1. Who we are
Customer Flow (“Customer Flow”, “we”, “us”) provides a business workspace at thecustomerflow.com for operations, documents, approvals, and compliance workflows — including import, export, finance, inventory, HR, grants, and related modules.
For privacy requests, email info@thecustomerflow.com. We treat the organization that owns a workspace as the customer. People who sign in (employees, invitees, and administrators) are users of that workspace.
2. Scope
This policy covers the Customer Flow website, sign-in, and the hosted application. It does not cover third-party government portals, banks, carriers, or other systems you may connect to from the product.
If your organization has a separate written agreement with us, that agreement controls if it conflicts with this policy.
3. Information we collect
We collect information in three layers: account data, workspace data you enter, and limited technical data needed to run the service.
- Account data: name, work email, phone number, password (stored hashed, never in plain text), organization name, industry, country, fiscal-year settings, role, and two-factor authentication details (such as a TOTP secret or SMS one-time codes).
- Workspace data: business records you create or upload — partners, consignments, invoices, inventory, payroll, grants, projects, documents, logos, and audit history. This data stays in your organization’s isolated workspace.
- Technical data: IP address, browser type, device, approximate time zone, session cookies, and security logs (sign-in attempts, permission checks).
- Payment and subscription data: plan, billing interval, trial dates, and status. We do not store full card numbers in the application when a payment provider is used.
- Support: messages you send to our contact email, including any files you attach.
5. How we use information
We use information to:
- Create and operate your organization workspace, including numbering, approvals, and the audit trail.
- Authenticate users, enforce roles and permissions, and detect abuse or unauthorized access.
- Generate documents, reports, and notifications you request.
- Provide trials, subscriptions, and account administration.
- Improve reliability and fix defects.
- Comply with law and respond to lawful requests.
6. Legal bases
Where data-protection law requires a legal basis, we rely on: performance of a contract with your organization; our legitimate interests in running a secure B2B service; consent where we ask for it (for example optional analytics or marketing email); and legal obligation when we must retain or disclose records.
8. Documents and generated files
Uploaded documents and files we generate for you (invoices, packs, exports) stay in your workspace. We do not use them to train public machine-learning models.
You are responsible for what you upload, including whether a file contains personal data of employees, customers, or suppliers, and for setting retention inside the product where those controls exist.
9. International processing
The service may be hosted on infrastructure in more than one country. If we transfer personal data out of your country, we use appropriate safeguards required by applicable law (such as contractual clauses with processors).
10. Retention
Account and workspace data is kept for as long as the organization maintains an active workspace, plus a limited period afterward so you can restore or export it, unless a longer period is required by law or for dispute resolution.
Security logs are kept for a shorter operational period. You may ask us to delete an organization account as described below.
11. Security
We use hashed passwords, session controls, role-based access, optional two-factor authentication, and isolation between organization workspaces. No method of transmission or storage is completely secure. You must choose strong passwords, keep invite links private, and grant the minimum permissions needed.
12. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export personal data, to object to or restrict certain processing, and to withdraw consent. Workspace administrators can often fulfill requests inside the product (user records, document deletion, exports).
If you cannot resolve a request with your administrator, email info@thecustomerflow.com from the address on your account. We may need to verify identity and will point organization-owned records to the customer’s administrator when they are the controller of that data.
13. Children
Customer Flow is a business service. It is not directed at children under 18. Do not create an account for anyone under 18.
14. Changes
We may update this policy. The effective date at the top of the page will change. Material changes will be posted on this page. Continued use after the effective date means you accept the updated policy.