Privacy Policy
Last Updated: February 8, 2026
1. Introduction
finroam GmbH ("finroam," "we," "us") takes your privacy seriously. We are a company incorporated in Switzerland(Canton of Zug).
This Privacy Policy explains how we collect, use, and protect your personal data when you use the finroam mobile application (the "App") and our website (www.finroam.com). By using our Service, you agree to the collection and use of information in accordance with this policy.
2. Who is Responsible? (Data Controller)
For the purposes of the Swiss Federal Act on Data Protection (FADP) and the EU General Data Protection Regulation (GDPR), the "Data Controller" responsible for your personal data is:
finroam GmbH
Sinserstrasse 67
6330 Cham
Switzerland
3. Information We Collect
We collect the minimal amount of data necessary to provide you with a great learning experience.
A. Information You Give Us
Account Data: When you sign up, we collect your email address, name, and username.
If you use "Sign in with Apple" or "Google," we receive an authentication token, not your password.
If you sign up with an email and password, your password is encrypted and hashed securely by our authentication provider; we do not have access to or store your actual password.
Profile Data: We store your learning progress, courses completed, and credentials earned.
Communications: If you contact support, we collect your name, email, and the content of your message.
B. Information Collected Automatically
Usage Data: We track which stories you play, your quiz scores, and how long you spend in the App.
Device Information: We collect technical details like your device model, operating system (iOS/Android), and app version to help us fix bugs.
Analytics: We use third-party analytics tools (like Google Analytics) and standard App Store analytics to understand aggregate user behavior.
4. How We Use Your Data
We process your data for the following specific purposes:
To Provide the Service: Logging you in, saving your progress, and issuing credentials. (Legal Basis: Performance of Contract)
To Improve finroam: Analyzing crash reports and usage patterns to fix bugs and improve our stories. (Legal Basis: Legitimate Interest)
To Send Updates: Sending you transactional emails (password resets) or our newsletter (if you opted in). (Legal Basis: Consent)
To Ensure Security: Preventing fraud and unauthorized access. (Legal Basis: Legitimate Interest)
Important: We do not show third-party advertisements in our App, nor do we sell your personal data to advertisers.
5. Public Credentials & Social Sharing
A unique feature of finroam is the ability to earn and share credentials.
Public Access: If you choose to share a credential via a public link, you acknowledge that specific details—including your Full Name, the Credential Name, and the Date of Issue—will be visible to anyone with the link.
Indexing: While we do not actively ask search engines to index these pages, we cannot control third-party platforms.
Revocation: You may revoke access to a credential at any time in your App settings. However, we are not responsible for screenshots or cached copies taken by third parties while the link was active.
6. How We Share Your Data
We do not sell your data. We only share it with trusted service providers ("Processors") that help us run our App. We may share data with the following categories of providers:
Cloud Hosting & Infrastructure: To store your account data and progress securely. (e.g., AWS, located in Switzerland/EU).
Analytics Providers: To understand how our App is used. (e.g., Google Analytics).
Email & Marketing Services: To send you newsletters and support emails. (e.g., Mailchimp).
App Stores & Payment Processors: To handle subscriptions and billing. (e.g., Apple and Google).
Note: For payments, Apple and Google act as the "Merchant of Record." finroam does not receive or store your credit card details.
7. International Data Transfers
While our primary database is located in Switzerland (via AWS Zurich), some of our tools (like marketing or analytics providers) may process data in the United States.
We ensure these transfers are protected under Swiss and EU law by relying on recognized legal frameworks (such as the Swiss-U.S. Data Privacy Framework) and standard contractual clauses (SCCs) where applicable.
8. Data Retention
We retain your personal data only for as long as your account is active or as needed to provide you with the Service.
If you delete your account: Your personal data (name, email, progress) is deleted from our active database immediately.
Backups: Residual copies may remain in our encrypted backups for up to 30 days before being permanently overwritten.
9. Your Rights (Swiss & GDPR)
You have the following rights regarding your data:
Right to Access: You can ask for a copy of the data we hold about you.
Right to Rectification: You can update your profile information in the App settings.
Right to Deletion: You can delete your account and all associated data directly within the App settings at any time.
Right to Withdraw Consent: You can unsubscribe from our newsletter by clicking the "Unsubscribe" link in the email.