Skip to main content

    Privacy Policy

    Last updated: August 2026

    Introduction

    FIN Compliance ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our compliance consulting and software-as-a-service (SaaS) platforms.

    Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the site or use our services.

    Information We Collect

    Personal Information

    We may collect personal information that you voluntarily provide to us when you:

    • Register for our services or create an account
    • Request information or contact us
    • Subscribe to our newsletter or marketing communications
    • Use our compliance platforms (RegReview.io, InvestPrep.io, ADScanner.io)
    • Participate in surveys or promotions

    This information may include: name, email address, phone number, company name, job title, mailing address, and billing information.

    Automatically Collected Information

    When you access our website or platforms, we automatically collect certain information including your IP address, browser type, operating system, access times, and pages viewed. We may also collect information about your location and device identifiers.

    How We Use Your Information

    We use the information we collect to:

    • Provide, operate, and maintain our consulting services and SaaS platforms
    • Process your transactions and manage your account
    • Send you service-related communications and updates
    • Respond to your inquiries and provide customer support
    • Send marketing and promotional communications (with your consent)
    • Improve our website, services, and user experience
    • Comply with legal obligations and protect our rights
    • Detect and prevent fraud or unauthorized access

    Data Security

    We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

    • Encryption of data in transit and at rest
    • Secure server infrastructure with regular security audits
    • Access controls and authentication requirements
    • Regular security training for our team members
    • Compliance with industry security standards

    Third-Party Disclosure

    We do not sell, trade, or otherwise transfer your personal information to outside parties except in the following circumstances:

    • Service providers who assist in operating our business (subject to confidentiality agreements)
    • When required by law or to respond to legal process
    • To protect our rights, property, or safety, or that of our users
    • In connection with a business transfer, merger, or acquisition

    Cookies and Tracking

    We use cookies and similar tracking technologies to enhance your experience on our website. Cookies are small data files stored on your device that help us remember your preferences and understand how you use our site.

    You can control cookies through your browser settings. However, disabling cookies may limit your ability to use certain features of our website and services.

    Cloud Hosting & Data Disclosure (Client Portals)

    For clients using our compliance portals and platforms (RegReview.io, InvestPrep.io, ADScanner.io, FIN Portals, and related client-facing applications), we believe in full transparency about where your data lives, how it is protected, and who controls it.

    Your data remains your own. FIN Group does not sell, license, or repurpose client data. You retain full ownership of all firm records, documents, communications, training materials, and uploaded content. Upon termination, client data can be exported or deleted at your request.

    Where Your Files & Data Are Stored

    Our portals are built on Lovable Cloud, which runs on Supabase infrastructure hosted on Amazon Web Services (AWS):

    • Database (Postgres): hosted on AWS EC2/RDS-class infrastructure
    • File Storage: uploaded documents, logos, and training materials are backed by AWS S3
    • Edge Functions: run on Deno Deploy (globally distributed, with Cloudflare as the network layer)

    Region / US-Based Servers

    Each project is provisioned in a specific AWS region. Our portals default to US-based AWS regions (typically us-east-1 / N. Virginia or us-west-1). Data does not leave that region at rest. If your firm requires a specific region (US-only, EU, etc.) for compliance reasons, we can confirm and configure this on request.

    Encryption

    • At rest: all database storage and S3 file storage is encrypted using AES-256
    • In transit: all connections (browser ↔ Cloud, Edge Functions ↔ DB, S3 uploads/downloads) are encrypted with TLS 1.2+
    • Secrets (API keys, OAuth client secrets, Stripe keys, etc.) are stored in an encrypted vault, never in plaintext
    • Passwords are hashed using bcrypt — never stored in plaintext

    Application-Level Access Controls

    • Row-Level Security (RLS) is enforced on every table — users can only read/write data scoped to their own firm
    • Sensitive operations (archiving logs, webhooks, admin actions) require the Service Role and run inside Edge Functions, never from the browser
    • TOTP multi-factor authentication is available for users requiring SEC/FINRA-grade authentication
    • The documents storage bucket is private — files are only accessible via short-lived signed URLs
    • Public collection links use 30-day signed upload URLs to a private bucket (uploads only, no read access)

    Underlying Compliance Posture

    • SOC 2 Type II certified (Supabase)
    • HIPAA-eligible infrastructure available (AWS BAA)
    • GDPR compliant
    • AWS underlying infrastructure is ISO 27001, SOC 1/2/3, PCI-DSS, and FedRAMP certified

    AI Processing & Model Sub-Processors

    Several FIN Group properties — including this site, RegReview.io, InvestPrep.io, ADScanner.io, and our client portals — use AI to assist with drafting, summarization, classification, and workflow automation. AI is always assistive; final compliance decisions are made by licensed humans.

    When AI features are used, prompts and the context required to answer them may be sent to enterprise large-language-model providers (currently OpenAI, Google (Gemini), and Anthropic) over encrypted server-to-server connections. These calls operate under zero data retention (ZDR) commercial terms, which means:

    • Your data is not used to train any foundation model
    • The model provider does not retain your inputs beyond what is required to return a response
    • API credentials are stored in encrypted server-side vaults and never exposed to the browser
    • You may opt any document, workflow, or data category out of AI processing by emailing support@fincompliance.io

    A full, current list of every third-party sub-processor that may handle FIN Group or client data — vendor, purpose, data category, region, and certifications — is published in our Trust Center. For specifics on how AI is used product by product, see our AI Use & Disclosure.

    California Privacy Rights (CCPA / CPRA)

    FIN Group is headquartered in California. If you are a California resident, you have the following rights regarding personal information we collect about you:

    • Right to know what categories of personal information we collect, the sources, the business purposes, and the categories of third parties we share it with
    • Right to delete personal information we have collected (subject to legal retention obligations applicable to compliance recordkeeping)
    • Right to correct inaccurate personal information
    • Right to opt out of any "sale" or "sharing" of personal information — FIN Group does not sell or share personal information for cross-context behavioral advertising
    • Right to limit use of sensitive personal information
    • Right to non-discrimination for exercising any of the above

    To exercise any of these rights, email support@fincompliance.io with the subject line "California Privacy Request." We will verify your identity before acting on the request and respond within 45 days.

    Your Rights

    Depending on your location, you may have certain rights regarding your personal information, including:

    • The right to access your personal information
    • The right to correct inaccurate information
    • The right to request deletion of your information
    • The right to opt out of marketing communications
    • The right to data portability
    • The right to withdraw consent
    • The right to opt out of AI processing on specific documents or workflows

    Contact Us

    If you have questions about this Privacy Policy or our privacy practices, please contact us at:

    FIN Compliance

    2950 Buskirk Avenue, Ste #300

    Walnut Creek, CA 94597

    Phone: 650-305-2688

    Email: support@fincompliance.io