Flowstarter
Privacy

Your data,handled with care.

We collect what we need to build, host, and support your site, and nothing more. No surveillance ad tech, no broker resale, no surprises.

Last updatedMay 2026

Draft: under legal review

The terms below describe our current operating practice and are binding on us. Final wording may be tightened by counsel before our public launch.

1. Who we are

Flowstarter is operated by Darius and Dorin, a two-person studio registered in the European Union. We act as the data controller for the marketing site (flowstarter.net) and as the data processor for the client sites and dashboards we build and host on your behalf. For all data-protection questions, write to privacy@flowstarter.net.

2. What data we collect

We collect the smallest amount of data that lets us deliver the service safely.

  • Account data: name, email, and (for paying clients) billing address and VAT number. Collected at sign-up and during invoicing.
  • Discovery-call submissions: the goals, business details, and current-site URL you share when booking a free call.
  • Site usage: anonymised analytics events such as page views, referrers, and aggregated device class. No cross-site tracking.
  • Uploaded content: copy, images, logos, and brand assets you (or your team) upload to your project. Stored encrypted at rest.
  • Cookies: a small number of strictly necessary cookies for auth and theme preference. Details on the cookie page.

3. How we use your data

  • Service delivery, scheduling calls, building your site, hosting it, providing the smart editor, and responding to support.
  • Billing: generating invoices, processing payments, and meeting our tax obligations.
  • Transactional email: confirmations, project updates, security alerts, and renewal notices.
  • Product improvement: aggregated, de-identified analytics used to improve the editor and the marketing site.
  • Marketing email: only with your explicit opt-in consent, and only to subscribers who actively chose to receive it.

4. Legal basis (GDPR Article 6)

  • Contract performance: for everything we do to deliver and support your project.
  • Legitimate interest: for aggregated analytics, security monitoring, and fraud prevention.
  • Legal obligation: for tax and accounting records.
  • Consent: for marketing email and any optional analytics or functional cookies.

5. Subprocessors we share data with

We use a small, vetted set of subprocessors. Each one has signed a data-processing agreement with us covering Article 28 GDPR requirements. The current list:

  • Clerk (US, EU SCCs): authentication and session management.
  • Supabase (EU region): primary database and file storage for client projects.
  • Hetzner (Germany / Finland): application hosting and customer-site servers.
  • Cloudflare (US, EU SCCs): DNS, edge CDN, and DDoS protection.
  • Stripe (Ireland): payments, invoicing, and tax calculation.
  • Resend (US, EU SCCs): transactional email delivery.
  • Calendly (US, EU SCCs): discovery-call scheduling.
  • Plausible (EU): privacy-friendly, cookie-less analytics for flowstarter.net.

We update this list before adding any new subprocessor. If you need an export for procurement, email legal@flowstarter.net.

6. International transfers

All production hosting lives in the European Union (Hetzner DE/FI, Supabase EU). A handful of subprocessors are headquartered in the United States (Clerk, Cloudflare, Stripe, Resend, Calendly). Each of those transfers is covered by the European Commission's Standard Contractual Clauses, and where applicable, by the EU–US Data Privacy Framework.

7. Retention

  • Account data: kept for the lifetime of the account, then deleted 30 days after closure.
  • Uploaded site assets: kept until you delete them, or 30 days after account closure.
  • Analytics events: retained for 12 months.
  • Billing and invoices: retained for 7 years to meet EU tax-record obligations.
  • Email logs: retained for 30 days for deliverability troubleshooting.

8. Your rights under GDPR

You have the right to:

  • Access: request a copy of the personal data we hold about you.
  • Rectification: correct any inaccurate or incomplete data.
  • Erasure: ask us to delete your data, subject to legal-retention obligations.
  • Portability: receive your data in a machine-readable format.
  • Objection: object to processing based on legitimate interest.
  • Restriction: limit how we process your data while a query is being resolved.
  • Complaint: lodge a complaint with your national data-protection authority.

To exercise any of these rights, email privacy@flowstarter.net. We verify the request and respond within 30 days.

9. Children

Flowstarter is not intended for anyone under the age of 16. We do not knowingly collect data from children. If you believe a child has submitted data to us, contact privacy@flowstarter.net and we will delete it.

10. Changes to this policy

We update this page whenever our practices change. Material changes are announced by email to active clients at least 14 days before they take effect. The “last updated” date at the top of this page always reflects the latest revision.

Questions about privacy? Write to privacy@flowstarter.net. Need a signed data-processing agreement? Email us at the same address and we'll send one over.