Privacy Policy
Last updated: August 24, 2026
This Privacy Policy describes how 14109015 Canada Limited (doing business as Fink Financial, “we”, “us”, or “our”) collects, uses, and shares personal information when you use finkfinancial.io and the related services (the “Service”).
We are a Canadian company based in Ontario. This policy is written to comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws. If you are outside Canada, your personal information will be transferred to, stored in, and processed in the United States (see International Transfers).
1. Who we are
Fink Financial is a personal budgeting and financial tracking application provided by 14109015 Canada Limited, a corporation registered in Canada.
Legal entity: 14109015 Canada Limited
Address: 6830 Raleigh Boulevard, London, ON N6P 1V5, Canada
Contact: contact@finkfinancial.io
2. What information we collect
We collect the minimum information needed to operate the Service.
a. Account information
- Your name and email address
- A password (stored only as a one-way hash — we never store it in plaintext)
- Email verification status and sign-in history
b. Financial data from connected banks (optional, via Plaid)
If you choose to connect a bank account, we use Plaid as our intermediary. Plaid authenticates with your financial institution on your behalf and provides us with:
- Account names, types, currencies, masks (last 4 digits), and balances
- Transaction history: amount, date, merchant name, description, pending status
- Loan and credit account metadata (interest rate, payment due date, etc.) when available
We never receive your bank username or password. Plaid handles the sign-in flow directly with your bank. You can review Plaid's privacy practices at plaid.com/legal.
c. Financial data you enter manually
Transactions, accounts, budgets, categories, goals, and any notes or memos you type in yourself.
If you deliberately attach an original receipt to a transaction, we store the encrypted image, its media type, size, and a cryptographic integrity digest. AI receipt scanning alone does not save the image; attachment is a separate action.
d. Uploaded financial documents and coaching data
If you use Add Data, we temporarily process the statements, spreadsheets, receipts, or screenshots you choose to upload. We create draft transactions and field-level source references so you can review them before anything is added to your ledger. Files are treated only as financial source material; instructions written inside a document cannot direct Fink or its AI systems.
If you use Financial Coach, we store the profile details you choose to provide, private encrypted conversations, scenario drafts, and records showing which reviewed household facts and official sources supported an answer. We do not ask for an exact address, SIN or SSN, bank credentials, or tax-document identifiers. Your files, messages, and financial records are not used to train AI models.
e. Billing information
If you subscribe to a paid plan, payment processing is handled by Stripe. We receive your subscription status, plan, billing period, and the last 4 digits of your payment method. We do not store your full card number, expiry, or CVV — Stripe stores those directly.
f. Usage and technical data
- IP address, browser, device, and operating system
- Error logs and performance metrics
- If you explicitly opt in, pseudonymous setup, daily-check, review, and planning events using broad count and timing ranges and a fixed vocabulary of outcomes
Opt-in product analytics never includes merchant or account names, transaction descriptions, balances, amounts, email addresses, notes, category names, or activity on other sites. You can turn it off at any time in Settings → Profile.
3. How we use your information
- To operate the Service — budgeting, syncing transactions, generating reports
- To authenticate you and secure your account
- To send transactional emails (verification, password reset, bill reminders, invite confirmations)
- To process subscription payments through Stripe
- With your explicit consent (Pro plans only), to auto-categorize transactions using AI models — the merchant name and transaction description are sent to the model provider (OpenAI or Google); the amount, your account identity, and other personally identifying context are not sent
- To extract draft transactions from financial files you choose to upload and, after your review and approval, add accepted rows to your household ledger
- To provide personalized financial education and planning scenarios using your approved records, profile, deterministic calculations, and current official guidance when it is needed
- To detect and prevent fraud, abuse, or security incidents
- With your explicit consent, to understand and improve the core product journeys
- To comply with legal obligations
We do not sell your personal information. We do not use your data to build profiles for advertising. We do not rent, trade, or otherwise monetize your financial data beyond charging you for the Service.
5. How we protect your information
- Bank access tokens (the credentials Plaid uses to pull transactions on your behalf) are encrypted at rest using AES-256-GCM authenticated encryption before being stored
- All network traffic between your browser, our servers, and our sub-processors is encrypted with TLS 1.2 or higher
- Database storage is encrypted at rest by our provider
- Original receipt attachments are additionally encrypted by Fink with AES-256-GCM and a dedicated application key before storage
- Financial uploads and coach conversations are encrypted with separate dedicated application keys; routine coaching context uses approved structured records rather than raw uploaded files
- Row-level security ensures one tenant's data cannot be queried from another tenant's session
- Passwords are stored as one-way bcrypt hashes; we cannot recover your password
- We maintain least-privilege internal access and log all administrative actions
Add Data files first upload to private quarantine storage. After safety checks, Fink replaces a retained source with an application-level AES-256-GCM encrypted object and deletes the initial quarantine object. This is server-side application encryption, not client-side or end-to-end encryption.
Despite these measures, no online service can guarantee absolute security. You can help by using a strong, unique password and keeping your email secure.
6. How long we keep your information
- While your account is active: we retain your data so the Service works
- After you delete your account: we delete personal data within 30 days, except where retention is required by law (tax records kept up to 7 years, as required by the Canada Revenue Agency)
- Plaid access tokens are revoked at Plaid and deleted from our systems as soon as you disconnect a bank or delete your account
- Receipt attachments remain only while you keep them attached; deleting one immediately removes its active reference and starts deletion of the encrypted private-storage object, with durable retries if the storage provider is temporarily unavailable; a payload-free audit record remains
- Original Add Data files are deleted seven days after commit or abandonment unless you explicitly choose Keep original; structured facts and source references that do not contain the original payload may remain with your ledger records
- Private coaching conversations can be exported by you and remain until you delete the conversation or your account
- Backups are retained for up to 35 days for disaster recovery, after which they are overwritten
- Opt-in product analytics are retained for no more than 90 days; turning the setting off stops future collection
7. Your rights
Under PIPEDA and applicable Canadian privacy laws, you have the right to:
- Access the personal information we hold about you
- Correct information that is inaccurate or incomplete
- Withdraw consent to processing (note: we cannot provide the Service without certain data)
- Delete your account and associated data
- Export your transaction history in CSV
- Complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) if you believe we have mishandled your data
To exercise any of these rights, email contact@finkfinancial.io. We will respond within 30 days.
9. Children
The Service is not intended for anyone under 13 years of age (or under 16 in applicable jurisdictions). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us at contact@finkfinancial.io and we will delete it.
10. International transfers
Our databases, application servers, and most of our sub-processors are located in the United States. If you are in Canada or elsewhere, your information is transferred to, and processed in, the United States under the safeguards described in Section 5. While transferred, your information may be subject to U.S. law, including lawful access requests by U.S. government authorities.
11. Changes to this policy
We may update this Privacy Policy from time to time. If changes are material, we will notify you by email or in-app before they take effect. The “Last updated” date at the top of this page reflects the most recent revision. Continued use of the Service after a change means you accept the revised policy.
12. Contact us
For questions about this Privacy Policy, or to exercise any of your rights:
Fink Financial
14109015 Canada Limited
6830 Raleigh Boulevard
London, ON N6P 1V5, Canada
contact@finkfinancial.io