>ƒFinForge

This Privacy Policy explains what personal data FinForge collects, why it is collected, how long it is kept, and what rights you have. It applies to the FinForge website (https://fin-forge.eu), the account and license API (https://api.fin-forge.eu), and the FinForge desktop application and Excel add-in (“FinForge”, “we”, “our”, “us”).

1. Data controller

The data controller is:

Florinmont OÜ [Registered address of Florinmont OÜ] Republic of Estonia

Contact for all privacy matters: [email protected]

2. What data we collect

2.1 Account data

  • Your email address, used as your account identifier and login.
  • A password hash. We never store plain-text passwords.
  • A pending email address when you request an email change, kept until the change is confirmed.

2.2 License and billing data

  • Your license key, plan, status, and entitlement flags.
  • Stripe customer and subscription identifiers, current period end, and trial end dates.
  • Payment status events received from Stripe.

We do not collect or store card numbers or full payment details. Payments are processed by Stripe, and card data goes directly to Stripe, never to our servers. Stripe’s processing is governed by Stripe’s own privacy policy.

2.3 Device activation data

To enforce the machine limit of your plan, the desktop application sends:

  • A keyed hash of a machine fingerprint. The raw fingerprint is never stored or transmitted; only the hash is kept.
  • A machine name you can edit in the app.
  • The time the device last contacted the activation service.

Releasing a machine is recorded so the account area can show removal history.

2.4 Support and communication data

  • Emails you send to [email protected] and our replies.
  • Transactional emails we send through Resend: password setup and reset links, and email change confirmations. We do not send marketing emails.

2.5 Administrative audit data

Actions performed by our administrators through the admin dashboard are logged with the administrator’s email, the action, the target account or license, and a short detail note. This log is used for security and abuse investigation.

2.6 What we do NOT collect

  • No website cookies. The website stores a session token in browser sessionStorage, which is removed when the tab closes.
  • No third-party analytics or tracking scripts on the website.
  • No financial or market data from the application. The app fetches market data directly from the data providers (for example Yahoo Finance, SEC EDGAR, OECD, and central banks) on your own machine. That data stays local and is never uploaded to our servers.

We process personal data only for the following purposes:

Purpose Data Legal basis (GDPR)
Providing the account, license, and activation service Account, license, device data Performance of contract (Art. 6(1)(b))
Processing payments and subscriptions License and billing data Performance of contract
Sending transactional emails Email address Performance of contract
Security, fraud prevention, and abuse investigation Audit log, activation data Legitimate interest (Art. 6(1)(f))
Keeping records required by law (for example accounting) Billing data Legal obligation (Art. 6(1)(c))

4. Who receives your data

We do not sell personal data and do not share it with anyone except:

  • Stripe, for payment processing (customer portal, subscriptions, invoices).
  • Resend, for sending transactional email.
  • Hetzner, which hosts our API and database in the European Union.
  • Cloudflare Pages, which hosts the website.

These providers act as data processors and are bound by contracts under Article 28 GDPR. Where a provider transfers data outside the EEA, the transfer is covered by the provider’s standard contractual clauses or adequacy arrangements.

5. How long we keep data

  • Account, license, and device data: for as long as your account or license exists.
  • Password setup and reset links: they expire after a short lifetime (approximately one hour) and are deleted on use.
  • The administrative audit log is kept for security and record-keeping purposes.
  • Data deleted with an account is removed together with the account, including its licenses, devices, and entitlements.

To delete your account and its data, write to [email protected] from the email registered on the account.

6. Security

  • Passwords are stored as salted hashes.
  • Machine fingerprints are stored only as keyed hashes.
  • All traffic between the app, the website, and the API uses TLS.
  • Session tokens are stored in sessionStorage only, never in cookies or persistent storage.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Your rights

Under the GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data (where no legal obligation requires us to keep it).
  • Restrict processing in certain situations.
  • Receive your data in a structured, commonly used format (data portability).
  • Object to processing based on legitimate interests.
  • Withdraw consent, where processing is based on consent.
  • Lodge a complaint with a supervisory authority. In Estonia that is the Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee).

To exercise any of these rights, email [email protected]. We respond within one month.

8. Children

FinForge is not directed at children under 16, and we do not knowingly collect personal data from them.

9. Changes to this policy

We may update this policy when our processing changes. The date at the top shows the current version. Material changes will be announced on the website.

Last updated: 6 October 2026.