Privacy Policy
Last updated: March 30, 2026
This Privacy Policy ("Policy") describes how Flowix ("Company," "we," "us," or "our") collects, uses, stores, shares, and protects information obtained from users ("User," "you," or "your") of the Flowix platform, website, and all related services (collectively, the "Service"). By accessing or using the Service, you consent to the data practices described in this Policy. If you do not agree with this Policy, you must discontinue use of the Service immediately.
We are committed to protecting your privacy and handling your data with transparency. This Policy should be read in conjunction with our Terms of Service.
1. Information We Collect
1.1 Information You Provide Directly
When you create an account, subscribe to a plan, or contact us, we may collect the following information:
- Account Information: Email address and password (hashed and salted — we never store plaintext passwords).
- Billing Information: Payment method details (processed and stored securely by Stripe, Inc.; we do not store full credit card numbers, CVVs, or banking details on our servers).
- Subscription Details: Your selected plan, billing cycle, payment history, and subscription status.
- Support Communications: Any information you provide when contacting our support team, including email content, attachments, and contact details.
- Preferences and Settings: Theme preferences, notification settings, and other user-configurable options.
1.2 Information Collected Automatically
When you access or use the Service, we automatically collect certain information, including:
- Device and Browser Information: Device type, operating system, browser type and version, screen resolution, and device identifiers.
- Log Data: IP address, access times, pages viewed, referring URL, and actions taken within the Service.
- Usage Data: Features used, scrape job history (type, parameters, timestamps, lead counts), and general interaction patterns with the Service.
- Cookies and Similar Technologies: We use cookies, local storage, and similar technologies to maintain your session, remember preferences, and analyze usage patterns. See Section 7 for more details.
1.3 Scraped Data
When you use the Service to perform scrape operations, the Service collects and stores data from third-party sources ("Scraped Data") on your behalf. This may include business names, phone numbers, email addresses, physical addresses, website URLs, ratings, reviews, and other publicly available information. This Scraped Data is associated with your account and treated as "Your Data" as defined in our Terms of Service.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To provide, maintain, operate, and improve the Service, including processing scrape jobs, displaying results, and enabling data export.
- Account Management: To create and manage your account, process authentication, and maintain account security.
- Billing and Payments: To process payments, manage subscriptions, send invoices and receipts, and handle billing-related communications. Refund Policy: Please note that all subscription payments are final, and we maintain a strict no refund policy for current, partial, or past billing cycles to protect against abuse.
- Communications: To send you transactional emails (e.g., account confirmations, password resets, billing notifications), and, where you have opted in, marketing communications about new features, promotions, or updates.
- Analytics and Improvement: To analyze usage patterns, monitor performance, identify bugs and issues, and improve the Service's functionality, reliability, and user experience.
- Security and Fraud Prevention: To detect, investigate, and prevent fraudulent activity, unauthorized access, abuse of the Service, and other security threats.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes, and to enforce our Terms of Service.
- Usage Limit Enforcement: To track and enforce subscription plan usage limits, including scrape quotas and free tier restrictions.
3. How We Share Your Information
We do not sell, rent, or trade your personal information to third parties. We may share your information only in the following circumstances:
3.1 Service Providers
We share information with trusted third-party service providers who assist us in operating the Service, subject to strict confidentiality obligations. These providers include:
- Stripe, Inc.: For payment processing and subscription management. Stripe receives your billing information directly and is subject to its own privacy policy.
- Supabase (via managed hosting): For database hosting, authentication, and serverless functions. Your account data, scrape job records, and Scraped Data are stored on Supabase infrastructure.
- Hosting and Infrastructure Providers: For website hosting, content delivery, and server infrastructure.
- Analytics Providers: For aggregated, anonymized usage analytics to help us improve the Service.
3.2 Legal Requirements
We may disclose your information if we believe in good faith that disclosure is necessary to:
- Comply with a legal obligation, court order, subpoena, or other legal process;
- Protect and defend the rights, property, or safety of Flowix, our users, or the public;
- Detect, prevent, or address fraud, security issues, or technical problems;
- Enforce our Terms of Service or other agreements.
3.3 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, dissolution, or sale of all or a portion of our assets, your information may be transferred to the acquiring entity. We will provide notice of such transfer and any changes to this Policy.
3.4 With Your Consent
We may share your information with third parties when you have given us explicit consent to do so.
4. Data Storage and Security
4.1 Data Storage
Your data is stored on secure servers provided by our infrastructure partners. We primarily use Supabase for database hosting, which employs industry-standard security measures including encryption at rest and in transit. Our servers may be located in the United States or other jurisdictions. By using the Service, you consent to the transfer and storage of your data in these locations.
4.2 Security Measures
We implement a variety of technical and organizational security measures to protect your information, including:
- Encryption of data in transit using TLS/SSL protocols;
- Encryption of sensitive data at rest;
- Password hashing using industry-standard cryptographic algorithms;
- Role-based access controls and Row Level Security (RLS) policies ensuring users can only access their own data;
- Regular security reviews and vulnerability assessments;
- Secure API key management and environment variable isolation.
4.3 No Guarantee of Absolute Security
While we strive to protect your personal information, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee the absolute security of your data. You acknowledge and accept this inherent risk when providing information to us.
4.4 Breach Notification
In the event of a data breach that compromises the security of your personal information, we will notify affected users and applicable regulatory authorities as required by law. Notification will be provided within seventy-two (72) hours of becoming aware of the breach, where feasible.
5. Data Retention
We retain your personal information and Scraped Data for as long as your account remains active or as needed to provide you the Service. Specifically:
- Account Information: Retained for the duration of your account and deleted within thirty (30) days of account closure, unless retention is required by law.
- Scraped Data and Lead Records: Retained for the duration of your account. You may delete individual scrape jobs and their associated leads at any time through the dashboard.
- Billing Records: Retained for a period of seven (7) years following the transaction for tax, accounting, and legal compliance purposes, as required by applicable financial regulations.
- Log Data: Retained for up to twelve (12) months for security, analytics, and debugging purposes, after which it is automatically purged or anonymized.
- Support Communications: Retained for as long as reasonably necessary to resolve your inquiry and for our records, typically up to three (3) years.
6. Refund and Cancellation Policy
To prevent abuse of our data services, we maintain a strict No Refund policy for all current, partial, or past subscription billing cycles. By completing a transaction on our platform, you acknowledge and agree that all payments are final. You may cancel your subscription at any time to prevent future recurring charges, but previous payments will not be refunded.
6. Your Rights and Choices
Depending on your jurisdiction, you may have the following rights regarding your personal information:
6.1 Access and Portability
You have the right to request a copy of the personal information we hold about you. You can export your Scraped Data at any time through the CSV export functionality in the Service.
6.2 Correction
You have the right to request that we correct any inaccurate or incomplete personal information we hold about you.
6.3 Deletion
You have the right to request the deletion of your personal information. You can delete your scrape jobs and associated leads through the dashboard. To request full account deletion, please contact us at the email address provided below. Please note that certain information may be retained as required by law or for legitimate business purposes.
6.4 Restriction of Processing
You may have the right to request that we restrict the processing of your personal information under certain circumstances, such as when you contest the accuracy of the data or object to its processing.
6.5 Objection
You may have the right to object to the processing of your personal information for direct marketing purposes or when processing is based on our legitimate interests.
6.6 Withdrawal of Consent
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
6.7 Non-Discrimination
We will not discriminate against you for exercising any of your privacy rights. We will not deny you the Service, charge you different prices, or provide a different quality of Service solely because you exercised a privacy right.
6.8 Exercising Your Rights
To exercise any of the above rights, please contact us at FlowixAssistance@outlook.com. We will respond to your request within thirty (30) days unless a longer response period is permitted by applicable law. We may need to verify your identity before processing your request.
7. Cookies and Tracking Technologies
7.1 What We Use
We use the following technologies to enhance the Service:
- Session Cookies: Essential cookies that maintain your authenticated session and enable core functionality. These are strictly necessary and cannot be disabled.
- Local Storage: Used to store user preferences (e.g., theme selection) and free tier usage tracking. This data remains on your device and is not transmitted to our servers unless necessary for Service functionality.
- Functional Cookies: Used to remember your choices and provide enhanced, personalized features.
7.2 Third-Party Cookies
Our payment processor (Stripe) may set its own cookies when you interact with payment forms. These are governed by Stripe's cookie policy. We do not control the cookies set by third-party services.
7.3 Managing Cookies
Most web browsers allow you to manage cookies through their settings. You can typically choose to block or delete cookies. However, disabling essential cookies may prevent you from using certain features of the Service, including authentication.
8. International Data Transfers
If you are accessing the Service from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States or other countries where our infrastructure providers maintain servers. These countries may have data protection laws that differ from the laws in your jurisdiction.
By using the Service, you consent to the transfer of your information to the United States and other countries as described in this Policy. Where required by applicable law (including the GDPR), we will ensure that appropriate safeguards are in place for international data transfers, such as Standard Contractual Clauses approved by the European Commission.
9. GDPR Compliance (European Economic Area Users)
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the following additional provisions apply:
9.1 Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Contract Performance: Processing necessary to perform our contract with you (providing the Service).
- Legitimate Interests: Processing necessary for our legitimate interests, such as improving the Service, preventing fraud, and ensuring security, provided these interests are not overridden by your rights.
- Consent: Processing based on your explicit consent, such as for marketing communications.
- Legal Obligation: Processing necessary to comply with a legal obligation to which we are subject.
9.2 Data Protection Officer
For GDPR-related inquiries, please contact us at FlowixAssistance@outlook.com.
9.3 Right to Lodge a Complaint
If you are located in the EEA, you have the right to lodge a complaint with your local supervisory authority if you believe that our processing of your personal data violates applicable data protection laws.
10. CCPA Compliance (California Residents)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to Know: You have the right to request information about the categories and specific pieces of personal information we have collected, the categories of sources, the business purpose for collection, and the categories of third parties with whom we share your information.
- Right to Delete: You have the right to request the deletion of your personal information, subject to certain exceptions.
- Right to Opt-Out of Sale: We do not sell your personal information. If this practice changes, we will provide you with the right to opt out.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
- Right to Correct: You have the right to request correction of inaccurate personal information.
- Right to Limit Use of Sensitive Personal Information: If we collect sensitive personal information as defined by the CPRA, you have the right to limit its use.
To exercise your CCPA/CPRA rights, please contact us at FlowixAssistance@outlook.com. We will verify your identity before processing your request and respond within forty-five (45) days.
11. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that a child under 18 has provided us with personal information without parental consent, we will take steps to delete such information immediately. If you believe that a child under 18 has provided personal information to us, please contact us at FlowixAssistance@outlook.com.
12. Scraped Data and Third-Party Privacy Rights
An important note regarding the data you collect through the Service:
The Scraped Data you collect through our Service may contain personal information of third-party individuals and businesses. When you collect and use this data, you become the data controller for that information and are solely responsible for:
- Ensuring your collection and use of Scraped Data complies with all applicable privacy and data protection laws;
- Providing appropriate notice and, where required, obtaining consent from individuals whose data you collect;
- Honoring opt-out, deletion, and other data subject requests from individuals whose data you process;
- Implementing appropriate security measures to protect the Scraped Data;
- Not using the data for purposes that are unlawful, unethical, or in violation of any applicable law or regulation.
Flowix acts as a data processor on your behalf when storing and managing Scraped Data. We do not independently use, analyze, sell, or share your Scraped Data except as necessary to provide the Service to you. We do not access or review your Scraped Data except for troubleshooting purposes at your request or as required by law.
13. Do Not Track Signals
Some browsers include a "Do Not Track" (DNT) feature that signals to websites that you do not want your online activity tracked. There is currently no unified standard for how companies should respond to DNT signals. At this time, we do not respond to DNT signals. However, you can manage your privacy preferences through the cookie and browser settings described in Section 7.
14. Third-Party Links
The Service may contain links to third-party websites or services that are not operated or controlled by us. This Privacy Policy does not apply to those third-party sites. We are not responsible for the privacy practices, content, or policies of third-party websites. We encourage you to review the privacy policies of any third-party websites you visit.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will update the "Last Updated" date at the top of this Policy and, where required by applicable law, provide you with additional notice (such as a prominent notice in the Service or an email notification). Your continued use of the Service after the effective date of any changes constitutes your acceptance of the revised Policy.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
16. Contact Information
If you have any questions, concerns, or complaints about this Privacy Policy, our data practices, or your personal information, please contact us at:
Flowix
Email: FlowixAssistance@outlook.com
We take all privacy concerns seriously and will respond to your inquiry within thirty (30) days.