1. Destruction Procedures: After the purpose of use is achieved, personal information will be destroyed in accordance with internal policies and relevant regulations.

  2. Destruction Methods

    1. Electronic files are permanently deleted using technical methods that prevent recovery.

    2. Paper documents are shredded or incinerated.

Article 6 (Provision of Personal Information to Third Parties)

Article 6 (Provision of Personal Information to Third Parties)

  1. The Company does not provide personal information to external entities without the Member’s prior consent.

  2. Exceptions include:

    1. When required by law or a government request (e.g., subpoena)

    2. When providing anonymized data for statistical, academic, or research purposes

    3. Other cases permitted under applicable laws

Article 7 (Delegation of Personal Information Processing)

Article 7 (Delegation of Personal Information Processing)

  1. The Company may delegate certain tasks involving personal information to third-party service providers to improve the Services. The Company will inform Members in advance in such cases.

  2. Specific details such as the delegated tasks, the service provider, and the retention period will be disclosed in this Privacy Policy or a separate notice.

Article 8 (Member Rights and How to Exercise Them)

Article 8 (Member Rights and How to Exercise Them)

  1. Members may request access, correction, deletion, or suspension of processing of their personal information at any time.

  2. For minors under 14 (if applicable under relevant U.S. state laws), the legal guardian may request the same actions on behalf of the minor.

  3. Members must promptly notify the Company of any changes to their personal information. The Company is not liable for any issues arising from outdated or incorrect information.

Article 9 (Protection of Children’s Personal Information)

Article 9 (Protection of Children’s Personal Information)

  1. The Company does not knowingly collect personal information from children under the age of 13 (or 14, depending on state regulations) without verifiable parental consent.

  2. If the Company must collect information from a child user, it will comply with the Children’s Online Privacy Protection Act (COPPA) and any other relevant laws.

Article 10 (Use of Cookies and Similar Technologies)

Article 10 (Use of Cookies and Similar Technologies)

  1. The Company may use cookies to provide personalized services and to analyze usage statistics.

  2. Members can refuse the storage of cookies through browser settings, but some features may be restricted as a result.

Article 11 (Behavioral Information Collection and Use)

Article 11 (Behavioral Information Collection and Use)

  1. The Company may analyze Members’ usage records to provide targeted advertising or personalized content (behavioral advertising).

  2. Members can opt out of behavioral information collection through relevant settings or preferences.

Article 12 (Technical and Administrative Measures for Personal Information Protection)

Article 12 (Technical and Administrative Measures for Personal Information Protection)

  1. To protect personal information, the Company implements measures such as:

    1. Encryption: Encrypting passwords and sensitive payment information

    2. Security Measures: Using antivirus software, monitoring network traffic, and applying security patches

    3. Access Control: Limiting access to personal information and establishing internal management policies

  2. The Company provides regular training to employees on data protection and strictly limits the number of personnel who handle personal information.

Article 13 (Linked Sites)

Article 13 (Linked Sites)

  1. The Company may provide links to external websites or resources. However, it is not responsible for the privacy practices or content of such linked sites.

  2. When Members follow such links, they should review the privacy policies of the respective sites.

Article 14 (Events and Promotions)

Article 14 (Events and Promotions)

  1. If the Company needs to collect additional personal information for specific events or promotions, it will clearly state the purpose, scope, and retention period, and obtain separate consent.

  2. After the event or promotion ends, any additional information collected will be destroyed immediately unless retention is required by law.

Article 15 (Privacy Officer and Contact)

Article 15 (Privacy Officer and Contact)

  1. The Company designates a Privacy Officer responsible for overseeing personal information protection, handling complaints, and addressing remedies regarding personal data.

    • Name: [Privacy Officer Name]

    • Department: [Department Name]

    • Contact: [Email / Phone Number]

  2. Members can direct any inquiries or complaints regarding personal information to the Privacy Officer, and the Company will respond promptly and in good faith.

Article 16 (Remedies for Infringement)

Article 16 (Remedies for Infringement)

  1. Members may seek assistance or file a complaint with the relevant institutions (e.g., the Federal Trade Commission) in cases of personal information infringement.

Article 17 (International Transfer of Personal Information)

Article 17 (International Transfer of Personal Information)

  1. If the Company stores data on servers outside the U.S. or entrusts personal information processing to an overseas vendor, it will inform Members in advance, including details about the transfer’s destination, date, method, and recipient.

  2. The Company complies with applicable U.S. laws and cross-border data transfer regulations.

Article 18 (Security Measures)

Article 18 (Security Measures)

  1. The Company takes appropriate technical and organizational measures to protect personal information from loss, theft, leakage, alteration, or unauthorized access. Measures include access control, encryption, and periodic security checks.

Article 19 (Action on Breach)

Article 19 (Action on Breach)

  1. If a data breach occurs that compromises personal information, the Company will promptly inform affected Members and take necessary steps to mitigate damage, as well as comply with any legal reporting requirements.

Article 20 (Changes to the Privacy Policy)

Article 20 (Changes to the Privacy Policy)

  1. The Company may modify this Privacy Policy to reflect changes in laws, internal policies, or security technology.

  2. In the event of significant changes, the Company will provide prior notice at least seven (7) days (or thirty (30) days for material changes) before the updated policy takes effect via the Services or by email.

Article 21 (Complaints Handling Department)

Article 21 (Complaints Handling Department)

  1. The Company may maintain a dedicated department to handle complaints related to personal information.

  2. Contact information for this department, including phone numbers and business hours, will be provided on the Company’s official website or within the app.

Article 22 (Members’ Obligations for Personal Information Protection)

Article 22 (Members’ Obligations for Personal Information Protection)

  1. Members should keep their personal information accurate and up to date, ensuring it is not disclosed to third parties without authorization.

  2. If a Member’s personal information is compromised or misused by an unauthorized party, they must immediately notify the Company. The Company will take swift action to minimize damage.

Article 23 (Use by Non-U.S. Residents)

Article 23 (Use by Non-U.S. Residents)

  1. This Policy also applies to non-U.S. users to the extent it does not conflict with local laws. Where local laws provide additional protections or requirements, the Company will follow those laws.

  2. Users may exercise their rights under local data protection regulations, and the Company will comply to the extent permitted by U.S. law.

Article 24 (Effective Date)

Article 24 (Effective Date)

  1. This Privacy Policy takes effect on [Month/Day/Year].

  2. Any previous version of this Privacy Policy is replaced by the current version.

Contact Us

Contact Us

If you have any questions or concerns about this Privacy Policy, please contact us at: info@finola.io