Privacy Policy
Last Updated: 30 August 2026
This Privacy Policy explains how Finsta, operated by Solutionize Tech, LLC (1111B South Governors Avenue, Dover, DE 19904, USA), collects, uses, shares, and protects personal data.
The Platform is for adults only: you must be at least 18 years old to use Finsta, and we do not knowingly collect data from anyone under 18. If you believe a minor is using the Platform, contact admin@solutionize.tech immediately.
1. Information We Collect
We collect information you provide directly, including your name, email address, mobile phone number, profile information, and payment details. We also collect usage data such as how you interact with the platform, device information, and IP addresses. Where you complete identity or age verification, we receive and retain the verification result and verified date of birth (see Section 12).
We also receive information from third parties. For example, when you arrive at Finsta from an advertisement, the advertising platform tells us which campaign or advertisement brought you, and we store that against your account.
1.1 Categories of personal information we collect
The table below lists the categories of personal information we have collected in the last twelve months, where each category comes from, why we collect it, and who we disclose it to for a business purpose. We disclose personal information only to the categories of recipient listed; we do not disclose it to anyone else except as described in Section 5.
Identifiers and contact data
- Examples: Name, username, email address, mobile phone number, account identifier, IP address, device identifiers
- Where it comes from: You; automatically from your device; sign-in providers
- Why we collect it: Creating and securing your account, logging you in, notifications, support, fraud prevention
- Disclosed to: Hosting, messaging-delivery and communications service providers
Account and profile information
- Examples: Profile text, profile picture and banner, preferences and settings, follows and subscriptions
- Where it comes from: You
- Why we collect it: Operating your profile and the features you use
- Disclosed to: Hosting and content-screening service providers
Commercial and transaction data
- Examples: Purchases, credit balances and spend, subscriptions, payouts, refunds, chargebacks, billing address
- Where it comes from: You; our payment and payout providers
- Why we collect it: Taking payment, paying creators, refunds and chargebacks, tax and accounting records
- Disclosed to: Payment providers, payout providers, accountants, tax authorities
Verification data
- Examples: Verification result, verified date of birth, verification reference and date
- Where it comes from: Our third-party identity verification provider
- Why we collect it: Confirming age and identity, meeting legal record-keeping duties
- Disclosed to: Identity verification provider; payment providers and auditors where required; law enforcement on lawful request
Biometric information
- Examples: Facial scan taken during verification and the biometric identifier derived from it (see Section 13)
- Where it comes from: You, through our third-party identity verification provider
- Why we collect it: Matching you to your identity document and detecting impersonation
- Disclosed to: Held by the identity verification provider only; not received or stored by Finsta
Content and communications
- Examples: Messages and media you send, media you upload, Digital Products, and the results of safety screening (category flags and timestamps)
- Where it comes from: You
- Why we collect it: Delivering the service and keeping the Platform safe and lawful
- Disclosed to: Messaging infrastructure and content-screening service providers; law enforcement where legally required
Session metadata
- Examples: That a session took place, start and end time, duration, participating accounts, connection quality. Session audio and video are not recorded (see Section 3)
- Where it comes from: Automatically, from the session
- Why we collect it: Billing, support, safety and fraud prevention
- Disclosed to: Hosting and real-time communications service providers
Usage, device and technical data
- Examples: Features and pages used, app events, device type, operating system, browser, app version, language, general location derived from IP address
- Where it comes from: Automatically, from your device
- Why we collect it: Operating and improving the service, security and fraud prevention
- Disclosed to: Hosting and product analytics service providers
Advertising and measurement identifiers
- Examples: Advertising identifiers, click identifiers, cookie and pixel identifiers, campaign attribution, install and signup events
- Where it comes from: Automatically; advertising platforms
- Why we collect it: Measuring how our advertising performs (Section 6)
- Disclosed to: Advertising platforms and measurement providers
Support and correspondence
- Examples: Emails and in-app support chats, complaints, appeals, reports and the records of how they were handled
- Where it comes from: You; other users who report content
- Why we collect it: Answering you, handling complaints and appeals, defending legal claims
- Disclosed to: Support-tooling service providers; legal advisers; law enforcement where legally required
Some of this is treated as sensitive personal information under U.S. state privacy laws — in particular biometric information used to identify you, government-issued identifier data handled during verification, and the contents of your messages. We use and disclose it only for the purposes described in this Policy: providing the service you asked for, safety and fraud prevention, and meeting our legal obligations. We do not use or disclose sensitive personal information for advertising, for profiling, or to infer characteristics about you.
2. How We Use Your Information
- To provide and improve our services
- To process payments and payouts
- To communicate with you about your account and our services
- To ensure safety and prevent fraud
- To measure how our advertising performs
- To comply with legal obligations
We process personal data where it is necessary to provide the services you request, where we have a legitimate interest (such as keeping the Platform safe and measuring our advertising), where you have given consent (such as marketing messages), or where the law requires it.
3. Interactions & Content
All interactions on Finsta — messages, calls, and content exchanges — are private between the involved parties, subject to the safety screening described below. We do not share your conversations or call content with third parties for their own purposes, and we disclose them only where required by law or to investigate violations of our Terms & Conditions.
To keep the Platform safe and lawful, content you upload or send — including media shared in private chats — is screened by automated third-party content-safety tools, and flagged items may be reviewed by Finsta's compliance function, to detect material prohibited by our Prohibited Content & Activity List. We retain the results of that screening, such as category flags and timestamps, not an additional copy of your messages. Message content itself is stored and delivered by the messaging infrastructure providers that operate chat on our behalf.
3.1 Live sessions are not recorded
We do not record live one-to-one video or voice sessions. The audio and video of a session are not recorded, stored or retained by us, and we keep no copy of what was said, shown or done during a session. There is no session recording for us to review, disclose, or produce, and none is created for moderation purposes.
What we do collect about a session is automated metadata: that a session took place, its start and end time and duration, the participating accounts, and technical connection information such as call quality and error codes. We use this metadata for billing, customer support, safety and fraud prevention, and we retain it with your other account records.
Recording a session yourself, by any means, is prohibited by our Prohibited Content & Activity List. If another user tells us they believe a session was recorded, we investigate it as a complaint under our Complaints & Content Removal Policy.
4. Payment Information
Payment processing is handled by secure third-party payment providers. We do not store your full card details. We retain transaction records as required for financial and legal compliance.
5. Data Sharing
We do not sell your personal information for money, and we have not done so in the last twelve months. We do not disclose your messages, your session metadata, the content you view, upload or purchase, your verification data or your biometric data to anyone for advertising purposes, and we do not make any of it available to data brokers.
We share information with trusted service providers who assist in operating our platform — such as hosting, messaging delivery, content screening, and payment and payout processing — subject to strict confidentiality obligations and to written terms limiting them to processing the data on our instructions. We also share the limited advertising measurement data described in Section 6. We may disclose information when required by law or legal process, and to protect the safety of users or the public.
The only data we make available that a U.S. state privacy law may treat as a "sale" or as "sharing" for cross-context behavioural advertising is the limited advertising-measurement data described in Section 6: advertising and click identifiers, cookie and pixel identifiers, your IP address, basic device or browser information, and the fact that an install, signup or subscription happened. No money is paid to us for it. You can opt out of it at any time — see Section 9.
6. Advertising & Analytics
Our advertising is directed to the United States. We buy advertising aimed at audiences in the United States, and the measurement described in this Section relates to that advertising. We do not direct advertising for Finsta to audiences outside the United States.
We advertise Finsta on third-party platforms, including social media platforms, search engines, and advertising networks. To understand which campaigns bring people to Finsta, we use measurement tools those platforms provide, such as software development kits in our apps and similar technologies on our websites.
What we send: a small set of events, such as an app install, an account signup, or a subscription, together with the technical identifiers those tools attach automatically — advertising and click identifiers, cookie or pixel identifiers, your IP address, and basic device or browser information. We do not send your name, username, email address, phone number, payment details, verification documents, or anything about your messages, calls, or the content you view, upload, or purchase.
What we receive: which campaign or advertisement a signup came from, so we can measure how our advertising performs. The advertising platform processes the data it receives under its own privacy policy and may use it for its own purposes, including improving how it delivers advertising.
You can limit this by declining non-essential cookies in the cookie choice shown on our websites, resetting or disabling your device advertising identifier in your device settings, adjusting personalised advertising controls in the advertising platform's own settings, or emailing admin@solutionize.tech.
7. Data Retention and Deletion
We retain your personal data for as long as your account is active or as needed to provide services. When you close your account, or ask us to delete your data, we delete or de-identify your personal data — except for the records listed below, which the law requires us to keep, or which we must preserve as evidence.
7.1 Records that cannot be deleted on request
Some records must be kept for a legally mandated period and cannot be deleted at your request, even if you close your account. Closing your account does not shorten these periods. They are:
Creator age and identity verification records — the verification result, verified date of birth, verification reference and date — together with the creator's attestation regarding persons depicted and any documentation the creator has produced to us
- How long we keep it: Seven (7) years from the date the content is last published or last transferred, whichever is later
- Why we keep it: Retention of verification and attestation records to evidence compliance with our Standards, to respond to complaints and legal process, and to meet card-network requirements
Reports of apparent child sexual abuse material, and the associated content, account records and connection logs
- How long we keep it: Preserved for at least one (1) year from the report, extended where a lawful preservation request, legal process or an ongoing investigation requires it
- Why we keep it: Reporting and preservation duties under 18 U.S.C. § 2258A
Reports of non-consensual intimate imagery — the reported material, the report itself, and the associated account and log records
- How long we keep it: Retained for as long as needed to investigate and action the report, decide any appeal, and respond to law enforcement or legal process, and in any event for the applicable limitation period
- Why we keep it: Preservation of evidence, our notice-and-removal duties for non-consensual intimate imagery, and the establishment or defence of legal claims
Transaction, payment, payout, refund, chargeback, invoice and tax records
- How long we keep it: Seven (7) years
- Why we keep it: Tax, accounting, anti-money-laundering, and card-network and payment-provider requirements
Records of complaints, appeals, moderation decisions and enforcement action
- How long we keep it: Retained for the applicable limitation period, and for as long as needed for audit by our payment partners
- Why we keep it: Audit obligations and the establishment or defence of legal claims
A limited fraud- and safety-suppression record where an account has been terminated for a serious breach — enough identifiers to recognise the account, and a record of the reason
- How long we keep it: Retained for as long as needed to keep the person off the Platform
- Why we keep it: Fraud prevention, protecting other users, and enforcing our Terms
Marketing opt-out and unsubscribe records
- How long we keep it: Retained indefinitely
- Why we keep it: So that we can continue to honour your opt-out
Where we keep a record under this Section, we restrict it to the purpose that requires it: it is not used for marketing, personalisation, advertising or advertising measurement, and access is limited to the people who need it. We delete or de-identify it once the period expires. When we respond to a deletion request, we will tell you which of these categories, if any, applied and why.
8. Where Your Data Is Processed
Platform content — the media you upload and the media exchanged in Interactions — is hosted with cloud infrastructure providers located in the European Union. Because Finsta is operated by a U.S. company, personal data is also accessed from and processed in the United States.
Platform content is not hosted on infrastructure located in, and our service providers are not permitted to process Platform content in, any jurisdiction in which the Platform's content or services are unlawful. Where a provider cannot meet that restriction, we do not use it for Platform content. Other personal data — account, billing, support and message-delivery data — may be processed by our service providers in the countries where they operate, and each provider is engaged on written terms limiting it to processing that data on our instructions and for the purposes described in this Policy.
Where data protection law requires safeguards for a transfer, we rely on appropriate mechanisms such as standard contractual clauses in our agreements with providers. If you would like to know the countries in which a particular category of data is processed, email admin@solutionize.tech and we will tell you.
9. Your Rights and Choices
Depending on where you live, you have some or all of the rights below. Residents of U.S. states with comprehensive privacy laws — including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and others as those laws come into force — have the rights marked, and we apply them to everyone in the United States rather than asking which state you are in.
- Know and access. Ask what personal information we hold about you, the categories we collect, where it came from, why we collect it, who we disclose it to, and get a copy of it.
- Correct. Ask us to correct personal information that is inaccurate.
- Delete. Ask us to delete personal information we hold about you. This right is subject to the records listed in Section 7.1, which the law requires us to keep and which we cannot delete on request.
- Portability. Get a copy of the information you gave us in a portable, machine-readable format.
- Opt out of sale, sharing and targeted advertising. Tell us to stop making the advertising-measurement data described in Section 6 available to advertising platforms. We do not sell personal information for money, and we do not use your content, messages or verification data for advertising at all.
- Limit the use of sensitive personal information. We already use sensitive personal information only for the purposes described in Section 1.1 — providing the service, safety and fraud prevention, and legal compliance — and never for advertising or profiling.
- Automated screening and your right to object. Automated screening can result in content being restricted or removed and, for serious or repeated breaches, in an account being suspended or closed. You can challenge any such decision under our Complaints & Content Removal Policy, and you may ask for the decision to be reviewed by a person.
- Non-discrimination. We will not deny you service, charge you a different price, or give you a lower quality of service because you exercised a privacy right.
- Withdraw consent. Where we rely on your consent — marketing messages, biometric verification (Section 13), non-essential cookies — you can withdraw it at any time, without affecting processing that already happened.
- Object, restrict and complain. If you are outside the United States, you may also have the right to object to or restrict certain processing, and the right to lodge a complaint with your local data-protection authority, in addition to contacting us.
9.1 How to make a privacy request
Email admin@solutionize.tech with "Privacy Request" in the subject line, or use the in-app support chat, or write to Solutionize Tech, LLC, 1111B South Governors Avenue, Dover, DE 19904, USA. Tell us which right you want to exercise.
We will ask for enough information to match your request to your account — normally that you can access the email address or phone number on the account. We use what you give us only to handle the request, and we do not ask you to complete identity verification, or to send us an identity document, just to make a privacy request. An authorised agent may make a request for you if you give them written permission and we can confirm it with you.
We respond within forty-five (45) days. If we need longer we will tell you within that period, explain why, and take no more than a further forty-five (45) days.
9.2 Appeals
If we refuse your request, we will tell you why in writing. You may appeal that decision within sixty (60) days by replying to our response, or by emailing admin@solutionize.tech with "Privacy Appeal" in the subject line. A different person from the one who decided the request will review the appeal, and we will give you a written decision with our reasons within forty-five (45) days. If we refuse your appeal, you may complain to your state attorney general, or, outside the United States, to your data-protection authority.
9.3 Do Not Track and Global Privacy Control
There is no common industry standard for "Do Not Track" browser signals, and our websites do not respond to them. Our websites do not currently detect a Global Privacy Control (GPC) signal automatically. Until they do, please use one of the opt-out routes above or in Section 6 — declining non-essential cookies in the cookie choice shown on our websites, resetting or disabling your device advertising identifier, or emailing us — and we will apply the opt-out to your account and to the advertising measurement described in Section 6.
10. Mobile Information and SMS
We collect your mobile phone number when you provide it at signup. We use your phone number for account verification, to protect the security of your account, and to send you account notifications such as payout confirmations and security alerts.
Only when you give separate opt-in consent, we also use your phone number to send you marketing text messages, such as creator activity alerts and credit offers. You can opt out of marketing texts at any time by replying STOP to any marketing message or by switching off marketing SMS in your app Settings.
No mobile information will be shared with third parties or affiliates for their own marketing or promotional purposes; we share mobile numbers only with service providers who deliver messages or operate our messaging campaigns on our behalf. Text messaging originator opt-in data and consent will not be sold or shared with any third party.
For full details of the messaging program, including message frequency and support contacts, see our SMS & Messaging Terms.
11. Marketing Emails
We collect your email address when you provide it at signup or when it is supplied by a third-party sign-in provider you use to sign in. We use it for account and transactional messages — receipts, payout confirmations, security alerts and service notices — which are not marketing and are sent for as long as you hold an account.
We send marketing emails, such as alerts about creators you follow, credit offers and product news, only where we have a lawful basis to do so. Where the law requires your consent, we ask for it separately and send marketing emails only if you give it; consent is never a condition of using Finsta, and declining changes nothing about your account.
You can withdraw consent or opt out at any time using the unsubscribe link in any marketing email, or by switching off marketing emails in your app Settings. We do not sell your email address, and we do not share it with third parties for their own marketing.
12. Identity & Age Verification
Creators complete identity and age verification before any funds are released to them. Verification is handled by a third-party provider as part of its onboarding, under that provider’s own terms, privacy policy and regulatory obligations. It checks identity, date of birth and ownership of the receiving account against a government-issued identity document, and may include a facial scan or other checks; what is collected is determined by the provider. We retain the right to ask you to send documents to us directly through support; those are held only for as long as needed to resolve the matter. Verification records are retained as set out in Section 7.1.
Every consumer must be at least 18 years of age and confirms this when accepting our Terms & Conditions at sign-up. Verification requirements are set out in our Age & Identity Verification Policy.
13. Biometric Data
As part of the verification described in Section 12, the third-party provider may collect biometric data — for example a facial scan, and a biometric identifier derived from it, used to match you to your identity document. What is collected is determined by that provider, under its own terms and privacy policy, and any notice or consent required for it is given by the provider at the time it is taken. If you do not wish to provide it, you should read that provider’s notice before completing verification; without completing verification you cannot receive payouts.
14. Children's Data
Finsta is strictly for adults. You must be at least 18 years old to hold an account, we do not direct the Platform or any of our advertising to children, and we do not knowingly collect personal information from anyone under 18. We do not knowingly sell or share the personal information of anyone under 16, and we do not process the personal information of a known minor for targeted advertising or profiling.
If we learn that an account holder is under 18, we close the account and delete the personal information associated with it, except any record we are legally required to retain or preserve under Section 7.1, or to report to the National Center for Missing and Exploited Children or to law enforcement.
If you believe a person under 18 is using the Platform, or that we hold information about a child, contact admin@solutionize.tech immediately and we will act on it. A parent or guardian may contact us at the same address to ask what we hold and to have it deleted.
15. Security
We implement industry-standard security measures including encryption to protect your personal information. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
16. Contact Us
If you have any questions about this Privacy Policy, please contact us at admin@solutionize.tech.
Privacy requests (access, correction, deletion, opt-out, appeals) — email admin@solutionize.tech with "Privacy Request" or "Privacy Appeal" in the subject line, use the in-app support chat, or write to us:
Solutionize Tech, LLC · 1111B South Governors Avenue, Dover, DE 19904, USA · admin@solutionize.tech