Privacy Policy
FINO Verify (Android, iOS, and web) · Last updated July 29, 2026
This policy explains what we collect across the public FINO Verify Android authenticity app, the account-enabled FINO Verify iOS app, gallofinoverify.com, and the FINO Wholesale web portal, why, and how we handle it. We keep this plain and honest: we collect only what we need to provide these services, we do not run any advertising or analytics SDKs, and we do not track you across other apps or websites.
The short version. The Android authenticity app requires no account. For a verification, it sends the registry identifier and, when present, the signature from the official FINO NFC link, plus your language choice and a new random request ID for that verification, to our verification service. It never uses or sends the NFC tag's hardware UID as an identity. The service records a verification event, a daily-salted truncated IP hash, and coarse network location for fraud and copied-chip detection. The app also downloads and privately caches the current FINO background image. Optional drop alerts on Android, iOS, and the website use purpose-specific installation and delivery identifiers only after you choose to enable them; they are not tied to a FINO account or used for analytics. The iOS app and wholesale portal separately store account and order information when you use those features. We do not sell your data, show ads, or embed third-party tracking.
1. Who we are
FINO Verify is published by GALLO FINO IP LLC (operating the Gallo Fino brand), Chino Hills, California, USA. For any privacy question or request, contact admin@gallofinosupport.com.
2. Who the app is for
The Android authenticity app is a public, account-free tool for anyone checking a Gallo Fino product with a compatible NFC phone. The account-enabled iOS app and FINO Wholesale portal are for Gallo Fino wholesale partners (approved businesses that order from us) and customers who view or claim their items and orders. None of these services is ad-supported.
3. What we collect
We only collect information you provide or that your device sends to run the app's features:
| Data | When / why we collect it |
|---|---|
| Email address | When you create an account or sign in (email/password or Sign in with Apple). Used to identify your account, look up your orders, send sign-in and account emails, and contact you about support. |
| Name | From your sign-up or your sign-in provider, and editable in your profile. Used to personalize your account. |
| Password (hashed) | If you sign up with email/password. We never store your actual password — only a one-way salted hash (PBKDF2). We cannot read it back. |
| Store name & contact handles (wholesale) | Optional. If you use the app as a wholesale partner, you may add your store name and the contact handles you choose to share — Instagram username, WhatsApp number, and phone. Used to identify your business and stay in touch about orders. |
| Shipping / order details | For wholesale checkout, the address and order items you enter so we can prepare your order and shipping. Address suggestions are powered by Google Places, and labels by Shippo. |
| Shipping payment | For wholesale checkout, shipping charges are paid through Stripe. Stripe processes your card directly; we receive a confirmation and the purchase record (what you bought), but we do not store your full card number. |
| Orders you view or claim | When you look up or claim an order with an order number and email, we confirm it against our store records and link it to your account so it appears in your order history and hat collection. |
| Android NFC verification data | When you verify a hat in the Android app, it sends the registry identifier and, when present, the signature contained in the official HTTPS FINO link read from NFC, or in an official HTTP or HTTPS FINO web link opened through Android's verified-link action. Before network access, the app always rebuilds that request as HTTPS. It also sends your selected language, a fixed app-version user agent, and a new random request ID used only to ensure that delivery retries for that one verification do not create duplicate scan records or counters. The request ID is not reused across separate verifications. Current provisioned tags require a signature; intentional legacy registry records may not have one, and our service enforces that requirement per record. The app does not use or send the tag hardware UID, an advertising ID, or a handset ID. Our service records the verification result, time, scan count, the one-verification request ID, the native client platform, a daily-salted truncated hash of the request IP address, and coarse country, region, and city supplied by our network provider to operate the registry and detect unusual or copied-chip activity. It does not store the raw request IP or full app user agent in the scan-event record. |
| Android appearance, language & branding | Your appearance and language choices stay in the app's private preferences. At startup, the app requests our public branding configuration, downloads the configured HTTPS background image, and keeps the last usable image in its private app storage. That branding request and direct image download include the fixed app-version user agent and ordinary network information such as the request IP, but no account, NFC tag, advertising, or handset identifier. The image may be delivered by our backend or our Shopify storefront/CDN. |
| Optional drop-notification identifiers & consent | FINO Verify may create a random, app-private installation identifier in local app or browser storage. It is not an advertising ID and does not identify the phone's hardware or a FINO account. We send it to our service only if you choose Allow notifications. An opt-in also sends the platform, notification provider, English or Spanish preference, consent version and time, a random purpose-specific subscription identifier, and the provider delivery endpoint: a Firebase Installation ID (FID) for Android or web, or an Apple Push Notification service (APNs) device token for iOS. Our service stores the active endpoint and a hash of it, plus a hash of the separate unsubscribe credential. Enrollment and removal requests also create short-lived, salted rate-limit hashes derived from the request IP; the raw IP is not stored in the drop-alert tables. These identifiers are used only to register, deliver, retry, secure, and turn off the drop alerts you requested. They are not combined with NFC scan history, account, purchase, or advertising data. |
| Basic diagnostics | To keep our apps and services reliable, we may store a failure type, error reason, time, source or client platform, and a redacted request route. Before a FINO verification-service failure is sent to our diagnostic store, the URL query and fragment are removed and the registry identifier in the /t/<id> route is replaced. The signed query value is not retained in that failure event. The Android app includes no analytics or crash-reporting SDK. Diagnostic records do not intentionally include your email, password, address, or message content. |
FINO Verify Android app
The Android app has no account, sign-in, form, checkout, camera, microphone, contacts,
precise-location permission, advertising SDK, analytics SDK, or crash-reporting SDK. It
accepts an NFC authenticity identity only from the official HTTPS FINO
gallofinoverify.com/t/<id> URL recovered from the tag's NDEF message
(including its Type-2 recovery path). Android verified web links may enter through HTTP or
HTTPS for that exact host and path; the app delegates only Android's web-link action and uses
HTTPS for the verification request. If that official link
cannot be read, the app shows a read error rather than authenticating a raw hardware UID.
Firebase Messaging auto-initialization stays off until you request drop alerts, and
Firebase Analytics collection remains off.
FINO Verify iOS app
The FINO Verify iOS app includes a few app-only features. When you use those features, we may collect or store:
- Device push token (APNs): if you allow notifications, Apple issues an app-specific device token that we store so we can send the notifications you requested, such as a support reply or an optional drop alert. Purpose-specific drop-alert consent and registration are stored separately from account notifications. The token is not an advertising or cross-app tracking ID.
- Drop-alert installation identifier: the app keeps one random purpose-specific identifier and unsubscribe proof in its Keychain. It is sent with a drop-alert registration only after you opt in, is not tied to your FINO account, and remains locally as a disabled record after opt-out so a retry or later re-enable cannot silently create a conflicting subscription.
- Profile photo: optional. If you set an avatar in the app, the image is stored for your account.
- In-app support messages: if you contact support in the app, we store the messages you send so we can read and reply.
4. What we do NOT do
- We do not use any third-party advertising or analytics SDKs.
- We do not enable Firebase Analytics or Firebase Cloud Messaging delivery-metrics export for drop alerts.
- We do not track you across other companies' apps or websites, and we do not build advertising profiles.
- We do not sell or rent your personal information.
- We do not access your contacts, microphone, GPS, or precise device location. The Android verification service handles coarse network location as described above.
- The public Android app does not create an account or collect profile, contact, order, payment, or message data through the app.
5. How we use your information
- To return an Android authenticity result, maintain scan counters, and detect unusual or copied-chip activity.
- To provide the current FINO background image in the Android app.
- To create and secure your account and sign you in.
- To show your orders, your hat collection, and (for wholesale) to prepare and ship your orders.
- To send account, verification, and password-reset emails.
- To send push notifications you've opted into (such as a reply to your support thread).
- To send the optional drop reminders and live-drop alert you specifically enabled.
- To answer your support requests.
- To keep the app working — diagnosing errors and reliability problems.
6. Sign in with Apple
You can create your account with Sign in with Apple. We receive only the information Apple shares to confirm your identity — a unique provider identifier, and your email and name where you've allowed it. If you use Apple's Hide My Email relay, we store the relay address; we never receive your real email. We verify this sign-in on our server and never use it to access anything else in your Apple account.
7. FINO Verify apps and website
Optional drop notifications on Android, iOS, and web
Drop notifications are optional. FINO Verify does not ask for notification permission until you choose Allow notifications on the drop surface. Android and gallofinoverify.com use Google Firebase Cloud Messaging; iOS uses APNs. The purpose-specific subscription is used only for reminders before the announced drop and an alert when it goes live.
You can use Turn off drop alerts or Turn off in the app or website to remove the active delivery endpoint and cancel unsent alerts. If the network request cannot finish, the native app keeps the local opt-out and shows a retry state rather than silently treating the remote removal as complete. Revoking notification permission in Android, iOS, or browser settings stops display but may not immediately remove the purpose-specific server record, so use the in-app or website control when available.
Android authenticity app
Android verification works without an account. The app can display the authenticity verdict, verification guidance, scan count, and — when a registry record supplies it — a verified wholesale store name and an optional Instagram link. It does not display the raw registry identifier, NFC hardware UID, chip technology, style, batch, or first-seen value. Instagram and support-email links open only after you choose them.
Other iOS push notifications
Push notifications are optional and only work if you allow them. When you do, Apple's Push Notification service (APNs) gives us a device token that we store to deliver notifications. Notification content is kept generic (for example, "You have a new reply") so sensitive details don't appear on your lock screen. You can turn notifications off at any time in iOS Settings; if you do, your device stops displaying them. Account-notification tokens are removed when they are no longer valid. Drop alerts use the separate turn-off flow described above.
iOS profile photos, support, and device sessions
In the FINO Verify iOS app, you can edit your name, profile photo, and (for wholesale users) store and contact details. You can also message support from the app and sign out of individual devices or sessions.
8. Where your data is stored & how it's secured
Our backend runs on Cloudflare. Account and order data is stored in Cloudflare's D1 database; app-only images such as FINO Verify profile photos are stored in Cloudflare R2 storage. All traffic between the app, web portal, and our servers is encrypted in transit (HTTPS/TLS).
- The Android app stores its settings and last usable background image in private app storage. During Activity recreation, Android may also retain only a SHA-256 marker of the last launch action and URL so the same restored payload is not verified twice; the raw signed URL is not placed in saved state. Android cloud backup and device-to-device transfer are disabled through explicit exclusion rules for this app.
- Passwords are stored only as a one-way salted hash (PBKDF2) — never in plain text.
- Sessions use revocable tokens, and we never store your raw session token in a readable form.
- Access to your data is limited to running the app's features and providing support.
9. Service providers
We share data only with the providers needed to run the app, and only for that purpose:
- Cloudflare — hosting, database, network processing, diagnostic-event storage, and image storage for our backend.
- Apple — Sign in with Apple, and Apple Push Notification service for iOS notifications.
- Google Firebase — Firebase Installations and Firebase Cloud Messaging register and deliver optional Android and website drop notifications. Google receives a per-installation FID and Firebase user-agent or app-version information needed to operate those services. We do not enable Firebase Analytics for this feature.
- Shopify and its storefront/CDN — our store platform, used to confirm and display your orders and to deliver the current Android background image when that image is hosted by our storefront.
- Stripe — payment processing for shipping charges at wholesale checkout. Stripe handles your card details directly; we do not store full card numbers.
- Google Places — address autocomplete when you enter a shipping address, so addresses are accurate. We send what you type into the address field to return suggestions.
- Shippo — generating shipping labels and rates. We share the order's name and shipping address to buy postage and produce a label.
- Resend and our operator mailbox provider — to send account, verification, and password-reset emails and internal copied-chip/security alerts. An unusual-scan alert may include the product registry identifier, scan count, alert reason, and coarse country so our operators can investigate.
These providers process data to provide the services above; we do not authorize them to use it for their own advertising. If you choose an optional wholesaler Instagram link, you leave FINO Verify and Instagram receives the ordinary information associated with your request under its own privacy terms.
10. Data retention
We keep your account information for as long as your account is active so the app keeps working for you. Android verification scan records and backend failure diagnostics currently have no fixed automatic deletion window. They are kept as needed to operate the authenticity registry, maintain scan history, investigate copied-chip patterns, troubleshoot failures, and meet legitimate business or legal obligations. When you ask us to delete your account, we remove your personal information from our active systems as described below. Some records may be retained where required for legitimate business or legal reasons (for example, order and tax records).
An active drop-alert subscription remains while you are opted in or until its provider endpoint is reported invalid. When our service confirms opt-out, it immediately blanks the endpoint and endpoint hash and cancels pending alerts. Disabled subscription records and sent, cancelled, or permanently failed delivery records are configured for scheduled deletion after 90 days, once related delivery rows have aged out. Salted rate-limit buckets expire after about 20 minutes. A disabled local installation/subscription proof may remain in private app, Keychain, or browser storage so retries and re-enrollment preserve the same consent record; clearing app or site data removes that local copy.
Firebase retains its FID until the app or website asks Firebase to delete the registration. Google states that after that deletion call, Firebase Cloud Messaging removes the FID from live and backup systems within 180 days. Provider processing is also subject to Google's or Apple's applicable terms and privacy practices.
11. FINO Wholesale web portal
The FINO Wholesale web portal at partners.finowholesale.com is the browser-based surface for approved wholesale partners to sign in, manage orders, and request account help. Password changes for the web portal happen through /forgot-password. For portal support or privacy questions, contact admin@gallofinosupport.com.
12. Your choices & deletion requests
You are in control of your data:
- The Android authenticity feature has no account and sends no stable user or handset identifier with an NFC verification, so we ordinarily cannot determine which scan belongs to a particular person. Optional drop alerts use separate installation identifiers that are not joined to scan history. You may ask us to de-identify the network-derived fields of a uniquely identifiable verification event. Provide only the registry ID (the text after
/t/), approximate date/time, and timezone. Do not send the full FINO URL, itsssignature, a password, or another secret. If no event or more than one event matches, we may be unable to attribute a record to you. We may also retain registry and security fields needed for fraud prevention, copied-chip investigations, legal obligations, or another legitimate purpose. - Drop alerts are opt-in. Use the app or website's Turn off control to revoke purpose-specific consent and request server-side removal. You can also block notifications in Android, iOS, or browser settings.
- Edit your name and, for wholesale accounts, store and contact details through the surface you use.
- Change your web portal password through /forgot-password.
- For the FINO Verify iOS app, you may edit your profile photo, sign out of individual devices or sessions, and turn other account notifications on or off in iOS Settings.
- Request a copy of your data, or request deletion of your account and personal information.
To request access or deletion, email admin@gallofinosupport.com from the address on your account when the request concerns an account. For an account-free Android scan request, include only the limited identifying details described above. FINO Verify iOS app users may also message us from the app's support screen. We'll confirm the request, explain any record we must retain, and process the deletion or de-identification we can complete.
13. Children
FINO Verify is intended for businesses and adult customers, including the public Android authenticity tool. It is not directed to children under 13, and we do not knowingly collect personal information from them.
14. Changes to this policy
We may update this policy as the app evolves. When we make a meaningful change we'll update the "Last updated" date above and, where appropriate, notify you in the app.
15. Contact
Questions or requests about your privacy:
admin@gallofinosupport.com
GALLO FINO IP LLC · Chino Hills, California, USA