FlowLane FlowLane Back to home
Legal

Privacy Policy

Last updated: 23 March 2026  ·  Effective: 23 March 2026

Table of Contents

  1. Overview & Scope
  2. Data We Collect
  3. How We Use Your Data
  4. Third-Party Services
  5. Data Storage & Security
  6. Data Retention
  7. Your Rights
  8. Children's Privacy
  9. Changes to This Policy
  10. Contact

1. Overview & Scope

This Privacy Policy describes how ArystoTech Software & AI Systems Ltd. ("we", "us", "our") collects, uses, and protects information when you use FlowLane — including the browser extension and web application at flowlanekanban.com.

We are committed to protecting your privacy. We collect only the minimum data required to provide the Service, and we never sell your personal information.

Free Tier users: Your board data never leaves your device. It is stored locally in your browser using chrome.storage.local. We have no access to it.

2. Data We Collect

2.1 Free Tier (No Account Required)

When using the Free Tier, no personal data is collected by us. All board data (projects, columns, cards) is stored locally in your browser via chrome.storage.local and is never transmitted to our servers.

2.2 Premium Tier (Account Required)

When you create an account and subscribe to the Premium Tier, we collect:

Data Source Purpose
Display name & email address Google / GitHub OAuth Account identification, transactional emails, support
Profile photo URL Google / GitHub OAuth Displayed in collaboration presence UI
Firebase UID Firebase Authentication Linking your data to your account
Board data (projects, columns, cards, comments) Created by you Cloud sync and real-time collaboration
Subscription status & tier Paddle webhook Granting/revoking Premium access
Paddle customer ID Paddle Linking billing records to your account
Presence data (last-active timestamp) Extension heartbeat Showing online collaborators; purged after 45 seconds of inactivity

2.3 Usage & Technical Data

We may automatically collect limited technical data to maintain service reliability, including:

  • Browser type and extension version (for bug reports you submit).
  • Cloud Function invocation logs (retained for up to 30 days by Firebase).

We do not use analytics trackers, advertising pixels, or session recording tools.

3. How We Use Your Data

We use the data we collect solely to:

  • Provide, maintain, and improve the Service.
  • Authenticate your identity and manage your account.
  • Sync your board data across devices (Premium Tier).
  • Enable real-time collaboration features (Premium Tier).
  • Process payments and manage your subscription via Paddle.
  • Send transactional communications (receipts, account alerts, downgrade notices).
  • Respond to support requests.
  • Comply with legal obligations.

We do not use your data for advertising, profiling, or any purpose beyond providing the Service.

4. Third-Party Services

We use the following sub-processors. Each is subject to their own privacy policy.

Provider Purpose Data Shared
Google Firebase Authentication, Firestore database, Cloud Functions Email, UID, board data, subscription status
Paddle.com Market Limited Payment processing, subscriptions, tax compliance (Merchant of Record) Email, Firebase UID, billing details
Google OAuth / GitHub OAuth Sign-in authentication Name, email, profile photo (as provided by your OAuth provider)

We do not share your data with any other third parties except as required by law.

5. Data Storage & Security

Premium Tier data is stored in Google Firebase Firestore, which is hosted on Google Cloud infrastructure with encryption at rest and in transit.

We implement reasonable technical and organisational measures to protect your data against unauthorised access, alteration, disclosure, or destruction, including:

  • Firestore Security Rules that enforce per-user data access controls.
  • Cloud Functions restricted to authenticated requests from the extension's origin.
  • HTTPS for all data in transit.
  • Paddle-managed, PCI-DSS-compliant payment processing (we never store card details).

No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

6. Data Retention

We retain your data for as long as your account is active or as necessary to provide the Service.

  • Active accounts: Data retained until you delete your account.
  • Presence data: Automatically purged after 45 seconds of inactivity.
  • Cloud Function logs: Retained up to 30 days by Firebase.
  • Billing records: Retained as required by Paddle and applicable tax law (typically 7 years).
  • Deleted accounts: Personal data removed within 90 days of deletion request, except data required for legal compliance.

7. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access — Request a copy of the personal data we hold about you.
  • Rectification — Request correction of inaccurate data.
  • Erasure — Request deletion of your personal data ("right to be forgotten").
  • Portability — Export your board data at any time using the JSON/CSV export feature built into FlowLane.
  • Objection / Restriction — Object to or request restriction of certain processing.
  • Withdraw Consent — Where processing is based on consent, withdraw it at any time by contacting us.

To exercise any of these rights, email us at support@flowlanekanban.com. We will respond within 30 days. We may need to verify your identity before processing your request.

8. Children's Privacy

The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal data, please contact us and we will delete it promptly.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date at the top of this page and, where appropriate, by sending a notice to your registered email address.

Continued use of the Service after changes are posted constitutes your acceptance of the updated policy.

10. Contact

For privacy-related questions, data requests, or concerns, please contact us:

  • Company: ArystoTech Software & AI Systems Ltd.
  • Email: support@flowlanekanban.com
  • Website: flowlanekanban.com
Home Privacy Policy Terms & Conditions Refund Policy Support

© 2026 FlowLane — ArystoTech Software & AI Systems Ltd. All rights reserved.