Privacy Policy
Last updated: July 23, 2026
This Privacy Policy explains how Flowly (“Flowly”, “we”, “us”) collects, uses, stores, and protects personal information when you use our CRM and appointment-booking platform (the “Service”). By using the Service you agree to the practices described here.
1. Who we are
Flowly is the data controller for the information described in this policy. For any question about this policy or to exercise your rights, contact us at anthonyautomates.dev@gmail.com.
2. Information we collect
- Account data: your name, email address, and login credentials when you create an account.
- CRM data you enter: the information about your leads, clients, bookings, forms, invoices, and workflows. You are responsible for this data.
- Data from people who book: name, email, phone, and any answers a visitor provides when booking an appointment through your booking page.
- Technical & usage data: IP address, browser type, pages visited, and logs needed to operate and secure the Service.
- Connected-integration data: credentials and data you choose to connect (for example Google, Resend, or WhatsApp via Green API).
3. Google user data (Google Calendar & Google Meet)
If you connect your Google account, Flowly requests only the minimum permissions needed for the booking module. Through the Google APIs, Flowly accesses:
- Your basic profile (email, name, and picture) to display the connected account.
- The list of your calendars, so you can choose which one receives bookings.
- Your availability (free/busy), so the Service does not offer times when you are already busy. This permission does not let us read the contents of your events.
- The ability to create, update, and delete the events that Flowly itself creates (your bookings), including the automatic generation of Google Meet links.
We use this data exclusively to create and keep your booking events in sync, generate Google Meet links, and calculate your availability. We do not use Google user data for advertising, we do not sell it, and we do not transfer it to third parties for purposes other than providing the Service. No human reads your Google data except where strictly necessary for security, to comply with the law, or with your explicit consent.
Flowly's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can revoke Flowly's access to your Google account at any time, either from the Integrations section inside the app or from your Google account permissions page.
4. Purpose and legal basis
We process your data to provide and maintain the Service, manage your account, process bookings, send Service-related communications, and comply with legal obligations. The legal bases are the performance of our contract (these terms), your consent (for example when connecting Google), and our legitimate interest in operating and securing the platform.
5. How we protect your data
We apply reasonable technical and organizational measures. Connections are encrypted with HTTPS/TLS. Google access and refresh tokens are stored encrypted at rest (AES-256-GCM) and are only accessible to server-side processes; they are never exposed to your browser. Access to data is restricted through row-level security policies.
6. Service providers
We rely on trusted providers that act as data processors:
- Cloudflare — application hosting and execution.
- Supabase — database and authentication.
- Google — Google Calendar and Google Meet, when you connect your account.
- Resend — transactional email, if you connect it.
- Green API — WhatsApp messaging, if you connect it.
7. Data retention
We keep your data for as long as you maintain an active account and as long as necessary to meet legal obligations. When you delete data or close your account, we delete or anonymize it within a reasonable period, unless the law requires us to keep it.
8. International transfers
Some providers may process data outside the European Economic Area. In those cases we ensure appropriate safeguards are in place, such as the European Commission's standard contractual clauses.
9. Your rights
You may exercise your rights of access, rectification, erasure, restriction, portability, and objection by writing to anthonyautomates.dev@gmail.com. You also have the right to lodge a complaint with the competent supervisory authority.
10. Cookies
We use strictly necessary cookies to sign you in and keep your session secure. We do not use third-party advertising cookies.
11. Children
The Service is not directed to children under 16, and we do not knowingly collect their data.
12. Changes to this policy
We may update this policy from time to time. We will post the revised version on this page and update the “Last updated” date.
13. Contact
If you have any question about this policy, email us at anthonyautomates.dev@gmail.com.