Privacy Policy

Last updated: 2026-09-15

This Privacy Policy describes how Finch Labs, Inc. (“Finch,” “we,” “us,” or “our”) collects, uses, and shares information when you use our advertising-automation platform available at finchlabs.ai (the “Service”). Finch Labs, Inc. is a Delaware corporation with its mailing address at 1908 Thomes Ave STE 44233, Cheyenne, WY 82001, USA.

1. Information we collect

We collect the following categories of information:

2. How we use information

3. Subprocessors and third parties

We use the following service providers (subprocessors) to operate the Service. Each has its own privacy policy linked below.

We do not sell or rent personal information to third parties for advertising purposes.

4. Google user data and Limited Use

When you connect a Google account, Finch requests access — Google Ads through our broker Pipeboard, Google Analytics 4 through a service account you grant access to — to the following Google services, and only for the purposes described:

We request the minimum scopes necessary for these features. We do not request write access to your Google Ads account and do not create, edit, pause, or delete your campaigns.

Limited Use. Finch Labs’ use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely, Google user data is used only to provide and improve the user-facing features described above. It is not used for serving advertising; not sold or transferred to third parties for any purpose other than providing the Service (or as required by law, or in connection with a merger/acquisition with continued protection); not used to develop, improve, or train generalized AI/ML models; and is accessible to humans only with your explicit consent, to investigate security or abuse, or where required by applicable law.

You can end Finch’s access at any time. Email privacy@finchlabs.ai and we disconnect the source; no new sync starts after that. A sync already running when we disconnect can finish and write what it had already fetched, so allow up to 10 minutes for the last one to land. How access was granted differs by platform, so ending it does too. Google Ads access is brokered through our data provider Pipeboard, so you also remove Finch’s access to your Google Ads account from that account’s access settings. Google Analytics 4 is read through a service account you granted Viewer on your property, so removing that access binding ends it. Where you granted Finch access directly from your Google Account, you can revoke it in your third-party access settings as well. Stored credentials are covered in section 8.

5. International data transfers

Finch Labs is based in the United States, and our subprocessors are located in the United States and the European Union. By using the Service, you consent to the transfer of your information to these jurisdictions. Where required, we rely on Standard Contractual Clauses or equivalent safeguards.

6. Data retention

We keep your account information and your connected-platform analytics data (ad performance, lead outcomes, store and web analytics) for as long as you use Finch. There is no automatic time limit on it, and we do not delete it on our own schedule. To have it deleted, email privacy@finchlabs.ai from the address registered to your account: we confirm receipt within 5 business days and delete your workspace and its data within 30 days, following a documented internal process. Amazon Information is the one exception with a fixed clock: rows older than 18 months are purged automatically, by each row’s own date, whether or not you ask, per Amazon’s Data Protection Policy. Server logs are retained for up to 30 days. After a deletion, copies can remain in our hosting provider’s encrypted backups until those backups expire on their normal rotation, and we keep a redacted record that the deletion happened (what was deleted and when, with the content itself removed). Those audit entries are redacted by workspace; an entry recorded without a workspace attached, which happens for platform-level actions, keeps what it recorded.

7. Your rights

8. Security

We use industry-standard measures to protect your data, including TLS in transit, encryption at rest, OAuth-token isolation per tenant, row-level security on the database, and minimum-privilege access for engineers. Platform credentials (access tokens, and references to credentials held in Google Secret Manager) are stored in our database, which our hosting provider encrypts at rest, and are readable only by Finch’s backend services, never by the browser. Disconnecting a source today stops syncing but does not yet erase the stored credential; erasing it on disconnect is a tracked engineering item, and the credential is erased when your data is deleted. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.

9. Children

The Service is not intended for children under 13 (or 16 in the EU/UK). We do not knowingly collect personal information from minors. If you believe a minor has provided us with information, contact privacy@finchlabs.ai and we will delete it.

10. Changes to this policy

We may update this policy from time to time. We will post the new version at this URL with an updated “Last updated” date. Material changes will be notified by email to active account holders at least 30 days before they take effect.

11. Contact

Privacy and data-protection inquiries: privacy@finchlabs.ai
General contact: support@finchlabs.ai
Mailing address: Finch Labs, Inc., 1908 Thomes Ave STE 44233, Cheyenne, WY 82001, USA