Flowchef Flowchef

Privacy Policy

Last updated: April 24, 2026

1. Scope and Purpose

Flowchef ("Flowchef", "we", "our", or "us") provides workflow automation software for teams and businesses. This Privacy Policy explains what personal data we collect, how we use and protect it, and what controls are available to you.

This policy applies to our public website, product applications, support channels, and related services. If you use Flowchef through an organization account, that organization may control your workspace data and account settings.

2. Data We Collect

Account and identity data: name, email, password hash, authentication events, organization/workspace membership, and profile preferences.

Workspace and workflow data: flow definitions, workflow metadata, connected app configuration, execution results, run counts, scheduling data, and operational logs generated when automations run.

Integration and token data: connection credentials or authorization tokens required to operate your configured integrations. Sensitive credentials are stored using encrypted storage controls and are processed only to run your workflows.

Billing data: plan selection, billing cycle, invoice references, subscription status, tax or country data, and limited payment metadata. Full card numbers are processed by our payment provider and are not stored by Flowchef.

Support and communications: tickets, contact form submissions, troubleshooting files, and communications you send to us.

Device and usage telemetry: IP address, browser type, device and OS information, pages visited, feature usage events, error logs, and security signals.

3. How We Use Data

We use collected information to provide and operate the service, including account access, workflow execution, subscription management, customer support, and reliability monitoring.

We also use data to detect abuse, investigate incidents, enforce product limits, improve usability, and communicate important service or legal notices.

Where required by law, we process data under one or more legal bases such as contract necessity, legitimate interests, legal obligations, and consent (for example, for optional marketing communications or non-essential cookies).

4. Processing of Workflow and Third-Party App Data

Flowchef processes data that you intentionally route through your flows. You control what systems are connected and what data fields are transferred between services.

Third-party apps connected through Flowchef have their own terms and privacy policies. We are not responsible for third-party handling practices once data is sent based on your configuration.

5. Billing and Payment Processing

We use third-party payment infrastructure (currently Polar) to process subscription payments, invoices, taxes, and renewals. Those providers process payment instruments under their own compliance programs and privacy terms.

Flowchef receives limited billing records needed for plan enforcement, fraud checks, accounting, and support.

6. Analytics, Product Improvement, and AI Features

We use operational analytics to understand platform performance, reliability, and feature adoption. Analytics are used to improve product quality, support planning, and security response.

When AI-assisted features are offered, data sent to those features is processed to provide that functionality. We do not sell customer personal data, and any broader data use is handled under this policy and applicable law.

7. How We Share Information

We may share data with:

  • cloud infrastructure, database, storage, observability, communications, and support vendors acting as service providers;
  • payment providers and financial partners for billing and fraud prevention;
  • professional advisors (legal, audit, and compliance) under confidentiality obligations;
  • authorities where required by law or lawful process;
  • a successor entity in a merger, acquisition, financing, or asset sale.

We do not sell personal information. We do not permit processors to use customer data for unrelated independent purposes.

8. International Data Transfers

Flowchef and our providers may process data in multiple countries. When data is transferred across borders, we use recognized transfer mechanisms and contractual safeguards as required by applicable privacy law.

You may contact us to request additional information about transfer safeguards relevant to your account.

9. Hosting, Storage, and Resilience

Flowchef runs on managed cloud infrastructure and Linux-based production systems, including relational databases, queue systems, and object storage compatible with Amazon S3-style services.

We maintain redundancy and backup procedures designed to reduce data loss risk. Disaster recovery runbooks and restoration procedures are reviewed and tested periodically.

Region strategy may vary by environment and customer requirements; deployment and residency details can be discussed for enterprise requests.

10. Security Measures

Our security program includes technical, administrative, and organizational controls designed for a multi-tenant SaaS platform.

  • Encryption in transit: data is transmitted over TLS (typically TLS 1.2+), including browser sessions and API traffic.
  • Encryption at rest: databases, backups, and object storage are encrypted at rest where supported by our providers.
  • Credential protection: passwords are stored as one-way hashes (bcrypt), and secrets are protected through restricted access and encryption controls.
  • Access control: role-based permissions, least-privilege access, environment separation, and controlled administrative workflows.
  • Internal safeguards: logging, monitoring, and auditable administrative actions for security and operational review.

11. Data Retention and Deletion

Retention periods depend on data type, plan level, legal obligations, and security needs.

  • Account and workspace data: generally retained while an account is active.
  • Operational and security logs: retained for a limited period to support reliability, billing verification, and abuse prevention.
  • Billing and financial records: retained as required by tax, accounting, and anti-fraud obligations.
  • Backups: deleted on a rolling schedule after expiry of backup retention windows.

Customers can request account deletion or data deletion through account controls or by contacting support. Following confirmed deletion, active systems are targeted for removal promptly, and residual copies may persist temporarily in backup media.

12. Your Privacy Rights and Controls

Depending on your location, you may have rights to access, correct, export, restrict, object to, or delete personal data, and to withdraw consent for consent-based processing.

We also provide in-product controls for account management, workspace membership, and connected app settings. If your account is managed by an organization, requests may need administrator approval.

13. Cookies and Similar Technologies

We use cookies and similar technologies for authentication, session continuity, security, and product analytics. Some cookies are essential to make the service function.

Where required, we request consent for non-essential cookies and provide controls through cookie banners or browser settings. Blocking essential cookies may affect site or product functionality.

14. Government and Legal Requests

We may disclose information when required by applicable law, subpoena, court order, or lawful government request.

Where legally permitted, we seek to narrow overbroad requests and may notify affected customers before disclosure.

15. Incident Response and Breach Notification

We maintain incident response procedures for triage, containment, eradication, recovery, and post-incident review. If a confirmed incident affects personal data, we will notify impacted customers and relevant authorities when required by law.

16. Compliance and Documentation

Our privacy and security program is designed to align with GDPR principles and commonly used control frameworks. We continuously improve controls related to access management, change management, secure development, and monitoring.

We can provide a Data Processing Addendum (DPA) and selected security or legal documentation for eligible customers. To request these materials, contact us using the details below.

17. Children's Privacy

Flowchef is intended for professional use and is not directed to children. We do not knowingly collect personal data from children under the age of 18.

18. Changes to This Policy

We may update this policy from time to time to reflect legal, operational, or product changes. Material updates will be posted on this page and, when appropriate, communicated through email or in-product notices.

19. Data Minimization and Purpose Limitation

We design product and operational workflows to collect and retain only the data reasonably needed to provide, secure, and improve the Service. Internal teams are expected to follow data handling standards that align access with business need and approved support or operational purposes.

We avoid using customer automation payloads for unrelated commercial profiling. Where product telemetry is used, we prioritize aggregate or pseudonymized analysis patterns where feasible.

20. AI and Model Training Commitments

Flowchef may provide AI-assisted capabilities for specific user workflows. Unless explicitly disclosed for a particular feature, we do not use customer workflow payloads to train generalized public models for unrelated third-party use.

Any AI provider used to deliver product functionality is evaluated as a processor under contractual and security controls, with use restricted to delivering requested feature outcomes.

21. Subprocessors and Vendor Governance

We rely on specialized infrastructure and service providers (for example cloud hosting, email delivery, monitoring, and billing) to operate Flowchef. Vendors handling customer data are subject to security and contractual review proportionate to service risk.

We maintain controls for vendor onboarding, least-privilege access, and periodic reassessment. For eligible customers, we can provide subprocessor and data handling details through our legal/security documentation workflow.

22. Security Operations and Assurance

Our security program includes ongoing monitoring, alerting, and operational review processes. We apply secure development and change management practices intended to reduce deployment risk and improve reliability.

We continuously mature controls with reference to recognized security frameworks, including GDPR accountability principles and control sets commonly associated with SOC 2 and ISO/IEC 27001-aligned programs. We can share additional security documentation for qualified customers where appropriate.

23. Data Residency and Transfer Safeguards

Customer data may be processed in multiple regions based on service architecture and vendor capabilities. For international transfers, we implement contractual and organizational safeguards intended to satisfy applicable legal requirements.

For customers with specific residency or transfer requirements, our team can discuss available deployment and contractual options through sales or support channels.

24. Business Continuity, Backup, and Recovery

Flowchef maintains backup and restoration processes designed to support continuity in the event of infrastructure disruption. We use redundancy-aware architecture across key service components and periodically review incident and recovery runbooks.

While no platform can guarantee zero-risk outcomes, our objective is to provide resilient service operations and transparent communication when materially relevant outages or incidents occur.

25. Contact Us and Documentation Requests

For privacy requests, DPA inquiries, subprocessor details, or security/legal documentation (including enterprise security questionnaires and available whitepaper materials), contact support@flowchef.io or use our support page at /support .