This Privacy Policy describes how FlowBack AI LLC (referred to here as "we", "us", or "our") collects, uses, and protects information when you visit flowbackai.com or engage with our AI consulting services. We keep this short, plain, and human — because privacy policies usually aren't.
01. Information we collect
Information you provide directly
When you submit an inquiry form, application, or audit booking, we collect the information you give us — typically your name, email address, business name, business stage, and the answers to the application questions. When you become a paying client, we also collect billing information (handled through third-party processors like Stripe — we never store full card details on our own systems).
Workshop and session recordings
Team workshops and some advisory sessions are recorded so you can keep and re-watch them — the recording is one of your deliverables. Recordings capture the voices, and where cameras are on the images, of everyone who attends, along with any business information discussed or shared on screen. You are told before recording begins, and you can ask us not to record at any point. Recordings are shared only with you, stored on US-based encrypted infrastructure, never used for marketing or public reference without your written permission, and never used to train any AI model. You can ask us to delete a recording at any time.
Information collected automatically
When you visit the site, our hosting provider may automatically collect basic technical data — IP address, browser type, device type, pages visited, time on page, and referring URL. The site uses Plausible Analytics, a cookie-free, privacy-first analytics tool. Plausible does not track individuals, build profiles across sites, or share data with third parties. We do not use ad-tracking pixels or behavioral retargeting on this site.
Cookies
The site uses minimal cookies, primarily to remember your preferences across visits. We do not use third-party advertising cookies. You can disable cookies in your browser without breaking the site.
02. How we use information
- To respond to your inquiries, applications, and questions
- To deliver the services you've engaged us for
- To send service-related communications (proposals, audit reports, invoices)
- To improve the site and our services
- To comply with legal obligations
We do not sell, rent, or trade your personal information. Ever. We do not use your data to train any AI model — yours or third-party.
03. Information sharing
We share information only with the third parties needed to run the business:
- Payment processors (e.g. Stripe) — to handle billing
- Scheduling tools (Calendly) — to book calls
- Video conferencing (e.g. Zoom, Google Meet) — to run remote workshops and advisory calls, including recording where agreed
- Hosting and email providers — to operate the site and reply to messages
- Analytics (Plausible Analytics) — cookie-free, anonymized site-usage data
Each of these vendors has its own privacy policy. We select tools that respect user privacy where we can.
We may also disclose information if legally required (e.g. by court order), or to enforce our rights or protect against fraud.
04. Client confidentiality
For paying clients, every engagement is covered by a mutual NDA by default. Your business data, customer information, and proprietary processes are confidential. We do not share client identities, screenshots of internal systems, or proprietary information without your written permission. Anonymized lessons learned may be discussed publicly — never anything that identifies you.
05. Data retention & storage
Inquiry and application data is retained for up to 24 months unless you ask us to delete it sooner. Active client data is retained for the duration of our engagement plus seven years afterward (for tax, legal, and accounting purposes). All data is stored on US-based infrastructure, encrypted in transit (HTTPS / TLS) and at rest. Anything stored in client-owned systems (CRMs, databases, etc.) is your data, on your retention schedule.
06. Your rights
You can ask us to:
- See what information we have about you
- Correct anything inaccurate
- Delete your information (where we're not legally required to keep it)
- Opt out of any non-essential communications
Email [email protected] with the subject line "Privacy request" and we'll respond within 30 days.
07. Children
This site and our services are not directed at children under 16. We do not knowingly collect information from anyone under 16.
08. International visitors
We're based in Tampa, Florida (United States). If you visit the site from outside the US, your information will be processed in the United States. By using the site, you consent to that transfer. If you're in the EU, UK, or California and have specific GDPR / CCPA / state-level rights, contact us and we'll honor them.
09. Security
We use reasonable technical and organizational measures to protect your information — encrypted connections (HTTPS), strong access controls on accounts, and least-privilege access on integrations. No system is perfectly secure, but we take this seriously and act fast on anything that looks off.
10. Changes to this policy
If we update this policy, we'll change the "Last updated" date at the top. Material changes get a notice via email to active clients. Continued use of the site after an update means you accept the revised policy.
11. Contact
Questions about this policy or your data? Email [email protected].