Legal
Privacy Policy
Effective: March 30, 2026 | Last updated: March 30, 2026
At Orgaflow ("we", "us", or "our"), your privacy is a priority. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data when you use our platform at orgaflow.dev.
1. Information We Collect
We collect information you provide directly and information generated as you use our service:
- Account information: name, email address, and password when you register.
- Organization data: company name, address, tax information, and preferences you enter into your workspace.
- Business data: customers, estimates, invoices, payments, tasks, and expenses you create within the platform.
- Billing information: payment details processed securely by Stripe. We do not store card numbers.
- Usage data: pages visited, features used, timestamps, IP address, browser type, and device information.
- Communications: messages you send to our support team, including via the live chat widget (if enabled).
2. How We Use Your Information
We use the collected information to:
- Provide, operate, and maintain the Orgaflow platform.
- Process payments and manage your subscription via Stripe.
- Send transactional emails (account confirmations, password resets, invoices).
- Provide customer support and respond to your requests.
- Monitor and improve the security, performance, and reliability of our service.
- Comply with legal obligations.
We do not sell your personal data to third parties.
3. Data Sharing
We share your data only with trusted third-party services necessary to operate Orgaflow:
- Stripe — payment processing and subscription management.
- Tawk.to — customer support chat widget (if enabled).
- Resend / Nodemailer — transactional email delivery.
- PostgreSQL hosting provider — secure database storage.
- Vercel — platform hosting and edge network.
All sub-processors are bound by data processing agreements and applicable privacy laws.
4. Data Retention
We retain your data for as long as your account is active. If you cancel your subscription, your data is retained for 30 days during which you can request an export. After this period, your data is permanently deleted from our systems. Some data may be retained longer to comply with legal obligations.
5. Security
We implement industry-standard security measures including TLS encryption in transit, encrypted storage at rest, access controls, and regular security reviews. However, no system is 100% secure. We encourage you to use a strong unique password and enable two-factor authentication when available.
6. Your Rights
Depending on your location, you may have the following rights:
- Access: request a copy of your personal data.
- Correction: request correction of inaccurate data.
- Deletion: request deletion of your account and data.
- Portability: export your business data in a machine-readable format.
- Objection: object to certain processing activities.
To exercise any of these rights, contact us at app@orgaflow.dev.
7. Cookies
We use cookies and similar technologies to operate and improve our service. For details, see our Cookie Policy.
8. Children's Privacy
Orgaflow is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or a prominent notice within the platform at least 7 days before changes take effect. Continued use of the service after the effective date constitutes acceptance.
10. Contact
For privacy-related questions or to exercise your rights, contact us at app@orgaflow.dev or via our contact page.
You can also write to: Orgaflow LLC, 1600 E 8th Ave A200, Tampa, FL 33605.