FinCoreFlow privacy policy

The mobile app, business workspace and associated web services.

Version
2026-09-10.2
Effective date
2026-09-10

1. Who we are and what this notice covers

FinCoreFlow is operated by FIN CORE FLOW (PRIVATE) LIMITED, B 431-1, ST. Capt. Nasir, Mohallah. Shah Hussain, Gujrat, Pakistan. Send privacy enquiries and account-deletion requests to privacy@fincoreflow.com.

This notice covers the FinCoreFlow Android and iOS apps, business workspaces and associated websites. We determine how account administration, service security and our own customer support information are used. Your business or accountant determines the purposes of the business records it supplies; we process those records to provide its requested services. Contact that business as well as us if your request concerns records it controls.

2. Information we process

Account and workspace information includes your name, work email, phone number where provided, user identifier, business details, memberships, roles and permissions. Authentication uses sign-in links and session credentials. We also process the account and service-plan information needed to provide access.

Documents and accounting information include the photos, images, PDFs and other supported files you choose to supply; extracted text, supplier/customer details, tax identifiers, dates, amounts, currencies, line items, VAT information, account codes and financial records. Documents can contain personal information about you or other people. Supply only information you are authorised to use.

Collaboration information includes questions, replies, support requests, attachments where supported, approval decisions and the history of changes to accounting records. Technical information includes request and session details, IP/network information processed by our hosting services, device/browser information, error reports, timestamps and operational events. We also retain hashed IP addresses in authentication-attempt records and, for applicable actions, IP addresses and user-agent strings in application audit records. Retention follows section 10 below.

A generated app-device identifier is required for mobile sign-in and session management and is collected even if push notifications are off. The generated identifier is not an advertising identifier. If you enable push notifications, we additionally process a notification delivery token, device platform, permission state, locale and time zone.

3. Where information comes from

Information comes from you, authorised members of your business, your accountant, and the documents and integrations your business chooses to use. Connected email, Google Drive or Microsoft OneDrive intake, where enabled, supplies selected documents and associated source information. Connection credentials and access permissions are used to operate the integration. These are workspace integrations, not unrestricted access to your phone's files or email.

The mobile app requests camera or photo-library permission when you choose the relevant capture action. File import uses the device's picker. It is not designed to collect your contacts, microphone recordings, precise GPS location or advertising ID. Personal information may nevertheless appear inside a document you supply.

4. Why information is used

We use information to authenticate you, enforce workspace permissions, process documents, prepare and display accounting records and reports, support accountant collaboration, deliver requested notifications, manage service access, resolve support requests, protect against misuse and investigate reliability problems.

Where data-protection law requires a legal basis, account and service administration may be necessary to perform our agreement with you; service security and troubleshooting serve our legitimate interests; statutory obligations may require record retention; and consent is used where required for optional processing. Business records are processed under the relevant business's instructions and applicable service arrangements. A device permission is not blanket consent to unrelated uses of your information.

5. OCR, AI assistance and correction history

Selected documents are uploaded to our backend. The OCR workflow can send document content to Microsoft Azure Document Intelligence and, where configured, Azure OpenAI for extraction or classification. Extracted information and confidence/review information are returned to the workspace. Your device does not perform the complete accounting or OCR process by itself.

OCR and account suggestions can be wrong. Authorised users must review source documents and confirm accounting actions. Correction history and learned account suggestions are associated with the business workspace. This notice does not grant permission to reuse one customer's documents or corrections to train a shared model for other customers. A separate training programme would require its own defined scope, notice and lawful authority.

6. Who can receive information

Authorised business members, assigned accountants and FinCoreFlow personnel supporting the service can receive information according to their access and responsibilities. Business records and some support requests are visible to authorised administrators/accountants in the workspace; do not assume a workspace support thread is a private conversation outside your business. Use the privacy contact for a private rights request.

Service providers support hosting, database and file storage, OCR/AI, transactional email, optional push delivery and diagnostics. The implementation includes Vercel, Neon, Microsoft Azure, Resend, Twilio for enabled phone verification, Expo with Apple/Google notification infrastructure, Sentry and PostHog in the relevant enabled paths. These providers do not all receive every document or every data category. For example, notification delivery uses tokens and notification payloads, while OCR services receive the documents submitted for processing.

Information may also be disclosed when required by law or necessary to address fraud, security incidents or legal claims. If you export or share a document through your device, the recipient or app you choose receives that copy under its own practices. The mobile app does not include advertising or ad-tracking SDKs in the reviewed dependency inventory.

7. International processing

FinCoreFlow is operated from Pakistan and uses international infrastructure providers. Storage location, remote support access and a provider's processing location are not necessarily the same. This notice does not promise that all processing stays in Finland, the EU or any other single country.

Where applicable law requires protections for an international transfer, the relevant transfer mechanism and service arrangements must apply. Contact the privacy address for information about the safeguards applicable to your service. No certification, EU representative appointment or executed transfer agreement should be inferred from the use of a provider's software.

8. Storage on your device

Session credentials and cached workspace information use the device's secure credential store. Pending document uploads are staged in a SQLCipher-encrypted local database whose key is kept in secure storage. The upload queue is scoped to the signed-in user and business.

Pending or failed document copies can remain on the device for retry, including after sign-out. The queued document content is cleared after the app observes successful server processing, or when you remove the pending item. Queue metadata can remain. This does not mean every temporary file on the device is stored in the encrypted queue: camera/picker/crop operations and document viewing can create temporary files managed by the app or operating system.

Opening an original PDF can download a temporary copy and invoke the device share sheet. The app attempts to remove its temporary copy when that operation returns. Copies you save or share elsewhere are not removed by signing out of FinCoreFlow or deleting your FinCoreFlow account. Keep your device secured, especially if other people use it.

9. Notifications, cookies and diagnostics

Push notifications are optional. You can turn them off in the app and in device settings. Transactional account/service communications and in-app work records are separate from optional push permission.

Web sign-in uses essential session storage. Where configured, PostHog processes selected website/backend usage events and Sentry processes diagnostic events. The native mobile dependency inventory does not contain these SDKs, but mobile requests can generate backend diagnostics and operational events.

PostHog's website configuration disables automatic event capture, automatic page-view/page-leave events and session recording. Explicitly implemented website events and server-side events can still be sent.

Where web analytics is configured, PostHog may derive approximate location from your IP address for analytics, including on web pages opened from the mobile app. This is coarse IP-derived location, not GPS location.

When configured, Sentry's browser diagnostics can record a sample of sessions in which errors occur. This error-session replay is configured to mask text and inputs and block media; it is separate from PostHog's disabled session recording and is not native mobile session recording. We do not describe all telemetry as anonymous or as containing no identifiers.

10. Retention and account deletion

Website inquiries do not require an account. We use the contact details and messages you provide to handle your inquiry, assign it to authorised staff and retain its connected customer-relationship history. A private access link grants access to your conversation; keep it confidential. Submitting an inquiry does not subscribe you to marketing. Closed inquiries that did not proceed to a customer relationship are reviewed for deletion after 12 months; this is a review point, not a promise of automatic erasure. Customer-linked records follow the applicable customer retention policy. You can request access, correction or deletion through privacy@fincoreflow.com without creating an account. We verify requests and review any continuing lawful need to retain information before taking action.

We aim to acknowledge privacy and account-deletion requests within three calendar days of receipt. Acknowledgement does not mean deletion is complete. We handle requests without undue delay and within applicable legal deadlines; this acknowledgement target does not extend those deadlines.

Retention depends on the information's purpose, the business's instructions, applicable accounting/tax duties, security needs and legal claims. We do not apply one universal period to every market and record. Accounting documents, audit history and business records may need to be retained after a user's access ends. Backup copies may persist until their applicable backup lifecycle expires.

You can request account deletion from Manage or More → Account and privacy → Request account deletion in the mobile app, or through the public account-deletion page linked below. The in-app action creates a request for review; it does not immediately delete your account or business books. If you cannot sign in or no longer have a workspace, use the public route.

We verify the request, identify the account and business records involved, and arrange deletion or anonymisation of information that no longer needs to be retained. Information retained for a legitimate obligation must be limited to that purpose; account suspension alone is not deletion. We explain relevant exceptions when handling the request. A person's account deletion must not erase other users' or a business's required accounting records without appropriate authority.

11. Your choices and rights

Depending on applicable law, you may request access, correction, deletion, restriction, portability or object to certain processing. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. You may also complain to your applicable data-protection authority, including Finland's Office of the Data Protection Ombudsman where relevant.

Contact privacy@fincoreflow.com with the account email and enough information to understand your request. We may ask for proportionate identity verification; do not send a password, sign-in link, full identity document or unrelated receipts with the initial request. We handle requests within the applicable legal time limits. The service is designed for business users, not for children.

12. Changes to this notice

We update this notice when the service or its information practices change. The adopted version and effective date identify the notice in effect. Material changes requiring additional notice or consent are handled through the appropriate service communication or consent process; merely editing this page does not establish that consent.