Privacy Policy
Last updated
Fintura Ltd ("Fintura", "we", "us") respects your privacy and is committed to protecting your personal data. This Privacy Policy describes how we collect, use, and protect your information when you use the Fintura platform.
1. Data We Collect
We collect and process the following types of personal and business data:
- Full name, email address, ID numbers
- Company registration numbers and tax details (e.g., SARS, CIPC)
- Uploaded identification and supporting documents
- Financial records submitted via the Platform
- Usage and activity data
- Communication preferences
When you sign up, we keep the marketing link (UTM parameters), the landing page and the referring page that led to the signup, with the account.
2. How We Use Your Data
We use your data to:
- Provide access to Fintura’s services and tools
- Process documentation with CIPC, SARS, and DOL on your behalf
- Personalise the Platform experience, including through Finnie
- Communicate with you, including service updates and marketing
- Monitor usage to improve Platform performance and support
- Email content (subject line, body, recipient address) you configure in Fintura's scheduled email templates is used solely to generate and send the email at the time you've configured. We do not use this content to train any machine-learning model, build advertising profiles, or sell to third parties.
- OAuth tokens granted to Fintura by Google or Microsoft are retained only as long as you keep the connection active. When you disconnect a mailbox in Fintura, or revoke access through your Google or Microsoft account directly, we delete the associated refresh tokens within 24 hours. Records of emails sent through your account are retained in your activity log for up to 12 months, and are then deleted automatically.
3. Sharing of Data
We may share your data with:
- Statutory bodies (CIPC, SARS, DOL) with your explicit authorisation
- Service providers, including Stripe, for payment processing
- Cloud service providers (with data potentially stored outside South Africa)
We do not sell or rent your data to third parties.
4. Data Security
We implement appropriate technical and organisational measures to protect your data. These include data encryption, access controls, and secure cloud storage. However, no system is completely secure and we cannot guarantee absolute security.
5. User Rights
Under POPIA, you have the right to:
- Access your personal data
- Request correction or deletion of your data
- Withdraw consent for data processing
- Lodge complaints with the Information Regulator
You may delete your account or request data deletion by contacting us at support@fintura.io.
6. Cookies and Analytics
We use cookies and similar technologies to enhance your experience and monitor usage. You can manage cookie preferences in your browser settings.
7. Marketing Communications
You may receive promotional communications from us. You can opt out at any time via the unsubscribe link in our emails or by contacting us.
8. Connected Email Accounts
Fintura lets you connect a Google or Microsoft email account so we can send scheduled emails to your clients on your behalf. When you choose to connect an account, you authorise Fintura through the provider's standard OAuth consent flow. We never receive your email password.
What we access from Google (Gmail)
When you connect Gmail, we request the following scopes from Google's OAuth API:
- https://www.googleapis.com/auth/gmail.send — to send the scheduled emails you configure in Fintura through your Gmail account
- https://www.googleapis.com/auth/userinfo.email — to confirm which Google account you've connected, so we can attribute scheduled emails to the right inbox
We do not access your inbox, your contacts, your drafts, your sent folder, your settings, your calendar, or any other Google data. We do not read replies your recipients send.
Fintura's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What we access from Microsoft (Outlook)
When you connect Outlook, we request the following permissions from Microsoft Graph:
- Mail.Send — to send the scheduled emails you configure in Fintura through your Outlook account
- MailboxSettings.Read — to read your Outlook signature (when supported by your Microsoft tenant) so it can be automatically appended to scheduled emails
- User.Read — to retrieve your basic profile (name, email address) so we can attribute scheduled emails to the right inbox
- offline_access — to refresh access tokens in the background so scheduled emails continue to send without you having to re-sign-in
We do not access your inbox, your contacts, your calendar, or any other Microsoft data. We do not read replies your recipients send.
How we store this access
We store the OAuth refresh and access tokens issued by Google and Microsoft in encrypted form so we can send scheduled emails on your behalf at the time you've configured them to send. We store the email subject and body content of each scheduled email until it has been sent successfully, after which we retain a copy in your activity log for audit and compliance purposes for up to 12 months. We do not share these tokens or this content with third parties.
How to revoke access
You can disconnect your Google or Microsoft account from Fintura at any time:
- Inside Fintura: Practice Management → Email → Connect → click Disconnect on the relevant tile. This immediately invalidates the stored access and refresh tokens on our side.
- From Google: Google Account → Security → Third-party apps with account access → find Fintura → Remove access
- From Microsoft: Microsoft Account → Privacy → Apps and services that can access your data → find Fintura → Remove
When you disconnect, any scheduled emails that haven't already sent will fail to send and will be marked as failed in your activity log. We will delete stored access and refresh tokens within 24 hours of disconnect.
9. Changes to this Policy
We may update this Privacy Policy from time to time. Users will be notified of material changes. Continued use of the Platform constitutes acceptance of the updated policy.
Third-Party Service Compliance
Fintura's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Fintura's use of information received from Microsoft Graph adheres to the Microsoft APIs Terms of Use and the Microsoft Online Services Data Protection Addendum.
Contact Us
Fintura Ltd
71-75 Shelton Street, London, WC2H 9JQ, United Kingdom
Email: support@fintura.io