Privacy Policy
Last updated: July 17, 2026
This policy explains what FlowPay ("we") collects, why, and what we do with it, across takeflowpay.com (the marketing site) and app.takeflowpay.com (the product). The short version: we collect what we need to run split-fee collection, Stripe handles all card data, and we do not sell personal information.
What we collect
- Account data: name, email, practice details, and the information needed to create your Stripe connected account. Sign-in is handled by Auth0; we do not store your password.
- Invoice data you enter: names and email addresses of the parties you invoice, invoice amounts and split shares, and per-party payment status.
- Payment data:processed by Stripe on Stripe's systems. Card numbers never touch FlowPay: every payment link is Stripe-hosted checkout. We receive payment metadata from Stripe (amounts, payment status, transaction references) to keep your invoice records current.
- Usage data: standard server logs (such as IP address and request times) for security and debugging, and marketing-site analytics as described below.
Analytics and cookies
The marketing site uses PostHog to count page views and see which pages and tools (like the pricing calculator) get used. PostHog stores a first-party identifier in cookies or browser storage to tell visits apart, and is configured to build an identified profile only if you identify yourself; ordinary browsing is recorded without one. The product at app.takeflowpay.com does not load PostHog, and payer data is never sent to analytics. We do not use advertising trackers.
Whose data it is
For your account data, FlowPay decides how and why it is processed. For the party names and email addresses you enter, you (the practice) are the controller of your clients' data: FlowPay processes it on your behalf to run collection, under our Data Processing Addendum.
What we use it for
To operate the Service: emailing each party its payment link and receipt, emailing a fresh link for the remaining balance when a partial payment lands, showing you per-party payment status, and sending account emails. Also to secure and debug the Service and to understand aggregate usage. We do not sell personal information and we do not use payer data for marketing. Parties to an invoice receive only emails about that invoice.
Who processes it for us
Our processors: Stripe (payment processing and merchant onboarding), Amazon Web Services (hosting and email delivery, US regions), Auth0 by Okta (authentication), and PostHog (marketing-site analytics). Each processes data only to provide its service to us.
Retention and deletion
We keep account and invoice records while your account is active and as required for legal, tax, and dispute-handling purposes. You can request deletion of your account data at hello@takeflowpay.com; we will delete what we are not legally required to retain. Payment records held by Stripe remain in your own Stripe account and under Stripe's policies.
Security
Data is encrypted in transit and at rest, and access to production data is limited to those who need it to run the Service. Card data is handled exclusively by Stripe's PCI-compliant infrastructure. Report vulnerabilities to security@takeflowpay.com.
Your rights
Depending on where you live, including under the GDPR and the CCPA, you may have rights to access, correct, delete, or export your personal information, and to object to or restrict certain processing. Write to hello@takeflowpay.com and we will honor applicable rights within the legally required time; we will not treat you differently for exercising them. Because we do not sell personal information, there is no sale to opt out of. If you are a party on an invoice, we may direct part of your request to the professional who invoiced you, since they control that relationship, and we will assist them in responding.
Changes and contact
We will announce material changes to this policy by email or in the Service before they take effect. Questions: hello@takeflowpay.com. For processing on behalf of practices subject to data-protection agreements, see our Data Processing Addendum.