Privacy Policy
Last updated: July 12, 2026
This Privacy Policy explains how Phloz ("Phloz", "we", "us", or "our") collects, uses, shares, and protects information about you when you visit our website or use our product (together, the "Service"). It applies to visitors to phloz.com, people who create an account, and people whose information our customers put into the Service.
1. Who we are
The Service is operated by Phloz, based in Vancouver, British Columbia, Canada. For privacy questions or to exercise your rights, contact privacy@phloz.com.
Controller vs processor. For information about our own visitors and account holders (e.g. your email, usage data), we act as the data controller. For the content our customers load into their workspaces about their own clients and contacts, the customer is the controller and we act as a processor on their behalf, under our Terms of Service and Data Processing Addendum. If your data is in a Phloz workspace operated by an agency you work with, please direct requests to that agency.
2. Information we collect
Account data: your name, email, workspace name, and role. Payment details are collected and processed by Stripe; we do not receive or store full card numbers.
Content data: anything you or your team put into Phloz — clients and contacts, tasks, messages, tracking-map entries, files, and settings.
Usage data: pages and features used, actions taken, approximate location derived from IP, device/browser information, and event logs, collected to operate, secure, and improve the Service.
Communications: emails and support messages you send us, and whether you open our transactional or marketing emails.
3. How we use information, and our legal bases
We use information to:
- provide, maintain, and secure the Service and authenticate you;
- process payments and manage subscriptions;
- send transactional emails (e.g. magic links, notifications) and, with your consent where required, product news;
- analyse and improve the product, and detect and prevent abuse;
- comply with legal obligations.
Where the EU/UK GDPR applies, our legal bases are: performance of a contract (to provide the Service you signed up for), our legitimate interests (to secure, improve, and market the Service in a proportionate way), your consent (for optional analytics cookies and marketing email, withdrawable at any time), and compliance with legal obligations.
4. Cookies and analytics
We use two categories of cookies and similar technologies:
- Strictly necessary— authentication sessions, security, and your consent + theme preferences. These are always on because the Service can't function without them.
- Analytics — Google Analytics 4, Google Tag Manager, and PostHog, used to understand product usage. These load only where permitted by your choice. We implement Google Consent Mode v2 and default non-essential storage to denied until you accept via our cookie banner.
You can change or withdraw your choice at any time — as easily as you gave it — using the "Cookie preferences" control in our site footer, or, if you have a Phloz account, under Settings → Privacy & cookies in the app. Your choice is stored in a first-party cookie shared across phloz.com and app.phloz.com, so setting it in either place applies to both. You can also clear or block cookies via your browser settings.
5. How we share information (sub-processors)
We share data only with service providers that help us run the Service, under contracts that require them to protect it and use it only on our instructions:
- Supabase — database, authentication, and file storage
- Vercel — application hosting and delivery
- Cloudflare — DNS and network security
- Stripe — payment processing
- Resend — transactional and inbound email
- Inngest — background job orchestration
- Upstash — rate limiting and abuse prevention
- Google (Analytics 4 & Tag Manager) — website and product analytics
- PostHog — product analytics
- Sentry — error monitoring
We may also disclose information if required by law, to protect our rights or users' safety, or in connection with a merger or acquisition (with notice where required). Our current sub-processor list— with each provider's purpose and location — is kept up to date, and material changes are announced to account holders.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
6. AI and connected clients
Phloz does not send your content to third-party AI providers on its own. Some features let a workspace connect an external AI assistant or other client through our MCP server; any data that client accesses is then governed by thatprovider's terms and privacy policy, under the workspace's control. AI-drafted message replies are never sent automatically — a person reviews and sends them.
7. International transfers
Data is stored and processed in the United States by our hosting providers. If you are in the EEA, UK, or Switzerland, transfers rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
8. Data retention
We retain account and content data for as long as your workspace is active and for 30 days after cancellation (to allow export), after which it is deleted or anonymised. Analytics data is retained for up to 26 months. We keep some records longer where required for legal, tax, or security purposes.
9. Your privacy rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict the processing of your personal data, and to object to certain processing. You can also withdraw consent at any time (this does not affect prior processing). To exercise any of these, email privacy@phloz.com; we respond within the timeframes required by applicable law and may need to verify your identity.
EEA/UK: you have the right to lodge a complaint with your local data protection supervisory authority.
California (CCPA/CPRA):you have the right to know, delete, and correct your personal information, and to opt out of "sale" or "sharing" — though, as noted above, we do not sell or share personal information. We will not discriminate against you for exercising these rights.
Canada (PIPEDA): you may access and request correction of the personal information we hold about you, and you have the right to complain to the Office of the Privacy Commissioner of Canada.
10. Security
We protect data with row-level security for tenant isolation, encrypted transport (TLS) for all traffic, signed authentication tokens, and least-privilege access controls. No system is perfectly secure, but security is an ongoing program; a SOC 2 audit is on our roadmap. If you believe you've found a vulnerability, see our security.txt.
11. Children
Phloz is a business tool not directed to children under 16, and we do not knowingly collect their personal data.
12. Changes
We may update this Policy from time to time. We'll revise the "Last updated" date above and, for material changes, notify account holders by email or in-app notice.
13. Contact
Questions or requests? Email privacy@phloz.com — Phloz, Vancouver, BC, Canada.