Privacy Policy

Last Updated: August 18, 2026

1. Introduction

VELRIO LIMITED, a company incorporated in the Republic of Cyprus ("VELRIO LIMITED," "we," "us," or "our"), is committed to protecting the privacy of individuals who use the Finestro platform available at finestro.io (the "Service"). This Privacy Policy outlines how we collect, use, process, and share Personal Data in connection with the Service.

This Privacy Policy is an integral part of our Terms of Service. By accessing or using the Service, you acknowledge that you have read, understood, and agree to the practices described herein. If you do not agree with this Privacy Policy, you must cease using the Service and may request deletion of your data by contacting [email protected].

VELRIO LIMITED determines the purposes and means of Processing your Personal Data and acts as the data controller under applicable data protection law.

The following definitions apply throughout this Privacy Policy:

2. Data Controller and Contact Information

The data controller responsible for the collection and Processing of your Personal Data through the Service is:

VELRIO LIMITED, a company incorporated in the Republic of Cyprus, with its registered address at Prodromou, 75, ONEWORLD PARKVIEW HOUSE, Floor 4, Nicosia, Republic of Cyprus 2063.

For privacy inquiries and data subject requests, contact: [email protected]. Please include "Privacy Inquiry" in the subject line of any privacy-related correspondence to help us direct your request promptly.

Depending on your location, payment method, or other relevant factors, your subscription or purchase may be processed by Findmy LLC, a Delaware limited liability company with its principal address at 501 E Las Olas Blvd, Suite 300, Fort Lauderdale, FL 33301, USA, acting as an authorized web distributor and merchant of record for certain transactions. In this capacity, Findmy LLC and VELRIO LIMITED act as joint controllers for the payment-related Personal Data processed in connection with those transactions. VELRIO LIMITED remains the sole controller for all other Personal Data collected through the Service.

3. Information We Collect

This section describes the categories of Personal Data we collect when you use the Service.

3.1 Information You Provide Directly

3.2 Information Collected Automatically

For EEA and UK users, we obtain prior consent before placing non-essential cookies. You may manage your preferences at any time through cookie settings. Cookies may be session-based (deleted when you close your browser) or persistent (remaining until expiration or manual deletion). You may also control cookies through browser settings or opt-out tools provided by the NAI, DAA, and EDAA.

3.3 Information from Third Parties

4. How We Use Your Information

We use the Personal Data we collect for the following purposes:

5. Legal Basis for Processing (EEA, UK, Brazil, Canada)

If you are located in the European Economic Area (EEA), the United Kingdom, Brazil, or Canada, we process your Personal Data only where we have a valid legal basis. The legal bases we rely upon include the following:

6. How We Share Your Information

We do not sell Personal Data for monetary consideration. We share Personal Data only as described below.

6.1 Service Providers (Processors). We engage reputable third-party service providers to perform functions on our behalf. Each provider is bound by a Data Processing Agreement (DPA) and, where applicable, Standard Contractual Clauses (SCCs). We share Personal Data with these providers only to the extent necessary for them to carry out their services. Our current sub-processors are listed below.

(a) Cloud Hosting and Infrastructure:

(b) Data Analytics, Attribution, and Performance Monitoring:

(c) Payment Processing:

(d) Email and Communications:

(e) Geolocation and IP Services:

(f) AI and Machine Learning Services:

(g) Tag Management:

If we engage a new sub-processor, we will update this Privacy Policy at least fourteen (14) days before the new sub-processor begins processing your Personal Data. If you have a reasonable objection to a new sub-processor, you may contact us at [email protected] within fourteen (14) days of the update.

6.2 Findmy LLC (Joint Controller for Payment Data). Findmy LLC, a Delaware limited liability company (501 E Las Olas Blvd, Suite 300, Fort Lauderdale, FL 33301, USA), acts as authorized web distributor and merchant of record for certain transactions. For payment-related Personal Data processed in connection with those transactions, Findmy LLC and VELRIO LIMITED act as joint controllers. VELRIO LIMITED remains the sole controller for all other Personal Data.

6.3 Advertising and Marketing Partners (Independent or Joint Controllers). Certain advertising and marketing platforms process Personal Data they receive from us as independent controllers or, where applicable, as joint controllers. When we share data with these platforms (for example, through pixels, conversion APIs, SDKs, or hashed identifiers for audience matching), these platforms process the data in accordance with their own privacy policies and terms. Our current advertising and marketing partners include:

Where we act as a joint controller with an advertising platform (for example, under Meta's Controller Addendum for Custom Audiences), we have entered into a joint controller arrangement that sets out each party's respective responsibilities. You may contact us at [email protected] to obtain a summary of any such arrangement.

Data shared with advertising platforms is limited to hashed identifiers and conversion data. We do not share names, email addresses in plaintext, or financial details for their independent use.

6.4 Sub-Processor Change Notification. The sub-processors and advertising partners listed in Sections 6.1 and 6.3 are current as of the "Last Updated" date of this Privacy Policy. If we engage a new sub-processor or advertising partner, we will update this Privacy Policy and provide at least fourteen (14) days' notice before the new provider begins processing your Personal Data. If you have a reasonable objection, you may contact us at [email protected] within fourteen (14) days of the update, and we will work with you to address your concerns.

6.5 Other Disclosures. We may share Personal Data: (a) to comply with applicable law, regulation, legal process, or enforceable governmental request; (b) in connection with a merger, acquisition, reorganization, or sale of assets, with notice to affected users; (c) with affiliated companies under common ownership with VELRIO LIMITED, subject to this Policy; or (d) with your consent.

7. Your Privacy Rights

Depending on your jurisdiction, you may exercise the following rights with respect to your Personal Data:

To exercise any of these rights, contact us at [email protected] with the subject line "Privacy Inquiry." We may verify your identity before fulfilling a request. We will respond within 30 days; if an extension is necessary due to complexity or volume, we will notify you within the initial 30-day period. No fee applies unless a request is manifestly unfounded or excessive.

Brazilian Users (LGPD): You hold all rights under LGPD Article 18, including confirmation of Processing, access, correction, anonymization, portability, deletion, and information about third parties with whom data has been shared. Contact [email protected] or the Brazilian National Data Protection Authority (ANPD) to exercise these rights.

Canadian Users (PIPEDA): You may request access to and correction of your Personal Data. We will respond within 30 days and inform you of any denial with reasons and available recourse, including the right to file a complaint with the Office of the Privacy Commissioner of Canada.

We are committed to honoring data subject rights regardless of your location, to the extent required by applicable law.

8. Age Requirements

8.1 The Service is designed for individuals who are at least eighteen (18) years of age. VELRIO LIMITED does not knowingly collect, solicit, or process Personal Data from anyone under the age of 18. If you are under 18, you may not use the Service, create an account, or provide any Personal Data to us.

8.2 In compliance with the U.S. Children's Online Privacy Protection Act (COPPA), we do not knowingly collect Personal Data from children under the age of 13. We also do not knowingly collect Personal Data from minors between the ages of 13 and 17.

8.3 If you are a parent or guardian and believe that your child has provided Personal Data to us without your consent, please contact us immediately at [email protected] with the subject line "Underage Data Report." Upon verification, we will take prompt steps to delete such data from our systems.

8.4 If we become aware that we have collected Personal Data from an individual under 18 without appropriate legal basis, we will delete that information as soon as reasonably practicable and take steps to prevent future collection from that individual.

9. International Data Transfers

VELRIO LIMITED stores Personal Data primarily on servers located in the United States (hosted by Amazon Web Services) and may process Personal Data within the European Union. When Personal Data is transferred from the EEA, the United Kingdom, or Switzerland to a country that has not received an adequacy decision from the relevant authority, we apply the following safeguards.

The primary destination country for cross-border transfers is the United States, where AWS, Findmy LLC, our payment processors (Stripe, Braintree, SolidGate), AI service providers (OpenAI, Google), analytics providers (Amplitude, HotJar, Sentry, AppsFlyer), advertising platforms, and other service providers operate. Some providers may also process data in the European Union or other jurisdictions. VELRIO LIMITED, as data controller, remains responsible for all transferred Personal Data, and your rights under applicable data protection law continue to apply regardless of where your data is processed.

10. Data Security

VELRIO LIMITED implements appropriate technical and organizational measures designed to protect Personal Data against unauthorized access, alteration, disclosure, or destruction.

These measures include, but are not limited to, the following:

No method of electronic transmission or storage is completely secure. While we take reasonable precautions to protect your Personal Data, we cannot guarantee absolute security. If you have reason to believe that your interaction with the Service is no longer secure, please contact us immediately at [email protected].

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make changes, we will revise the "Last Updated" date at the top of this Privacy Policy.

If we make material changes to this Privacy Policy, we will provide you with advance notice through one or more of the following methods: (a) a prominent notice on the finestro.io website; (b) an in-Service notification; or (c) an email to the address associated with your account. We will provide such notice before the changes take effect, giving you the opportunity to review the revised Privacy Policy.

Your continued use of the Service after the effective date of any updated Privacy Policy constitutes your acceptance of the revised terms. Where applicable law requires your consent for a particular change in how we process your Personal Data, we will obtain that consent before implementing the change.

If you do not agree with any changes to this Privacy Policy, you should cease using the Service and may request deletion of your Personal Data by contacting us at [email protected].

12. United States Privacy Rights

This section provides disclosures required under United States state privacy laws. If you are a resident of a state with applicable privacy legislation, you may have the rights described below.

12.1 California (CCPA/CPRA). We collect the following categories of Personal Information as defined under the California Consumer Privacy Act, as amended by the California Privacy Rights Act: identifiers; categories of Personal Information described in Cal. Civ. Code Section 1798.80(e); protected classification characteristics; internet or other electronic network activity information; geolocation data; and inferences drawn from the above.

Sale and Sharing. We do not sell Personal Information for monetary consideration. Our use of certain advertising technologies (pixels, conversion tracking, hashed identifier matching with Meta, Google, and TikTok) may constitute "sharing" under CCPA/CPRA. Categories shared include identifiers (hashed email addresses, device IDs) and internet or network activity. You may opt out by adjusting cookie preferences or contacting [email protected]. We honor opt-out preference signals, including Global Privacy Control, where required by law.

California Rights: right to know, right to delete, right to correct, right to opt out of sale or sharing, right to limit use of sensitive Personal Information, and right to non-discrimination. To exercise any right, contact [email protected]. Authorized agents are accepted with proper written authorization. For Shine the Light requests, email [email protected] with the subject line "Request for California Shine the Light Information."

12.2 CCPA Classification Table

Recipient Category Role under CCPA Purpose Categories of PI Shared
Cloud hosting (e.g., AWS) Service Provider Host and store data All categories
Analytics and monitoring (e.g., Google Analytics, Amplitude, HotJar, Sentry) Service Provider Analyze usage, monitor errors, improve Service Identifiers, Internet/Network Activity, Geolocation
Attribution analytics (e.g., AppsFlyer) Service Provider Deep linking, attribution Identifiers, Internet/Network Activity, Geolocation
Payment processors (e.g., Stripe, Braintree, SolidGate) Service Provider Process payments Identifiers, Commercial information
Billing partner (Findmy LLC) Service Provider Billing, subscriptions, refunds Identifiers, Commercial information
Email and communications (e.g., Reteno) Service Provider Transactional and marketing emails Identifiers
Geolocation/IP services (e.g., Geoapify, ip-api.com) Service Provider Approximate location for content, currency, fraud prevention Identifiers (IP address), Geolocation
AI/ML providers (e.g., OpenAI, Google Gemini) Service Provider Power AI features Internet/Network Activity (query content)
Tag management (e.g., Google Tag Manager) Service Provider Deploy analytics and marketing tags Identifiers, Internet/Network Activity
Ad platforms (e.g., Meta, Google Ads, TikTok, AppLovin) Third Party (independent/joint controller) Targeted advertising, conversion tracking, user acquisition Identifiers (hashed), Internet/Network Activity

12.3 Other US State Privacy Rights. Residents of Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and other states with applicable privacy statutes may exercise the following rights where provided by law: opt out of targeted advertising; opt out of the sale of Personal Data; opt out of profiling in furtherance of decisions that produce legal or similarly significant effects; and the right to appeal a denial of a request. To exercise these rights, contact [email protected]. We honor Global Privacy Control signals. To appeal a decision regarding your request, email [email protected] with the subject line "Privacy Appeal."

13. Data Retention

VELRIO LIMITED retains Personal Data only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. The following retention periods apply:

Data Category Retention Period
Account and profile data Duration of active account, plus 30 to 60 days following account deletion to complete processing
Support communications 1 to 2 years from the date of the communication
Analytics data Anonymized after 14 months (Google Analytics default retention period)
Financial and transaction records 7 years, as required by applicable accounting and tax laws
Legal compliance records As required by applicable law or regulation
Dispute resolution records Duration of any active dispute, claim, or proceeding, plus any applicable limitation period
Fraud prevention records Minimal records of banned or flagged accounts retained as necessary to prevent recurring fraud

Backup systems store encrypted copies of data. Backup media are cycled out on a regular schedule. If deleted data is restored from a backup, we will re-execute the deletion promptly upon identification.

When Personal Data is no longer required for any of the purposes set out above, we will either delete or anonymize it so that it can no longer be associated with an identifiable individual. Anonymized data may be retained indefinitely for statistical and analytical purposes.

14. Control Tracking

You have several options for controlling the use of cookies and similar tracking technologies when using the Service.

Third-party services integrated into the Service may respond to Do Not Track (DNT) signals or similar mechanisms according to their own policies. VELRIO LIMITED does not make any representations regarding how third parties respond to DNT signals or other opt-out mechanisms. For information on a third party's tracking practices, please consult that party's privacy policy directly.

15. Contact Us

The data controller responsible for your Personal Data is:

VELRIO LIMITED (a company incorporated in the Republic of Cyprus)

Registered Address: Prodromou, 75, ONEWORLD PARKVIEW HOUSE, Floor 4, Nicosia, Republic of Cyprus, 2063

For all privacy inquiries, data subject requests (including requests to access, correct, delete, or port your Personal Data), and questions regarding this Privacy Policy, please contact us at: [email protected]

When contacting us, please include a clear subject line (for example, "Privacy Inquiry" or "Data Subject Request") so that we may direct your correspondence to the appropriate team promptly.

We will acknowledge receipt of your inquiry and provide a substantive response within thirty (30) days of receiving your request. If additional time is required due to the complexity or volume of requests, we will notify you of the extension and the reasons for the delay within the initial 30-day period, in accordance with applicable law.