Skip to content

Privacy Policy

Draft — not yet in effect.

This document is being prepared and has not been finalised or reviewed by a lawyer. Highlighted fields are still to be completed. It does not currently form an agreement between you and Flowcove.

Last updated / effective date: [DATE] · Data controller: [Legal entity name], Nepal · Contact: ayushshah447@gmail.com

This explains what Flowcove collects, why, where it's stored, and what you can do about it. It is written for the product as it works today — a free early-access workspace, with no payment integration and no AI features.

1. Who we are

Flowcove is a task-management workspace for agencies, operated by [Legal entity name] in Nepal. Questions about this policy: ayushshah447@gmail.com. We aim to reply within [response time].

2. What Flowcove does

Agencies use Flowcove to run client work: tasks, comments, internal notes, documents, file attachments, and a portal their contacts can open. Sign-in is an emailed link or Google. There is no password, and there is no way to pay us today.

3. What we collect

What we do not collect. We do not ask for or check passwords. We do not take card numbers or process payments. We do not sell personal information, and we do not set advertising or cross-site tracking cookies. We do not ask for precise location from your device. We do not send your content to an AI provider, and we do not use it to train AI models.

  • Account data: name, email, agency name, and your profile photo if you upload one — or the name, email, and photo Google sends if you choose Google sign-in.
  • Client Content: tasks, sub-tasks, comments, internal notes, documents, file attachments, messages, and the client and contact records you create, and the invoices you send your clients (the PDF plus the amount and due date you enter).
  • Payment details you publish: the bank name, branch, account name and number, PAN and payment QR images you add in your payment settings. We show them to your own client contacts in their portal so they can pay you. They are not used to charge anyone.
  • Usage and security data: server and application logs, device and browser information, and an approximate location derived from the network request, stored on the session so you can see where a sign-in came from. That is not GPS.
  • Product activity: a record of key actions in the product — for example that a client was added, a task was shared, a contact signed in or an invoice was paid — with the time and the ids involved, not the content. It is kept in our own database, is never sent to an analytics vendor, and we use it only to understand how the product is used.
  • Analytics: Vercel Web Analytics, which does not use a cookie. It records page views and aggregate details such as referrer, browser, operating system, device type, and country. It does not identify you, and we do not receive a personal profile from it.
  • Payment data: none. Flowcove does not process payments. When your clients pay you, the money moves between you and them, outside Flowcove. There is no way to pay us today either; if Fonepay goes live, payment completes in your own bank or wallet app by QR — we never see or store card numbers and hold no stored payment method.

4. Your clients' data

Your clients don't have workspace accounts. A client record is not a member of your agency. If you invite a contact, they can open a portal with a link emailed to them — no password, and no account to create. Until you do that, they never see the workspace. You still record information about them: names, contact details, and whatever appears in tasks, documents, and files.

A contact with portal access receives the emails you have switched on for their portal: new comments, approval requests, status changes, messages and invoices. You control those switches, and you can stop email to an individual contact. A contact who wants the emails stopped can ask you, or email us.

For that information you are the controller and Flowcove is the processor — we hold it on your behalf and act on your instructions. You're responsible for having a lawful basis to collect it, and for telling your clients about it if your jurisdiction requires that.

5. How we use it

  • To provide and operate the Service, including the portal.
  • To send email the Service needs — sign-in links, invitations, account notices, and the portal notifications and invoices an agency sends its clients. We do not send marketing email.
  • To keep the Service secure, including recognising a session and investigating abuse.
  • To understand, in aggregate, which pages and features are used — via the cookieless analytics and the product activity record described above.
  • To meet legal obligations.

Where GDPR or a similar law applies, we process account data to perform our contract with you, for legitimate interests (securing and improving the Service), for consent where required, and to comply with law.

6. Cookies

We use essential cookies to keep you signed in, plus one hint cookie for the marketing site. We do not set analytics or advertising cookies, and we do not track you across other sites. Because of that, we do not show a cookie banner. Clearing cookies signs you out of Flowcove; it does not delete your account.

CookiePurposeDurationHow to opt out
better-auth.session_tokenKeeps you signed in. Not readable by page scripts.7 days, refreshed while you use FlowcoveRequired to use a signed-in workspace. Sign out to clear it.
better-auth.session_dataA short-lived copy of that session, so we don't read the database on every request.5 minutesRequired while you are signed in.
fc_sessionA one-bit hint (the value is only "1") so the marketing site can show a signed-in link. It is not a credential and cannot open your account.30 daysClear this cookie in your browser. You stay signed in.
fc_hostRemembers which agency address your session belongs to, so you land on the right one. It grants no access on its own.30 daysClear it in your browser. The next page load sets it again.
flowcove_portal_sessionKeeps a client contact signed in to their portal. Only sent to portal pages, and not readable by page scripts.7 days from the sign-in linkRequired to use the portal. Clearing it signs the contact out.

We do not currently respond to a Do Not Track signal, because we do not set tracking cookies. If that changes, this section will be updated first.

7. Sharing — our sub-processors

We don't sell your data. We share only with the providers below, under contract, and with legal authorities when required by law.

ProviderWhat it handlesWherePrivacy policy
NeonThe database — account data and Client ContentSingaporePolicy
VercelApplication hosting, and cookieless Web AnalyticsSingapore (sin1) — web app and APIPolicy
Cloudflare R2File attachments you upload[verify bucket region]Policy
CloudflareRealtime connections so the workspace can update without a refreshCloudflare's networkPolicy
ResendEmail only — sign-in links, invitations and account notices, plus the portal notifications and invoice emails an agency sends its clients[verify — US-based]Policy
Better AuthSign-in and account events for agency team members (sign-ups, sessions, workspaces), for security and account administration. Client contacts are not included.[verify region]Policy
GoogleSign-in, only if you choose Continue with Google. We receive the name, email, and profile photo Google provides.Google's infrastructurePolicy

Fonepay is not yet integrated. If and when it is, it will process payments in Nepal and this list will be updated before that happens.

8. Retention

We keep account data and Client Content while the account is active and for [period] after closure, unless law requires longer. You can request deletion.

Server and application logs are kept for [log retention], for security and debugging. The session cookie lasts 7 days. Analytics aggregates stay with Vercel under its own retention; we do not hold a separate copy that identifies you.

9. Your rights

Depending on your jurisdiction, you may access, correct, export, or delete your data, or object to certain processing. Email ayushshah447@gmail.com. We may need to confirm it is you. We aim to respond within [response time].

If GDPR or UK GDPR applies to you: you may also restrict processing, ask us to move data you provided, and withdraw consent where we rely on it. You can complain to your supervisory authority. We have not appointed a data-protection officer or an EU or UK representative: [if required, name and contact].

If the California Consumer Privacy Act applies to you: you may know, correct, and delete personal information we hold, and you may use an authorised agent. Flowcove does not sell or share personal information for cross-context behavioural advertising, and we do not offer a financial incentive for it.

10. Data storage & international transfers

Your data is processed outside Nepal. Our database — which holds your account data and everything you and your team create, including the client information you record — is operated by Neon in Singapore. The web app and the API are hosted by Vercel in Singapore (sin1). File attachments and realtime connections are processed by Cloudflare. Email is sent by Resend. Traffic may also pass through other regions as a normal part of the internet.

There is no Nepal-region option from our database provider, so this is structural rather than a preference. By using Flowcove you understand your data is stored and processed abroad. The safeguard we rely on for those transfers is [transfer mechanism — counsel].

11. Children

Flowcove isn't intended for anyone under 18, and we don't knowingly collect personal data from children. If you believe a child has given us data, email ayushshah447@gmail.com and we will delete it.

12. Security

  • Data is encrypted in transit.
  • Our infrastructure providers encrypt stored data at rest. We do not operate our own disks.
  • Tenant isolation is enforced at the database level using row-level security, not only in application code — one agency's queries cannot return another agency's rows.
  • Access controls limit who on our side can reach production data.
  • There is no password to leak. Sign-in is a link or Google.

No system is perfectly secure. If a breach affects your personal data, we will notify you as required by law.

13. Changes

We'll post updates on this page and change the date at the top. We'll notify you of material changes — by email or in the product — before they take effect.

14. Contact

ayushshah447@gmail.com. Operator: [Legal entity name], Nepal. There is no separate privacy inbox yet.