PRIVACY POLICY

what is collected, why, and how to make it stop

Effective 20 August 2026

THE SHORT VERSION


1. WHO IS RESPONSIBLE

The data controller is Henry Finn, an individual doing business as a sole proprietor in California, United States. Contact details are on the contact page. Privacy questions and requests go to henry@henryfinn.com.


2. WHAT IS COLLECTED

Information you give me

Information collected automatically

What is never collected

No full card numbers, no CVV codes, no bank credentials, no government ID numbers, no biometric data, and no health data. I do not knowingly collect sensitive personal information as defined by California law, and I do not use or disclose any for purposes requiring a right to limit.


3. WHY IT IS COLLECTED, AND THE LEGAL BASIS

PurposeData usedLegal basis (UK/EU)
Taking payment, delivering what you boughtPurchase and contact detailsPerformance of a contract
Support, refunds, and replying to youContact and purchase detailsPerformance of a contract
Receipts, renewal notices, service emailsEmail, purchase detailsPerformance of a contract
Tax, accounting, and legal recordsTransaction recordsLegal obligation
Fraud prevention and site securityLog and transaction dataLegitimate interests
Understanding site trafficAnalytics dataConsent, or legitimate interests where consent is not required
Marketing emails, if you asked for themEmail addressConsent

Marketing email only ever goes out if you opted in, and every one of them has a one-click unsubscribe. Service emails such as receipts, renewal notices, and security notices are part of the transaction and are sent regardless, because you need them.


4. WHO IT IS SHARED WITH

Your personal information is not sold, rented, or traded. Ever. It is shared only with the service providers needed to run this business, each bound to use it solely to provide their service:

ProviderWhat forTheir policy
Stripe, Inc.Payment processing, fraud checks, receiptsstripe.com/privacy
Google (Analytics)Aggregate traffic measurementpolicies.google.com/privacy
Vercel Inc.Website hosting and deliveryvercel.com/legal/privacy-policy
Email providerSending and receiving mailPer that provider's policy
Accountant / tax adviserBookkeeping and tax filingUnder professional confidentiality

Information may also be disclosed where legally required by valid legal process, where necessary to establish or defend legal claims, or to a successor if the business is transferred, in which case you will be told first.


5. COOKIES AND TRACKING

This site sets Google Analytics cookies (_ga and related), which last up to 24 months and count visits. Stripe sets cookies on its own checkout pages for fraud prevention and to make payment work. No advertising, remarketing, or cross-site tracking cookies are used, and there are no third-party ad networks on this site.

How to opt out


6. HOW LONG IT IS KEPT


7. YOUR RIGHTS

Everyone

Whoever and wherever you are, you can ask me to tell you what I hold about you, give you a copy, correct it, or delete it. Email henry@henryfinn.com. I will respond within 30 days, free of charge, and I will not treat you any differently for asking. I may need to confirm your identity first, usually just by replying from the address on file.

California residents (CCPA/CPRA)

You have the right to know what is collected and why, to access and port it, to correct it, to delete it, to limit the use of sensitive personal information, and to opt out of sale or sharing. I do not sell or share personal information, and have not in the preceding 12 months, including the personal information of anyone under 16. There is therefore no "Do Not Sell or Share" link to click, but a Global Privacy Control signal is honoured anyway. You may use an authorized agent, and you will never be discriminated against for exercising a right.

UK and EU residents (UK GDPR / GDPR)

You additionally have the right to restrict processing, to object to processing based on legitimate interests, to data portability, to withdraw consent at any time without affecting prior processing, and to lodge a complaint with your supervisory authority (in the UK, the ICO). No automated decision-making with legal or similarly significant effects is carried out.

International transfers

This business is in the United States, and its providers are US-based, so data is processed in the US. Where personal data is transferred from the UK or EU, the providers named above rely on Standard Contractual Clauses or an equivalent approved mechanism.


8. SECURITY

The site is served over HTTPS. Payment pages are hosted by Stripe, which is certified to PCI Service Provider Level 1, the highest level in the payments industry. Accounts use multi-factor authentication where the provider supports it, and access to client material is limited to what is needed to do the work. No system is perfectly secure, but if a breach ever affects your personal information you will be notified without undue delay and as required by law.


9. CHILDREN

Nothing here is directed at children under 16, and information is not knowingly collected from them. If you believe a child has provided personal information, email me and it will be deleted promptly.


10. LINKS TO OTHER SITES

This site links out to other sites, including social profiles and portfolio companies. Their privacy practices are their own, and this policy does not cover them.


11. CHANGES

This policy can be updated. The effective date at the top shows the current version. Material changes will be announced on this page and, where I hold your email address, emailed to you.


12. CONTACT

Privacy questions, requests, and complaints: henry@henryfinn.com, or by post to the address on the contact page. A reply comes within 30 days, and usually within 2 business days.