FlowTrig FlowTrig
0% Booting workspace
Privacy Policy

Your privacy, clearly explained.

Exactly what personal data FlowTrig collects, how we use and share it, your rights over it, and how we keep it safe — in plain language.

Last updated: July 2026 GDPR · DPDP · CCPA aligned Meta / WhatsApp compliant
Encrypted
In transit & at rest
Never sold
We don’t sell your data
Your region
IN / EU / US hosting
Delete anytime
Full erasure on request
01

Overview

This Privacy Policy explains how FlowTrig (“FlowTrig”, “we”, “us”), operated by FlowTrig, collects, uses, shares and protects personal data when you use the FlowTrig platform, dashboard, APIs and related services (the “Service”).

FlowTrig is built on the official WhatsApp Business Platform and adjacent channels (Instagram, Facebook, Telegram). You are the data controller of your customers’ data; FlowTrig acts as a data processor, handling it only to deliver the Service on your instructions. This policy works alongside our Terms & Data.

02

Personal Data We Collect

We collect and process the following categories of data:

  • Account data — name, email address, phone number, company name and billing details.
  • Contact & CRM data — your customers’ names, phone numbers, tags, segments and notes you store.
  • WhatsApp & conversation data — messages, media (images, documents, audio, video), call recordings/transcripts and metadata across connected channels.
  • Automation data — flows, templates, chatbot training material and trigger logs.
  • Payment data — processed by our payment providers; we store transaction status, not full card numbers.
  • Technical data — IP address, device / browser information, cookies and usage analytics needed to operate and secure the Service.
  • Data from other sources — limited information from connected platforms (e.g. Meta) and public / marketing sources to keep your records accurate.
03

How We Use Your Data

We use the data above only to:

  • Operate, maintain and deliver the Service and its automations.
  • Route messages, calls, payments and bookings across your connected channels.
  • Provide AI-assisted replies and chatbots (using the AI provider key you supply).
  • Provide customer support, process billing and send service notifications.
  • Monitor security, prevent abuse and improve product performance.
  • Comply with legal obligations and the policies of Meta / WhatsApp.

We do not sell your data or your customers’ data, and we do not use your conversation content to train our own AI models.

4b

Social Logins & Connected Platforms

If you connect or sign in using a third-party account (Facebook, Instagram, Google), we receive limited profile information from that provider — typically your name, email, profile picture and account ID — based on that platform’s privacy settings. When you connect a business channel (WhatsApp, Instagram, Facebook, Telegram), we also receive the data needed to send and receive messages on your behalf.

We use this information only to operate the features you enable. We do not control, and are not responsible for, how the third-party platform independently uses your data — please review that provider’s own privacy policy.

05

Data Sharing & Third Parties

We share data only with sub-processors essential to the Service, each bound by data-protection obligations:

  • Meta / WhatsApp, Instagram, Facebook, Telegram — to deliver messaging on their platforms.
  • Payment processors (e.g. Razorpay / Stripe) — to process transactions you initiate.
  • AI providers (OpenAI, Anthropic, Google, etc.) — only via the API key you connect.
  • Cloud, hosting & analytics providers — for hosting, storage, delivery and usage measurement.

We disclose data to authorities only where legally compelled. We never sell personal data to advertisers or data brokers.

06

Storage & Security

Your data is encrypted in transit (TLS) and at rest. Access is least-privilege, protected by authentication and audit logging. We host on secured infrastructure aligned with SOC 2 and ISO 27001 practices. You may choose your data region (IN / EU / US) where available. While we apply strong protections, no method of transmission or storage is 100% secure.

07

Data Retention

We retain personal data only as long as your account is active or as needed to provide the Service, comply with legal obligations, resolve disputes and enforce agreements. On account closure we delete or anonymize personal data within 90 days, except where longer retention is legally required. Encrypted backups may persist for a limited window before routine rotation.

08

Your Rights & Choices

Subject to applicable law, you have the right to:

  • Access a copy of the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Delete your data (“right to be forgotten”).
  • Export / port your data in a portable format.
  • Object to or restrict certain processing, and withdraw consent.
  • Lodge a complaint with your local data-protection authority.

You can opt out of marketing anytime by replying “STOP” / “UNSUBSCRIBE” to our messages or emailing us; we may still send essential service notices. Exercise most of these in the dashboard or by emailing privacy@flowtrig.com. We respond within the timelines required by law.

09

Data Deletion Process

To request deletion of your account and associated personal data:

  • In-app: Settings → Account → Delete account, or
  • Email privacy@flowtrig.com from your registered address with the subject “Data Deletion Request”.

We verify your identity, then permanently delete or anonymize your personal data within 90 days, and instruct sub-processors to do the same, except where retention is legally required. We confirm by email once completed.

10

Cookies & Tracking

We use essential cookies (for login, security and preferences) and, with your consent, analytics cookies (e.g. Google Analytics) to understand usage and improve the Service. You can accept or reject non-essential cookies via our cookie banner, and manage them in your browser at any time. Rejecting non-essential cookies will not affect core functionality.

11

GDPR, DPDP & CCPA Compliance

We handle personal data consistent with the EU/UK GDPR, India’s Digital Personal Data Protection Act, 2023 (DPDP) and California’s CCPA/CPRA. This includes lawful bases for processing, honoring data-subject / consumer rights, data-processing terms with sub-processors, and safeguards for cross-border transfers. Under CCPA, we do not sell or “share” personal information as those terms are defined, and we do not discriminate against you for exercising your rights.

11b

US State Privacy Rights

If you are a resident of California, Virginia, Colorado, Connecticut, Utah or another US state with a comprehensive privacy law, you have the right to: know what personal information we collect and how it is used; access and obtain a copy of it; correct inaccuracies; request deletion; and opt out of targeted advertising, the “sale” or “sharing” of personal information, and profiling. We do not sell or share your personal information for cross-context behavioral advertising, and we do not discriminate against you for exercising these rights.

How to exercise & appeal: submit a request to privacy@flowtrig.com. We verify your identity, then respond within the timeframe required by law (generally 45 days, extendable once). If we decline, you may appeal by replying to our decision; if the appeal is denied you may contact your state Attorney General. You may use an authorized agent with valid proof of authorization.

11c

Do-Not-Track Signals

Most browsers and some operating systems offer a “Do-Not-Track” (DNT) setting. No uniform standard for recognizing DNT signals has been finalized, so we do not currently respond to DNT browser signals. If a standard is adopted that we are required to follow, we will update this policy accordingly.

12

Children’s Data

The Service is intended for businesses and is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

13

Changes to This Policy

We may update this Privacy Policy to reflect changes in our Service, law or practices. Material changes will be notified via the dashboard or email. The “Last updated” date at the top reflects the latest revision. Continued use after changes take effect constitutes acceptance.

14

Contact & Grievance Officer

For privacy requests, data deletion or questions about this policy, contact our Grievance & Data Protection Officer:

  • Email: privacy@flowtrig.com
  • Address: FlowTrig — Kolkata, India

We aim to acknowledge data requests within 72 hours and resolve them within statutory timelines.

This document is provided for transparency and is not legal advice. We recommend review by qualified legal counsel for your jurisdiction before going live.

FT 60s Hi 👋 a quick hello from our founderWhat FlowTrig does — in 60 seconds