Privacy
Privacy Policy
- Operator
- FlowChat
- Contact
- info@aviacms.com
- Postal address
- Mastichari
Who this covers
FlowChat is software that lets a business send interactive forms to people through WhatsApp. It runs in two ways, and which one applies decides who is responsible for your data:
- Self-hosted. A business installs FlowChat on its own server. That business is the operator, and this policy describes what the software does on their behalf.
- Hosted service. FlowChat runs FlowChat and businesses use it as customers. FlowChat is the operator.
In both cases the business using FlowChat decides what its forms ask and what it does with the answers. FlowChat provides the software.
What is stored
Account details for people who sign in: name, email address, a hashed password, role, and the time of the last sign-in. Passwords are stored only as a one-way hash and cannot be read back.
WhatsApp connection details for the business's own number: the WhatsApp Business Account ID, the phone number ID, and an access token issued by Meta. The access token and the encryption keys for form data are encrypted before they are written to the database.
Form answers submitted by the business's customers: their phone number, a name where the form asks for one, and whatever else the form was built to collect — a booking, an order, a survey response, a delivery address.
Message activity: when a message was sent, delivered and read, and the events Meta reports back about it. This is what makes delivery tracking possible.
Technical records: IP address and browser identifier for signed-in actions, an append-only audit trail of privileged changes, and error logs used to diagnose failures. Credentials are redacted from the audit trail before storage.
Cookies: one session cookie that keeps you signed in, and a CSRF token that protects forms against cross-site requests. Both are essential to the product working; neither is used for advertising or tracking.
Why it is stored
- To deliver the forms the business sends, and to record the answers.
- To connect to the WhatsApp Business Platform on the business's behalf.
- To keep accounts secure, and to let a business see who changed what.
- To diagnose faults and prevent abuse.
- To bill for a subscription, where the install has billing switched on.
Data is not sold. It is not used for advertising. It is not shared with anyone except the processors listed below.
Who else processes it
- Meta Platforms, Inc. — every message and every form answer passes through the WhatsApp Business Platform, which Meta operates. Meta's own terms and privacy policy apply to that processing.
- Payment provider — where subscription billing is enabled, card details are handled directly by the payment provider. FlowChat never receives or stores a card number.
- Hosting provider — the server the software runs on, which stores the database and logs listed above.
How long it is kept
Account data, form answers and message records are kept for as long as the business using FlowChat needs them. A business can delete its own records at any time from the admin panel, and an operator can delete a business entirely. Logs and the audit trail are kept for a shorter period for security and troubleshooting.
Your rights
Depending on where you live, you may have the right to see a copy of your data, to have it corrected, to have it deleted, to receive it in a portable format, or to object to how it is used. To exercise any of these, see the Data Deletion Instructions.
If you filled in a form sent by a business, that business controls your data and is the right place to ask. FlowChat will pass on anything it receives.
Security
Access tokens, encryption keys and passwords are encrypted or hashed at rest. Access is scoped so that one business cannot read another's records, and privileged actions are recorded in an audit trail. No system is perfectly secure, but the software is built so that a leaked database does not hand over working credentials.
Children
FlowChat is a business tool and is not intended for use by children.
Changes
This policy may be updated. Material changes will be reflected in the effective date shown at the top of this page.
Contact
Questions about this policy, or about your data, go to info@aviacms.com. Postal enquiries: Mastichari.
See also: Privacy Policy, Terms of Service, Data Deletion Instructions.