Last updated: September 2, 2026

Finli Privacy and Security

1. Introduction

Finli, Inc. (“Finli,” “we,” “us,” or “our”) respects your privacy and is committed to protecting the personal information we collect and process. This Privacy Policy explains how we collect, use, disclose, and safeguard information in connection with our website at finli.com, our applications, and the digital back-office and business-operations services we provide (collectively, the “Services”).

Finli provides a white-labeled operating platform for financial institutions that serve small businesses, including tools for invoicing and billing, payments, subscription billing, customer communications, business insights, and related financial-wellness features. Please read this Privacy Policy carefully. By using the Services, you acknowledge the practices described here.

2. Scope and Our Role

Finli plays different roles depending on how the Services are used:

  • As a service provider / processor. When a financial institution deploys Finli’s white-labeled Services to its own business customers, the financial institution is generally the party responsible for those customers’ personal information (the “business” or “controller”), and Finli processes that information on the institution’s behalf under a written agreement and its documented instructions. In that role, the financial institution’s own privacy notice may also apply, and Finli handles personal information only as needed to provide the Services.
  • As a controller. For Finli’s own website, direct business relationships, marketing, and internal operations, Finli determines how and why personal information is processed, and this Privacy Policy governs those activities.

Where an obligation in this Privacy Policy conflicts with Finli’s contract with a financial-institution client, the contract governs Finli’s handling of that client’s data.

3. Information We Collect

   3.1 Information You Provide to Us
  • Account and registration information, such as name, email address, phone number, and login credentials.
  • Business information, such as business name, address, industry, tax identifiers, and details about products and services.
  • Transaction and billing information, such as invoices, payment activity, and records generated through use of the Services. Payment card and bank-account details are handled by our payment processors and are not stored by Finli except as described in this Policy.
  • Communications, such as the content of messages, support requests, and other information you choose to provide.
   3.2 Identity Verification and Biometric Information

For certain account products, and to prevent fraud and verify identity, Finli may collect and process government-issued identification documents, a biometric identifier or biometric information (such as a facial scan used to confirm a match to an identity document), and date of birth (including age). This information is used solely for identity assurance, fraud prevention, and compliance purposes. See Section 6 (Sensitive Personal Information and Biometric Data) for additional detail. Finli’s financial-literacy programming does not collect personal information and does not use biometric verification.

   3.3 Information We Collect Automatically
  • Device and technical information, such as IP address, browser type, operating system, and device identifiers.
  • Usage information, such as pages viewed, features used, and dates and times of access.
  • Cookies and similar technologies, as described in Section 13.
   3.4 Information From Third Parties
  • Financial-institution partners who deploy the Services and provide information about their business customers.
  • Service providers and identity-verification vendors that support fraud prevention and identity assurance.
  • Analytics and infrastructure providers that help us operate and secure the Services.

4. How We Use Information

Finli uses personal information for the following purposes:

  • To provide, operate, maintain, and improve the Services.
  • To verify identity, prevent and detect fraud, and protect the security and integrity of the Services.
  • To process transactions and deliver invoicing, payment, and related functionality.
  • To communicate with you, including service-related notices and support.
  • To comply with legal, regulatory, and contractual obligations.
  • To analyze usage and develop new features, using aggregated or de-identified information where feasible.

Finli collects and processes personal information only for specified, explicit, and legitimate purposes, and limits use to those purposes or as otherwise permitted by law or by the instructions of a financial-institution client.

5. How We Share Information

Finli does not sell personal information. We share personal information only as described below:

  • Service providers and sub-processors. We share information with vendors that perform services on our behalf — for example, cloud hosting and storage (Amazon Web Services), customer-relationship management (Salesforce), email and collaboration (Google Workspace), and payment processing. These providers are bound by written agreements requiring appropriate confidentiality and security protections, and they are prohibited from selling or using the information for their own marketing.
  • Financial-institution partners. Where Finli provides white-labeled Services, we share information with the applicable financial institution as necessary to deliver the Services.
  • Legal and compliance. We may disclose information to comply with applicable law, regulation, legal process, or enforceable governmental request, or to protect the rights, property, or safety of Finli, our users, or others.
  • Business transfers. In connection with a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Privacy Policy.
  • With your consent. We may share information for other purposes with your consent or at your direction.

6. Sensitive Personal Information and Biometric Data

Certain information Finli collects — including government-identification data, biometric identifiers or biometric information, and precise identity attributes — is considered “sensitive personal information” under laws such as the California Consumer Privacy Act (as amended by the CPRA) and may be subject to state biometric-privacy laws such as the Illinois Biometric Information Privacy Act (BIPA).

With respect to biometric identifiers and biometric information, Finli:

  • Collects and uses this information solely for identity verification and fraud prevention, and not to sell or to market to you.
  • Provides notice and obtains consent for the collection and use of biometric data where required by law. 
  • Applies encryption and access controls to protect this information, consistent with the standard of care we apply to other confidential data.

Finli limits the use and disclosure of sensitive personal information to the purposes permitted under applicable law.

7. Data Retention

Finli retains personal information for as long as we have a legitimate business need, or as required to meet legal, regulatory, or contractual obligations. When information is no longer needed, it is securely deleted or de-identified. Personally identifiable information is retained only for as long as there is a legitimate business purpose, and is deleted following a verified request where we do not have a legal obligation or other lawful basis to retain it. Specific retention periods are maintained in Finli’s internal data-management procedures.

8. Data Security

Finli maintains an information-security program with administrative, technical, and physical safeguards designed to protect personal information. These include encryption of data in transit and at rest, role-based access controls with multi-factor authentication for privileged access, network segmentation, logging and monitoring, vulnerability management, and personnel security and training. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Your Privacy Rights

Depending on where you live and applicable law, you may have rights regarding your personal information, which may include:

  • The right to know or access the personal information we hold about you.
  • The right to request correction of inaccurate personal information.
  • The right to request deletion of personal information, subject to legal exceptions.
  • The right to opt out of the “sale” or “sharing” of personal information (note: Finli does not sell personal information).
  • The right to limit the use and disclosure of sensitive personal information.
  • The right not to receive discriminatory treatment for exercising your privacy rights.

To exercise these rights, contact us using the information in Section 16. We will verify your request before responding and will respond within the timeframes required by applicable law. You may use an authorized agent to submit a request on your behalf where permitted. If Finli processes your information on behalf of a financial institution, we may direct your request to that institution or assist it in responding.

10. Financial Information and the Gramm-Leach-Bliley Act (GLBA)

When Finli provides Services to or on behalf of a financial institution, certain information may constitute nonpublic personal information under the Gramm-Leach-Bliley Act (GLBA) and its implementing regulations. In those cases, Finli handles such information in accordance with its agreements with the financial institution and applicable law, and the financial institution’s GLBA privacy notice may also apply to that information. 

11. Children’s Privacy

The Services are intended for businesses and adults and are not directed to children. Finli does not knowingly collect personal information from children under the age of 13 (or a higher age where required by applicable law). If you believe a child has provided us with personal information, please contact us and we will take appropriate steps to delete it.

12. Data Location

Finli is based in the United States, and personal information is stored and processed in the United States (including in cloud data centers located in the U.S. West region). If you access the Services from outside the United States, you understand that your information may be transferred to and processed in the United States.

13. Cookies and Tracking Technologies

Finli and its providers use cookies and similar technologies to operate and secure the Services, remember preferences, and analyze usage. You can control cookies through your browser settings; disabling certain cookies may affect functionality. 

14. Third-Party Services and Links

The Services may link to or integrate with third-party websites and services that we do not control. This Privacy Policy does not apply to those third parties, and we encourage you to review their privacy notices.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last Updated” date above and, where appropriate, provide additional notice. Your continued use of the Services after an update indicates your acknowledgment of the revised Privacy Policy.

16. Contact Us

If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact us at:

Finli, Inc.

Email: support@finli.com

Mailing address: 444 E Huntington Drive, Suite 207, Arcadia, California, 91006

Website: finli.com