Flowral Flowralby WIINK
Features Who it's for How it works Pricing
Sign in Start free
Legal

Privacy Policy

Last updated: 27 July 2026 · Effective: 27 July 2026

Draft — not yet reviewed by a lawyer. The technical detail here reflects how Flowral actually works today, but every field marked LIKE THIS must be completed, and the document should be reviewed by counsel before publication. Verify the sub-processor list against your live infrastructure before relying on it. Delete this banner once that's done.

Contents

  1. Who controls your data
  2. Our role: controller or processor
  3. What we collect
  4. Why, and on what legal basis
  5. Who we share it with
  6. International transfers
  7. How long we keep it
  8. How we protect it
  9. Your rights
  10. Cookies & local storage
  11. Guests & clients
  12. Children
  13. Changes
  14. Contact

This policy explains what Flowral collects, why, who else sees it, and what you can do about it. We've tried to describe the system as it actually is rather than in generalities.

The short version: we collect what's needed to run your workspace and bill you, we don't sell anything to anyone, we don't use your project content for advertising, and we don't train AI models on it.

1. Who controls your data

The data controller is LEGAL ENTITY NAME, REGISTERED ADDRESS, COUNTRY. Contact: hello@wiink.io. Our data protection contact is DPO NAME / EMAIL, or "not required — see below".

2. Our role: controller or processor

The distinction matters for who you go to about what:

  • For account and billing data — your name, email, subscription — we are the controller.
  • For content inside a workspace — flows, tasks, comments, attachments — we act as a processor on behalf of the workspace owner, who is the controller. If you're a member or guest of someone else's workspace and want content removed, ask the workspace owner first; we act on their instructions.

3. What we collect

CategoryWhat exactlyWhere it comes from
AccountName, email address, profile picture, sign-in providerYou, or the provider you sign in with (Google, Microsoft, WIINK)
CredentialsIf you use a password, a salted hash — never the password itselfYou
WorkspaceWorkspace name and logo, membership and roles, invitations you sendYou and your teammates
Project contentFlows, tasks, sub-tasks, dependencies, notes, tags, comments, completion stateYou and your teammates
AttachmentsFiles you upload to tasks and commentsYou
ActivityA log of changes — who did what, and whenGenerated as you use the app
SessionsA session identifier stored in your browser to keep you signed inGenerated at sign-in
BillingSubscription status, seat count, renewal date, and identifiers issued by StripeStripe
TechnicalServer logs, including IP address and error diagnosticsGenerated automatically

We never see your card details. Payment pages are hosted by Stripe; card numbers go to Stripe directly and never touch our servers. We store only the customer and subscription identifiers Stripe gives us.

4. Why, and on what legal basis

PurposeLegal basis (GDPR Art. 6)
Providing the Service — running your workspace, storing your flowsPerformance of a contract
Authentication and keeping accounts securePerformance of a contract; legitimate interests (security)
Taking payment and issuing invoicesPerformance of a contract; legal obligation (tax records)
Transactional email — invites, sharing notices, billing noticesPerformance of a contract
Diagnosing faults and preventing abuseLegitimate interests (a working, secure service)
Product updates and marketing emailConsent — and you can withdraw it at any time

What we don't do: we don't sell personal data, we don't share it with advertisers, we don't use your project content to train machine-learning models, and we don't profile you for automated decisions with legal effects.

5. Who we share it with

We use a small number of service providers ("sub-processors"). Each is bound by contract to protect your data and use it only on our instructions.

ProviderWhat they doData involved
StripePayments, invoicing, tax calculationName, email, billing address, card details (held by Stripe), tax ID
Amazon Web ServicesFile storage (S3, EU — Ireland) and transactional email (SES)Attachments you upload; recipient address and content of transactional emails
Google · Microsoft · WIINKOptional single sign-on, only if you choose that methodYour name, email and profile picture, released by them to us at sign-in
HOSTING PROVIDERApplication and database hostingAll of the above at rest

We may also disclose data where legally required — a valid court order, for example — or to establish or defend legal claims. If a business transfer ever occurred, we would tell you before your data became subject to a different policy.

6. International transfers

Your data is stored in PRIMARY DATA LOCATION, e.g. the EU (Ireland). Some providers may process data outside the EEA; where that happens we rely on the European Commission's Standard Contractual Clauses or an adequacy decision.

7. How long we keep it

  • Workspace content — for as long as the workspace exists. Deleting a flow removes it from the app; residual copies may persist in encrypted backups for up to BACKUP WINDOW, e.g. 30 days.
  • Account data — until you delete your account, plus RETENTION PERIOD, e.g. 30 days to allow recovery from mistaken deletion.
  • Invoices and tax records — retained as long as tax law requires, typically e.g. 7–10 years.
  • Server logs — LOG RETENTION, e.g. 90 days.

Downgrading from Pro to Free deletes nothing. A failed payment deletes nothing.

8. How we protect it

  • All traffic is encrypted in transit with TLS, and data is encrypted at rest.
  • Passwords are stored as salted hashes; we cannot read them.
  • Attachments live in a private bucket that is never publicly listable. Downloads use short-lived signed links that expire in minutes.
  • Access to production systems is limited to staff who need it.

No system is perfectly secure. If a breach affects your personal data and is likely to put your rights at risk, we will notify the relevant supervisory authority within 72 hours and tell you without undue delay.

9. Your rights

If you're in the EEA or UK, you have the right to access your data, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent where consent is the basis.

Email hello@wiink.io and we'll respond within one month. If we're acting as a processor for a workspace you don't own, we'll forward your request to that workspace's owner and support them in answering it.

You also have the right to complain to your local data protection authority — in COUNTRY, that is SUPERVISORY AUTHORITY.

10. Cookies & local storage

Flowral is deliberately light here. We use no advertising cookies and no third-party analytics trackers.

  • Session token — stored in your browser's local storage to keep you signed in. Strictly necessary.
  • Preferences — small local-storage entries such as your light/dark theme and last-opened flow. Strictly necessary for the app to behave as you left it.
  • Stripe — sets its own cookies on its hosted checkout pages, for fraud prevention. See Stripe's privacy policy.

Because we set no non-essential cookies, there's no consent banner to click through. If that ever changes, we'll ask first.

11. Guests & clients

A flow can be shared with someone outside the workspace. If you're a guest, we hold your name and email so access can be granted and the person who invited you can see who has access. Guests see only the flows shared with them. The workspace owner controls that sharing — including revoking it.

12. Children

Flowral is a tool for work and is not directed at children. We don't knowingly collect data from anyone under 16. If you believe a child has given us personal data, contact us and we'll delete it.

13. Changes

We'll update this policy as the product changes. The "last updated" date at the top always reflects the current version, and for material changes we'll notify you by email or in the app before they take effect.

14. Contact

Privacy questions, or to exercise any right above: hello@wiink.io, or write to LEGAL ENTITY NAME, REGISTERED ADDRESS.

Flowral Flowralby WIINK

The project tool that shows your team exactly what's ready to work on — built for agencies and teams that ship client work.

Product

Features Who it's for How it works Pricing

Use cases

Creative & marketing Dev & product studios Consulting & services Talk to us

Company

Contact Privacy Terms
© 2026 Flowral — flowral.app · All rights reserved. A WIINK product — made for teams that ship.