At Finish & Flourish, we are committed to protecting your privacy and ensuring the security of your personal information. This policy explains how we collect, use, and protect your data when you use our self-discovery journey platform.
Account Information
- Name and email address (via Google OAuth)
- Profile picture (optional, from Google account)
- Account creation and last login dates
Journey Data
- Your responses to self-discovery questions
- Mood ratings and emotional check-ins
- Journey completion times and session metadata
- AI-generated insights (for Pro users)
Usage Information
- Device information and browser type
- IP address and general location data
- Pages visited and features used
- Error logs and performance data
Payment Information
- Payment processing data (handled securely by Stripe)
- Subscription status and billing history
- We do not store credit card information directly
- Provide and improve our self-discovery journey experience
- Generate personalized AI insights for Pro users
- Track your progress and maintain your journey history
- Process payments and manage subscriptions
- Send important account and service updates
- Analyze usage patterns to improve our platform
- Provide customer support and respond to inquiries
- Ensure platform security and prevent abuse
Security Measures
- End-to-end encryption for data transmission
- Secure database storage with access controls
- Regular security audits and vulnerability assessments
- Multi-factor authentication for admin access
Data Access
- Only authorized personnel can access your data
- AI processing uses data anonymization and privacy-preserving techniques
- We never sell or share your personal data with third parties
- Data is processed in secure, compliant cloud environments
- AI insights are generated without storing personal data with third-party AI providers
We use trusted third-party services to provide our platform:
- Google OAuth: For secure authentication and account creation
- Stripe: For secure payment processing (PCI DSS compliant)
- OpenAI: For generating personalized insights (data anonymized)
- Vercel: For hosting and content delivery
- Neon Database: For secure data storage
You have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your personal data
- Portability: Export your data in a machine-readable format
- Withdrawal: Withdraw consent for data processing
- Objection: Object to certain types of data processing
To exercise these rights, please contact us at privacy@finishflourish.com
- Account data: Retained while your account is active
- Journey responses: Retained for your personal growth tracking
- Usage analytics: Anonymized and retained for up to 2 years
- Payment records: Retained as required by law (typically 7 years)
- Deleted account data: Permanently removed within 30 days
GDPR Compliance (EU Users)
For users in the European Union, we comply with the General Data Protection Regulation (GDPR):
- Lawful basis for processing: Consent and legitimate interests
- Right to be forgotten: Complete data deletion upon request
- Data portability: Export your data in standard formats
- Data Protection Officer contact: dpo@finishflourish.com
CCPA Compliance (California Users)
For California residents, we comply with the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt-out of sale of personal information (we don't sell data)
- Right to non-discrimination for exercising privacy rights
Cookies and Tracking
We use essential cookies and similar technologies to:
- Maintain your login session and preferences
- Provide security and prevent fraud
- Analyze usage patterns (anonymized)
- Improve platform performance and user experience
You can manage cookie preferences in your browser settings.
If you have questions about this Privacy Policy or our data practices:
Email: privacy@finishflourish.com
Website: finishflourish.com
Response Time: We aim to respond within 72 hours
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. We will notify users of significant changes via email or through our platform. Continued use of our service after changes constitutes acceptance of the updated policy.