Skip to legal content
Back to homeLegal

Privacy Policy

This Policy explains what personal data CraftFlow processes, why it is used, who may receive it, and the choices and rights available to individuals.

Effective date
July 20, 2026
Last updated
July 20, 2026
Version
2026-07-20.3

1. Scope

This Privacy Policy applies to the CraftFlow website, accounts, application, support, billing administration, and related services. It does not govern independent services that publish their own privacy notices.

2. Who controls personal data

Craftflow controls personal data used to operate CraftFlow accounts, workspaces, and the service from Brazil. Workspace customers control business records they enter about their own customers, suppliers, employees, and contacts; CraftFlow processes those records to provide the service.

Provider roles may differ by activity and contract. This Policy does not automatically characterize every provider as a processor.

3. Data you provide directly

  • name, email address, studio or workspace name, and selected business type;
  • workspace membership and role information;
  • support messages and request information;
  • business records such as materials, suppliers, recipes, products, production batches, inventory movements, customers, and sales; and
  • legal acceptance versions and acceptance time.

4. Data collected automatically

Our identity provider supplies an account identifier and authentication metadata needed to maintain a session. Infrastructure providers may process IP address, request time, device or browser information, identifiers, and security or diagnostic logs to deliver and protect the service.

The application uses browser storage required for authentication and preferences such as the collapsed sidebar. A visitor may manually select the landing-page language; that non-sensitive preference may be stored locally. Access tokens are not manually stored in localStorage.

5. Workspace and business data

Workspace records may include personal data entered by a customer, such as names, email addresses, phone numbers, documents, addresses, notes, sales, and responsible team members. The customer decides what to enter and must have an appropriate lawful basis and provide required notices. CraftFlow uses this data to perform requested workflows and keep workspaces isolated.

6. Billing information

Paddle may independently process information required for localized pricing, checkout, subscriptions, receipts, tax calculation, fraud prevention, billing support, disputes, chargebacks, and refunds. This may include IP address, approximate location, selected billing country, and device or browser information. CraftFlow does not independently maintain a visitor geolocation database and does not directly receive full payment-card numbers or security codes. We receive limited billing metadata needed to administer access and requests.

7. Authentication information

A specialized identity provider manages registration, login, password reset, email verification, credentials, and authentication state. CraftFlow receives the account identifier, email, display name, and verification status needed to activate or restore an account. CraftFlow does not receive or store account passwords.

An email service delivers transactional account messages and may process the destination address, display name, delivery metadata, status, and timestamps. These messages are not marketing communications.

8. Why data is processed

  • create accounts and workspaces, authenticate users, and enforce tenant isolation;
  • provide materials, costing, production, inventory, sales, reporting, and billing functions;
  • calculate requested costs, quantities, margins, and summaries;
  • process subscriptions and prevent duplicate or fraudulent transactions;
  • provide support and communicate service or legal changes;
  • secure, diagnose, maintain, and improve reliability; and
  • comply with legal obligations and establish, exercise, or defend legal claims.

9. Help, support, and privacy-request data

The Help & Requests Center may process user and workspace identity, request category and description, bug reproduction steps, feedback, transaction references, refund-review details, messages, status history, timestamps, and authorized reviewer actions. Public privacy requests may include contact and account details, request type, description, verification state, and status history.

This information is used to review requests, diagnose problems, prevent abuse, improve the service, manage billing, maintain records, comply with law, and exercise or defend rights. Submission does not guarantee a personal response or a particular outcome.

10. Optional diagnostic information

A bug report may optionally include application version, page, browser, operating system, and capture time. CraftFlow does not intentionally request passwords, authentication tokens, full payment-card information, private keys, or unrelated confidential business data. Do not include sensitive information unless necessary and lawful.

12. Service providers and third parties

Data is shared only as reasonably needed with infrastructure, authentication, billing, professional advisory, and support providers; to complete a requested transaction; during a lawful business reorganization; or when required by law or necessary to protect rights and safety.

13. Hosting, identity, and data infrastructure

CraftFlow uses specialized providers to host the service, authenticate accounts, and store business data. These providers process relevant identifiers, content, requests, and diagnostic information under their terms. Business records are accessed through controlled CraftFlow services.

14. Paddle

Paddle operates hosted checkout, payment processing, receipts, tax and invoice functions, subscription management, and the Customer Portal. Paddle may act as merchant of record and independently process information for fraud prevention, billing support, disputes, chargebacks, refunds, and legal compliance. Review Paddle's checkout notice for its final commercial role and practices.

15. Analytics, cookies, and local storage

CraftFlow does not currently initialize an optional analytics system and does not claim to use non-essential analytics cookies. No marketing-cookie banner is currently required for functionality that is not present.

Required browser storage may restore authentication and remember sidebar and landing-language preferences. The language preference is not treated as sensitive personal information. If optional analytics or advertising technologies are introduced, this Policy and consent controls will be updated where required.

16. International processing

CraftFlow's infrastructure and service providers, including Paddle for payments, may process data in countries other than yours. Where required, transfers use applicable contractual, organizational, or legal safeguards. Exact regions depend on production configuration and provider agreements.

17. Retention

Open requests are retained while under review. Resolved support, billing, refund, dispute, and privacy records may be retained for operational, security, accounting, compliance, and legal purposes.

Unnecessary diagnostic information is removed or anonymized when no longer required. Exact periods vary by record and applicable requirements. Deleted data may remain temporarily in protected backups until normal expiration.

18. Account deletion and exports

Use the public Privacy Request page to request account deletion or an available export. We will verify authority, explain records that must be retained, and process eligible data within applicable time limits. Workspace owners should export needed records before closure. Immediate or universal recovery after deletion is not guaranteed.

19. Security

CraftFlow uses reasonable administrative, technical, and organizational measures, including authenticated access, workspace isolation, server-side authorization, managed infrastructure, and restricted secret handling. No system is absolutely secure, and we cannot promise that unauthorized access or loss will never occur.

20. Your privacy rights

Subject to applicable law and exceptions, you may request confirmation; access; correction; deletion, anonymization, or restriction; portability where applicable; sharing information; objection; or withdrawal of consent where consent is the basis. Withdrawal does not affect prior lawful processing.

You may also contact the competent data protection authority. Where LGPD applies, requests will be handled consistently with its rights and procedures.

21. Automated decisions

CraftFlow does not currently implement solely automated decisions that produce legal or similarly significant effects. Operational calculations reflect user-entered information. If relevant automated decision-making is introduced, this Policy will explain the logic and review rights.

22. How to exercise your rights

Anyone may use the public Privacy Request page without signing in. Account holders may use the same channel from Settings. We may verify identity and authority before disclosing or changing data. Workspace-record requests may need to be directed to the customer that entered the information. Contact details supplied for a request are not used for marketing.

23. Children

CraftFlow is designed for people legally capable of operating or representing a business and is not directed to children. If we learn that a child's data was submitted without a lawful basis or required authorization, we will take appropriate steps.

24. Changes to this Policy

We may update this Policy when practices, providers, law, or the service changes. The version and dates identify the current text. Material changes will receive reasonable notice, and consent will be requested only when legally required.

25. Contact

Privacy questions and rights requests can be submitted through the public Privacy Request page. CraftFlow does not offer inbound email or telephone support for ordinary product support. A contact email collected in the form may be used to verify identity or communicate about that request.