1. What this policy covers
This Privacy Policy describes what data FlowRepp ("we," "us," or "our") collects when you visit flowrepp.com, create an account, or use the FlowRepp review-routing platform. It also explains how we use, retain, and share that data, and what rights you have under applicable data protection laws including GDPR (EU/UK) and CCPA (California).
2. Data we collect
We collect three categories of data:
- Account data: name, work email, business/trade type, password (hashed; never stored in plain text), company name, and any optional profile fields you choose to fill in.
- Customer feedback data: customer names, contact details (phone or email), review text, ratings, sentiment scores, and routing decisions. This is the feedback that you — the business — authorize us to ingest from the review platforms you connect, or that you submit directly to us through your dashboard.
- Usage data: pages visited, features used, IP address, browser type, and aggregate event counts for analytics and conversion-funnel measurement.
3. How we use your data
We use the data we collect to:
- Provide and operate the review-routing service, including sentiment scoring and routing-rule execution.
- Authenticate you, bill you through Stripe, send transactional and onboarding emails, and notify you of service changes.
- Measure aggregate usage of the Service so we can prioritize improvements. We do not use your customer feedback content to train third-party AI models.
- Detect and prevent abuse or violations of our Terms of Service.
4. Third-party processors
To run the Service, we share specific data with vetted vendors. The list below covers the processors in active use as of this policy's last-updated date:
- Stripe — billing and subscription management. Receives your name, email, and payment-method details. See Stripe's privacy policy for how they handle data.
- Google Business Profile API — review ingestion and sentiment scoring on reviews you authorize us to read. Subject to Google's API Services User Data Policy, including the Limited Use requirements (link).
- Yelp Fusion API — review ingestion from connected Yelp business listings, using an API key you provide.
- OpenAI — provides sentiment scoring on review text. We send the review text only; we do not send customer contact details or your account credentials.
- Polsia Email Proxy — sends transactional emails (signup confirmation, onboarding drip, billing receipts) on our behalf.
- R2 (Cloudflare) — hosts any optional assets you upload through the platform.
We require each of these processors to protect your data under terms no less protective than those in this Privacy Policy.
5. Data retention
- Account data: retained while your account is active, and deleted within 30 days of account closure, except where retention is required by law (e.g., tax records).
- Customer feedback data: retained while your account is active plus 90 days thereafter, so you have a grace window to export after cancellation. Manual deletion is available from your dashboard at any time.
- Billing records: retained for 7 years to comply with tax and accounting obligations.
6. Cookies and analytics
We use a single first-party analytics cookie (`repflow_sid`) for session authentication. We also use Polsia Analytics, a cookie-light first-party pixel that records anonymous visit events (no cross-site tracking, no advertising profile). We do not use Google Analytics, Facebook Pixel, or other advertising trackers.
7. Your rights (GDPR & CCPA)
If you are in the EU, UK, EEA, or California, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate personal data.
- Erasure — ask us to delete your personal data, subject to retention requirements above.
- Portability — receive your data in a structured, machine-readable format.
- Objection / restriction — object to processing or ask us to restrict it, in particular for direct marketing or analytics-only processing.
- Withdraw consent — withdraw any consent you previously gave, at any time, without affecting earlier processing.
To exercise any of these rights, email support@flowrepp.com. We respond within 30 days. You may also lodge a complaint with your local data protection authority.
8. Security
We protect data through industry-standard measures: TLS encryption in transit, password hashing with PBKDF2 (310,000 iterations, SHA-512) and per-user salts, session tokens in httpOnly cookies, principle-of-least-access roles for company membership, and audit logging on sensitive endpoints. No system is perfectly secure; if you discover a vulnerability, please email support@flowrepp.com.
9. International transfers
FlowRepp is operated from the United States. If you use the Service from the EU, UK, or another jurisdiction with cross-border transfer rules, your data will be transferred to and processed in the United States. We rely on Standard Contractual Clauses or equivalent safeguards where required.
10. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we'll update the "Last updated" date at the top of this page and, for material changes, give you reasonable notice by email or in-product.
11. Contact us
If you have any questions about this Privacy Policy or how your data is handled, email support@flowrepp.com.