Fin-Delivery

Fin Delivery

Privacy Notice

What we collect about you as a customer, why, and how long we keep it.

Effective 27 August 2026 · Applies to the Fin Delivery app and website

Suomi · English · Courier app notice

This notice explains in plain language what data we handle when you order food through Fin Delivery. If anything is unclear, ask us — we will answer.

In short

We use your location only while the app is open: to set your delivery address, to show nearby restaurants, and to let you follow your delivery on a map. The app cannot collect location in the background — that permission is blocked in the app package itself, not merely promised. We do not sell your data.

1. Controller

Fin Delivery Oy
Business ID 3584658-3
Nöykkiönlaaksontie 42, 02330 Espoo, Finland

Privacy matters: info@fin-delivery.com

We have not appointed a Data Protection Officer. If we appoint one, we will update this section.

The controller is Fin Delivery Oy. We process the data described in this policy across all of our own services. Our platform may offer food, other goods and services from various sellers and providers, and that offering may expand. The purposes, legal bases and your rights are the same whatever you order from the platform, and we do not ask for separate consent for our range to grow.

If we ever offer a service that would involve special categories of personal data — health data, for example — we will say so separately and ask for whatever consent is required. Otherwise this policy covers the whole platform.

2. What this notice covers

This notice applies to the customer app and our website. If you work for us as a courier, the courier app privacy notice applies instead — they are separate records and we do not combine them.

This policy covers everything offered on our platform, whether food, another product or a service.

It does not cover what restaurants or the payment provider do with data as controllers in their own right.

3. What we collect and why

CategoryExamplesWhy
Account detailsName, email, phone number, language preference, password in protected formCreating your account, signing in, contacting you
AddressesDelivery addresses you save, door codes, delivery instructionsGetting the delivery to your door
Order dataItems ordered, restaurant, time, price, delivery statusFulfilling the order, customer support, accounting
Payment dataTransaction reference, payment method type, amountProcessing payment and refunds
Location dataDevice location while the app is open, delivery coordinates of an orderSee section 4
Device dataDevice model, OS version, app version, notification tokenDiagnosing faults, delivering notifications
Sign-up technical dataIP address and browser identifier at the moment the account is createdPreventing abuse and fake accounts
Usage data in the appWhat was shown to you and where in the list, what you opened, what you added to the cart, which screen you were on, session identifier and timeSee section 9 — ordering content and developing recommendations
ContactsSupport messages and reviewsProviding support, service quality
Marketing refusalWhether you have refused marketing emailsHonouring the refusal
Data obtained from external sourcesMostly area-level statistics; we tell you separately about any data concerning you personallyTargeting content and communications, see section 9.3
How you heard about usVoluntary answer given at registrationPlanning our marketing
Campaign identifierWhich campaign or link brought you to the serviceMarketing measurement, see section 8.1

We do not collect special categories of personal data (health, beliefs or similar) and we do not ask for them. We do not store your card number — the payment provider handles it.

4. Location data

4.1 What location is used for

4.2 What we do not do

The app does not collect your location in the background. This is not merely a promise: the background location permission is blocked in the app package, so the operating system does not grant the app that right at all, even if someone asked for it.

We therefore do not track your movements between orders, do not keep a location history, and do not build a movement profile of you.

4.3 What is retained from location

We do not keep a continuous location trail. Only two things are retained:

You can withdraw location permission at any time in your device settings. The app works without it; you will simply type the address yourself.

4.4 Address search in supported areas

In Finland, address search is available in supported areas, currently the Finnish capital region. The request passes through Fin Delivery’s server to the Digitransit address-search service. To provide address suggestions, Digitransit receives the search text you enter and, where used, the coordinates of the active delivery location. For reverse address lookup, location coordinates are sent. The app does not contact Digitransit directly, and we do not send your name, email address, phone number, order history or Fin Delivery customer identifier to it. If you select and save an address, we retain the selected address as described in sections 3, 4.3 and 10. Address search is not available in Estonia; there the app uses the device location or a previously saved address.

5. Legal bases for processing

ProcessingLegal basis (GDPR)
Maintaining your account, delivering orders, payments6(1)(b) — performance of a contract
Accounting and tax records6(1)(c) — legal obligation
Preventing abuse and keeping the service safe6(1)(f) — legitimate interest
Storing the campaign identifier and measuring marketing within our own service6(1)(f) — legitimate interest
Targeted benefits, discounts and campaign prices6(1)(f) — legitimate interest
Automated fraud prevention measures, such as temporarily blocking an account6(1)(f) — legitimate interest; you can always have the decision reviewed by a person by contacting us
Using location while the app is open6(1)(b), together with the device location permission
Ordering content and developing recommendations6(1)(f) — legitimate interest
Service messages and push notifications relating to your order6(1)(b) — performance of the contract
Marketing emails6(1)(a) — consent, or an existing customer relationship under the Finnish Act on Electronic Communications Services 917/2014
Personalising the content of marketing emails6(1)(f) — legitimate interest
Using data obtained from external sources to target content and communications6(1)(f) — legitimate interest

6. Who we share data with

"Seller" means a restaurant or any other provider of goods or services on our platform.

We do not sell personal data. If we measure advertising results together with advertising platforms in a way that would require disclosing personal data, we will ask for your consent separately before we begin.

7. Transfers outside the EU/EEA

Our database and servers are located inside the EU, in Amazon Web Services' Stockholm region (eu-north-1). No transfer outside the EU takes place for your orders, addresses or account details.

Some of the services we use are US companies: Stripe (payments), Expo (push notification relay), Apple and Google (push notification delivery), Google (error monitoring and advertising measurement), AppsFlyer (advertising measurement) and Meta (advertising measurement). For these, any transfer relies either on a European Commission adequacy decision (EU–US Data Privacy Framework) or on the Commission's Standard Contractual Clauses.

8. Analytics, advertising and consent

8.1 How we know how you found us

When you come to the service from an advert or campaign, the link carries an identifier of our own. That identifier travels with you as far as registration and is stored with your account — for example, the fact that you arrived from a particular campaign. This is how we know which campaigns work and where it is worth spending.

This does not use your phone's advertising identifier or any information stored on your device. The identifier comes from the link straight to our server. We do not follow you in other apps or on other websites. The processing relies on legitimate interest (Article 6(1)(f)) and therefore needs no separate consent.

We may also ask at registration where you heard about us. Answering is voluntary.

We also use tools that measure advertising results and how the service is used.

On our website Google Analytics runs from the moment the page opens, but by default in a mode where no identifiers or cookies are stored on your device. Only after your consent may it store them. The Meta pixel, by contrast, does not load at all before you consent.

In our apps we introduce the equivalent tools — Firebase and AppsFlyer — on the basis of your consent, and do not start them before it. Measurement results may be passed to advertising platforms such as Google and Meta. The set of tools may change.

You can withdraw consent at any time by writing to info@fin-delivery.com, and we are adding withdrawal to the app settings as well. Withdrawing does not affect how the service works, and no feature is conditional on consent.

8.2 Service messages and push notifications

We send you messages that belong to your order: the order confirmation, notice that the restaurant has accepted it, the courier's journey and arrival, and the receipt. These are delivered by email and push notification. They form part of performing the contract (Article 6(1)(b)), not marketing.

You can turn push notifications off in your phone's operating system settings at any time. You will then not receive delivery progress notifications and will follow the order in the app instead. Emails relating to your order are still sent, because they form part of the contract.

8.3 Marketing by email

We send marketing by email. Push notifications concern your order. If we introduce other channels for marketing, you can refuse it there just as easily and free of charge, and we will tell you how in the message itself.

Marketing emails — offers, new restaurants, campaigns and reminders — rely either on

Every marketing email carries an unsubscribe link. One click is enough, it is free, and we do not ask for a reason. You can also write to info@fin-delivery.com at any time. A refusal takes effect without delay and is permanent.

Service messages relating to your order continue after a refusal, so that your orders work.

8.4 What marketing emails contain

The content of marketing emails is personalised: we choose which products, restaurants and offers to show using the same logic as the order of the home screen — your order history, your usage data, your delivery area and the external sources described in section 9.3.

These are two separate things and we keep them separate: permission to send a message rests on your consent or on the customer relationship, and the choice of what the message contains rests on legitimate interest. You can refuse each separately. The unsubscribe link stops the messages entirely. Objecting under section 9.5 stops the personalisation, so you still receive messages but they are generic and the same for everyone.

9. Recommendations and the order of content

9.1 What affects what you see

We order the content of the app to be relevant to you. What affects it:

Some placements may be paid. Where a seller has paid for visibility, it is clearly marked, for example as "Ad" or "Sponsored". Paid visibility does not change the price you pay and never surfaces a seller who does not deliver to your address. We state this openly because consumer law requires it.

The most visible example is the "Order again" row, where we show products you have ordered before. We use the same information to decide the order in which restaurants and products appear. We decide ourselves whether to weight general popularity or your own history, and we develop this continuously.

9.2 Why we collect usage data

We collect information about what is shown to you and what you open so that we can order the content better. We use this both now and to develop recommendations going forward.

9.3 External data sources

We order content primarily on the basis of our own data: what you order, what you open and where we deliver. We may also supplement this with sources outside our own service. These include, for example, public and open statistical datasets, public registers maintained by authorities to the extent the law permits their use for this purpose, and datasets produced by commercial data providers.

The purpose is one and the same: to understand better which products and restaurants suit you, and to order both the content of the app and our communications accordingly.

Most of this is area-level statistical data that does not concern you as a person — it describes, for example, a postal code area, not an individual resident of it. If we obtain data from an external source that concerns you personally, we will tell you the source, the categories of data and the purpose in accordance with Article 14 GDPR, within one month at the latest or at the latest when we first communicate with you. The right to object in section 9.5 applies to such data as well.

We do not obtain or infer special category data. Data concerning health, belief, ethnic origin, political opinion or trade union membership is not collected from any source and is not derived from any dataset.

9.4 What we do not do

9.5 Legal basis

This processing relies on legitimate interest (GDPR Article 6(1)(f)). Our interest is to provide a service in which you find what you want quickly. The processing is ordinary and to be expected in a food ordering service, it does not concern sensitive data, and it has no legal effect on you — we order a list, we do not make decisions about you.

We order content by profiling, but this is not automated decision-making within the meaning of Article 22 GDPR.

This is on by default from your first order onwards. We do not ask for separate consent, because the processing relies on legitimate interest — but you can object at any time and we will stop it for you.

Your right to object

You can object at any time to your usage data being collected and used to order content. Send a message to info@fin-delivery.com. We will stop it for you and will not ask why.

Once you have objected, the home screen is ordered purely by distance and general popularity. The service otherwise works exactly as normal.

Email is the channel for this. We handle the request without delay and confirm it to you.

10. Retention periods

DataRetention
Account and basic detailsUntil you delete your account, see section 11
Saved addressesUntil you delete them or delete your account
Order history and delivery coordinatesAs part of accounting records, see below
Accounting records and vouchersUnder the Finnish Accounting Act (1336/1997): vouchers 6 years, accounting books and financial statements 10 years
Usage data in the app24 months, after which only in aggregated form without identifiers
Support messages2 years
Sign-up IP and browser identifier12 months
Campaign identifierFor as long as the account exists
Marketing refusalsIndefinitely — a refusal must be retained in order to be honoured

We cannot delete data that accounting law requires us to keep before that period expires. Such records are pseudonymised when your account is deleted — they no longer connect to you by name.

11. Deleting your account

You can request deletion of your account by sending a message to info@fin-delivery.com. Full instructions, and a complete list of what is deleted and what is retained, are on the Account deletion page.

Once requested, the account is locked immediately, every active session is ended, and you can no longer sign in or place orders. Personal data — profile, contact details, saved addresses, notification tokens — is deleted after 30 days.

You can cancel the request within that period by contacting info@fin-delivery.com. You cannot cancel by signing back in, because the account is locked from the moment the request is received. Once deletion has run, it cannot be undone.

After deletion, what remains is only the vouchers and payment transactions that accounting law requires, with identifying details replaced by a pseudonym.

12. Your rights

We respond to requests within one month. If a request is unusually broad, we will tell you about the extension.

13. Age limit

The service is intended for people aged 18 and over. We do not knowingly collect data from anyone younger. If we discover that an account was created by someone below the age limit, we delete it.

If you are a guardian and suspect your child has created an account, contact info@fin-delivery.com.

14. Security

Connections between the app and our servers are encrypted. Passwords are never stored in plain text. Access to customer data is limited to people who need it for their work.

If a data breach occurs that is likely to result in a high risk to your rights, we will notify you and the supervisory authority within the time the law requires.

15. Changes to this notice

If we change this notice materially, we will tell you in the app before the change takes effect. Previous versions are available on request.

16. Contact

Fin Delivery Oy · Business ID 3584658-3
Nöykkiönlaaksontie 42, 02330 Espoo, Finland
info@fin-delivery.com