Fince
AI Scan LHDN-ready Waitlist
Join the waitlist

Legal

Privacy Policy

Effective Date: 1 June 2026 · Last Updated: 4 June 2026

This Policy explains how Filmpeak Studio (the operator of Fince) collects, uses, shares, stores, and protects your personal data. It complies with the Malaysian Personal Data Protection Act 2010 (as amended in 2024) and with Apple App Store privacy requirements.

Contents

  1. Who We Are
  2. Data We Collect
  3. How We Use Your Data
  4. Who Processes Your Data
  5. Cross-Border Data Transfers
  6. Data Retention
  7. Account Deletion & Data Removal
  8. Your Rights Under PDPA
  9. Data Security
  10. Data Breach Notification
  11. Children's Privacy
  12. Data Protection Officer
  13. Changes to This Policy
  14. Contact

1. Who We Are

Fince ("we", "us", or "our") is operated by Filmpeak Studio, a sole proprietorship registered in Malaysia (SSM Business Registration No. 202503331274 / TR0333439-W), with registered address at 126-S Lorong Pala 6B, Taman Teluk Intan, Jalan Sultan Abdullah, 36000 Teluk Intan, Perak, Malaysia.

By using the Fince mobile application and related services (the "Service"), you consent to the practices described in this Policy.

2. Data We Collect

We collect only the data necessary to provide and improve the Service.

2.1 Account & Contact Information

  • Name
  • Email address
  • Password (stored as a salted hash; never stored in plaintext)
  • Workspace name and business profile details (if you create a workspace)

2.2 Financial & Business Records ("Ledger Data")

  • Income and expense transactions you record
  • Receipt images you upload or capture
  • Merchant names, amounts, dates, categories, and notes
  • Project, client, and workspace metadata
  • Tax-related metadata you choose to record
  • Recurring transaction rules

2.3 Receipt Image Data (processed by AI)

When you scan a receipt, the image and any text extracted by OCR are sent to Google Cloud Document AI for processing. See Section 4.3 for details.

2.4 Device & Usage Data

  • iOS device model and OS version
  • App version and locale
  • Crash diagnostics (collected via Apple's standard diagnostics framework; only if you have opted in at the iOS level)
  • Aggregated usage statistics via Apple App Analytics (only if you have opted in to "Share With App Developers" at the iOS level)

We do not use third-party analytics, advertising SDKs, or tracking pixels.

2.5 Camera & Photo Library Access

If you grant permission, the Service accesses your camera (to capture receipts) and/or your photo library (to import receipt images). Permission is requested in-app and can be revoked at any time via iOS Settings.

2.6 Identifiers

We assign a unique internal account ID to your account. We do not collect IDFA (Identifier for Advertisers) and do not perform cross-app tracking.

2.7 Biometric Authentication (Face ID / Touch ID)

If you enable App Lock, the Fince app uses your iOS device's biometric authentication (Face ID or Touch ID) or your device passcode to unlock the app. This check is performed entirely on your device by iOS — your biometric data (facial scan, fingerprint) is never sent to us, never leaves your device, and is never stored on our servers. We only receive a "success" or "failure" signal from iOS.

App Lock is optional and can be enabled or disabled at any time via Settings > Security > App Lock inside the app.

We do not collect: precise location data, contacts, calendar, health data, browsing history, or biometric data (Face ID / Touch ID is handled entirely on your device — see Section 2.7).

3. How We Use Your Data

PurposeLegal Basis (PDPA)
Create and maintain your accountPerformance of contract
Record, categorise, and display your financial dataPerformance of contract
Process receipt images via OCRPerformance of contract
Send service-related emails (verification, billing, security)Performance of contract / legitimate interest
Send product updates and marketing communicationsSeparate, opt-in consent
Improve the Service and develop new features (anonymised data only)Legitimate interest
Detect and prevent fraud, abuse, and security incidentsLegitimate interest / legal obligation
Comply with legal, tax, or regulatory obligationsLegal obligation

We will not use your personal data for any purpose materially different from those described above without your further consent.

4. Who Processes Your Data

Your data is processed by Filmpeak Studio and the following Sub-Processors. Each provider operates under its own published privacy and security commitments.

4.1 Apple Inc.

RoleApp Store distribution, In-App Purchase processing, and (optionally) App Analytics.
ResidencyAs published by Apple.
ReferenceApple Privacy Policy

4.2 Supabase, Inc.

RoleDatabase (PostgreSQL), authentication, and serverless edge functions.
Data processedAccount data, ledger data, session tokens.
ResidencyCurrently the Tokyo Region (Japan). We are in the process of migrating to the Singapore Region. Users will be notified before migration commences.
ReferenceSupabase Privacy Policy

4.3 Google LLC — Cloud Document AI

RoleReceipt OCR processing.
Data processedReceipt images and extracted text (merchant, amount, date, line items).
Residencyasia-southeast1 (Singapore).
RetentionImages are not retained by the Document AI API after processing; data logging is disabled in our Google Cloud configuration.
ReferenceGoogle Cloud Privacy Notice

4.4 Google LLC — Google Workspace

RoleEmail infrastructure (SMTP) for service communications via noreply@fince.my and gchinsiong@fince.my.
Data processedRecipient email address, message contents.
ReferenceGoogle Workspace DPA

We do not sell your personal data to any party.

5. Cross-Border Data Transfers

Because some of our Sub-Processors operate outside Malaysia, your personal data may be transferred to, stored in, or processed in Japan (Supabase, transitioning), Singapore (Google Cloud Document AI; Supabase, post-migration), and other jurisdictions where Apple and Google operate.

In accordance with the PDPA 2024 amendments on cross-border transfers, we ensure that:

  • each Sub-Processor provides an equivalent level of protection to that required under Malaysian law, evidenced by their published privacy commitments and data processing agreements;
  • transfers are limited to what is necessary to perform the Service;
  • you have given consent to such transfers by accepting this Policy when you create an account.

6. Data Retention

Data categoryRetention period
Active account dataFor the duration of your account
Deleted account dataPermanently deleted within 30 days of deletion request, except as required by law
Encrypted backupsUp to 60 days after deletion, after which they are overwritten
Billing & subscription recordsSeven (7) years (Malaysian tax record retention requirement)
Aggregated, anonymised dataIndefinite (cannot identify you)

7. Account Deletion & Data Removal

In-app deletion. You can delete your account directly inside the Fince app at any time via:

Settings > Account > Delete Account

Account deletion will:

  • terminate your access to the Service;
  • queue your ledger data, receipts, and personal information for permanent deletion;
  • cancel any free-tier relationship.

Active paid subscriptions must be cancelled separately via your Apple ID subscriptions settings.

Deletion is irreversible. You may export your ledger data via Settings > Export Data before deletion.

8. Your Rights Under PDPA

Under the Malaysian PDPA (as amended in 2024), you have the right to:

  1. Access the personal data we hold about you.
  2. Correct inaccurate or incomplete personal data.
  3. Withdraw consent to processing, where processing is based on consent.
  4. Request deletion of your personal data (subject to legal retention requirements).
  5. Object to processing for direct marketing purposes.
  6. Data portability — receive a copy of your data in a structured, machine-readable format (CSV/JSON). The Service provides an in-app export tool.
  7. Lodge a complaint with the Personal Data Protection Commissioner of Malaysia.

To exercise these rights, contact our Data Protection Officer (Section 12).

9. Data Security

We protect your data using industry-standard measures, including:

  • Encryption in transit (TLS 1.3) for all client–server communications;
  • Encryption at rest for database storage (provided by Supabase);
  • Salted password hashing (provided by Supabase Auth);
  • Optional in-app biometric lock (Face ID / Touch ID) and device passcode authentication, performed entirely on your device, as an additional security layer (see Section 2.7);
  • Role-based access controls inside our infrastructure;
  • Principle of least privilege for staff and contractors;
  • Regular review of Sub-Processor security postures.

No method of transmission or storage is 100% secure. We continue to improve our safeguards but cannot guarantee absolute security.

10. Data Breach Notification

In line with the PDPA 2024 amendments, if a personal data breach occurs that is likely to result in significant harm to affected users, we will:

  • notify the Personal Data Protection Commissioner of Malaysia within 72 hours of becoming aware of the breach, where required;
  • notify affected users without undue delay, describing the nature of the breach, the data affected, the measures taken, and steps users can take to protect themselves.

11. Children's Privacy

Fince is intended for users 13 years of age or older. We do not knowingly collect personal data from children under 13. If we become aware that we have collected personal data from a child under 13, we will delete it promptly. Users between 13 and 17 may only use the Service with the consent of a parent or legal guardian — see Section 2 (Eligibility) of our Terms of Service for details.

12. Data Protection Officer (DPO)

Our designated Data Protection Officer is responsible for overseeing PDPA compliance and is your point of contact for any privacy queries or rights requests.

Data Protection Officer
Filmpeak Studio (Fince)
Email: gchinsiong@fince.my
General contact: gchinsiong@fince.my

13. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last Updated" date at the top reflects the most recent revision. Material changes will be notified via in-app notice or email at least seven (7) days before they take effect.

14. Contact

For privacy questions, data subject requests, or to escalate a concern:

Data Protection Officer: gchinsiong@fince.my
General contact: gchinsiong@fince.my

Filmpeak Studio
SSM Reg. No. 202503331274 / TR0333439-W
Malaysia

You may also contact the Personal Data Protection Commissioner of Malaysia.

Fince

Automated bookkeeping for freelancers & solo founders in Malaysia.

Product

AI Scan LHDN-ready Waitlist

Company

About Blog Contact

Legal

Privacy Policy Terms of Service
© 2026 Fince. Made in Malaysia. RM-native bookkeeping