01Who We Are and How to Reach Us
CollabFlow is a collaboration pipeline and payment tracker for creators, freelancers, and other independent professionals (the "Service"). This policy explains what personal data we handle, why, and what you can require us to do about it.
- Controller: [LEGAL ENTITY NAME], [REGISTERED ADDRESS], India.
- Privacy contact: support@getcollabflow.com.
- Grievance Officer (India, under the Information Technology Rules, 2021 and the Digital Personal Data Protection Act, 2023): [GRIEVANCE OFFICER NAME], reachable at support@getcollabflow.com. We acknowledge grievances within 24 hours and resolve them within 15 days.
- EU and UK representative (GDPR Article 27): [EU ARTICLE 27 REPRESENTATIVE — NAME AND EU ADDRESS]. Individuals in the EEA and the UK may contact our representative instead of us on any matter relating to this policy.
This page describes our actual practices. It is not an independent audit, and we do not claim any security certification.
02Our Role in Your Data
Data privacy law distinguishes between deciding why data is processed and merely processing it on someone else's instructions. Both apply to us, in different places.
- We are the controller for your account, profile, billing, and usage data. We decide what to collect and why, and this policy is our notice to you.
- We act on your instructions for the content you bring into CollabFlow: the email messages your keywords match, the brands and contacts you record, the team members you add, and the Notion pages you link. You choose what enters the Service, and we process it to run the features you turn on. Where that content includes personal data about other people, you are responsible for having a lawful basis for it. See Brands, Contacts, and Other People You Add.
If you use CollabFlow through a business and need a written data processing agreement with Standard Contractual Clauses, email us and we will provide one.
03Personal Data We Collect
Account and identity
You sign in with Google. We do not operate password sign-up, and we never receive or store your Google password. From Google we receive your name, email address, and basic profile information under the profile and email scopes.
Creator profile
- Contact and location details you choose to add: phone number, bio, city, country, and postal code.
- Your preferred display currency and Smart Reply settings.
- Social profile handles and links, such as Instagram, YouTube, and TikTok.
Pipeline records
- Brands: company name, contact person, email address, phone number, social handles, and your notes.
- Collaborations: campaign details, deliverables, amounts, dates, stage, status, and any linked Notion page reference.
- Team members: name, email address, and phone number of people you assign work to. These are records inside your account, not user logins.
- Payments: amounts, dates, methods, and notes you record.
- Briefs: brief templates, the questions they contain, the answers submitted, and the unique link identifier that lets a recipient open the brief form.
Gmail content
If you connect Gmail, we store the keywords you define and, for messages that match them, the thread subject, snippet, sender, recipients including any cc and bcc visible to your account, timestamps, and the full body of the matched message. We store the full body because the Service shows you the message in context and uses it to draft replies and extract collaboration details. Replies sent through CollabFlow are stored against the thread.
Connection credentials
OAuth access and refresh tokens for Gmail and Notion, together with the connected account identifier and granted scopes. Tokens are encrypted before they are written to the database.
Billing
Subscription status, plan, billing interval, and the identifiers our payment provider returns. We never receive or store full card numbers. Card details are entered directly with our payment provider.
Technical and usage data
Server and application logs containing IP address, browser user agent, requested pages, timestamps, and error diagnostics, plus counters that measure your usage against your plan limits.
Early access waitlist
If you request early access on this website, we store your email address, whether you consented to product updates, and the date you signed up.
04Brands, Contacts, and Other People You Add
CollabFlow necessarily holds personal data about people who are not our users: the brand contacts you record, the team members you assign, the people who email your connected inbox, and the people who complete a brief you sent.
- Between you and them, you decide what to record and you are responsible for having a lawful basis, for giving any notice their local law requires, and for responding if they ask what you hold. We process this data only to provide the Service to you.
- If one of those people contacts us directly with a privacy request, we will normally refer them to you as the person who controls the record, and we will help you respond. Where the law requires us to act ourselves, we will.
- Brief submissions are collected through a link containing a unique, unguessable identifier. Anyone holding that link can open the form, so treat brief links as confidential and do not publish them.
05Why We Process Your Data, and Our Legal Bases
For people protected by the GDPR or UK GDPR, we must have a legal basis for every purpose. Ours are as follows.
- To provide the Service — creating your account, storing your pipeline, matching emails to keywords, drafting and sending replies, syncing Notion content, and showing your payment tracking. Basis: performance of our contract with you.
- To connect Gmail and Notion — reading and sending on your behalf through those APIs. Basis: your consent, given in the Google or Notion permission screen and withdrawable at any time by disconnecting.
- To take payment and manage subscriptions. Basis: performance of our contract, and compliance with tax and accounting law for the resulting records.
- To keep the Service secure and working — logging, debugging, abuse and fraud prevention, enforcing plan limits, and backups. Basis: our legitimate interests in operating a secure and sustainable service. We have weighed this against your interests and limited it to what running the Service requires.
- To send service messages such as billing notices, security alerts, and material changes to these documents. Basis: performance of our contract and our legitimate interest in keeping you informed. You cannot opt out of these while you hold an account, because they concern the Service you are paying for.
- To send product and launch updates to waitlist subscribers. Basis: your consent, withdrawable through the unsubscribe link in every message.
- To comply with legal obligations and to establish, exercise, or defend legal claims. Basis: legal obligation and legitimate interests.
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use it for advertising profiling.
06Google User Data and Limited Use
CollabFlow's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
The scopes we request, and why
- https://www.googleapis.com/auth/gmail.readonly — to find the inbound emails that match the keywords you define and turn them into collaboration records. This scope is read-only; we cannot modify or delete anything in your mailbox.
- https://www.googleapis.com/auth/gmail.send — to send replies from your connected address, in the matched thread. This scope only sends; it grants no additional read access.
- profile and email — to identify you and create your account.
We also subscribe to Gmail push notifications through Google Cloud Pub/Sub so that matched mail is picked up promptly rather than by continuous polling.
Our Limited Use commitments
- We use Google user data only to provide and improve the user-facing features described in this policy.
- We do not transfer Google user data to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition.
- We do not use Google user data for serving advertisements of any kind.
- We do not sell Google user data.
- We do not use Google user data to develop, improve, or train generalised or non-personalised artificial intelligence or machine learning models. See AI Processing for exactly how AI is used.
- We do not allow humans to read your Gmail data, except where you give explicit consent for specific messages (for example when you ask support to investigate a problem), where it is necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data is aggregated and anonymised.
You can revoke CollabFlow's access at any time from your CollabFlow settings, or from your Google Account permissions page. Keyword matching and reply sending stop immediately when access is revoked.
07AI Processing
Two features use a large language model. We tell you exactly what leaves our systems, because one of them processes your email content.
- Smart Reply and brief extraction: when a matched email is processed, we send the message subject and body (truncated to roughly 12,000 characters) and the definitions of the fields we are trying to fill to Google's Gemini model, so it can extract details such as budget, deliverables, and deadlines and draft a reply.
- Collaboration creation from a submitted brief: we send the labels and values a recipient submitted, and the brand name if known, to produce a draft collaboration record.
Data is sent to Google's Gemini API as a service provider processing on our behalf. It is not used to train generalised AI or machine learning models, by us or by the model provider. We do not fine-tune models on your data.
Accuracy and your control
- AI output can be wrong. Extracted amounts, dates, and terms are drafts for you to check, not verified facts.
- If you enable automatic Smart Reply, replies may be sent from your Gmail address without you reviewing each one. That is the point of the feature, but it means a mistaken or unintended reply can reach a brand. You control whether the feature is on, and you can turn it off at any time in your settings.
- We do not make automated decisions that produce legal effects concerning you or similarly significantly affect you within the meaning of GDPR Article 22.
- If you would rather not use AI processing at all, leave Smart Reply disabled. The rest of the Service works without it.
08Where Your Data Is Stored and Transferred
Your CollabFlow database is hosted in the European Union, in the Frankfurt region (AWS eu-central-1). That is where your account, pipeline, and stored email content live at rest.
We are transparent about the limits of that statement, because "hosted in the EU" is often claimed and rarely qualified:
- Our company and our personnel are located in India, so authorised staff access data from outside the EEA when operating and supporting the Service.
- Some sub-processors necessarily process data elsewhere. Google, Notion, and our payment and email providers operate global infrastructure. Sending a reply through Gmail or fetching a Notion page means data travels to those providers.
India has not received an adequacy decision from the European Commission. Where personal data of people in the EEA or the UK is transferred to us or to a sub-processor outside those regions, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant), together with supplementary measures including encryption in transit and at rest and access limited to the personnel who need it. You can request a copy of the relevant transfer mechanism by emailing us.
09Service Providers and Sub-Processors
We use a small set of vendors to run the Service. Each is bound by a contract that limits them to processing data on our instructions. We publish the full list, with each vendor's purpose and processing location, on our sub-processor page, and we update it whenever the list changes.
In summary, they cover database and cache hosting, server hosting and network protection, the Google and Notion integrations you connect, AI processing, transactional email, and payment processing.
We may also disclose data where we are legally required to, to enforce our Terms or Acceptable Use Policy, to protect our rights or someone's safety, or in connection with a merger, acquisition, or sale of assets — in which case we will notify you before your data becomes subject to a different privacy policy.
10How Long We Keep Data
- Account, profile, and pipeline data — for as long as your account is active. After you delete your account, removed from live systems within 30 days.
- Gmail message content — for as long as your Gmail connection is active. Removed within 30 days of you disconnecting Gmail or deleting your account.
- OAuth tokens — deleted when you disconnect the integration or delete your account. We also stop the associated Gmail notification subscription at that point.
- Billing and transaction records — retained for up to eight years after the transaction, because Indian tax and company law require us to keep them. This retention survives account deletion and cannot be waived by request.
- Server and application logs — up to 90 days, then deleted or aggregated.
- Encrypted backups — overwritten on a rolling cycle of no more than 35 days. Data you delete can persist in a backup until that cycle completes, after which it is gone.
- Early access waitlist — until you unsubscribe, or 24 months after your last interaction, whichever comes first.
11Security
- All traffic to and from the Service is encrypted in transit using HTTPS/TLS.
- Data is encrypted at rest by our managed database provider, and Gmail and Notion access tokens are separately encrypted at the application layer before being written to the database, so a database copy alone does not yield usable tokens.
- Sign-in is delegated to Google, so there is no CollabFlow password for an attacker to steal, guess, or leak.
- Administrative access is limited to the small number of people who need it to operate and support the Service.
- Session cookies are transmitted only over HTTPS, and requests are protected against cross-site request forgery.
No service can promise perfect security, and we do not. We hold no SOC 2, ISO 27001, or equivalent certification, and we will say so plainly rather than imply otherwise. You are responsible for securing the Google account used to access CollabFlow; we strongly recommend enabling two-factor authentication on it.
12If There Is a Data Breach
If a personal data breach occurs, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, as GDPR Article 33 requires, and we will notify the Data Protection Board of India as the DPDP Act requires. Where the breach is likely to result in a high risk to your rights and freedoms, we will notify you directly and without undue delay, describing what happened, what data was involved, and what you should do.
13Your Privacy Rights
Exercise any of these by emailing support@getcollabflow.com. We respond within 30 days and will tell you if we need longer. We do not charge for these requests or treat you worse for making one. We may need to verify your identity first.
Everyone
- Delete your account from your account settings. This stops your Gmail notification subscription, cancels any active subscription on a best-effort basis, and deletes your data on the timetable in How Long We Keep Data.
- Disconnect Gmail or Notion at any time, from CollabFlow or from your Google or Notion account.
- Correct your profile and records directly in the app.
- Export your data. Self-service export is not yet available in the app. Until it is, email us and we will send you a machine-readable copy of your collaborations, brands, and payment records within 30 days at no charge.
EEA and UK
You have the right to access your data, to have it corrected or erased, to restrict or object to processing (including processing based on our legitimate interests), to data portability, and to withdraw consent at any time without affecting processing already carried out. You also have the right to lodge a complaint with the supervisory authority in your country of residence or work; we would appreciate the chance to address it first.
India
As a Data Principal under the Digital Personal Data Protection Act, 2023, you may obtain a summary of the personal data we process and the processing activities undertaken, request correction, completion, updating, or erasure, nominate another individual to exercise your rights in the event of your death or incapacity, and raise a grievance with our Grievance Officer. If we do not resolve it, you may complain to the Data Protection Board of India.
California and other US states
You may request to know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients; to have it corrected or deleted; and to be free from discrimination for exercising these rights. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is no opt-out to offer. You may use an authorised agent, and we will ask for proof of authorisation. Residents of Colorado, Connecticut, Virginia, and other states with comparable laws have equivalent rights, including the right to appeal a refusal.
14Age Requirement
CollabFlow is a business tool for adults. It is not directed at children, and you must be at least 18 years old to create an account. We do not knowingly collect personal data from anyone under 18. If we learn that we have, we will delete the account and its data promptly. If you believe a minor has given us data, contact us and we will act.
16Changes to This Policy
We update this policy as the Service changes. The date at the top always reflects the current version. If a change materially affects your rights or how we use your data — for example a new category of data, a new purpose, or a new sub-processor handling your email content — we will notify account holders by email or in-app notice at least 30 days before it takes effect, so you can object, export your data, or close your account. Continued use after that date means the updated policy applies.
Contact
Privacy questions, data requests, or integration concerns:
Postal: [LEGAL ENTITY NAME], [REGISTERED ADDRESS], India. Grievance Officer: [GRIEVANCE OFFICER NAME]. EEA and UK representative: [EU ARTICLE 27 REPRESENTATIVE — NAME AND EU ADDRESS].