Skip to main content

Legal

Privacy Policy

How OK | Flows handles account data, operational response data, and service-level requests.

Last updated: August 6, 2026

Data ownership

Form owners control what they publish and the response content they collect. Respondents should contact the form owner for requests tied to a specific submission.

01

Overview

The application processes information required to operate accounts, forms, responses, optional uploads and integrations, analytics, and product support. The exact controller, processor, legal basis, and retention obligations depend on the deployment and the form owner's use case.

Form owners control the questions they publish and the response content they collect. Respondents should contact the form owner directly for requests related to a specific form submission.

The source does not define one universal production retention period. Account, form, response, draft, analytics, and delivery-log records persist according to deletion and operational cleanup behavior configured for the deployment. Provider-side retention must be reviewed separately before release.

02

What We Collect

Categories of data we process.

Account Data

Information you provide when creating an account.

  • Email address
  • Profile name when provided
  • Avatar URL when provided
  • Authentication metadata

Form Response Data

Data collected through forms you create.

  • Respondent answers
  • Submission and draft timestamps
  • Uploaded file URLs when configured
  • Session and funnel identifiers

Usage Data

Information about how you use our service.

  • Page and route visits
  • Conversion-event properties
  • Core Web Vitals
  • Referrer and device information

03

Processing Services and Destinations

Infrastructure and optional destinations used by the current application.

Supabase

Provides authentication and the application database used for accounts, forms, responses, drafts, configuration, and operational logs.

Cloudflare R2

Stores respondent uploads only when file storage is configured and a published form accepts an eligible upload.

Umami

Measures anonymous pageviews, defined conversion events, and Core Web Vitals under the controls described in the Cookie Policy.

Owner-selected destinations

A form owner can configure signed delivery to a Salesforce Marketing Cloud CloudPage and mapped Data Extension workflow.

The current product does not implement advertising or data-broker workflows. Service providers process data to operate the application, while configured integrations deliver data according to the form owner's instructions. Processor terms, regions, retention, and international-transfer requirements must be approved before production.

04

Your Rights

Depending on applicable law and the organization responsible for the data, you may have the following rights.

01

Access

Request a copy of your personal data

02

Correction

Update inaccurate or incomplete data

03

Deletion

Request removal of your personal data

04

Portability

Export your data in a common format

Privacy Requests

For account-level access, correction, or deletion requests

privacy@okflows.com