Privacy Policy
Effective September 21, 2026
This policy explains how Flow handles information through buyflow.io, its website analytics service, and its payment-provider integrations, including the Flow Stripe App.
Privacy contact: pfcteam@prepforcerts.org
If you visit a website that uses Flow, that website’s operator controls its tracking setup. Contact that operator first about its data use. We can help route a request.
1. Who this policy covers
Flow is operated by Brian Reynolds in the United States (“we,” “us,” or “our”). We provide website analytics and revenue attribution. We handle account, billing, support, and service-security information to operate our service. For analytics collected on a customer’s website, we process information on that customer’s instructions. That customer is responsible for its notices, lawful basis, and any required consent.
This policy applies to the hosted service at buyflow.io.
2. Information we handle
- Account and support information: your name, email address, password hash, project names and domains, settings, support messages, and account activity.
- Website analytics: random visitor and session identifiers, event times, page paths, referrer paths, campaign source and tags, broad device type, and events or properties supplied by a website operator. An operator can also supply a user identifier. These identifiers can link activity over time; they are not a promise that a person cannot be identified.
- Revenue information: payment-provider account, customer, checkout, order, payment, and refund identifiers; dates; payment status; amounts; currency; live or test mode; and attribution references that link a payment to a visit.
- Flow subscription information: your selected plan, usage, Stripe customer and subscription identifiers, and payment status. Stripe processes your card information. Flow does not store full card numbers or card security codes.
- Connection and security information: internet requests expose an IP address and browser information to our network and hosting services. We use technical information for delivery, rate limits, and security. Full IP addresses are not stored as Flow analytics event fields.
The standard tracker removes query strings and fragments from page and referrer URLs. It filters some common sensitive property names. These filters do not remove every possible personal detail: paths, campaign tags, custom events, and user identifiers can still contain information supplied by a customer. Customers must not send passwords, card details, or sensitive personal information in tracking events.
3. How we use information
We use information to create accounts, deliver reports, connect visits with revenue, manage subscriptions and usage limits, answer support requests, prevent abuse, fix faults, and meet legal obligations. We do not sell personal information or use customer analytics or payment data for cross-site targeted advertising.
Where a legal basis is required for information we control, we rely on performance of our agreement, legitimate interests in operating and securing the service, legal obligations, or consent where required. Customers determine the appropriate legal basis for analytics on their own websites.
4. Stripe and other payment integrations
When you connect Stripe through the Flow Stripe App, Stripe shows the permissions for your approval. Flow uses the connection to read account details, Balance, Charges and Refunds, and Checkout Sessions. It uses this data to confirm your account and payment mode, import payments and refunds, and link checkouts to website visits. Flow does not use this connection to create charges, issue refunds, or move money.
Stripe API responses can contain more information than a report needs. Flow stores the reporting fields described above, rather than full Stripe response objects. OAuth access and refresh tokens, manual API keys, and provider signing secrets are encrypted in the application database. A manual key’s permissions depend on the key you provide; use the limited permissions shown in the setup flow.
Other supported providers send signed payment and refund notifications after you configure their webhooks. Each provider has its own privacy policy and terms. Stripe’s handling of information is described in the Stripe Privacy Policy.
You can disconnect an integration in Flow to remove its stored connection credentials and stop new imports. To revoke a Stripe App authorization at Stripe, also uninstall Flow in Stripe’s Installed apps settings. For a manual connection, revoke the key or remove the webhook in the provider’s dashboard. Disconnecting does not delete report history or cancel a Flow subscription.
5. Cookies and browser storage
Flow uses an essential, HTTP-only session cookie for account sign-in. It expires after eight hours. The analytics tracker uses first-party browser storage for a random visitor ID, session and campaign information, queued events, and opt-out choices. Some values remain until the site clears them or you clear browser storage.
The standard tracker stops collection when Global Privacy Control or Do Not Track is enabled. Website operators can configure it to wait for consent and can call its consent and opt-out controls. A customer’s consent setup and any other tracking on its site are that customer’s responsibility. Clearing browser storage can also clear an opt-out choice.
7. Storage, security, and retention
Flow applies access controls, password hashing, HTTPS for the hosted service, and encryption for stored integration credentials and backups. No service can guarantee complete security. Keep your credentials private and report a suspected security issue to our contact address.
Live analytics and imported revenue records are subject to a 12-calendar-month retention window. Account settings, subscription records, and support correspondence remain as needed to provide the service, resolve disputes, and meet legal obligations. Disconnecting an integration keeps existing report history until it expires or is deleted.
Encrypted backups normally rotate on a 30-day schedule. Deleted data can remain in a backup until that backup is removed. A retained recovery copy can remain longer if backup jobs fail or retention is legally required. Backups are used for recovery, not normal reporting.
Information may be processed where Flow and its service providers operate, including the United States. Applicable safeguards are required where data protection law restricts a transfer. Contact us before sending data that requires a specific hosting location, transfer agreement, or data processing agreement.
8. Access, deletion, and other choices
You can update project settings, export available reports, disconnect providers, and delete projects through Flow. For account deletion or a request to access, correct, delete, restrict, or receive a copy of personal information, email pfcteam@prepforcerts.org. We may need to verify the request and identify the relevant account or website. Do not send passwords or payment secrets.
Your rights depend on your location and may include objection to processing, withdrawal of consent, and a complaint to a data protection authority. We respond within the period required by applicable law. Some records may need to be kept for legal or security reasons. Removing a visitor’s link from revenue records can leave payment totals in reports.
If you are a visitor to a customer’s website, contact that website operator for a request about its analytics. We assist customers with requests concerning the data we process for them.
9. Children
Flow is a business service and is not directed to children under 13. Customers must not knowingly use it to collect personal information from children under 13 without the legal authority and safeguards required for that activity. Contact us if you believe such information was sent to Flow.
10. Changes and contact
We will update the effective date when this policy changes. We will provide additional notice of material changes where required. For privacy questions or requests, contact pfcteam@prepforcerts.org.