Skip to main content
Privacy Policy

Effective Date: 13 July 2025
Last Reviewed: 13 July 2025

Privacy Snapshot

Below is a high‑level overview. For full details, read the complete Policy that follows.

Key PointWhat it means
No sale or shareWe never sell or share your personal information for cross‑context behavioural advertising.
Why we collect dataTo run the platform, process payments, secure our systems, improve the product and—only with your consent—send you marketing.
Your controlsDownload, correct, delete or restrict your data; opt‑out of marketing; manage cookies; withdraw consent at any time.
Security firstData encrypted in transit & at rest, SOC‑2‑aligned controls, annual pen‑tests, 72‑hour breach notice.
Regional complianceGDPR (EU/UK), CPRA & other U.S. state laws, PIPEDA (Canada), Data Privacy Framework certified.
Sub‑processorsStripe, Supabase, Vercel, Microsoft Azure Blob Storage, Twilio, SendGrid (live list & 30‑day objection window).
Changes30 days' advance e‑mail / in‑app notice before any material change.

Flowdara Privacy & Data Protection Policy

Effective Date: 13 July 2025
Last Reviewed: 13 July 2025

Flowdara, Inc. and its subsidiaries ("Flowdara", "we", "our" or "us") respect your privacy. This Privacy & Data Protection Policy ("Policy") describes how we collect, use, disclose, and protect your personal information when you interact with our booking platform, websites, mobile applications, application‑programming interfaces (APIs) and related services (collectively, the "Services").

Layered approach. This Policy is our comprehensive disclosure. Where required, we also provide contextual "just‑in‑time" notices (e.g., cookie banner, OAuth consent screens). If a regional law offers you stronger rights or imposes stricter duties, we comply with that law.

1. Definitions

TermMeaning
ControllerThe entity that determines the purposes and means of processing personal information. Flowdara acts as Controller for End‑Users who create accounts directly with us. When you interact with a Flowdara Subscriber (e.g., a practitioner using our SaaS), that Subscriber is the Controller and Flowdara acts as Processor.
End‑UserAny natural person who uses the Services, including Subscriber staff and consumer clients who book, pay for, or attend an appointment.
Personal Information / Personal DataInformation that identifies, relates to, describes, or can reasonably be linked—directly or indirectly—to a natural person, as defined by applicable law (GDPR, CPRA, PIPEDA, etc.).
Sensitive Personal InformationA special category of data subject to additional protections (e.g., health data, precise geolocation, biometric identifiers).
Other InformationData that cannot reasonably be used to identify an individual (e.g., aggregated statistics). We commit not to re‑identify de‑identified data.

2. Scope & Applicability

This Policy applies to all users in North America and the United Kingdom (preparatory compliance) and governs every point of collection—websites, mobile apps, emails, APIs, support channels, and marketing touch‑points.

The Services are not directed to children under 16. We do not knowingly collect data from children under 13. See Section 13.

3. What We Collect & Why

3.1 Data‑Processing Matrix

CategoryExamplesPurposeLegal Basis*Retention
Account & ContactName, email, postal address, telephoneAccount creation, authentication, supportContract; Legitimate InterestDuration of account + 3 yrs
CredentialsEncrypted passwords, OAuth tokensSecure log‑in, SSOContract; Legitimate InterestUntil deletion; rotated < 90 days
Payment & BillingLast 4 digits card, billing address, Stripe ID, transaction historyProcess payments, refunds, fraud preventionContract; Legal Obligation (tax)7 yrs (tax/PCI)
Booking DataAppointment date/time, location, service typeProvide and manage ServicesContractDuration of account + 1 yr
Usage & DeviceIP, browser, OS, device ID, clickstream, cookies, crash logsService performance, analytics, securityLegitimate Interest26 months (Google Analytics default)
Marketing PreferencesOpt‑in status, communication channelsSend offers & newslettersConsentUntil opt‑out + 30 days
Support RecordsChat / email transcripts, call recordingsTroubleshooting, quality assuranceLegitimate Interest2 yrs
Sensitive Data †Health notes entered by Subscriber; precise geo (optional)Only when strictly necessary for a booked serviceExplicit Consent; Art 9 GDPRAs instructed by Subscriber or 30 days after service

* Legal basis references GDPR Articles 6 & 9 and equivalent concepts under CPRA & PIPEDA. When multiple bases apply we rely on the strongest lawful option.

† We do not proactively request sensitive data. If you voluntarily provide it, we treat it with heightened protections (encryption, limited access, short retention, audit logging).

4. How We Use Personal Information

  1. Service delivery & account administration – create profiles, schedule bookings, send confirmations.
  2. Payment processing & fraud prevention – via Stripe (PCI‑DSS Level 1).
  3. Product research & development – aggregate analytics, A/B testing, error diagnostics.
  4. Security & abuse prevention – monitor logs, investigate suspicious activity, enforce Terms.
  5. Marketing (opt‑in only) – newsletters, promotions, referral programmes; unsubscribe anytime.
  6. Legal & compliance – tax records, contractual enforcement, regulatory reporting.
  7. Corporate events – mergers, acquisitions, or asset sales with appropriate confidentiality safeguards.

We never use Stripe payment data or sensitive health information for marketing or profiling.

5. Cookies, Pixels & Tracking Technologies

We use first‑ and third‑party cookies, web beacons, local storage, and similar technologies to:

  • Keep you signed in;
  • Remember preferences;
  • Measure site performance;
  • Detect fraud.

5.1 Consent & Controls

  • EU/UK users: non‑essential cookies are blocked until you click "Accept" on our banner; granular settings available.
  • Global Privacy Control (GPC): honoured for U.S. state "Do Not Sell/Share" signals.
  • Analytics opt‑out: install Google Analytics Opt‑out Add‑on.

Full details appear in our Cookie Policy.

6. How & With Whom We Share Data

RecipientPurposeSafeguard
StripePayment processingDPA + SCCs + PCI‑DSS certification
SupabaseManaged Postgres DB, file storageAES‑256 at rest; TLS 1.2; DPA + SCCs
Microsoft Azure Blob StorageMedia uploads & backupsEncryption at rest; separate encryption keys; DPA + SCCs
VercelHosting & edge cachingISO 27001; DPA + SCCs
Twilio / SendGridSMS & email deliverySOC 2; DPA + SCCs
Authorized SubscriberProvide requested serviceController–Processor contract
Government / Law enforcementLegal complianceLegal obligation + minimisation
Corporate successorsM&A, financing, reorgConfidentiality & DPF/SCCs

7. Your Privacy Rights & How to Exercise Them

  1. Access / Know
  2. Correct / Rectify
  3. Delete / Erase
  4. Portability (machine‑readable JSON/CSV)
  5. Restrict / Object
  6. Opt‑out of marketing
  7. Do Not Sell or Share – GPC signals accepted.
  8. Appeal – If we decline your request, you may appeal within 45 days.

Submit requests via Account → Privacy Dashboard or email privacy@flowdara.com with subject "Data Subject Request". We will verify identity (two‑factor challenge or signed request via logged‑in session) and respond within:

  • 45 days (U.S. state laws) – extendable once by 45 days;
  • 1 month (GDPR/UK GDPR) – extendable by 2 months for complexity.

If you believe we have not resolved your concern, you may lodge a complaint with your local supervisory authority (contact links provided in the Privacy Dashboard).

8. Security Measures

  • Encryption – TLS 1.2+ in transit; AES‑256 at rest (Supabase & Azure).
  • Access controls – role‑based, least‑privilege, MFA for all staff.
  • Monitoring & audits – SOC‑2‑aligned controls, annual penetration tests, quarterly vulnerability scans.
  • Incident response – 24×7 on‑call team, forensic logging, 72‑hour regulator & user notice window if breach likely to result in risk.
  • PCI‑DSS – Stripe stores all card data; Flowdara never stores raw PAN.

9. Data Retention

We keep Personal Information only as long as necessary for the purposes described or as required by law:

  • Active account – data retained while account open.
  • Financial records – 7 years (tax & accounting).
  • Support tickets & logs – 2 years.
  • Marketing opt‑out lists – indefinitely (to honour opt‑out).

When retention expires, data is securely erased or anonymised within 60 days.

10. International Transfers

Servers are located in the United States and Canada; backups in UK South Azure region (for UK rollout). Transfers from EEA/UK/Switzerland rely on Standard Contractual Clauses and (where applicable) our EU‑U.S./UK/Swiss Data Privacy Framework certification. Supplementary measures include encryption, access logging, and strict sub‑processor vetting.

11. Integrations & Limited‑Use Disclosure

If you connect Flowdara to Google Calendar™ or other OAuth providers, we will access calendar metadata solely to display availability and create events you ask us to create. Flowdara's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Humans do not read calendar content except with your explicit consent for support or security reasons.

12. Children

We do not knowingly collect data from children under 13 (COPPA). Parents who believe a child has provided us data may contact privacy@flowdara.com for immediate deletion. Minors aged 13–15 may use the Services only with verifiable parental consent; UK/EU users aged 13–16 require guardian consent per GDPR Article 8.

13. Changes to This Policy

Minor updates are posted at https://flowdara.com/privacy. Material changes (those that reduce your rights or expand processing) will be announced 30 days in advance via email and in‑app notices. Continued use after the effective date constitutes acceptance.

14. Contact & Data Protection Officer

Data Controller: Flowdara, Inc.
DPO & Privacy Office:
210 SW Century Dr., Bend, OR 97702, USA
✉︎ privacy@flowdara.com
☎︎ +1 (541) xxx‑xxxx

EU/UK representative details will be added prior to UK launch and will appear here.

For unresolved GDPR complaints you may contact the Irish Data Protection Commission or your local supervisory authority. For Data Privacy Framework complaints see Section 14 of the DPF Principles.

© 2025 Flowdara, Inc. All rights reserved.