Privacy Policy
Last updated: August 12, 2026
FlowShot does not sell your personal data. This policy explains what we collect, why we collect it, and how you can control it.
1. Who we are
FlowShot (“FlowShot”, “we”, “us”) is a project-management platform for photo and video production teams. Our service is available at flowshot.space and related subdomains. For privacy inquiries, contact us at privacy@flowshot.space.
2. What we collect
We collect the following categories of data:
- Account information — your name, email address, and password (stored as a salted hash via Firebase Authentication).
- Organisation data — your studio or company name, team member profiles, roles, and settings you configure inside FlowShot.
- Project data — project details, client information, notes, statuses, and any custom fields you create.
- Files and media — videos, photos, and documents you upload for project work or review. These are stored on our CDN provider.
- Usage data — pages visited, features used, and actions taken inside the application (e.g., which modules you open, button clicks that indicate feature usage). On the marketing site, Google Analytics and PostHog collect selected usage events only after you accept optional analytics.
- Device information — browser type, operating system, screen resolution, and device identifiers.
- Log data — IP address, request timestamps, HTTP method, and response codes collected automatically by our infrastructure.
- Support correspondence — the email address and message you provide when you contact us through the support form or by email.
We do not collect payment card numbers directly — all payment processing is handled by Creem (see Section 4).
3. How we use your data
We use collected data to:
- Provide, operate, and improve the FlowShot service.
- Authenticate your account and enforce access controls.
- Send transactional emails (account verification, password reset, notifications) via Resend.
- Process subscription payments via Creem.
- Detect and fix bugs via Sentry error monitoring.
- Measure marketing-site visits and selected conversion events through Google Analytics and PostHog, but only after you accept optional analytics.
- Translate review comments (DeepL) when you request translation.
- Read and reply to questions, problem reports, and product suggestions you send us.
We do not use your data for advertising or sell it to third parties.
4. Third-party services
FlowShot relies on the following sub-processors:
- Google Firebase — authentication, Firestore database, and file storage. Data is stored on Google Cloud Platform infrastructure.
- Creem — subscription billing and payment processing as our merchant of record. Creem handles all payment card data under their own PCI-DSS compliance.
- Video CDN — CDN and video streaming for uploaded media.
- Sentry — application error monitoring. Error events may include stack traces and anonymised request context.
- Google Analytics (optional) — marketing-site page and conversion measurement after consent. Advertising signals and ad personalisation are disabled in our configuration.
- PostHog (optional) — selected marketing-site interaction measurement after consent. Automatic click capture and session recording are disabled in our configuration.
- Resend — transactional email delivery.
- DeepL — machine translation of project chat, review comments, and team posts when you request it.
- DocuSeal — e-signature infrastructure retained for limited legacy access. Contracts are not part of the current public FlowShot offer.
Each sub-processor is bound by a data-processing agreement and we select only providers that maintain appropriate security certifications.
5. Google Account data (Calendar and Drive integrations)
If you choose to connect your Google Calendar or Google Drive, FlowShot requests access to your Google Account with your explicit consent. Both integrations are optional and are off by default.
What we access. With Google Calendar, FlowShot creates, updates, and deletes calendar events that it created for your projects and team events. It does not read events created by you or by other applications. With Google Drive, FlowShot creates project folders and can access only the files and folders it created; the rest of your Drive is not visible to FlowShot.
How we store it. Your Google access and refresh tokens are encrypted at rest and stored against your user account. We store the identifiers and dates of the calendar events we created so we can keep them in sync. We do not copy the contents of your calendar or your Drive into FlowShot.
How we use it. Solely to provide the calendar sync and cloud-storage features you enabled. We do not use Google user data for advertising, we do not sell it, we do not use it to develop, improve, or train generalised artificial intelligence or machine learning models, and we do not transfer it to third parties except as necessary to provide these features, to comply with applicable law, or as part of a merger or acquisition. Human access is limited to the cases Google's policy permits: your explicit consent, security investigations, compliance with applicable law, or aggregated and anonymised operational analysis.
How to revoke it. Disconnect the integration in FlowShot under Settings → Organization → Integrations, which deletes the stored tokens, or revoke FlowShot's access from your Google Account permissions page. Revoking stops any further syncing; events already written to your calendar and folders already created in your Drive remain yours.
FlowShot's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Data storage and security
All FlowShot data is stored on Google Cloud Platform infrastructure. Data in transit is protected by TLS 1.2+. Data at rest is encrypted using AES-256 (managed by Google Cloud). Media files uploaded to Bunny.net are served over HTTPS and access is controlled by signed URLs.
We maintain logical data isolation between organisations — one organisation cannot access another organisation's data by design.
7. Data retention
- Active accounts — data is retained for as long as your account exists.
- After account deletion — active data is purged within 30 days.
- Backup copies — may persist in encrypted backups for up to 90 days before being overwritten.
- Creem billing records — retained as required by financial regulations (typically 7 years), but are Creem's responsibility under their own policy.
8. Cookies
FlowShot uses essential browser storage for session authentication, app functionality, and remembering your consent choice. Google Analytics and PostHog load on the marketing site only after you accept optional analytics. We do not use advertising or retargeting cookies. You can change your choice through Cookie settings in the site footer. For the full list, purposes, and durations, see our Cookie Policy.
9. Your rights under GDPR (EEA residents)
If you are in the European Economic Area, you have the following rights under the General Data Protection Regulation:
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — correct inaccurate or incomplete data.
- Right to erasure — request deletion of your data (subject to legal retention requirements).
- Right to restriction — ask us to stop processing your data in certain circumstances.
- Right to data portability — receive your data in a machine-readable format.
- Right to object — object to processing based on legitimate interests.
To exercise any of these rights, email privacy@flowshot.space. We will respond within 30 days.
10. Your rights under CCPA (California residents)
California residents have the right to know what personal information we collect, to request deletion of that information, and to opt out of its sale. FlowShot does not sell personal information. To submit a request, contact privacy@flowshot.space.
11. Children's privacy
FlowShot is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact privacy@flowshot.space and we will delete it promptly.
12. Operational logging for abuse prevention
We log technical metadata associated with media streaming requests — IP-derived identifiers, timestamps, video and review-page IDs, and view counts — to detect and prevent abuse. This data is retained for up to 30 days in operational logs and is not used for marketing or shared with third parties beyond our infrastructure providers (Firebase, Bunny.net).
13. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to the account owner at least 14 days before they take effect. The date at the top of this page reflects the most recent revision.
14. Contact
For any privacy-related questions or to exercise your rights, contact us at privacy@flowshot.space.