← FLOWA

Privacy Policy

Last updated: June 18, 2026

FLOWA (“FLOWA”, “we”, “us”) provides an order-management platform that lets businesses receive and manage customer orders from Instagram, WhatsApp, and Shopify in one dashboard. This policy explains what we collect, how we use it, and the choices you have. By using FLOWA you agree to this policy.

1. Who controls the data

The business (the “Merchant”) that connects its channels is the controller of its customers’ data. FLOWA processes that data on the Merchant’s behalf to provide the service. If you are a customer of a Merchant, please also refer to that Merchant’s own privacy notice.

2. Information we collect

  • Account data: name, email, phone, business details, and login credentials of Merchant users.
  • Connected-channel data: when a Merchant connects a channel, we access the messages and order-related content needed to create orders — including Instagram Direct Messages and post comments, WhatsApp messages, and Shopify orders, products, and customers.
  • Customer data: names, handles, phone numbers, addresses, and the content of messages your customers send to the Merchant’s connected accounts.
  • Usage data: log and device information used to operate and secure the service.

3. How we use information

  • To read incoming messages and turn order requests into structured orders.
  • To send messages back to customers on the Merchant’s connected channels at the Merchant’s direction (e.g. order confirmations).
  • To provide the dashboard, analytics, customer records, and team features.
  • To secure, maintain, and improve the service, and to comply with law.

4. Meta Platform data (Instagram & WhatsApp)

FLOWA uses the official Meta APIs (Instagram Messaging API and WhatsApp Business Cloud API). We access Instagram and WhatsApp message content only after a Merchant explicitly connects their account, and only to provide the order-management features described above. We do not sell this data, do not use it for advertising, and do not share it except with the sub-processors listed below or as required by law. Our use of information received from Meta APIs follows Meta’s Platform Terms and Developer Policies.

5. AI processing

To extract order details (product, quantity, size, address, etc.) from messages, we send message content to our AI sub-processor (Anthropic) for parsing. It is used solely to return the structured order and is not used to train models.

6. Sub-processors

We share data with service providers strictly to run FLOWA:

  • Anthropic — AI message parsing
  • Supabase — database & storage
  • Railway — application hosting (API)
  • Vercel — application hosting (web)
  • Upstash — queue/cache
  • Meta & Shopify — the channels you connect

7. Retention

We keep data for as long as the Merchant’s account is active or as needed to provide the service. Merchants can delete data or close their account at any time; see Data Deletion below.

8. Your rights & data deletion

You may request access to, correction of, or deletion of your data. To request deletion of data FLOWA holds — including data obtained via Instagram or WhatsApp — see our Data Deletion instructions. When a Merchant disconnects a channel or removes the FLOWA app, we stop accessing that channel and delete the associated tokens.

9. Security

Data is encrypted in transit (TLS). Access tokens are encrypted at rest. We restrict access to data on a need-to-know basis.

10. Contact

Questions or requests: privacy@flowa-app.co.