Privacy Policy

Last updated: April 11, 2025

Introduction

This Privacy Policy explains how we collect, use, store, and protect your data when you use Inflowdash.

For users in the European Union (EU), European Economic Area (EEA), United Kingdom, and Switzerland, we act as a data controller under the General Data Protection Regulation (GDPR) and other applicable data protection laws regarding the personal data we collect through the service.

By using Inflowdash, you agree to the collection and use of information in accordance with this policy.

Information We Collect

Information from Stripe

Inflowdash connects to your Stripe account through the Stripe API and accesses the following types of data:

  1. Subscription details (start dates, end dates, billing cycles)
  2. Revenue information and financial data
  3. Customer payment status
  4. Renewal dates and subscription terms
  5. Customer identifiers (name and email)

Account Information

When you register, we collect:

  1. Your name and email address
  2. Company name
  3. Account preferences and settings

Usage Data

We automatically collect certain information when you use the Inflowdash

  1. Log data (IP address, browser type, pages visited)
  2. Device information
  3. Dashboard interaction data
  4. Feature usage statistics

How We Use Your Information

We use the collected data for the following purposes:

  1. To provide, operate, and maintain the Dashboard functionality (legal basis: performance of contract)
  2. To display your subscription revenue data and renewal calendar (legal basis: performance of contract)
  3. To improve and personalize your user experience (legal basis: legitimate interests)
  4. To send essential notifications about your account or subscriptions (legal basis: performance of contract)
  5. To respond to your inquiries and support requests (legal basis: performance of contract)
  6. To detect and prevent technical issues or unauthorized access (legal basis: legitimate interests)
  7. To comply with legal obligations (legal basis: compliance with a legal obligation)

For each processing activity, we've identified the legal basis under GDPR. We only process personal data when we have a valid legal ground for doing so.

Data Storage and Security

We implement appropriate security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  1. Encryption of sensitive data at rest and in transit
  2. Secure storage of API credentials
  3. Regular security assessments
  4. Limited employee access to your data

Data Sharing and Third Parties

We do not sell, trade, or rent your personal information to third parties. We may share information with:

  1. Service providers who assist us in operating the service (hosting and analytics)
  2. Legal authorities when required by law

Your Rights and Choices

You have the right to:

  1. Access the personal information we hold about you
  2. Correct inaccurate or incomplete information
  3. Request deletion of your data from our systems ("right to be forgotten")
  4. Export your data in a portable format
  5. Restrict or object to our processing of your data
  6. Withdraw consent at any time where we rely on consent to process your information
  7. Lodge a complaint with a supervisory authority
  8. Revoke API access permissions at any time through your Stripe dashboard

For EU/EEA users, these rights are provided under the General Data Protection Regulation (GDPR). We will respond to all requests within 30 days.

Data Retention

We will retain your information only for as long as your account is active or as needed to provide you with our services. We will retain and use your information as necessary to comply with legal obligations, resolve disputes, and enforce our agreements.

Updates to This Policy

We may update this Privacy Policy periodically. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date.

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at [email protected]

California Privacy Rights

If you are a California resident, you have specific rights regarding your personal information under the California Consumer Privacy Act (CCPA). Please contact us to exercise these rights.

International Data Transfers

If you access Inflowdash from the European Economic Area (EEA), UK, or Switzerland, please be aware that your information may be transferred to, stored, and processed in countries outside these regions, including the United States where our servers are located.

For transfers from the EEA to countries not considered adequate by the European Commission, we have put in place appropriate safeguards such as Standard Contractual Clauses (SCCs) to ensure your data is protected. You may request a copy of these safeguards by contacting us using the information provided in the "Contact Us" section.

Data Protection Officer

For users in the EU/EEA, we have appointed a Data Protection Officer (DPO) who is responsible for matters relating to privacy and data protection. You can contact our DPO at [email protected] for any GDPR-related inquiries.

Legal Basis for Processing (GDPR)

We only process personal data when we have a valid legal ground for doing so. The legal grounds depend on the services you use and how you use them. They include:

  1. Processing necessary to perform our contract with you
  2. Processing based on our legitimate interests
  3. Processing based on your consent
  4. Processing necessary to comply with our legal obligations

Automated Decision Making

Inflowdash does not engage in fully automated decision-making that has significant effects on users. Any data analytics features are tools to help you make your own business decisions.