Privacy Policy

Last updated: 25 June 2026

This policy explains what personal data ClientFlows collects, why we collect it, and the rights you have over it under UK GDPR and the EU GDPR.

Who we are

ClientFlows is a booking and client-management platform for service professionals, operated by Sole Trader T/A ClientFlows, CB6 1HE, United Kingdom. For the purposes of data protection law, the operator is the data controller for account and billing data, and a data processor for the client data that businesses store in the platform.

What data we collect

  • Name, email address and phone number
  • Appointment history (bookings, services, dates, status)
  • Intake form responses submitted before appointments
  • Payment records (subscription status; card data is held by Stripe, not by us)

Why we collect it

We process this data solely to provide the booking and client-management service — creating and managing appointments, maintaining client records, taking subscription payments, and sending booking-related emails.

How long we keep it

Subscription and account data is retained for the duration of your service plus 12 months. Client data is deleted when an account is closed, or earlier on request.

Your rights

Under UK GDPR / GDPR you have the right to access, rectify, erase, and port your personal data, and to object to or restrict its processing. To exercise any of these rights, contact us using the details below.

Account owners can also do this themselves at any time from Settings → Your data & privacy: download a complete export of your data, or permanently delete your account (which removes your business and its data and cancels any active subscription).

If you use ClientFlows as a client of a business (a booking or portal account), deleting your account removes your login and anonymizes the personal details held about you — your name, email, phone number, notes, and intake form answers. Businesses retain only anonymized, non-identifying booking records for their own accounting.

Third parties we share data with

  • Stripe — payment processing and card data storage
  • Supabase — database and file storage (EU/UK region)
  • Resend — transactional email delivery
  • Vercel — application hosting
  • Upstash — rate limiting (short-lived per-IP request counters to prevent abuse)

Each provider processes data only as needed to deliver their part of the service, under their own data-processing terms.

Cookies

We use cookies for session management only (keeping you signed in). We do not use advertising or tracking cookies.

Contact

For any privacy question or to exercise your rights, contact us at privacy@clientflows.uk.