Skip to content

Legal

Privacy Policy

Effective: April 14, 2026  ·  Last updated: October 3, 2026

1. Information We Collect

We collect the following categories of information:

Account Information

Name, email address, and password (hashed with bcrypt — we never store plaintext passwords) when you register.

Payment Information

Billing details are processed and stored exclusively by Stripe. QodFlow does not store, access, or process full credit card numbers, CVVs, expiration dates, or bank account details. We store only a Stripe customer ID and subscription ID for billing management.

User-Generated Content

Jobs, stages, team settings, tags, activity logs, QR code configurations, and other data you create within the Service. You are solely responsible for the content you enter, including ensuring it does not contain sensitive personal data of third parties beyond what is necessary.

Technical and Usage Data

IP address, browser type and version, device information, operating system, referring URLs, pages visited, click patterns, session duration, and timestamps. This data is collected automatically for security, fraud prevention, analytics, and service improvement.

Cookies and Tracking Technologies

We use the following types of cookies:

  • Essential cookies: Session management, authentication, workspace selection, and qodflow_consent (stores your analytics choice for 12 months), and qodflow_region (30 days) which remembers whether you are in a region where we must ask before loading analytics. Required for the Service to function.
  • Attribution cookies: qodflow_attr (90 days) records which ad or campaign first brought you here (including the Google gclid, gbraid or wbraid, Meta fbclid, Microsoft msclkid, TikTok ttclid, LinkedIn li_fat_id, X twclid or Reddit rdt_cid click identifier) and is set only if you have not opted out; qodflow_src (90 days) records which campaign or website first brought you here (for example utm_source), for our own measurement. It contains no advertising identifiers and is never shared with advertising platforms. In the EEA, UK and Switzerland it is set only after you accept. When you sign up, this campaign source is saved to your account, kept until the account is deleted, and used only for internal reporting; in the EEA, UK and Switzerland, withdrawing consent while signed in removes it from your account. qodflow_ref records a referral code you arrived with. Used only to credit referrals and measure campaigns.
  • Analytics cookies: Google Analytics and Meta Pixel for usage measurement and ad attribution. Once loaded, Google and Meta set their own cookies (_ga*, _fbp, _fbc). These load only if you have not opted out (banner or Global Privacy Control); visitors in the EEA, UK and Switzerland are asked first and nothing loads until they accept.

You can opt out of analytics at any time via the cookie banner or the control below, by enabling the Global Privacy Control signal in your browser, or through your browser cookie settings. Disabling essential cookies may prevent you from using the Service.

2. How We Use Your Information

  • To provide, operate, maintain, and improve the Service
  • To process payments and manage subscriptions via Stripe
  • To authenticate your identity and manage your account
  • To send transactional emails (account confirmation, password reset, billing receipts, team invitations)
  • To measure product usage and improve the Service through analytics
  • To detect and prevent fraud, abuse, and security threats
  • To enforce our Terms of Service
  • To comply with legal obligations
We do not sell your personal information for cash. We do not share your data with data brokers. However, like most online services, we use Google Analytics and the Meta (Facebook) Pixel, plus Meta server-side conversion events, for measurement and ad attribution. Under broad CCPA / CPRA definitions, these tools may constitute “sharing for cross-context behavioral advertising.” You can opt out at any time using the controls described in Section 7 (Your Privacy Rights).

3. Third-Party Services and Sub-Processors

We use the following third-party services that may process your data as part of providing the Service:

ServicePurposeData Location
StripePayment processingUS
Neon (PostgreSQL)Database hostingUS-East (AWS)
VercelApplication hosting & CDNUS / Edge
ResendTransactional & marketing email deliveryUS
SentryError monitoring (no session replay)US
Upstash (Redis)Rate limiting & short-lived cacheUS
CloudflareDNS, CDN, DDoS protection, inbound email routingGlobal edge
Google (Analytics & Ads)Usage analytics and ad-conversion measurement (click identifiers and, through enhanced conversions, a hashed email address)US
MetaAd attribution pixel and server-side conversion events (hashed email address, hashed account ID, IP address, browser user agent, browser identifier (_fbp) and click identifier) — only when analytics is not opted outUS
Google (Sign-in)OAuth sign-inUS

We are not responsible for the privacy practices or security of these third-party services. We encourage you to review their respective privacy policies.

4. Data Sharing and Disclosure

We may share your information only in these circumstances:

  • Service providers: With the sub-processors listed above, solely to provide the Service.
  • Legal compliance: When required by law, subpoena, court order, or governmental request.
  • Safety: To protect the rights, property, or safety of QodFlow, our users, or the public.
  • Business transfers: In connection with a merger, acquisition, or sale of assets. You will be notified via email before your data is transferred to a new entity.
  • With your consent: In any other case, only with your explicit consent.

5. Data Storage and Security

  • Your data is stored on servers in the United States (AWS infrastructure via Neon and Vercel).
  • We implement industry-standard security measures including: HTTPS/TLS encryption in transit, bcrypt password hashing, secure JWT session management, and role-based access controls.
No method of electronic transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. You are responsible for using a strong, unique password and safeguarding your account credentials. We are not responsible for unauthorized access resulting from compromised credentials, shared passwords, or vulnerabilities in your own systems or devices.

6. Data Retention

  • Active accounts: Data is retained as long as your account is active.
  • Deleted accounts: All personal data and workspace content is permanently and irreversibly deleted, except as listed below. We cannot recover deleted data.
  • Billing records: May be retained for up to 7 years to comply with financial and tax regulations.
  • Free-trial abuse prevention: If you start a free trial, we keep a one-way cryptographic hash of your email address for 12 months, then delete it automatically. We do not keep the address itself, and the hash cannot be reversed to recover it. Its only use is to check whether an address has already used its one free trial, so that deleting and re-creating an account cannot be used to claim unlimited trials.
  • Server logs: Retained for up to 90 days for security and debugging purposes.
  • Anonymized data: Aggregated, non-personally-identifiable usage data may be retained indefinitely for analytics and product improvement.

7. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Update or correct inaccurate data via your account settings.
  • Deletion: Delete your account and all associated data from account settings.
  • Portability: Download a JSON export of your profile and the workspaces you own (stages, tags, jobs) yourself from Settings → Profile → “Export my data (JSON)”. For any other request, email hello@qodflow.com.
  • Opt-out of analytics: Disable analytics cookies via your browser settings or a cookie-blocking extension.
  • Non-discrimination: We will not discriminate against you for exercising your privacy rights.

To exercise any of these rights, contact us at hello@qodflow.com. We will respond within 30 days (or sooner if required by applicable law).

8. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (as amended by the CPRA):

  • Right to know: What personal information we collect, use, and disclose.
  • Right to delete: Request deletion of your personal information.
  • Right to opt-out of sale/sharing: We do not sell personal information for cash. We do use Google Analytics and the Meta Pixel for measurement and ad attribution, which may qualify as “sharing for cross-context behavioral advertising” under CPRA. To opt out: enable the Global Privacy Control (GPC) signal in your browser, or email hello@qodflow.com with subject “Opt out of sharing.”
  • Right to non-discrimination: We will not deny you services or charge different prices for exercising your CCPA rights.

To submit a verifiable consumer request, email hello@qodflow.com.

9. European Users (GDPR)

If you are located in the European Economic Area (EEA) or United Kingdom:

  • Legal basis: We process your data based on: contract performance (providing the Service), legitimate interest (security, fraud prevention, analytics), and your consent (marketing cookies).
  • Additional rights: You have the right to restriction of processing, objection to processing, and the right to lodge a complaint with your local supervisory authority.
  • Data transfers: Your data is transferred to and processed in the United States. By using the Service, you consent to this transfer. We rely on Standard Contractual Clauses (SCCs) where applicable.
  • Data Processing Agreement: If your organization requires a DPA, contact us at hello@qodflow.com.

10. International Data Transfers

The Service is operated from the United States. If you access the Service from outside the US, your data will be transferred to and processed in the United States, which may have different data protection laws than your country of residence. By using the Service, you consent to this transfer.

11. Children’s Privacy

QodFlow is not directed at children under 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware that a child under 18 has provided us with personal data, we will take steps to delete such information promptly. If you believe a child has provided us with data, please contact us.

12. Data Breach Notification

In the event of a confirmed security incident that affects your personal information, we will notify affected account-owner emails on file without undue delay and in any event within seventy-two (72) hours of confirmation, as required by California Civil Code §1798.82 (CCPA), GDPR Article 33, UK GDPR, and other applicable laws. Where required by law, we will also notify the appropriate regulator within the timeframe that law specifies.

The notification will include: the nature of the incident, the categories and approximate number of data records affected, the steps we are taking to mitigate the incident, and recommended actions for you. We will publish updates on our status page as remediation progresses.

This commitment mirrors and is consistent with QodFlow’s Terms of Service §16 (Data Loss and Backups). In the event of any inconsistency between this Privacy Policy and the Terms of Service on breach notification, the longer protection applies.

13. Do Not Track

We honor the Global Privacy Control (GPC) signal: when your browser sends it, or when you opt out, Google Analytics, Google Ads and Meta Pixel scripts are not loaded, advertising click identifiers are not stored, and no pixels or server-side conversion events are sent. Outside the EEA, UK and Switzerland, the first-party campaign-source cookie (qodflow_src) may still be set; it contains no advertising identifiers and is never shared with advertising platforms. Vercel's cookieless performance metrics (Vercel Analytics and Speed Insights), which store no personal data and set no cookies, continue to run. We do not respond to the older “Do Not Track” (DNT) header. You can also opt out through the cookie banner, the control in Section 1, or by disabling cookies in your browser.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notice at least 14 days before they take effect. The “Last updated” date at the top of this page reflects the most recent revision. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.

15. Contact

For privacy-related questions or to exercise your data rights, contact us at:

QodFlow

5900 Balcones Drive #29311

Austin, TX 78731, USA

Email: hello@qodflow.com

QodFlow is operated by DGD OPCO, LLC.

← Terms of Service© 2026 QodFlow. All rights reserved.