Privacy

Privacy policy

Last updated July 30, 2026

Information we process

We process account identifiers, organization settings, client and invoice records, project approvals, payment records, communications, product events, and technical security information. We do not store raw card data.

Why we process it

  • Provide, secure, support, and improve PaidFlow.
  • Deliver requested emails and record relevant delivery events.
  • Synchronize subscriptions and optional agency payment events.
  • Meet legal obligations and prevent abuse.

AI-assisted features

AI preflight sends a minimized invoice summary to OpenAI only when an authorized user requests it. Card details, bank account numbers, identity documents, credentials, and unnecessary personal data are excluded. API requests are configured not to be stored by the model provider, and suggestions require user review.

Service providers

PaidFlow may use Supabase for data and authentication, Resend for transactional email, Stripe for subscriptions and optional connected payments, OpenAI for requested AI features, Sentry for error monitoring, PostHog for privacy-conscious analytics, and Vercel for application hosting.

Retention and security

Retention depends on account status, contractual requirements, legal obligations, and backup cycles. Controls include tenant-level database policies, restricted storage, encrypted transport, signed webhooks, role-based access, audit history, and short-lived file access.

Your choices

Depending on applicable law, individuals may request access, correction, deletion, portability, or objection. Organization owners can export records and manage team access. Requests can be submitted through the contact page.