Privacy Policy

Effective Date: January 31, 2026

1. Introduction

At Floovioo ("we," "our," or "us"), we value your privacy. This Privacy Policy explains how we collect, use, and share information about you when you use our website, mobile application, and other online products and services (collectively, the "Services").

2. Information We Collect

Information You Provide to Us

We collect information you provide directly to us, such as when you create an account, connect an integration (QuickBooks, Zoho, Google), or contact customer support. This may include your name, email address, business details, and connection credentials.

Automated Collection

When you access our Services, we automatically collect certain information about your device and usage, including your IP address, browser type, and interaction data.

3. Google API Data Usage

Floovioo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Service: User Data Policy, including the Limited Use requirements.

We specifically use Google OAuth to allow you to log in to our Services and to process documents stored in your Google Drive or access data in Google Sheets as part of your automated workflows. We do not sell your Google API data to third parties.

4. How We Use Information

  • To provide, maintain, and improve our document automation services.
  • To process transactions and send related information.
  • To monitor and analyze trends, usage, and activities.
  • To detect, investigate, and prevent fraudulent transactions and other illegal activities.

5. Sharing of Information

We may share information about you with third-party vendors, consultants, and other service providers who need access to such information to carry out work on our behalf (e.g., Stripe for payments, OpenAI for document analysis). We do not share your private business data for marketing purposes.

6. Security

We take reasonable measures to help protect information about you from loss, theft, misuse, and unauthorized access. This includes encryption of sensitive credentials (tokens) and use of secure Content Security Policies.

7. Third-Party Integrations

When you connect third-party services to Floovioo, we access and store data from those services on your behalf. The following describes what data is accessed and why:

Stripe (Payment Processing)

We use Stripe to process subscription payments and invoices. Stripe receives your name, email, and payment method details. We store your Stripe customer ID and subscription status. Stripe's privacy practices are governed by the Stripe Privacy Policy. We never store full card numbers.

QuickBooks, Xero & Zoho Books (Accounting)

When you connect an accounting integration, we request OAuth authorization and store your access and refresh tokens securely. We access invoices, customers, payments, and related financial records solely to provide the document automation features you have enabled. We do not share this financial data with any third parties beyond what is necessary to operate the service.

HubSpot (CRM)

If you connect HubSpot, we access contact, company, and deal data to power your branding and document workflows. We request only the scopes necessary for these operations (crm.objects.contacts.read, crm.objects.companies.read, crm.objects.deals.read).

Google Sheets & Google Drive

When you use Google Sheets integration, we access the spreadsheets you specify to read and write data as part of your automated workflows. We do not access files beyond what you explicitly configure. Our use of Google data complies with the Google API Services User Data Policy, including the Limited Use requirements.

Zapier & n8n (Automation)

Zapier and n8n integrations operate via webhooks. Data payloads sent to or received from these platforms pass through our servers only to trigger the workflow you have configured. We do not retain webhook payload data beyond the execution of that workflow.

Gmail (Transactional Email)

We use Gmail SMTP credentials only to send transactional emails on your behalf (e.g., invoice delivery, notifications). We do not read your inbox or access any emails you receive.

8. Cookies & Tracking

Necessary Cookies (always active)

We set a session cookie (connect.sid) to keep you signed in. This cookie is essential for the platform to function and does not require your consent under GDPR's legitimate interest basis.

Optional / Analytics Cookies

If you consent, we may set cookies to understand how users interact with the platform so we can improve it. These are only activated after you accept cookies via our consent banner.

Withdrawing Consent

You can withdraw cookie consent at any time by clearing your browser's cookies or local storage for floovioo.com. The consent banner will reappear on your next visit.

9. Data Retention

  • Active accounts: Data is retained for as long as your account is active and you use our Services.
  • Deleted accounts: When you delete your account, your personal data is anonymized or purged within 30 days, except where we are required by law to retain it longer.
  • Integration tokens: OAuth access and refresh tokens for connected integrations are deleted immediately when you disconnect the integration.
  • Usage logs: API usage and audit logs are retained for up to 12 months for security and billing reconciliation purposes, then purged.

10. Your Rights (GDPR — EU/EEA Users)

If you are located in the European Union or European Economic Area, you have the following rights under the General Data Protection Regulation (GDPR):

  • Right to Access Request a copy of the personal data we hold about you.
  • Right to Erasure Request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
  • Right to Portability Request your data in a structured, machine-readable format.
  • Right to Rectification Request correction of inaccurate personal data.
  • Right to Restrict Processing Request that we limit the processing of your data in certain circumstances.
  • Right to Object Object to processing of your data where we rely on legitimate interest as the legal basis.

To exercise any of these rights, email us at bonzocreatives@gmail.com. We will respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with your national data protection supervisory authority.

11. Contact Us

If you have any questions about this Privacy Policy, please contact us at:

bonzocreatives@gmail.com