1. Introduction
Flovanta ("we", "us", "our") provides accounts receivable automation and invoice reminder services for marketing agencies.
This Privacy Policy explains what personal information we collect when you use our platform, how we use it, who we may share it with, and the rights you have over your data — including rights under the General Data Protection Regulation (GDPR) and equivalent laws.
By using Flovanta, you agree to the collection and use of information as described in this policy. If you are using Flovanta on behalf of an organisation, you confirm you have the authority to agree on that organisation's behalf.
2. Data we collect
Information you provide directly
- Account and profile information: name, work email address, company name, job title, and optionally a phone number.
- Billing and invoice data: billing contact details, invoice numbers, amounts, due dates, and payment status.
- Support and sales correspondence you send us via email or the contact form.
- Files and invoice data you upload during onboarding or while using the service.
Automatically collected information
- Usage metrics and logs: which features you use, timestamps, and performance data.
- Technical data: IP address, browser type and version, device type, and operating system.
- Cookies and similar technologies used for analytics, performance measurement, and essential functionality.
Payment information
We use Stripe to process all payments. Flovanta never stores full credit card numbers, CVV codes, or other sensitive payment credentials on our servers. Payment data is collected and processed directly by Stripe on their PCI DSS-compliant infrastructure.
3. Google Sign-In
Flovanta uses Google Sign-In only to authenticate users securely. We request the standard Google OAuth scopes openid, email, and profile.
We use basic profile information provided by Google, such as name and email address, to create and manage the user's Flovanta account.
4. How we use your data
We process personal data to:
- Provide, operate, and improve the Flovanta service.
- Process payments and manage your subscription (via Stripe).
- Send you transactional communications: account confirmations, payment receipts, and service notices.
- Respond to support requests and sales enquiries.
- Perform analytics to understand usage patterns and improve product quality.
- Monitor for abuse, fraud, and security incidents.
- Comply with our legal obligations and enforce our Terms of Service.
We do not sell your personal data to third parties. We do not use your data for advertising purposes unrelated to Flovanta.
5. Lawful bases & GDPR
If you are in the European Economic Area (EEA) or the United Kingdom, we rely on the following lawful bases to process your personal data:
- Performance of a contract — to provide the services you have signed up for.
- Compliance with legal obligations — to meet applicable tax, accounting, or regulatory requirements.
- Legitimate interests — to improve the product, prevent fraud, and communicate about relevant updates, where these interests are not overridden by your rights.
- Consent — where we have asked for and received your explicit consent (e.g. optional marketing communications).
Your GDPR rights
If you are in the EEA or UK, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request deletion of your data ("right to be forgotten") subject to legal retention requirements.
- Restrict or object to certain types of processing.
- Receive your data in a portable, machine-readable format.
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with a supervisory authority (in Ireland: the Data Protection Commission).
To exercise any of these rights, contact us at hello@flovanta.com. We may need to verify your identity before processing your request.
6. Third parties & international transfers
We share your data only with service providers necessary to deliver the product:
- Hosting and infrastructure providers (cloud services).
- Stripe for payment processing.
- Analytics providers for product usage measurement.
- Email delivery providers for transactional emails.
We do not share your data with advertisers, data brokers, or unrelated third parties.
Personal data may be transferred to and stored in countries outside your jurisdiction, including countries outside the EEA. When we transfer data internationally, we use appropriate safeguards such as European Commission adequacy decisions or Standard Contractual Clauses (SCCs) as required by applicable law.
7. Data retention
We retain personal data only for as long as necessary to fulfil the purposes described in this policy, comply with legal obligations, resolve disputes, and enforce our agreements.
- Active account data is retained for the duration of your subscription.
- After account closure, we retain data for up to 90 days to allow account recovery, then delete or anonymise it unless a longer retention period is required by law.
- Invoice and financial data may be retained for up to 7 years for tax and accounting compliance.
- Support correspondence is retained for up to 3 years.
8. Security
We implement reasonable and industry-standard technical and organisational measures to protect your personal data, including:
- Encryption of data in transit (TLS) and at rest.
- Access controls limiting data access to authorised personnel.
- Regular security reviews and monitoring.
- Stripe's PCI DSS-compliant infrastructure for payment data.
No system is completely secure. While we take appropriate steps to protect your data, we cannot guarantee absolute security. In the event of a personal data breach that is likely to result in high risk to your rights, we will notify you and the relevant supervisory authority as required by applicable law.
9. Cookies
We and our partners use cookies and similar tracking technologies for:
- Essential functionality: session management and authentication.
- Analytics: understanding how the product is used to improve it.
- Performance: measuring page load times and stability.
You can control or disable cookies through your browser settings. Disabling essential cookies may affect core product functionality. We do not use cookies for advertising or cross-site tracking.
10. Children
Flovanta is designed for business use and is not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take prompt steps to delete that information.
11. Your rights & how to contact us
For all privacy-related questions, data subject requests, or to exercise your rights under applicable law, please contact us:
We aim to respond to all requests within 30 days. If your request is complex or you have submitted multiple requests, we may extend this period by a further two months and will notify you accordingly.
12. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:
- Post the updated policy on this page with a revised effective date.
- Notify users via email or an in-product notice where the changes are significant.
We encourage you to review this policy periodically. Continued use of Flovanta after an update constitutes acceptance of the revised policy.
Thank you for trusting Flovanta with your data. We are committed to handling it responsibly and transparently.