Privacy Policy
Last updated: April 26, 2026
Flowipy ("we", "us", "our") respects your privacy and is committed to protecting your personal data in compliance with the General Data Protection Regulation (GDPR).
Data Controller
Flowipy, operated by Hoffstedts (Sweden), is the data controller for your account data. Contact: info@flowipy.com.
Data We Collect
- Account data: name, email address, business name, phone number
- Billing data: processed securely by Stripe (we do not store credit card numbers)
- Usage data: pages visited, features used, IP address, browser type
- Customer data: your end-users' names, emails, and booking details (you are the data controller for this data)
How We Use Your Data
- To provide and maintain the service
- To process payments via Stripe
- To send transactional emails (booking confirmations, account notifications)
- To improve our product based on aggregated usage patterns
Legal Basis for Processing (GDPR Article 6)
- Contract performance: processing necessary to provide the service you subscribed to
- Legitimate interest: analytics and product improvement
- Consent: marketing emails (only with your explicit opt-in)
Data Processing Agreement (DPA)
When your customers book through Flowipy, you are the Data Controller and Flowipy acts as the Data Processor. We only process customer data on your behalf and according to your instructions to facilitate bookings.
Third-Party Services
- Stripe (payments) — stripe.com/privacy
- Supabase (hosting & database) — EU data centers
- MailerLite (newsletters, if enabled) — mailerlite.com/legal/privacy-policy
- MailerSend (transactional email) — GDPR compliant
Data Retention
We retain your account data for as long as your account is active. After account deletion, we remove your personal data within 30 days. Backups may retain data for up to 90 days.
Your Rights Under GDPR
You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your data ("right to be forgotten")
- Export your data in a portable format
- Object to processing based on legitimate interest
- Withdraw consent at any time
To exercise these rights, email info@flowipy.com.
International Transfers
Your data is primarily stored in EU data centers. If any data is transferred outside the EU, we ensure appropriate safeguards (e.g., Standard Contractual Clauses).
Changes
We may update this policy. Significant changes will be communicated via email.
