Privacy Policy
Effective date:
This Privacy Policy explains how FlowingMail ("FlowingMail", "we", "us") - a product of Sadonis - collects, uses, discloses, and safeguards information when you visit flowingmail.com or use our email automation platform (the "Service"). It applies to information processed about (a) visitors to our marketing site, (b) registered users and their team members, and (c) individuals whose contact data customers import into the Service for the purpose of sending email campaigns.
1. Information we collect
Account information. When you create an account we collect your name, email address, password (hashed), company name, and authentication tokens. OAuth logins additionally expose a provider-issued user identifier.
Customer content. Data you upload to the Service - contacts, templates, workflows, campaign statistics - is stored on our behalf and is considered your content. FlowingMail processes this content only to operate the Service.
Provider credentials. FlowingMail runs on your own email provider (Resend, SendGrid, Mailgun, Amazon SES, or raw SMTP). We store the API keys or SMTP credentials you supply, encrypted at rest, and use them solely to dispatch email on your behalf.
Usage data. Server logs, request metadata, approximate IP-derived geography, device and browser identifiers, and product-event telemetry (e.g. feature usage) for security, billing reconciliation, and product improvement.
Payment data. Billing is handled by a third-party payment processor. We receive a payment token, the last four digits of your card, and billing metadata. We do not store full card numbers.
2. How we use information
- Provide, operate, and secure the Service
- Authenticate users and protect against abuse
- Process payments and invoices
- Send transactional messages (password resets, receipts, security alerts)
- Respond to support requests
- Analyze aggregate usage to improve reliability and features
- Comply with legal obligations and enforce our Terms
3. Legal bases (EEA / UK)
Where GDPR or UK GDPR applies, we rely on: performance of a contract to provide the Service, legitimate interests in running and improving the Service, legal obligations, and - where required - consent (which you may withdraw at any time). For email sent by customers to their own recipients, the customer is the controller and FlowingMail is the processor.
4. Sharing and subprocessors
We share information only with subprocessors that help us deliver the Service (cloud hosting, database, observability, payment processing) and with authorities where legally required. The email provider you select (Resend, SendGrid, Mailgun, Amazon SES, or your SMTP server) is a separate controller or processor of the messages it delivers - you choose it, you configure it, and their privacy terms govern their processing.
A current list of our subprocessors is available on request.
5. International transfers
FlowingMail may process data in jurisdictions other than where you reside. Where we transfer personal data from the EEA, UK, or Switzerland to a jurisdiction without an adequacy decision, we rely on Standard Contractual Clauses or an equivalent approved mechanism.
6. Retention
Account data is retained while your account is active and for a reasonable period thereafter for billing, dispute resolution, and legal obligations. Customer content is deleted on request or within a reasonable period after account termination, except where retention is legally required. Backups are rotated on a standard schedule and may persist for a short window after primary-store deletion.
7. Your rights
Subject to applicable law, you may request access to, correction of, deletion of, or portability of your personal data, and you may object to or restrict certain processing. If you are a resident of California, Colorado, Virginia, or other US states with comprehensive privacy laws, you have additional rights including the right to opt out of certain sharing and to non-discrimination for exercising your rights.
If you are an end recipient of an email sent through FlowingMail, please contact the customer who sent you that email - they are the controller of your data. We will assist the customer in responding to your request.
8. Cookies and analytics
We use strictly necessary cookies for authentication and session security, and a small set of first-party analytics signals to measure aggregate site performance. We do not sell personal information. Where required, we request consent for non-essential cookies.
9. Security
We apply technical and organizational measures appropriate to the risk, including encryption in transit (TLS), encryption at rest for secrets such as provider credentials, access controls, and audit logging. No system is completely secure; please use a strong, unique password and enable multi-factor authentication where offered.
10. Children
The Service is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. The effective date above indicates when it was last revised. Material changes will be communicated via the Service or by email to the account owner.
12. Contact
Questions about this policy or our privacy practices can be directed to [email protected]