Privacy

Privacy Policy

How Flowmails collects, uses, stores, and shares the data you provide when you use our custom-domain email platform.

Last updated 2026-07-03.

1 · Data controller

The data controller for the Service is:

  • Operator: Flowmails — operated by an individual independent developer (sole trader). No registered business entity or registered address exists; the operator is reachable at the privacy contact below for any data-controller correspondence.
  • Data residency: All personal data we process is stored in Cloudflare’s global edge network and D1 / R2 / KV stores — never on infrastructure we operate ourselves. Cloudflare data centres are located in the United States, the European Union, the Asia-Pacific region, and other locations Cloudflare operates in (see Cloudflare’s network map).
  • Privacy contact: support@flowmails.net
  • Data Protection Officer: not currently appointed. For any privacy matter, contact the privacy email above and a member of theFlowmails team will respond.

2 · What we collect

2.1 Information you give us. Account information (name, email, hashed password); payment information (transaction amount, payment status, currency, order id) — we do not store full card numbers; card data is handled by the payment processor (see §5); support correspondence (emails, tickets, and feedback you send us).

2.2 Information we collect automatically. Device and network information (IP address, device model, operating system, browser type, timezone); usage data (pages visited, features used, action logs, session length); and log data (request times, error logs, performance metrics).

2.3 Third-party login (Google). When you sign in with Google, we receive the basic profile information (name, email, profile photo URL) that you authorise Google to share. We do not receive your Google password or your contact list.

3 · How we use your data

We use the data we collect to operate the Service, bill you, support you, and meet our legal obligations. The table below sets out each purpose, the categories of data involved, and the legal basis under the EU GDPR that authorises the processing.

PurposeLegal basis
Provide and maintain the ServiceContract performance
Billing and payment processingContract performance
Customer supportContract performance / legitimate interest
Service notices (billing, security, policy updates)Legitimate interest
Security and fraud preventionLegitimate interest
Product analytics and improvementLegitimate interest
Legal complianceLegal obligation

We may aggregate or de-identify data for statistical analysis. Aggregated data cannot be linked back to an individual.

4 · Cookies and tracking

The Service uses a small number of cookies and similar storage technologies, classified below.

TypePurposeCan you disable?
Strictly necessaryAuthentication, security, and core functionalityNo
FunctionalRemembering UI preferences (e.g. last-visited tab)Yes
AnalyticsAnonymous usage statistics that help us improve the productYes

We do not currently use marketing cookies or third-party advertising trackers. You can adjust your preferences through your browser’s cookie settings at any time.

5 · Sharing and disclosure

We do not sell your personal information, including as “sale” is defined under applicable law (such as the California Consumer Privacy Act). We share your information only with the parties listed below, and only to the extent necessary to deliver the Service.

  • Service providers. Cloud infrastructure (Cloudflare Workers, D1, R2, KV, Email Services), payment processors, customer support tooling, and analytics providers — each bound by a confidentiality agreement. Card data is processed exclusively by our PCI-DSS-compliant payment processors (Waffo Pancake for the Waffo gateway; Creem and PayPal for the alternative gateways) and is never stored on our servers.
  • Legal and regulatory. Where required by valid law, court order, or a competent regulatory authority.
  • Business transactions. If Flowmails is acquired, merged, or sells substantially all of its assets, your information may be transferred — with notice to you and the same level of protection under this Policy.
  • With your consent. For any other purpose, with your explicit prior consent.

6 · Data security

We protect your data with technical and organisational measures designed for the risks involved:

  • Encryption in transit: all client traffic uses TLS 1.2 or higher.
  • Encryption at rest: passwords are stored as salted hashes; sensitive tokens and API keys are stored encrypted at rest.
  • Access control: least-privilege access; employees and contractors are bound by confidentiality and access is logged.
  • Audits: periodic security reviews and vulnerability scanning of the production environment.

If a security incident affects your rights, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the incident, in line with GDPR Article 33. Please keep your account credentials confidential; never share them with anyone.

7 · Data retention

We keep your data only for as long as we need it for the purposes set out in §3, or as required by law. The table below shows the retention windows currently in force.

Data typeRetentionAt expiry
Account informationFor the lifetime of the account; 90 days after cancellationDeleted or anonymised
Transaction records1 years (per local tax / accounting requirements)Archived then deleted
Support correspondence1 yearsSecurely deleted
Security audit logs3 monthsSecurely deleted

8 · Your data rights

Subject to applicable law (including the EU GDPR and the UK GDPR), you have the following rights with respect to your personal data:

  • Right to be informed: know what data we collect and how we use it (this Policy).
  • Right of access: request a copy of the personal data we hold about you.
  • Right to rectification: correct inaccurate or incomplete information.
  • Right to erasure: request deletion of your data in certain circumstances.
  • Right to restrict processing: limit how we process your data in certain circumstances.
  • Right to data portability: receive your data in a structured, machine-readable format.
  • Right to object: object to processing based on legitimate interest or for direct marketing.
  • Right to withdraw consent: where processing is based on consent, withdraw it at any time without affecting prior lawful processing.

To exercise any of these rights, email support@flowmails.net with your account email and a description of the request. We will respond within 30 calendar days. If you believe we have not handled your request properly, you have the right to lodge a complaint with your local data protection authority.

9 · Marketing and opt-out

We do not currently send marketing email. We may occasionally send product updates — for example, a notice about a new plan tier or a major feature release. If you would prefer not to receive those messages, follow the unsubscribe link in the email or contact us at support@flowmails.net. Service-essential notices (billing, security incidents, policy changes) are not affected by this opt-out.

10 · International data transfers

The Service is built on Cloudflare’s global network, and the data we process may be stored or processed in Cloudflare data centres outside your country of residence (including, potentially, the United States, Singapore, and the European Union). When we transfer personal data across borders, we rely on the European Commission’s Standard Contractual Clauses (SCCs) and equivalent safeguards to ensure your data remains protected to the standards set out in this Policy.

11 · Children’s privacy

The Service is intended for users who are at least 18 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at support@flowmails.net and we will delete the information promptly.

12 · Third-party links and services

The Service may contain links to third-party websites or integrate with third-party services (such as Cloudflare Email Services, Cloudflare Email Routing, and Cloudflare Workers). This Policy applies only to the data we collect directly. We are not responsible for the privacy practices of third parties, and we encourage you to read their policies before providing them with your information.

13 · Changes to this Policy

We may update this Policy from time to time. For material changes, we will give you at least 15 days’ notice by email and update the “Last updated” date at the top of this page. Continued use of the Service after the effective date constitutes acceptance of the revised Policy.