Privacy Policy

Last Updated: July 15, 2026

SoloFlow ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use the SoloFlow application, websites, and services (collectively, the "Services").

This policy is designed to comply with global data protection laws, including the EU General Data Protection Regulation (GDPR), the UK Data Protection Act 2018 (UK GDPR), the California Consumer Privacy Act (CCPA/CPRA), the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA), the Australian Privacy Act 1988, the New Zealand Privacy Act 2020, and the Indian Digital Personal Data Protection Act, 2023 (DPDP Act).

1. Data We Collect

We collect data necessary to provide a freelance business operating system. The categories of data we collect include:

  • Account Information: Name, email address, password hash, regional/country defaults, and display currency.
  • Project & Opportunity Data: Client names, client email addresses, client contact numbers, opportunity details (stages, expected revenue, expected completion dates), and business expenses.
  • AI Integration & Processing: Optional User-supplied OpenAI API keys and Project context sent to Large Language Models (LLMs) to generate follow-up drafts and business insights.
  • Subscription & Billing Details: Subscription tier data (Pro status, period ends, and payment provider tokens). We use PCI-DSS compliant payment processors (Stripe and Razorpay) and do not store card details on our servers.

2. Lawful Bases for Processing (EU & UK Users)

Under GDPR and UK GDPR, we process your personal data under the following legal bases:

  • Contractual Necessity: Processing is required to deliver the core features of the Services under our Terms of Service.
  • Legitimate Interests: Processing is necessary for our legitimate business interests, such as improving system performance, safeguarding system security, and analytics.
  • Consent: Where you provide explicit consent (e.g., when adding custom API keys or enabling optional communication features). You may withdraw consent at any time.

3. Indian DPDP Act Compliance & Data Fiduciaries

For residents of India, SoloFlow acts as a Data Fiduciary. By using our Services and entering client or financial details, you confirm that you are the Data Principal or have obtained lawful consent from your clients (as Data Principals) to input their contact details.

  • Rights of the Data Principal: You have the right to access summary details of data processed, correct inaccuracies, erase outdated data, nominate another individual in the event of death/incapacity, and seek grievance redressal.
  • Grievance Officer: In compliance with Section 6 of the DPDP Act, any complaints, data questions, or grievances can be addressed directly to our compliance officer at compliance@soloflow.ai. We will respond within the statutory timeframe.

4. US CCPA/CPRA & Global Privacy Rights

We do not sell or share your personal information (including client data) for cross-context behavioral advertising. We do not engage in profiling or automated decision-making that produces legal effects.

Depending on your jurisdiction (including the US, EU, UK, Canada, Australia, and New Zealand), you possess the following rights:

  • Right to Know & Access: The right to request confirmation of data collection and receive a portable copy of your database record.
  • Right to Correct & Rectify: The right to request correction of inaccurate data.
  • Right to Delete & Erase: The right to erase all account records and customer files. Deletion is permanent and removes all records from our primary databases.
  • Right to Non-Discrimination: We do not discriminate against Users who exercise their privacy rights.

5. AI Processing & Third-Party Services

When generating business insights or drafting follow-up messages, raw context (Project title, client name, and Expected Revenue) is transmitted securely to third-party Large Language Model providers (like OpenAI) via API. Your data is not used to train global underlying models. You can supply your own API key to ensure full custody and audit control of your request parameters.

6. International Transfers & Retention

Your data is stored within secured cloud databases (Supabase / AWS PostgreSQL) and protected with strict access controls. Data is retained only for as long as your account remains active. You can execute full database cleanup or request account erasure at any time in the Settings portal.

7. Contact and Redressal

If you have questions about this policy, wish to exercise your data protection rights, or lodge a formal inquiry, please contact our Compliance Manager at:

Email: compliance@soloflow.ai
Address: SoloFlow Technologies, Legal & Compliance Dept. (Remote-First Workspace)

← Back to SoloFlow