Privacy Policy

Effective Date: Jul 1, 2026

At Flowgrid, we are committed to protecting your privacy and the privacy of your website visitors. This Privacy Policy describes how we collect, use, and process your personal data as an account holder, and the data we process on your behalf, as your service provider, via our analytics, session replay, and AI-assisted reporting features.

1. Information We Collect

Information You Provide Us (Account Data)

When you create an account, we collect personal data such as your name, email address, company name, and billing details. This information is used for account management, billing, and communication.

Data Collected on Your Website (Usage Data)

Our analytics script, when installed on your website, collects usage data from your visitors. This may include:

  • Page visits, interactions, and events (e.g., clicks, scrolls, form submissions)
  • Visitor identifiers (a pseudonymous unique ID stored in a cookie on the visitor's device)
  • Approximate geographic location (country, region, city), resolved from the visitor's IP address at the time of collection
  • Browser type, operating system, and device information
  • Referral sources, UTM parameters, and entry/exit pages

IP addresses:We use each visitor's IP address to resolve the approximate location above. The resolved location is stored and shown to you, the website owner, in your dashboard. When analytics data is viewed through a shared, read-only dashboard link (rather than by you as the logged-in owner), we strip location data, hash the visitor identifier, and remove other identifying fields before display — see "Shared Dashboard Links" in Section 5.

Identity Data Captured from Forms (Passive Identification)

To power our visitor-identification and customer-intelligence features, our script also passively captures contact and profile details that your visitors type into forms on your website — this can include their email address, first and last name, phone number, company, and address — as they fill in the fields, even if the form is never submitted. This behaviour is active by default when the script is installed. You may also explicitly send us identity data (for example, by identifying a logged-in user of your own site).

We take deliberate steps to limit what is captured:

  • We never read sensitive fields such as passwords, credit-card numbers, CVV/CVC codes, national ID / SSN, or PINs — the script does not even attach to those fields.
  • Passive capture is automatically skipped on sensitive pages such as checkout, account-settings, and admin areas.
  • Phone numbers captured passively are stored only as an irreversible hash; a raw phone number is only recorded if the visitor explicitly submits it.
  • Captured identity data is used to recognise returning visitors and to enrich analytics and CRM matching — it is not sold or used for cross-site advertising.
  • Capture honours the visitor's tracking-consent signal: when consent is denied, our script does not capture this data.

Important: Because you (or your client) are the Data Controller for your visitors' data, you are responsible for disclosing this collection in your own privacy notice and for obtaining any consent required by applicable law (e.g., GDPR, POPIA) before deploying our script.

Session Replay

If you enable Session Replay, our script records a visual reconstruction of a visitor's on-page activity — page structure, mouse movement, scrolling, and on-screen changes — so you can review how visitors actually use your site. Session Replay does not capture audio, camera, or microphone data.

Sensitive fields: Our recording technology does not guarantee automatic masking of every input on every page. If your site collects passwords, payment card details, or other sensitive information, you are responsible for excluding those pages or elements from Session Replay, or using our masking configuration where available, before turning the feature on.

Advertising Platform Click Identifiers

When conversion tracking is enabled, our script captures advertising platform click identifiers from the page URL or a first-party cookie, so you can see which advertising campaigns are driving conversions. These include:

  • gclid - Google Ads Click Identifier
  • fbclid - Facebook/Meta Click Identifier
  • ttclid - TikTok Click Identifier
  • msclkid - Microsoft Advertising Click Identifier
  • twclid - Twitter/X Click Identifier
  • dclid - DoubleClick Click Identifier
  • li_fat_id - LinkedIn First-Party Ad Tracking Identifier

These identifiers are collected by default whenever conversion tracking is enabled on your site, and are used solely for attribution within your own analytics — we do not share them with third parties or use them for cross-site tracking. Collection stops if you (or your own consent-management tooling) set our opt-out cookie before the script loads. You are responsible for obtaining any consent required by law(for example, under GDPR/ePrivacy or similar rules in your visitors' jurisdictions) before enabling advertising click-identifier tracking on your site.

2. How We Use Your Information

  • To Provide the Service: We use your account data to deliver and maintain our service, and the usage data collected on your behalf is used to generate the analytics reports and session replays you see in your dashboard.
  • To Power AI-Assisted Features: If you use our AI Insights panel or chat features, see Section 3 below.
  • To Improve Our Service: We analyze anonymized, aggregated usage of our own platform to improve features and user experience.
  • For Billing and Communication: We use your account information to manage your subscription, process payments, and send you important service-related updates.
  • For Security and Compliance: We use data to monitor for and prevent fraudulent activity, ensure platform security, and comply with legal obligations.

3. AI-Assisted Features

Our AI Insights panel and related chat features use a third-party AI inference provider to generate summaries and answer questions about your analytics data. When you use these features, a relevant excerpt of your dashboard data (for example, aggregated metrics, recent trends, or the specific records needed to answer your question) along with your prompt and chat history is sent to that provider for processing. This provider acts as our subprocessor and is contractually restricted to processing this data solely to return a response to you.

We do not use your account or visitor data to train our own foundation models. If your data retention settings require restricting this feature, contact us before enabling it.

4. Information Sharing

We do not sell any personal data to third parties. We share data with the following categories of trusted third-party service providers (subprocessors) who assist us in operating our business. These providers are bound by confidentiality and data-processing agreements and may only use the data to perform services on our behalf:

  • Payment processing: Lemon Squeezy and Stripe (billing, fraud prevention)
  • Analytics data storage & querying: Tinybird
  • Application database & authentication: Supabase
  • Caching, queuing & rate limiting: Upstash (Redis, QStash)
  • Cloud hosting, storage & email delivery: Amazon Web Services (S3, SES) and Resend
  • AI-assisted feature processing: our AI inference subprocessor, described in Section 3

This list reflects our current subprocessors and may change as our service evolves; we will update this policy when it does.

4. Information Sharing

We do not sell any personal data to third parties. We share data with the following categories of trusted third-party service providers (subprocessors) who assist us in operating our business. These providers are bound by confidentiality and data-processing agreements and may only use the data to perform services on our behalf:

  • Payment processing: Lemon Squeezy and Stripe (billing, fraud prevention)
  • Analytics data storage & querying: Tinybird
  • Application database & authentication: Supabase
  • Caching, queuing & rate limiting: Upstash (Redis, QStash)
  • Cloud hosting, storage & email delivery: Amazon Web Services (S3, SES) and Resend
  • AI-assisted feature processing: our AI inference subprocessor, described in Section 3

This list reflects our current subprocessors and may change as our service evolves; we will update this policy when it does.

5. Cookies and Tracking

We use cookies and similar technologies (e.g., local storage) to manage sessions and operate our own platform. When our script is deployed on your website, it sets cookies and other identifiers (visitor ID, session ID, UTM/click-identifier cache) to enable the analytics features described above; these are set by default unless our opt-out cookie is present when the script loads. See our Cookie Policy for the specific cookies we use and their duration. As the website owner, you are responsible for your own Cookie Policy and for obtaining any consent from your visitors required by law before our script sets non-essential cookies on their devices.

Shared Dashboard Links: When you generate a shared, read-only link to your dashboard for someone outside your account, we automatically redact the data shown through that link: geographic location and email fields are removed, the visitor identifier is one-way hashed, and the browser user-agent string is truncated. Full detail remains visible only to you and your team when logged in.

6. Your Data Rights

Depending on your location and applicable law (such as GDPR), you may have the right to:

  • Right to Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Ask us to correct any inaccurate or incomplete data we have.
  • Right to Erasure: Request the deletion of your personal data under certain conditions.
  • Right to Object: Object to the processing of your personal data.
  • Right to Portability: Request that we transfer your data to another organization or directly to you.

Account holders can exercise these rights by contacting us at the email below. Website visitors:because your website owner controls what visitor data is collected, visitors should first direct access, correction, or deletion requests to the website they visited. We provide account holders with tools to export or permanently delete an individual visitor's data from our systems on request, and we will honor a verified request forwarded to us directly where required by law.

7. Data Retention

We will retain your account data for as long as your account is active and for a reasonable period thereafter to comply with our legal obligations, resolve disputes, and enforce our agreements.

Analytics & Session Replay Data:Visitor-level data (page visits, click events, form submissions, conversion data, and session replays) is retained for as long as your account is active. You or the website owner may request deletion of an individual visitor's data at any time (see Section 6); enterprise customers may request a custom retention or scheduled-deletion arrangement. We are working toward an automatic default retention window and will update this policy with a specific timeframe once that is in place.

8. Security Measures

We employ a variety of technical and organizational security measures to protect your data from unauthorized access, use, or disclosure, including data encryption in transit, access controls, and secure hosting environments through the subprocessors listed in Section 4. While we strive to protect your data, no method of transmission over the internet is 100% secure.

9. International Data Transfers

Your information may be transferred to and maintained on computers located outside of your country or other governmental jurisdiction where the data protection laws may differ. We will take all reasonable steps to ensure that your data is treated securely and in accordance with this Privacy Policy.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through a prominent notice on our website before the changes take effect. Your continued use of the service after any such changes constitutes your acceptance of the new Privacy Policy.

Last updated: Jul 1, 2026. If you have any questions about this Privacy Policy, please contact ToastLabz at info@toastlabz.com.