Flow.

Privacy Policy

Effective September 21, 2026

This policy explains how Flow handles information through buyflow.io, its website analytics service, and its payment-provider integrations, including the Flow Stripe App.

Privacy contact: pfcteam@prepforcerts.org

If you visit a website that uses Flow, that website’s operator controls its tracking setup. Contact that operator first about its data use. We can help route a request.

1. Who this policy covers

Flow is operated by Brian Reynolds in the United States (“we,” “us,” or “our”). We provide website analytics and revenue attribution. We handle account, billing, support, and service-security information to operate our service. For analytics collected on a customer’s website, we process information on that customer’s instructions. That customer is responsible for its notices, lawful basis, and any required consent.

This policy applies to the hosted service at buyflow.io.

2. Information we handle

The standard tracker removes query strings and fragments from page and referrer URLs. It filters some common sensitive property names. These filters do not remove every possible personal detail: paths, campaign tags, custom events, and user identifiers can still contain information supplied by a customer. Customers must not send passwords, card details, or sensitive personal information in tracking events.

3. How we use information

We use information to create accounts, deliver reports, connect visits with revenue, manage subscriptions and usage limits, answer support requests, prevent abuse, fix faults, and meet legal obligations. We do not sell personal information or use customer analytics or payment data for cross-site targeted advertising.

Where a legal basis is required for information we control, we rely on performance of our agreement, legitimate interests in operating and securing the service, legal obligations, or consent where required. Customers determine the appropriate legal basis for analytics on their own websites.

4. Stripe and other payment integrations

When you connect Stripe through the Flow Stripe App, Stripe shows the permissions for your approval. Flow uses the connection to read account details, Balance, Charges and Refunds, and Checkout Sessions. It uses this data to confirm your account and payment mode, import payments and refunds, and link checkouts to website visits. Flow does not use this connection to create charges, issue refunds, or move money.

Stripe API responses can contain more information than a report needs. Flow stores the reporting fields described above, rather than full Stripe response objects. OAuth access and refresh tokens, manual API keys, and provider signing secrets are encrypted in the application database. A manual key’s permissions depend on the key you provide; use the limited permissions shown in the setup flow.

Other supported providers send signed payment and refund notifications after you configure their webhooks. Each provider has its own privacy policy and terms. Stripe’s handling of information is described in the Stripe Privacy Policy.

You can disconnect an integration in Flow to remove its stored connection credentials and stop new imports. To revoke a Stripe App authorization at Stripe, also uninstall Flow in Stripe’s Installed apps settings. For a manual connection, revoke the key or remove the webhook in the provider’s dashboard. Disconnecting does not delete report history or cancel a Flow subscription.

5. Cookies and browser storage

Flow uses an essential, HTTP-only session cookie for account sign-in. It expires after eight hours. The analytics tracker uses first-party browser storage for a random visitor ID, session and campaign information, queued events, and opt-out choices. Some values remain until the site clears them or you clear browser storage.

The standard tracker stops collection when Global Privacy Control or Do Not Track is enabled. Website operators can configure it to wait for consent and can call its consent and opt-out controls. A customer’s consent setup and any other tracking on its site are that customer’s responsibility. Clearing browser storage can also clear an opt-out choice.

6. When information is shared

Authorized Flow personnel can access information when needed to operate, secure, or support the service. We use service providers for network delivery and security, payment processing, email, and related operations. Cloudflare delivers and protects buyflow.io. We also use Cloudflare Web Analytics on buyflow.io to measure visits and page performance through its browser beacon. This monitoring is separate from the Flow tracker installed on customer websites. Stripe processes Flow subscriptions. A payment provider receives the requests and attribution references needed for an integration you enable.

We may disclose information when required by law, to protect rights and security, or as part of a business transfer subject to appropriate protections. We do not make customer reports public by default. Customers can export and share their own reports.

7. Storage, security, and retention

Flow applies access controls, password hashing, HTTPS for the hosted service, and encryption for stored integration credentials and backups. No service can guarantee complete security. Keep your credentials private and report a suspected security issue to our contact address.

Live analytics and imported revenue records are subject to a 12-calendar-month retention window. Account settings, subscription records, and support correspondence remain as needed to provide the service, resolve disputes, and meet legal obligations. Disconnecting an integration keeps existing report history until it expires or is deleted.

Encrypted backups normally rotate on a 30-day schedule. Deleted data can remain in a backup until that backup is removed. A retained recovery copy can remain longer if backup jobs fail or retention is legally required. Backups are used for recovery, not normal reporting.

Information may be processed where Flow and its service providers operate, including the United States. Applicable safeguards are required where data protection law restricts a transfer. Contact us before sending data that requires a specific hosting location, transfer agreement, or data processing agreement.

8. Access, deletion, and other choices

You can update project settings, export available reports, disconnect providers, and delete projects through Flow. For account deletion or a request to access, correct, delete, restrict, or receive a copy of personal information, email pfcteam@prepforcerts.org. We may need to verify the request and identify the relevant account or website. Do not send passwords or payment secrets.

Your rights depend on your location and may include objection to processing, withdrawal of consent, and a complaint to a data protection authority. We respond within the period required by applicable law. Some records may need to be kept for legal or security reasons. Removing a visitor’s link from revenue records can leave payment totals in reports.

If you are a visitor to a customer’s website, contact that website operator for a request about its analytics. We assist customers with requests concerning the data we process for them.

9. Children

Flow is a business service and is not directed to children under 13. Customers must not knowingly use it to collect personal information from children under 13 without the legal authority and safeguards required for that activity. Contact us if you believe such information was sent to Flow.

10. Changes and contact

We will update the effective date when this policy changes. We will provide additional notice of material changes where required. For privacy questions or requests, contact pfcteam@prepforcerts.org.