Privacy Policy
How Inflow Manager handles information used to provide Inflow Manager.
This policy describes information processed when you visit the public website, create an account, use the private workspace, contact support or purchase a paid plan.
1. Information you provide
We process account details such as name and email address, workspace records you create, settings, support enquiries, billing references and any files you deliberately upload. Designated secret fields and encrypted tenant backups use application cryptography as implemented by the service.
2. Security and session information
The service processes security information needed for authentication, two-factor authentication, active sessions, login history, auditing and abuse prevention. Public contact submissions store source IP and user-agent identifiers only as one-way hashes rather than retaining the raw values in the contact-message table.
3. Billing information
Billing records may include plan, invoice, amount, currency, payment status, provider identifiers and receipt information. Payment card credentials are handled by external payment providers; this application is not designed to store complete card numbers or CVV.
4. Why information is processed
Information is used to provide and secure the service, enforce account quotas, deliver notifications, process billing, respond to support requests, prevent abuse, maintain audit history, generate customer-requested exports/backups and comply with applicable legal obligations.
5. Payment and communication providers
When configured, relevant information may be transmitted to payment gateways, email providers, Telegram, WhatsApp or web-push providers to perform the action you request or the notification route you enable. Each external provider processes information under its own terms and privacy practices.
6. Tenant isolation and support access
Customer workspace records are owner-scoped. Platform support access is designed to be time-limited and read-only, and normal support impersonation explicitly blocks Credential Vault, recovery, billing, privacy and account-security areas.
7. Data export and tenant backup
Basic privacy export is available regardless of plan. Eligible plans may offer tenant-scoped encrypted backup. The customer chooses the backup passphrase; the server does not store that passphrase. Platform-wide disaster backups remain restricted to Super Admin operations.
8. Retention
Workspace information is generally retained while the account remains active. Financial and audit information may be retained separately for accounting, fraud prevention, dispute handling or legal obligations. Public support enquiries may be retained as needed to resolve and document the enquiry.
9. Account deletion
Account deletion is a deliberate process separate from subscription cancellation. After the configured deletion grace period, workspace records are purged and the retained account identity is anonymized. Financial and audit records can remain subject to their separate retention rules.
10. Cookies and local browser storage
The service uses session cookies and related browser storage necessary for authentication, CSRF protection, secure application behavior and PWA functionality. The current application architecture does not require advertising cookies to operate the product.
11. Your choices
You can update account information, configure notification preferences, export your data, create eligible backups, cancel billing and initiate account deletion through the authenticated account area. Some retained financial or security records may not be immediately deletable when legitimate retention obligations apply.
12. Security
Security controls include strong-password requirements, mandatory customer TOTP setup, recent-password confirmation for sensitive actions, encrypted database sessions, security headers, audit logging and owner-scoped authorization. No system can guarantee absolute security, so you should also protect your device, email account and recovery methods.
13. Policy changes
We may update this policy when product behavior, providers or legal requirements change. The current published version replaces previous public versions.
14. Contact
Privacy questions can be submitted through the Contact page.