Mobile App Privacy Policy
Last Updated: July 23, 2026
Flowambe
Privacy Policy
Last Updated: July 23, 2026
Summary of Key Points
This summary highlights what matters most. The full policy below has the complete details.
- We collect name, contact details, event data, device information, and communication logs to operate Flowambe.
- WhatsApp is an operational notification channel - not a social plugin. Your phone number and message content are transmitted to Meta Platforms as a data processor under their terms.
- We do not sell personal information.
- We do not use identifiable customer event data to train third-party AI models without authorisation.
- You can request deletion of your account in-app (once the in-app flow is live) or via legal@flowambe.com. Account data is deleted within 7 days of a verified request.
- We operate in Nigeria and the United States and process data under GDPR, UK GDPR, NDPR, and CCPA where applicable.
- For questions: legal@flowambe.com
1. Introduction
This Privacy Policy explains how Flowambe, Inc. ("Flowambe," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information when you use our website, mobile applications, beta products, pilot programmes, event workspaces, communications, forms, and related services.
This Privacy Policy applies to:
- website visitors
- people who contact us or join a waitlist
- beta testers and pilot participants
- event hosts and planners
- vendors, staff, assistants, and other event participants
- users invited to an event workspace
- people who receive Flowambe-supported communications through WhatsApp, email, push notifications, SMS, or similar channels
- mobile app users
If you do not agree with this Privacy Policy, do not use Flowambe or provide personal information to us.
2. Flowambe's Role
Flowambe provides software and coordination-support tools for event planning and live event execution. Depending on the context, Flowambe may process information provided directly by you, by an event planner, by an event host, by a vendor, by a member of an event team, by an invited user, or by our systems.
For beta and pilot events, an event planner or organiser may provide information about hosts, vendors, staff, guests, assistants, venues, schedules, and communications. Flowambe may be demoed or tested in Nigeria and may also be demoed or tested in the United States. The person or organisation that provides information about third parties is responsible for ensuring they have the right to do so.
3. Information We Collect
3.1 Account and Contact Information
We may collect: name; email address; phone number; username or account identifier; password or authentication credentials; organisation, company, or event business name; role or title; profile information; communication preferences; date of birth (where provided); and physical address (where provided).
3.2 Social Login Data
You may register or log in using a third-party account (Google, Apple, or similar). When you do, we receive profile information from that provider - typically your name, email address, and profile picture. We use this only for the purposes described in this Policy. We are not responsible for how those providers handle your data - review their privacy policies separately.
For Apple Sign In specifically: if you delete your account, we are required by Apple to call their revocation endpoint to invalidate your Apple Sign In session. This is handled automatically by our deletion executor.
3.3 Website and Inquiry Information
If you visit the website, join a waitlist, request a demo, complete a survey, or contact us, we may collect: contact details; inquiry details; business or event information; survey responses; feedback; marketing preferences; and communications with us.
3.4 Event Information
In connection with beta tests, pilots, event workspaces, or product use, we may collect:
- event name, type, date, time, venue, and location
- event timeline, agenda, schedule, tasks, dependencies, milestones, buffers, and deadlines
- planner, host, vendor, staff, assistant, and participant information
- role assignments and permissions
- vendor service details, availability, readiness, status, and updates
- guest or participant information, where provided
- notes, instructions, operational details, and event-specific communications
- task confirmations, delay reports, readiness updates, status changes, and execution logs
- changes made to timelines, tasks, dependencies, assignments, or statuses
- audit trail entries - every task action is recorded with the acting user's ID and a timestamp
- support requests, bug reports, usability feedback, and operational observations
3.5 Communications Information
Flowambe uses the WhatsApp Business Cloud API as an operational notification channel - not a social media plugin. Through this channel, we send task alerts, timeline updates, vendor reminders, readiness requests, and related operational messages. When we do, we transmit your phone number and message content to Meta Platforms, Inc. as a data processor. Meta processes this data under its own terms and privacy policies.
We may also send communications via email, push notifications, or SMS. In connection with all communication channels, we may collect or process: sender and recipient information; phone numbers and email addresses; message content; delivery status; timestamps; replies or confirmations; communication metadata; and opt-out or preference information.
You may manage your WhatsApp notification preferences in your account settings. Turning off WhatsApp notifications stops future operational messages but does not affect account-level security messages.
3.6 Device, Usage, and Technical Information
We automatically collect: IP address; device type; browser type; operating system; app version; referring pages; pages or features viewed; date and time of access; session activity; clicks, interactions, and usage patterns; diagnostic logs; crash reports; performance data; and authentication and security logs.
3.7 Mobile App Information
If you use a Flowambe mobile app, we may collect: account and login information; event workspace activity; app usage data; device identifiers or app instance identifiers; crash and diagnostic data; push notification tokens (stored in user_device_tokens and tied to your specific device); notification preferences; and permissions you grant through your device or app settings.
We will not intentionally access device features such as contacts, camera, microphone, location, photos, or files unless the app feature requires it and appropriate permission is requested.
3.8 Payment Information
Flowambe does not currently process payments. If we later support paid services, we may collect billing contact details, transaction metadata, plan information, invoice information, and payment status. Payment card or bank details would be processed by third-party payment processors and would not be stored directly by Flowambe. We will update this Policy before introducing payments.
3.9 Sensitive Information
Flowambe is not designed to collect highly sensitive personal information unless necessary for a specific event coordination purpose. If sensitive information is submitted - for example, date of birth or physical address for event logistics - we may process it as necessary to provide, support, secure, or improve the service, or as required by law.
Users should avoid submitting government identification numbers, financial account numbers, health information, or other highly sensitive details unless specifically required by the service.
4. Legal Bases for Processing (GDPR / UK GDPR)
If you are in the European Economic Area (EEA), United Kingdom, or another jurisdiction where we must identify a lawful basis for processing, the following table summarises our bases:
| Processing Activity | Legal Basis | | --------------------------------------------------------- | ------------------------------------------------------------------------------- | | Creating and managing your account | Performance of a contract (Article 6(1)(b)) | | Operating event workspaces, tasks, and timelines | Performance of a contract (Article 6(1)(b)) | | Sending operational WhatsApp notifications | Consent - you opt in when you enable WhatsApp notifications (Article 6(1)(a)) | | Sending transactional email (account, security, deletion) | Performance of a contract / Legitimate interests (Article 6(1)(b) and (f)) | | Push notification delivery | Consent - you grant permission at device level (Article 6(1)(a)) | | Security logging, fraud prevention, audit trails | Legitimate interests - protecting the security of the service (Article 6(1)(f)) | | Product analytics and improvement | Legitimate interests - improving the service (Article 6(1)(f)) | | Compliance with legal obligations | Legal obligation (Article 6(1)(c)) | | Marketing communications (if any) | Consent (Article 6(1)(a)) |
If you are located in Canada, we process your information based on express or implied consent, or under the limited exceptions permitted by Canadian privacy law. If you are located in Nigeria, processing is governed by the Nigeria Data Protection Regulation (NDPR), which is addressed in Section 14.
5. How We Use Information
We may use personal information to:
- provide, operate, maintain, and improve Flowambe
- create and manage accounts and event workspaces
- support event timelines, tasks, dependencies, assignments, and updates
- provide role-based access control
- facilitate event-related communications through WhatsApp, email, push notifications, and SMS
- send administrative, operational, support, and service-related messages
- provide beta, pilot, or live event support
- troubleshoot, debug, monitor, and secure the service
- analyse product performance, reliability, usability, and usage
- develop new features, workflows, templates, and product improvements
- respond to inquiries, support requests, and feedback
- conduct surveys, interviews, and product research
- prevent misuse, fraud, abuse, unauthorised access, and security incidents
- comply with legal, regulatory, contractual, accounting, tax, and operational obligations
- enforce terms, policies, and agreements
- protect the rights, safety, and property of Flowambe, users, participants, and others
6. Use of Event Data for Product Improvement
Flowambe may use event data, beta observations, usage information, feedback, logs, and support information to improve the product, debug issues, develop templates, enhance reliability, refine user experience, and understand how events operate in real-world conditions.
Flowambe will not sell personal information.
Flowambe will not knowingly use identifiable customer event data to train third-party artificial intelligence models without appropriate authorisation. We may use de-identified, aggregated, or anonymised information for analytics, testing, benchmarking, product development, and service improvement.
7. How We Share Information
7.1 With Authorised Event Users
Information in an event workspace may be visible to users invited to that event based on their assigned role and permissions. This may include planners, hosts, vendors, staff, assistants, contractors, or other participants.
7.2 With Flowambe Personnel and Contractors
Authorised Flowambe personnel and contractors may access personal information and event data as reasonably necessary to operate, test, support, secure, debug, monitor, and improve Flowambe.
7.3 With Named Third-Party Processors
We share data with the following key service providers, each bound by data processing agreements:
| Provider | Purpose | Data Shared | | -------------------------------------------------- | --------------------------------------------------------------------------- | ----------------------------------------------- | | Meta Platforms, Inc. (WhatsApp Business Cloud API) | Operational notifications - task alerts, timeline updates, vendor reminders | Phone numbers, message content | | Amazon Web Services (AWS / SES) | Cloud hosting, database infrastructure, transactional email | All service data, email addresses | | Expo | Push notification delivery | Push notification tokens, notification payloads | | Google (OAuth) | Social sign-in | Name, email, profile picture (on sign-in only) | | Apple (Sign In with Apple) | Social sign-in and token revocation | Apple user identifier, email relay |
We may also engage providers for cloud storage, analytics, error monitoring, crash reporting, customer support, security tools, and professional services. These providers process information only as instructed.
7.4 With Event Organisers or Account Administrators
If your access is provided through an event organiser, planner, host, company, or administrator, that person or organisation may be able to access, manage, export, modify, or delete information associated with the event workspace or account.
7.5 For Legal, Safety, and Security Reasons
We may disclose information if we believe it is reasonably necessary to: comply with applicable law, legal process, or government request; enforce terms, agreements, or policies; detect, investigate, prevent, or address fraud, security, abuse, or technical issues; protect the rights, property, or safety of Flowambe, users, event participants, or others; or respond to emergencies or threats of harm.
7.6 Business Transfers
If Flowambe is involved in a merger, acquisition, financing, reorganisation, sale of assets, bankruptcy, or similar transaction, information may be disclosed or transferred as part of that transaction, subject to appropriate confidentiality or legal protections.
7.7 With Consent or at Your Direction
We may share information with your consent or at your direction.
8. Cookies and Similar Technologies
Flowambe may use cookies, pixels, local storage, analytics tools, and similar technologies to operate the website and app, remember preferences, understand usage, improve performance, support security, and measure marketing effectiveness.
You may be able to control cookies through your browser settings. Some features may not work properly if cookies or similar technologies are disabled.
We do not currently use third-party targeted advertising cookies. If that changes, we will update this Policy and provide appropriate notice and controls.
California law requires us to disclose how we respond to Do-Not-Track (DNT) signals. No uniform technology standard for recognising DNT signals has been finalised, and we do not currently respond to DNT signals. We will update this Policy if that changes.
9. Data Retention
We retain personal information for as long as reasonably necessary for the purposes described in this Policy. The table below sets out our default retention periods:
| Data Category | Retention Period | | ---------------------------------------------------------- | -------------------------------------------------------------------------- | | Active account data | Until account deletion, then deleted or anonymised within 7 days | | Notification logs (email, push, WhatsApp delivery records) | 90 days | | WhatsApp message logs | 90 days, then phone number anonymised | | OTP records | Deleted on use or expiry, whichever is sooner | | Push notification tokens (user_device_tokens) | Deleted when device is inactive for 12 months, or on account deletion | | Audit trail records (execution events, commit histories) | Life of the event plus 2 years, then anonymised | | Account deletion request records (scrubbed) | 3 years (compliance evidence) | | Email suppression entries (SES bounce/complaint records) | Retained until manually reviewed - operational necessity, not account data | | Anonymised event records where shared with other users | Life of the event | | De-identified analytics data | Indefinitely |
We may retain de-identified, aggregated, or anonymised information for analytics, product development, security, and business purposes beyond these periods. Backup copies and logs may persist for a short additional period before deletion in accordance with our backup practices.
10. Account Deletion
10.1 How to Request Deletion
You may request deletion of your account by:
- Using the in-app account deletion flow in Settings -> Delete account (once the in-app flow is live - this is currently in development)
- Emailing legal@flowambe.com
- Visiting flowambe.com/account-deletion (the public data-safety intake form)
All channels feed the same deletion process. The in-app authenticated flow is required to satisfy Apple App Store Review Guideline 5.1.1(v).
10.2 What We Delete
When a verified deletion request is accepted:
- All active sessions and tokens are revoked immediately. You are logged out on all devices.
- Within 7 days: your personal data is permanently deleted or anonymised per the data map below.
- Account data deleted includes: name, email address, phone number, date of birth, physical address, avatar, authentication credentials, OTPs, push notification tokens, role assignments, in-app notifications, notification delivery records, and invitation records addressed to you.
- WhatsApp message logs: phone number is anonymised. Message records may be retained for webhook audit purposes.
- Events you planned: if you are the sole party, the event and its timeline are deleted. If other members exist, the event is transferred to another member and your name, email, and avatar are removed from all visible surfaces. You will not appear in event summaries, team member lists, or notification payloads visible to others.
- Audit trail entries authored by you (execution events, commit histories): retained but anonymised - your user ID is replaced with a tombstone. The underlying records are needed to maintain event integrity for other participants.
10.3 What We Retain
After deletion, we retain only:
- A tombstone users row (no PII) - needed to maintain foreign key integrity in audit tables.
- Anonymised audit trail rows - needed for event integrity for other members.
- The deletion request record itself (PII fields scrubbed) - retained for 3 years as compliance evidence.
- Email suppression entries - retained to protect our email sender reputation (not account data).
Nothing is retained purely for convenience. If a retention reason cannot be stated, the data is deleted.
10.4 Timeline and Confirmation
When we receive your deletion request, you will receive an acknowledgement email confirming receipt and the timeline. When the deletion executor completes, you will receive a separate confirmation that your account and personal data have been permanently deleted.
We will process deletion requests within 7 days of verification. In some cases involving complex event ownership, this may take slightly longer - we will notify you if so.
10.5 Reauthentication
To protect your account from unauthorised deletion, the in-app flow requires reauthentication before accepting your request. Email users complete a one-time password verification. Google and Apple users present a fresh identity token. Completion of the reauthentication step revokes all existing sessions.
11. Automated Processing
Flowambe's timeline engine and notification system perform automated processing, including risk level classification, anchor conflict detection, and safety gap alerts on event timelines. These determine how tasks, alerts, and readiness warnings are surfaced to event planners and participants.
If you believe an automated determination has produced an outcome that significantly affects you, you may contact us at legal@flowambe.com to request human review. EEA and UK users have the right under GDPR Article 22 to object to purely automated decisions that produce legal or similarly significant effects.
12. Data Security
We use reasonable administrative, technical, and organisational measures designed to protect personal information from unauthorised access, loss, misuse, alteration, or disclosure. These measures include role-based access control, account authentication, access restrictions, confidentiality expectations, limited contractor access, cloud security controls, monitoring, logging, and other safeguards appropriate to the stage and nature of the service.
No system is perfectly secure. We cannot guarantee absolute security. If you believe your account has been compromised, contact us immediately at legal@flowambe.com.
13. International Processing and Data Transfers
Flowambe is incorporated in Delaware, United States. We process data in the United States, Nigeria, and other locations where Flowambe, its personnel, contractors, or service providers operate.
If you are in the EEA or United Kingdom, please be aware that Nigeria does not have an EU adequacy decision, and the United States' adequacy framework (the EU-US Data Privacy Framework) covers only certified US organisations. Where we transfer your data to these jurisdictions, we rely on Standard Contractual Clauses (SCCs) with our service providers or other appropriate safeguards to protect your data in transit.
By using Flowambe or providing information to us, you understand that your data may be processed in these locations.
14. Nigeria Data Protection Regulation (NDPR)
Flowambe is operated and tested in Nigeria and acknowledges the requirements of the Nigeria Data Protection Regulation (NDPR) 2019 and the Nigeria Data Protection Act 2023 (NDPA). Where applicable:
- We process personal data only with a valid legal basis (consent, contractual necessity, legal obligation, or legitimate interests).
- We obtain express consent for marketing communications directed to Nigerian users.
- We respect the right of Nigerian data subjects to access, correct, or request deletion of their personal data. Requests may be sent to legal@flowambe.com.
- We take reasonable steps to ensure that any transfer of personal data outside Nigeria is made to countries with adequate data protection laws or under appropriate contractual safeguards.
- Where required by NDPR/NDPA, we conduct and file annual data protection audits through a licensed Data Protection Compliance Organisation (DPCO).
15. Your Privacy Rights
15.1 Rights for EEA, UK, and Switzerland Users
Under the GDPR, UK GDPR, or Swiss data protection law, you have the right to:
- Access - request a copy of the personal data we hold about you
- Rectification - request correction of inaccurate or incomplete data
- Erasure - request deletion of your personal data (see Section 10)
- Restriction - request that we limit processing of your data in certain circumstances
- Portability - receive your data in a structured, machine-readable format
- Object - object to processing based on legitimate interests or for direct marketing
- Withdraw consent - where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing
- Human review of automated decisions - see Section 11
To exercise these rights, contact legal@flowambe.com. We may need to verify your identity before processing your request.
If you are in the UK and unhappy with our handling of your data, you may complain to the Information Commissioner's Office (ICO):
- Website: ico.org.uk/make-a-complaint
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
EEA users may also complain to the data protection authority in their EU member state. Swiss users may contact the Federal Data Protection and Information Commissioner (FDPIC).
15.2 Rights for US Residents (CCPA / State Privacy Laws)
If you are a resident of California, Colorado, Connecticut, Virginia, Texas, or other states with comprehensive privacy laws, you may have the following rights:
- Right to know whether we process your personal data
- Right to access your personal data
- Right to correct inaccuracies in your personal data
- Right to request deletion of your personal data
- Right to obtain a portable copy of your personal data
- Right to non-discrimination for exercising your rights
- Right to opt out of the sale of personal data (we do not sell personal data)
- Right to opt out of targeted advertising (we do not currently use targeted advertising)
- Right to appeal if we decline to act on your request - email legal@flowambe.com
To exercise your rights, visit flowambe.com/account-deletion or email legal@flowambe.com. We may ask you to verify your identity before processing your request.
CCPA Categories of Personal Information Collected in the Past 12 Months:
| Category | Examples | Collected | | --------------------------------------------- | --------------------------------------------------- | -------------------------------- | | A. Identifiers | Name, email, phone, IP address, account name | YES | | B. Personal information (CA Customer Records) | Name, contact information, financial information | YES | | C. Protected classification characteristics | Date of birth (where provided) | YES (limited) | | D. Commercial information | Transaction information, payment data | NO (payments not active) | | E. Biometric information | Fingerprints, voiceprints | NO | | F. Internet or network activity | IP address, session data, usage logs, crash reports | YES | | G. Geolocation data | Precise device location | NO | | H. Audio, electronic, or sensory information | Call recordings | NO | | I. Professional / employment information | Role, title, business name | YES (limited) | | J. Education information | Student records | NO | | K. Inferences drawn from personal information | Profile or preference inferences | NO | | L. Sensitive personal information | Government IDs, health data, etc. | NO (we actively discourage this) |
We do not sell personal information and have not done so in the preceding 12 months. We do not share personal information for targeted advertising.
15.3 Data Subject Access Requests
You may request a copy of the personal information we hold about you by emailing legal@flowambe.com. We currently fulfil these requests manually within 30 days of verifying your identity. We are working to build a self-serve data export endpoint.
16. Children's Privacy
Flowambe is not intended for use by children under 18 years of age (or the equivalent minimum age in the relevant jurisdiction). We do not knowingly collect, solicit, or market to children under 18.
If you are a parent or guardian and believe your child's personal information has been collected by Flowambe without appropriate consent, contact us immediately at legal@flowambe.com. We will deactivate the account and take reasonable steps to delete the data promptly.
Event organisers should avoid submitting children's personal information unless it is strictly necessary for event coordination and is properly authorised by a parent, guardian, or other person with legal authority.
17. Notification Preferences
You can control how Flowambe communicates with you:
- WhatsApp notifications - toggle on or off in your account notification settings. Turning this off stops operational messages sent via the WhatsApp Business API. This preference is stored in your account and processed each time a notification is dispatched.
- Push notifications - managed through your device's operating system settings. You can withdraw permission at the device level at any time.
- Email - operational and transactional emails (account activity, security, deletion confirmations) cannot be turned off while your account is active. Marketing emails, if any, include an unsubscribe link.
Some operational, security, or account-related messages may still be sent where necessary regardless of communication preferences.
18. Third-Party Services
Flowambe may contain links to or integrations with third-party services, including WhatsApp (Meta), email providers, analytics providers, cloud providers, payment processors, app stores, and other tools. Third-party services are governed by their own terms and privacy policies. Flowambe is not responsible for third-party practices outside our control.
19. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Updated versions will be posted with a revised effective date. If changes are material, we will provide additional notice - for example, via email or an in-app notification.
Your continued use of Flowambe after an updated Privacy Policy is posted means you acknowledge the updated policy.
20. Contact
For questions, privacy requests, or data subject rights requests:
Flowambe, Inc.
Email: legal@flowambe.com
Website: flowambe.com/account-deletion (data deletion form)
For UK ICO complaints: ico.org.uk/make-a-complaint
For NDPR inquiries or data protection audit questions, contact us at the email above.
© 2026 Flowambe, Inc. All rights reserved.