Privacy Policy
Last updated: December 27, 2024
1. Introduction
Welcome to Detail Flow CRM. We respect your privacy and are committed to protecting your personal data. This privacy policy explains how we collect, use, disclose, and safeguard your information when you use our business management platform.
2. Information We Collect
We collect information that you provide directly to us, including:
- Account Information: Name, email address, phone number, business name, and password when you create an account.
- Business Data: Customer information, appointment schedules, invoices, estimates, and service records that you enter into the platform.
- Payment Information: Billing details and payment card information processed through our secure payment provider (Square).
- Communications: Messages, feedback, and support requests you send to us or through our platform.
- Usage Data: Information about how you interact with our services, including features used and actions taken.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Process transactions and send related information
- Send appointment reminders, notifications, and service communications
- Respond to your comments, questions, and customer service requests
- Monitor and analyze usage patterns to improve user experience
- Detect, prevent, and address technical issues and security threats
- Comply with legal obligations
4. Information Sharing
We do not sell your personal information. We may share your information only in the following circumstances:
- Service Providers: With third-party vendors who perform services on our behalf (e.g., payment processing, SMS/email delivery, cloud hosting).
- Legal Requirements: When required by law or to respond to legal process.
- Business Transfers: In connection with a merger, acquisition, or sale of assets.
- With Your Consent: When you have given us explicit permission to share your information.
5. Third-Party Platform Integrations
Detail Flow CRM lets a business optionally connect its own third-party accounts — such as Google Business Profile, Facebook, and Instagram — so it can manage that presence from inside the application. These connections are always initiated by the business, require explicit consent on the provider's own sign-in screen, and can be revoked at any time.
Google user data
When a business connects a Google Business Profile, we request only the access needed to provide the features it has asked for. With that access we may read the business locations the account manages, read reviews and ratings for those locations, and — at the business's direction — publish posts to its own locations.
- How we use it: Only to display this information inside the connected business's own account and to publish content that the business explicitly creates and submits.
- How we store it: Access and refresh tokens are encrypted at rest. Synced content (such as reviews) is cached so it can be displayed in the application.
- What we never do: We do not sell Google user data, do not transfer it to third parties for advertising or profiling, do not use it for advertising, and do not allow humans to read it except where required for security, to resolve a support issue you raise, or to comply with law.
- Revoking access: A business can disconnect at any time in the application's settings, or revoke access directly in its Google Account permissions. On disconnect we delete the stored tokens and the cached data associated with that connection.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy , including its Limited Use requirements.
Meta (Facebook and Instagram) data
When a business connects a Facebook Page or Instagram professional account, we may access its Pages and connected accounts, publish content the business creates, retrieve engagement and performance metrics for that content, and — where the business enables messaging features — read and send messages on its behalf. This data is used only to provide those features to that business, is encrypted at rest, and is deleted when the business disconnects the account.
Deleting integration data
You can request deletion of data associated with a connected account at any time. See our Data Deletion Request page for how to submit a request and what happens after you do.
6. Data Security
We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication requirements
- Secure data centers with physical security measures
7. Data Retention
We retain your personal data for as long as your account is active or as needed to provide you services. We may also retain and use your information to comply with legal obligations, resolve disputes, and enforce our agreements.
8. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of your personal data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your personal data
- Portability: Request transfer of your data to another service
- Opt-out: Opt out of marketing communications
To exercise these rights, please contact us at [email protected] ) : ( our privacy team
9. Children's Privacy
Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.
11. Contact Us
If you have any questions about this Privacy Policy, please contact us at:
Email: [email protected]
Detail Flow CRM