Privacy Policy
Last Updated: September 24, 2026
Authlayer, Inc., a Delaware corporation operating the Finlens platform (“Finlens,” “we,” “us,” or “our”), respects your privacy and is committed to protecting personal information.
This Privacy Policy explains how we collect, use, disclose, and otherwise process personal information in connection with our websites, applications, products, and services, including the Finlens platform (collectively, the “Services”).
This Privacy Policy applies to personal information that Finlens processes for its own business purposes, including information about visitors to our website, users of our Services, billing and administrative contacts, prospective customers, and other individuals who interact with Finlens.
Finlens also processes certain information on behalf of our business customers. When Finlens processes personal information contained in Customer Data on behalf of a customer, Finlens acts as a processor or service provider, and the customer acts as the controller or business with respect to that information. Such processing is governed by our Data Processing Addendum and applicable customer agreement. Requests relating to personal information contained in Customer Data should generally be directed to the applicable Finlens customer.
Our Data Processing Addendum similarly provides that Customer Personal Data is processed by Finlens as a processor/service provider, while Account Data used for account administration and billing is processed by Finlens as an independent controller.
1. Personal Information We Collect
We collect personal information in several ways depending on how you interact with Finlens.
Information You Provide to Us
We may collect information you provide directly to us, including:
- name;
- business email address;
- telephone number;
- company name;
- job title or role;
- account credentials and account configuration information;
- billing and subscription information;
- communications with us;
- customer-support requests;
- survey responses;
- feedback; and
- other information you choose to provide.
Billing and Payment Information
We use Stripe and other payment infrastructure to process payments for Finlens subscriptions.
Finlens may receive billing-related information such as the name of the customer, billing contact information, transaction status, payment method type, invoice information, and payment identifiers.
Finlens does not directly store full payment-card numbers.
This use of Stripe for payment of Finlens subscriptions is separate from the optional Stripe integration that customers may connect to Finlens for accounting and revenue-management purposes.
Customer and Financial Data
When a customer uses the Services, Finlens may process financial and accounting information provided by or on behalf of that customer.
Depending on the features used, this information may include:
- transactions;
- bills;
- invoices;
- general-ledger data;
- charts of accounts;
- balances;
- fixed-asset information;
- payment and revenue information;
- transaction descriptions;
- vendor, customer, payee, and counterparty information;
- connected-account metadata;
- accounting categorizations;
- journal entries;
- reconciliations; and
- other accounting or financial information.
The categories of Customer Personal Data processed through Finlens are further described in our DPA.
Finlens does not directly store banking login credentials or full payment-card numbers. Banking connectivity is handled through applicable integrations and service providers.
Information From Connected Services
Customers may choose to connect third-party services to Finlens, including:
- QuickBooks Online;
- Stripe;
- Plaid; and
- other accounting, banking, payment, spend-management, or financial platforms.
When a customer connects one of these services, Finlens receives information authorized by the customer and uses it to provide the requested functionality.
Our DPA identifies these integrations as customer-authorized Third Party Products rather than Finlens subprocessors.
Website and Device Information
When you visit our website or use the Services, we may automatically collect information such as:
- IP address;
- browser type and version;
- device type;
- operating system;
- approximate location derived from IP address;
- referring and exit pages;
- pages viewed;
- features used;
- dates and times of activity;
- interactions with our website or application;
- session and event data; and
- diagnostic, error, and performance information.
We use technologies including cookies, software development kits, pixels, tags, local storage, and similar technologies to collect this information.
Analytics and Session Information
We use analytics technologies, including:
- PostHog;
- Google Analytics; and
- Google Tag Manager.
We may also use session-replay or similar technologies to understand how users interact with our website and Services, diagnose usability problems, and improve our products.
Session-replay technologies may capture interactions such as clicks, navigation, page movement, and similar usage events. We configure these technologies to avoid intentionally collecting sensitive financial information through session replay where reasonably practicable.
Sales and CRM Information
We use Attio and related business systems to manage prospective and existing customer relationships.
We may collect or maintain information such as:
- business contact information;
- company information;
- communications with Finlens;
- sales activity;
- meeting information;
- relationship history; and
- publicly available professional information.
Information From Other Sources
We may receive information from:
- publicly available sources;
- referral partners;
- business partners;
- customers;
- service providers;
- social networks;
- advertising platforms; and
- other sources where permitted by law.
2. How We Use Personal Information
We may use personal information to:
- provide, operate, maintain, and improve the Services;
- create and administer accounts;
- authenticate users;
- provide accounting, reconciliation, categorization, financial-management, and related functionality;
- process payments and administer subscriptions;
- connect and synchronize customer-authorized integrations;
- provide technical support;
- respond to questions and requests;
- monitor the performance, reliability, and security of the Services;
- detect, investigate, and prevent fraud, abuse, and security incidents;
- troubleshoot errors;
- analyze use of our website and products;
- improve product design and functionality;
- develop new products and features;
- communicate about the Services;
- provide onboarding and transactional communications;
- send marketing communications;
- conduct sales and customer-relationship activities;
- measure the effectiveness of marketing campaigns;
- advertise and retarget our Services;
- comply with applicable law;
- enforce our agreements; and
- protect Finlens, our customers, users, and others.
3. Artificial Intelligence and Machine Learning
Finlens uses artificial-intelligence and machine-learning technologies as part of the Services.
These features may be used to:
- categorize transactions;
- generate categorizations and suggestions;
- propose Journal Entries;
- provide recommendations;
- analyze financial information; and
- respond to natural-language questions about customer financial data.
Finlens uses third-party AI providers, including OpenAI and Anthropic, as well as providers supporting embeddings and document processing.
Where necessary to provide AI functionality, relevant Customer Data may be transmitted to these providers.
Our AI providers are engaged under commercial API arrangements under which Customer Data submitted through the applicable APIs is not used to train their models. Those providers may process or temporarily retain information for limited operational purposes such as security, abuse detection, service delivery, and legal compliance.
Finlens generates journal entries and ledger postings through deterministic computation within Finlens infrastructure. AI providers may be used in an upstream categorization process, but Customer Data is not transmitted to an AI provider for the deterministic journal-entry-generation step itself.
4. How We Disclose Personal Information
We may disclose personal information as described below.
Service Providers and Subprocessors
We engage service providers and subprocessors to help operate Finlens.
These providers may perform functions including:
- cloud hosting;
- database and file storage;
- authentication;
- document processing;
- AI processing;
- customer support;
- logging;
- monitoring;
- analytics;
- email delivery;
- marketing; and
- payment processing.
Our current technology providers include service providers such as DigitalOcean, Google Cloud Platform, Amazon Web Services, Stytch, OpenAI, Anthropic, Voyage AI, Qdrant, Extend, Taggun, Resend, Atlas, Slack, Sentry, Plaid, Better Stack and PostHog. We may add or remove new technology providers at any time. The updated list of subprocessors can be found at https://www.finlens.app/dpa
We require subprocessors handling Customer Personal Data to be subject to appropriate contractual data-protection obligations.
Connected Services
When a customer directs Finlens to connect to a third-party service, we may disclose or receive information as necessary to establish and operate that connection.
Third-party Connected Services are governed by their own terms and privacy practices.
Analytics and Advertising Partners
We may disclose certain website, device, cookie, and interaction information to analytics and advertising partners.
We use or may use technologies provided by companies such as Google, Meta, PostHog, and similar providers for:
- analytics;
- audience measurement;
- advertising attribution;
- retargeting;
- advertising optimization; and
- cross-context behavioral advertising or targeted advertising.
Some disclosures for these purposes may constitute “sharing,” “targeted advertising,” or similar activity under applicable U.S. state privacy laws.
Business Transactions
If Finlens is involved in a merger, acquisition, financing, restructuring, bankruptcy, sale of assets, or similar corporate transaction, personal information may be disclosed or transferred as part of that transaction.
Legal and Safety Purposes
We may disclose personal information where we reasonably believe disclosure is necessary to:
- comply with applicable law;
- respond to subpoenas, court orders, or other lawful government requests;
- enforce our agreements;
- protect the security of the Services;
- investigate fraud or abuse;
- protect the rights, property, or safety of Finlens, our customers, our users, or others; or
- establish, exercise, or defend legal claims.
With Your Direction or Consent
We may disclose personal information where you or the relevant customer instructs us to do so or otherwise consents to the disclosure.
5. Sale and Sharing of Personal Information
Finlens does not sell personal information for monetary consideration.
We may, however, disclose certain website, device, cookie, and usage information to advertising partners for retargeting, targeted advertising, advertising measurement, or cross-context behavioral advertising.
Under certain state privacy laws, these disclosures may be considered a “sale,” “sharing,” or “targeted advertising” even though Finlens does not receive money in exchange for the information.
Where required by applicable law, you may opt out of such activities.
Finlens does not Sell or Share Customer Personal Data that it processes as a service provider on behalf of its customers, except as permitted by applicable data protection law and the applicable customer agreement.
6. Cookies and Similar Technologies
Finlens uses cookies and similar technologies to:
- operate the website and Services;
- remember preferences;
- maintain sessions;
- measure website traffic;
- understand product usage;
- diagnose technical issues;
- conduct analytics;
- measure marketing effectiveness; and
- provide or measure advertising.
Some cookies are necessary for the Services to function. Others may be used for analytics or advertising.
Where required by applicable law, we provide mechanisms that allow users to manage non-essential cookies or opt out of certain advertising-related processing.
You may also be able to control cookies through your browser settings.
7. Your Privacy Choices
Marketing Communications
You may unsubscribe from promotional emails by using the unsubscribe link included in those communications.
You may continue to receive transactional or service-related communications, including account notices, security messages, billing notices, and support communications.
Targeted Advertising and Sharing
Where applicable, you may request that Finlens not sell or share your personal information or use it for targeted advertising.
We will honor legally required opt-out mechanisms and recognized opt-out preference signals where applicable.
Cookies
You may use available cookie controls or your browser settings to limit certain cookies.
Disabling cookies may affect the operation of some features.
8. U.S. State Privacy Rights
Residents of certain U.S. states may have privacy rights under applicable law.
Depending on your state and the circumstances, those rights may include the right to:
- confirm whether we process your personal information;
- access personal information;
- obtain a copy of personal information;
- correct inaccurate personal information;
- request deletion of personal information;
- opt out of the sale of personal information;
- opt out of sharing for cross-context behavioral advertising;
- opt out of targeted advertising;
- opt out of certain profiling activities; and
- appeal a denial of a privacy request.
These rights are subject to applicable legal exceptions and eligibility requirements.
To exercise a privacy right, contact us at support@finlens.app.
We may need to verify your identity before completing a request.
You may also use an authorized agent where permitted by law. We may require evidence that the agent is authorized to act on your behalf.
We will not discriminate against you for exercising applicable privacy rights.
9. California Privacy Notice
This section supplements the rest of this Privacy Policy for California residents where the California Consumer Privacy Act, as amended, applies.
We do not have actual knowledge that we sell or share the personal information of consumers under 16 years of age.
Depending on your interaction with Finlens, we may collect the following categories of personal information:
Category
Examples
Identifiers
Name, business email address, telephone number, IP address, account identifiers
Customer records information
Contact and account information
Commercial information
Subscription information, transaction information, purchase history
Internet or network activity
Website activity, product usage, browser and device information
Approximate geolocation
Approximate location derived from IP address
Professional information
Employer, job title, role, business contact details
Financial and accounting information
Transactions, invoices, bills, ledgers, balances and related financial records where processed through the Services
Inferences
Information derived from product, website, sales, or marketing interactions
Other information
Communications, support requests, feedback and related information
We collect these categories from the sources and for the purposes described throughout this Privacy Policy.
We may disclose these categories to service providers, subprocessors, connected services at customer direction, analytics providers, advertising providers, and other recipients described in this Privacy Policy.
We do not sell personal information for monetary consideration.
We may share certain online identifiers, internet activity, cookie information, and similar data with advertising providers for cross-context behavioral advertising or retargeting.
Where applicable, California residents may exercise their rights by contacting support@finlens.app or using any opt-out mechanism provided on our website.
10. Customer Personal Data
Finlens primarily provides Services to businesses.
Where Finlens processes Customer Personal Data on behalf of a customer, the customer determines the purposes and means of processing and Finlens processes that information according to the customer's instructions and our Data Processing Addendum.
If your personal information appears in data submitted to Finlens by one of our customers—for example, because you are that customer's employee, customer, vendor, payee, or counterparty—you should generally direct privacy requests to that customer.
Finlens will assist its customers in responding to eligible privacy requests as required by applicable law and our DPA.
11. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to:
- provide the Services;
- maintain business and financial records;
- comply with legal obligations;
- resolve disputes;
- prevent fraud and abuse;
- maintain security; and
- enforce our agreements.
Retention periods vary depending on the type of information, the purpose for which it was collected, contractual requirements, and applicable law.
For Customer Personal Data, our customer agreements and DPA provide more specific deletion rules.
Following termination or expiration, customers may request export or deletion of Customer Personal Data in accordance with those agreements.
Backup copies are deleted in the ordinary course within 30 days after deletion from active production systems.
12. Security
We maintain administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure.
Our safeguards include measures such as:
- encryption in transit;
- encryption at rest;
- private-network database infrastructure;
- role-based access controls;
- tenant isolation;
- authentication controls;
- input validation;
- rate limiting;
- webhook-signature verification;
- centralized logging;
- error and performance monitoring;
- audit trails; and
- encrypted backups.
Our DPA describes additional technical and organizational measures used to protect Customer Personal Data.
No system can guarantee absolute security, and we cannot guarantee that unauthorized access, loss, or misuse will never occur.
13. Data Location
Finlens's application infrastructure and primary data storage are located in the United States.
Customer Personal Data is hosted and stored on infrastructure located in the United States.
Certain service providers may process information in other locations as disclosed by those providers or in our applicable subprocessor documentation.
14. Children
The Services are intended for business use by individuals who are at least 18 years of age and are not directed to children. We do not knowingly collect personal information from individuals under 18. If we learn that we have collected personal information from a child under 18, we will take reasonable steps to delete it
15. Third-Party Services and Links
Our Services may contain links to or integrations with third-party websites, applications, and services.
Finlens does not control the privacy practices of those third parties.
Your interactions with third-party services are governed by the applicable third party's privacy policy and terms.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect:
- changes to our Services;
- changes to our data practices;
- changes to technology;
- changes to applicable law; or
- other operational or business developments.
When we update this Privacy Policy, we will revise the “Last Updated” date above.
Where required by applicable law, we will provide additional notice of material changes.
17. Contact Us
If you have questions about this Privacy Policy, our privacy practices, or your privacy rights, contact us at:
Authlayer, Inc. (Finlens)
Email: support@finlens.app