Loading...

Privacy Policy

How Finbotics collects, uses, and protects information when you visit our website, use our lending software, or receive our operational services.

Last updated: 27 August 2026

1. Who we are

Finbotics (“we”, “us”, or “our”) provides unified lending management systems, related software products, and operational services to banks, finance companies, credit unions, alternative lenders, embedded lenders, and other organisations. This Privacy Policy explains how we handle personal information in connection with:

  • our public websites, marketing, and demo or contact forms;
  • our lending management software, portals, APIs, and related applications (the “Platform”);
  • implementation, support, consulting, training, and other operational services; and
  • sign-in and identity features, including Google OAuth and similar third-party authentication.

If you have questions about this Policy, contact us at hi@finbotic.ai or write to us at IFZA Dubai Building A1, Unit 001, Dubai Digital Park, Dubai Silicon Oasis.

2. Scope and roles

Depending on the relationship, we may act as:

  • Controller of personal information we collect for our own purposes, such as website visitors, sales leads, partner inquiries, job applicants, and our own user accounts; and
  • Processor of personal information that our business customers (lenders and their partners) submit to the Platform or ask us to process while providing operational services. In that case, the customer determines the purposes and means of processing, and we process that information under their instructions and our agreement with them.

This Policy describes our own practices. Our customers’ privacy notices govern how they use borrower, applicant, and other end-customer data in their lending programmes.

3. Information we collect

3.1 Information you provide

You may give us information when you request a demo, book a consultation, contact us, apply for a job, become a partner, create an account, or use the Platform. This may include:

  • identity and contact details (name, email address, phone number, company, job title, office location);
  • messages, attachments, CVs, and other content you submit;
  • account credentials and profile details; and
  • preferences, product interests, and support requests.

3.2 Information from Google and other sign-in providers

If you choose to sign in with Google, Microsoft, or a similar identity provider, we receive the information you (or your organisation) authorise that provider to share with us. For Google OAuth this typically includes your name, email address, profile picture, and a unique account identifier. We do not receive your Google password. We only request scopes needed to authenticate you and operate the account features you use.

You can revoke our access at any time in your Google Account permissions. Revoking access may prevent you from signing in until you reconnect an identity method.

3.3 Information collected automatically

When you visit our website or use the Platform, we may collect device and usage information such as IP address, browser type, pages viewed, referring URL, timestamps, approximate location derived from IP, and diagnostic logs. We may use cookies, session tokens, and similar technologies to keep you signed in, remember preferences, protect the service, and understand how our sites are used.

3.4 Customer and operational data

When a customer uses our lending systems or operational services, they may upload or generate data needed to originate, underwrite, service, collect, report on, or otherwise manage loans. That data can include borrower and applicant details, financial and KYC information, documents, decisions, communications, and related operational records. We process this information to provide the contracted services, not to market to those individuals for our own purposes.

4. How we use information

We use personal information to:

  • operate, maintain, and improve our website, Platform, and operational services;
  • create and authenticate accounts, including via Google OAuth and similar providers;
  • respond to inquiries, provide demos, support, training, and implementation services;
  • process job applications and partner requests;
  • communicate about products, service updates, and (where permitted) marketing;
  • monitor security, prevent fraud and abuse, and enforce our terms;
  • comply with law, regulators, and contractual obligations; and
  • analyse aggregated or de-identified usage to improve reliability and features.

We do not sell personal information. We do not use Google user data to serve personalised advertising, to build independent marketing profiles, or for any purpose other than providing or improving user-facing features of our services.

5. Google API Services User Data Policy (Limited Use)

Finbotics’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular, information obtained via Google APIs is used only to:

  • authenticate users and create or link their accounts;
  • display basic profile information inside the product (for example, name, email, and avatar); and
  • provide support, security, and account administration for those users.

We do not transfer Google user data to third parties except as necessary to operate the service (for example, hosting and security providers acting on our instructions), to comply with law, or with your direction. We do not use Google user data for advertising. Human access to Google user data is limited to cases such as user-requested support, security investigations, legal compliance, or with your consent.

6. How we share information

We may share personal information with:

  • Service providers who host infrastructure, email, analytics, security, identity, or similar functions on our behalf;
  • Our customers and partners, where you interact with them through the Platform or they administer your account;
  • Professional advisers such as lawyers, auditors, and insurers;
  • Authorities when required by law, legal process, or to protect rights, safety, and security; and
  • A successor in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate protections.

We may also share aggregated or de-identified information that does not reasonably identify you.

7. Cookies and similar technologies

We use essential cookies and similar technologies to operate the site and keep sessions secure. We may also use analytics cookies to understand traffic and improve the experience. You can control cookies through your browser settings. Blocking some cookies may affect sign-in or other features.

8. Retention

We keep personal information only as long as needed for the purposes described in this Policy, including to provide services, meet legal, accounting, and reporting requirements, resolve disputes, and enforce agreements. Marketing lead records are typically retained while we have an active relationship and for a reasonable period afterwards. Account data is retained while the account is active and for a limited period after closure unless a longer period is required. Customer lending data is retained according to the customer’s instructions and contract.

When Google or another provider no longer authorises access, or you delete your account, we delete or de-identify related authentication data except where we must retain it for security, audit, or legal reasons.

9. Security

We use administrative, technical, and organisational measures designed to protect personal information, including access controls, encryption in transit where appropriate, logging, and least-privilege practices. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. International transfers

We operate from offices including the United Arab Emirates and Singapore and may process information in other countries where we or our providers operate. Where required, we use contractual and other safeguards for cross-border transfers.

11. Your rights

Depending on your location and our role, you may have the right to access, correct, delete, or restrict personal information, to object to certain processing, to withdraw consent, or to port your data. To exercise these rights for information we control, contact us at hi@finbotic.ai. If your data is processed in a customer’s lending programme, please contact that organisation first; we will assist them as required by our contract.

You may also lodge a complaint with a data protection authority in your jurisdiction.

12. Children

Our website, Platform, and services are intended for businesses and professionals. We do not knowingly collect personal information from children under 16. If you believe we have collected such information, contact us and we will take appropriate steps to delete it.

13. Third-party sites

Our sites may link to third-party websites, maps, or services. Their privacy practices are governed by their own policies. This Policy does not cover those third parties.

14. Changes

We may update this Policy from time to time. The “Last updated” date at the top will change when we do. Continued use of our website, Platform, or services after an update constitutes acceptance of the revised Policy where permitted by law. Material changes that affect Google user data will remain consistent with the Google API Services User Data Policy.

15. Contact

Privacy requests: hi@finbotic.ai

You can also reach us through our Contact Us page.

See also our Terms & Conditions.

Top