Fingermark’s Privacy Policy
Last Updated: September 2026
Welcome to our Privacy Policy. This policy is applicable to all websites we own and operate, as well as the products and services we provide, including but not limited to our kiosks, digital menu boards, Eyecue, Supersonic, and any other products or services we may offer.
When we refer to ‘Fingermark’, ‘we’ (or ‘our’ or ‘us’), that means Fingermark Limited and all its associated companies. At Fingermark we are committed to safeguarding your privacy and the security of your personal data. This policy aims to comply with the privacy and data protection laws applicable in the jurisdictions where we operate and process personal data including the regulatory frameworks of New Zealand, Australia, the United States, and Canada. Our commitment extends to adhering to internationally recognised standards for data protection and security. You can find detailed contact information for all Fingermark offices on the Contact page of our website.
As industry leaders, Fingermark is at the forefront of the QSR industry’s technological transformation. We optimize and empower QSRs by leveraging our world-leading technology solutions to increase speed and efficiency throughout their operations. As the QSR industry evolves, so do we. Our dedication to continuous innovation is evident in our focus on advanced AI and computer vision technology solutions that are applicable to QSRs globally.
Our Data Protection Principles
Our approach to data protection is centred around four key principles that guide our handling of personal data:
Transparency: We process personal data with openness, honesty, and transparency.
Enablement: We use personal data to create connections, enhance productivity, and foster growth.
Security: We prioritize industry-leading security measures to protect the personal data entrusted to us.
Stewardship: We acknowledge the responsibility that comes with processing personal data.
Fairness: We collect information using fair and lawful means, avoiding practices that are unreasonably intrusive.
Children’s Privacy
Our websites and services are not intended for, nor do we knowingly collect personal data from, children under the age of 13 (or other applicable age of consent in relevant jurisdictions). If we become aware that we have inadvertently collected personal data from a child without verifiable parental consent, we will take reasonable steps to delete it promptly. If you believe we might have any information from or about a child, please contact us immediately.
How We Collect Your Data
When you visit our websites or use our services, we collect personal data through the following methods:
Information You Provide Directly: We may ask for your personal data when you sign up for our newsletter, request a product or service demo, apply for a job, join online events or webinars, contact us with inquiries, or request support. You have the choice to withhold personal data, but this might limit your access to certain parts of our websites or services.
Information We Collect Automatically: We gather information like your IP address and device type automatically when you use our websites or services. We also track your navigation through our platforms, such as the pages you visit and the links you click, to improve your user experience.
Information from Third Parties: While most of the information we collect is directly from you, we may also collect personal data from publicly available sources or trusted third-party partners. This information complements and enhances our services, helping us provide better personalization and improvements. These partners may include, for example, marketing and advertising networks, data enrichment providers, or publicly available databases.
When we collect personal information directly from you, we will ensure you are aware of why we are collecting it, who it will be shared with, and the consequences of not providing it. We will also clarify whether providing the information is mandatory or voluntary, the consequences of not providing it, and your rights to access and request correction of that information.
We do not assign unique identifiers to individuals for the purpose of cross-platform tracking or identification. In the limited circumstances where we may assign a unique identifier (such as an internal session ID or customer reference number) while providing services to our customers, it is used strictly for operational necessity—such as managing a specific product interaction or service session—and is not used to identify the individual across separate, unrelated systems.
We only process your personal data when:
It is necessary to fulfill a contract with you.
We have legitimate interests that are not overridden by your rights. Our legitimate interests include improving our products and services, marketing our offerings, detecting and preventing fraudulent activities, and ensuring the security of our systems.
- We are legally obligated to do so.
- We have obtained your consent.
- Failure to provide personal data may impact our ability to deliver our products and services, and some website features may not be accessible.
For any questions or requests related to your personal data, such as access, correction, amendment, or deletion, please contact us.
How We Use Your Data
We use your personal data primarily to operate our websites and provide the services you have requested. Additionally, we may use your personal data for the following purposes:
Communication: We may provide information you’ve requested, deliver operational updates, and send marketing communications based on your preferences. We may contact you via email, telephone, SMS, or in-product messages.
Support: We assist in resolving technical support issues and other matters related to our websites and services.
Improvement: We analyze your usage patterns to enhance our websites and services, making them more efficient and user-friendly.
Security: We detect and prevent fraudulent or malicious activities and ensure that our platforms are used in compliance with our terms of use.
Marketing: In addition to marketing communications, we may use your data for targeted online advertising through our platforms or third-party websites.
Analysis and Reporting: We create aggregated and anonymized analytics and reports based on the personal data we collect to share with the public or third parties.
We strive to ensure the accuracy, completeness, and integrity of personal data processed in accordance with the purposes outlined in this policy.
Sharing Your Data
There are situations in which we may share your personal data with third parties. We will only disclose your personal data to the following entities:
- Other companies within the Fingermark group.
- Third-party service providers and partners that assist us in providing functionality, supporting service delivery, or marketing our products and services. We ensure all such third parties are subject to robust data processing agreements, including appropriate confidentiality and security clauses, to ensure they maintain similar standards of protection and, where applicable, comply with SOC 2 or equivalent frameworks. We may also utilise subprocessors to assist in providing our services. For a comprehensive list of our subprocessors and their respective data processing activities, please refer to our Trust Centre at https://trust.fingermark.ai/
- Regulators, law enforcement agencies, government authorities, courts, or other parties when required to comply with applicable laws or to establish, exercise, or defend our legal rights. We will notify you of such disclosures when possible and appropriate.
- Actual or potential buyers in connection with a purchase, merger, or acquisition of any part of our business.
- Others with your explicit consent.
We do not sell your personal information, nor do we share it for cross-context behavioral advertising.
International Data Transfers
Your data may be transferred to and processed in countries other than your own, each with varying legal frameworks. When we share personal data with third parties in different countries, we implement safeguards to ensure its protection. We also ensure that any third-party service providers adhere to robust data protection agreements.
For further information, please contact us using the details provided in the “Contact Us” section below.
Security
We place a high priority on the security of your personal data. We have implemented technical and organizational measures to safeguard your data, including access controls, data encryption (in transit and at rest where appropriate), network security controls, regular security assessments, and a defined incident response plan.
Fingermark™ securely stores limited data with our cloud service providers. These service providers were chosen because they are compliant with the following Standards:
- ISO/IEC 27001 – Security Management Controls
- ISO/IEC 27017 – Cloud Specific Controls
- ISO/IEC 27018 – Personal Data Protection
- AICPA System and Organisation Controls (SOC).
For a comprehensive overview of our security measures, compliance certifications, and trust principles, please visit our Trust Centre at the Fingermark Trust Center.
Data Retention
The duration for which we retain your personal data depends on its nature and our ongoing business needs. We retain your data for as long as we maintain a relationship with you and for a period afterward in accordance with our data retention policies. After this period, we ensure data is deleted or anonymized.
Data Breach Notification
Fingermark takes the security of your personal data seriously. In the unlikely event of a data breach, we have established procedures to assess and respond to such incidents promptly. In accordance with applicable laws and regulations in the jurisdictions where we operate, we will notify affected individuals and relevant supervisory authorities without undue delay where a breach is likely to result in a high risk to the rights and freedoms of individuals. Following any confirmed breach, we will conduct a post-incident review to identify and implement improvements to our data security and breach response processes. Our goal is to prevent future occurrences and continually enhance our data protection posture.
Your Rights
You have rights related to your personal data, including the right to:
- The right to erasure (also known as the ‘right to be forgotten’): Request the restriction or deletion of your personal data when it is no longer necessary for the purpose for which it was collected, or if you withdraw consent and no other legal basis for processing exists.
- The right to data portability: Obtain your personal data in a structured, commonly used, and machine-readable format and transmit it to another controller where the processing is based on consent or contract and carried out by automated means
- The right to object to automated decision-making and profiling: If we engage in automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you, you have the right to object to such processing.
- The right to opt out of marketing communications at any time.
- The right to access your personal information free of charge.
- The right to know what personal data we hold about you and ensure it is accurate and up to date.
- The right to object to our continued processing of your personal data.
To exercise these rights, please direct your requests to privacy@fingermarkglobal.com. We will respond to your request in accordance with applicable regulatory time frames, typically within one calendar month, or as otherwise required by law. Upon receiving a request to access or correct your personal data, we will take appropriate steps to verify your identity before proceeding with any action. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.
Cookies and similar technologies
We use cookies and similar technologies (e.g., web beacons, pixels) on our websites:
- Necessary: Required to enable basic features of the site, such as providing secure log-in or adjusting your consent preferences.
- Functional: Used to perform certain functionalities like sharing content on social media platforms, collecting feedback, and other third-party features.
- Analytical: Used to understand how visitors interact with the website, providing information on metrics such as the number of visitors, bounce rate, traffic source, etc.
- Performance: Used to understand and analyze key performance indexes of the website to deliver a better user experience.
- Advertisement: Used to provide customized advertisements based on browsing history and analyze the effectiveness of ad campaigns.
Our website may use both first-party cookies (set by Fingermark) and third-party cookies (set by partners like advertising networks).
Managing Your Cookie Preferences:
You have control over these preferences through the consent management tool on our website. You can also manage cookies through your web browser settings, including disabling them entirely, though this may affect the functionality and features of our websites.
Contact Us
If you have concerns about how we handle your personal data, please contact us via email at info@fingermarkglobal.com. We value your feedback and are here to assist you.
If you have questions about your personal data or our services, please reach out to us at privacy@fingermarkglobal.com.
For specific inquiries regarding data protection, you may also contact our designated Privacy Lead/Data Protection Officer (DPO) at privacy@fingermarkglobal.com.
We commit to responding to all data subject requests and privacy concerns within the regulatory timeframes applicable to your jurisdiction.
As a technology company, we prefer email communication to ensure that you receive the most relevant and timely support in accordance with regulatory time frames.ce with regulatory time frames.