How Finvorais handles personal data — what is collected, who else sees it, and what you can ask us to do about it.
Last updated
Several sections below describe services only if they are switched on. As of the date at the top of this page, this site runs no advertising, no analytics and no third-party newsletter provider. Those sections are kept because the position can change, and this page will be updated on the day it does — but nothing in them applies today.
The site is Finvorais, at https://finvorais.com. The organisation responsible for deciding how personal data is handled here (the “data controller”, in the language of several privacy laws) is Penugonda Kalyani, an individual publisher based in India. This site is not operated by a registered company. No postal address is published; write to the address below and one will be provided if you need it for a legal or regulatory purpose.
Privacy questions go to hello@finvorais.com, which is read by the person who runs the site.
No Data Protection Officer has been appointed, and no EU or UK representative. Those obligations attach to organisations carrying out large-scale or systematic monitoring; this is a small publication that runs no advertising, no analytics and no tracking, and holds nothing beyond newsletter addresses and ordinary email correspondence. If that changes, so does this paragraph.
Requests to this site are logged by the hosting platform, as they are on essentially every website. A log entry typically contains the IP address the request came from, the time, the URL requested, the response status, the referring page and the browser’s user-agent string. These logs exist to keep the site running and to investigate abuse and outages, not to build a profile of you.
Analytics are disabled by default in this deployment’s configuration, and no analytics script is loaded outside a production build. Where the operator has enabled them, one or more of Google Analytics, Microsoft Clarity, Plausible or Umami may run. What each collects differs — page URLs, referrer, approximate location derived from IP, device and browser type, and in Clarity’s case a recording of interactions such as scrolling, clicks and mouse movement on the page. Analytics only run in production builds, and the configuration has a “respect Do Not Track” option that is on by default; see the cookie policy for what that means in practice.
If you subscribe to the newsletter, you give us an email address. That address is used to send the newsletter and nothing else — it is not sold, rented, or used to build advertising audiences. Every email includes an unsubscribe link, and unsubscribing takes effect immediately. Depending on the configured provider, the address is stored with a third-party email service (see third parties below).
If you email us, we keep the message and your address for as long as needed to deal with it, and afterwards as a record of the correspondence.
There are no user accounts, no logins and no passwords. There is no comment system. Nothing on this site asks for a payment card, a phone number, a date of birth or a government identifier, and you should be suspicious of any page here that appears to.
The site itself sets no tracking cookies. The light/dark theme preference is stored in your browser’s localStorage under the key theme — that is local to your device and is never sent to the server. Third-party services, where enabled, do set cookies. The full breakdown, including how to block or delete them, is in the cookie policy.
Each of the following applies only if the operator has enabled that service.
These providers act under their own privacy policies, which govern what they do with the data they receive. We do not sell personal data and we do not share it with anyone beyond the services listed here and anyone we are legally obliged to give it to.
Where a law such as the GDPR requires a legal basis, these are the ones relied on:
Depending on where you live, you may have some or all of the following rights. We will act on a request from anyone, regardless of jurisdiction, where it is technically possible to do so.
Readers in the EU and UK will recognise these as the rights in Articles 15 to 21 of the GDPR, and also have the right to complain to their national supervisory authority.
California. If you are a California resident, you may request disclosure of the categories of personal information collected and the purposes for it, request deletion, and opt out of any “sale” or “sharing” of personal information for cross-context behavioural advertising. Serving personalised ads may count as “sharing” under the CCPA/CPRA. To opt out, either disable personalised ads at adssettings.google.com, enable Global Privacy Control in your browser, or email us. We will not treat you differently for exercising these rights.
India. Under the Digital Personal Data Protection Act, 2023, you may access and correct your personal data, request its erasure, nominate someone to exercise your rights on your behalf, and raise a grievance. Grievances go to Penugonda Kalyani, who is the Grievance Officer for the purposes of the Act, at hello@finvorais.com. Because this site is run by one person, that is the same address as everything else on this page — which is the point: there is no queue to be lost in.
To exercise anything above, email hello@finvorais.com with enough detail to identify the data in question. We may need to ask a question or two to confirm we are talking to the right person. We aim to respond within 30 days.
This site is written for adults making their own financial decisions and is not directed at children. We do not knowingly collect personal data from anyone under 13, or under 16 where local law sets that higher age. If you believe a child has given us personal data, email us and we will delete it.
The hosting, analytics and advertising services used here operate globally, so data may be processed in countries other than the one you are in — in practice, often the United States. Where the law requires a transfer mechanism, the providers rely on their own (typically Standard Contractual Clauses or an adequacy decision). The primary jurisdiction for this site is India, where the publisher is based. Note that much of what this site writes about is United States law — that is the subject matter, not the law governing this site or your data.
The site is served over HTTPS and there is no user account system to compromise. That said, no method of transmission or storage is completely secure, and we cannot guarantee the security of data held by third-party providers.
When this policy changes, the “last updated” date at the top of the page changes with it. Material changes — a new category of data, a new third party, a new purpose — will be flagged on the site, and where the law requires fresh consent, we will ask for it rather than assume it. The current version is always the one on this page.
Privacy questions, requests and complaints: hello@finvorais.com. General enquiries are handled through the contact page.