Last updated: March 8, 2026
ClientFlow ("we", "us", or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect information when you use ClientFlow CRM ("the Service").
Account Information:
When you create an account, we collect your name, email address, company name, and password (stored as a secure hash).
Customer Data:
Data you enter into the Service, including contacts, deals, emails, documents, invoices, and activity logs. This data is owned by you and processed by us solely to provide the Service.
Usage Data:
We collect technical data including IP addresses, browser type, device information, and pages visited to improve the Service and ensure security.
Cookies:
We use essential cookies for authentication and session management. With your consent, we use PostHog for product analytics to improve the Service. You can manage your preferences via our cookie consent banner.
Your data is stored in secure, encrypted databases hosted by Supabase (PostgreSQL). All data is transmitted over HTTPS/TLS. We implement row-level security policies to ensure complete data isolation between tenants. Backups are performed daily and retained for 30 days.
We do not sell, trade, or rent your personal data. We may share data with:
We use the following third-party service providers to operate the Service. Each is bound by a data processing agreement:
| Provider | Purpose | Data Processed | Location |
|---|---|---|---|
| Supabase | Database & Authentication | All customer data | US / EU |
| Vercel | Frontend hosting | IP addresses, browser info | Global CDN |
| Sentry | Error monitoring | Error traces, user IDs | US |
| Stripe | Payment processing | Payment details | US |
| Nango | OAuth token management | OAuth tokens | EU |
| OpenAI | AI features (optional) | Contact/deal summaries | US |
| PostHog | Product analytics | Usage events, page views | EU |
| Resend | Transactional email | Email addresses | US |
| Better Stack | Uptime monitoring | Service availability | EU |
You have the right to:
To exercise these rights, visit Settings > Profile in your account dashboard or contact us at privacy@clientflow.com.
We retain your data for as long as your account is active. Upon account cancellation, your data is retained for 30 days to allow for reactivation, after which it is permanently and irreversibly deleted from all systems including backups.
Your data may be processed in countries other than your own. We ensure appropriate safeguards are in place, including Standard Contractual Clauses where required, to protect your data in accordance with applicable data protection laws.
The Service is not intended for individuals under 16. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us immediately.
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service at least 30 days before the changes take effect.
For privacy-related inquiries, contact our Data Protection Officer at privacy@clientflow.com.