FlowRota Privacy Policy
FlowRota (“we”, “our”, “us”) values your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you use our services, including our web app, mobile app, and related tools or platforms (collectively, the “Service”).
1. Who we are
FlowRota is a workforce management and staff scheduling platform that helps businesses manage shifts, time off, and team communication efficiently.
For privacy enquiries, contact us at contact@flowrota.com
2. Information we collect
a. Information you provide directly
- Your name, email address, and password when creating an account
- Company and team information such as department names or roles
- Shift, time-off, and attendance data entered in the system
- Payment and billing information (handled securely by our payment provider, Paddle)
b. Information collected automatically
- Device and browser details (type, version, IP address)
- Usage and log data (pages visited, actions taken, timestamps)
- Cookies or local storage data for login sessions and preferences
3. How we use your information
- To operate and improve the FlowRota platform
- To manage user accounts and authenticate logins
- To process subscription payments and invoices
- To send notifications, updates, and important service messages
- To comply with legal or tax obligations
4. How we share your information
We do not sell your personal data. We only share it with trusted third-party providers when necessary to deliver our services:
- Paddle — our payment processor, which securely handles all subscription and billing information. We do not store your card details ourselves. See Paddle’s privacy policy at paddle.com/legal/privacy .
- Wasabi — our document and file storage provider, used for securely storing files and attachments uploaded through the FlowRota platform. See Wasabi’s policy at wasabi.com/legal/privacy-policy .
- ImageKit — our image delivery and optimisation service, used to store and serve images (such as profile photos) for faster loading and reliability. See ImageKit’s policy at imagekit.io/privacy .
5. Legal basis for processing
We process your data based on:
- Your consent (e.g. when signing up or opting into messages)
- Our contractual obligations to provide the FlowRota service
- Legitimate business interests (e.g. improving functionality)
- Legal compliance (e.g. tax and payment records)
6. Data retention
We retain your data for as long as necessary to provide the Service, comply with legal obligations, or resolve disputes. Account data is deleted upon request or after account closure.
7. Data storage and security
We use secure cloud infrastructure, encryption, and access controls to protect your data. File storage is handled via Wasabi and ImageKit, which comply with GDPR and industry security standards.
8. Your rights
You have the right to:
- Access, correct, or delete your personal data
- Request a copy of your data (“data portability”)
- Withdraw consent where applicable
- Lodge a complaint with the ICO (UK) or your local regulator
To make a data request, contact us at contact@flowrota.com
9. Cookies and local storage
We use cookies and local storage to improve user experience and keep you signed in. You can manage cookie preferences in your browser settings.
10. Updates to this policy
We may update this policy from time to time. Updates will be posted on this page with a revised “Last updated” date.