HyveFlow

Privacy Policy

Last updated: July 2026

In short: we collect what we need to run HyveFlow for your shop, we don't sell your data, and the customer information you put into HyveFlow belongs to you — we only process it on your behalf. You can request an export or deletion any time.

1. Who this covers

This policy explains how HyveFlow ("we," "us") handles information for the businesses that use HyveFlow ("Shops") and the people who work at them. It also explains how we handle the personal information a Shop stores in HyveFlow about its own customers.

2. Information we collect

We do not store payment card numbers. Payments are handled through QuickBooks/Intuit and other providers, subject to their own security and terms.

3. How we use information

We use information to provide, maintain, secure, and improve HyveFlow — to run the order workflow, send transactional emails (order updates, invoices, proofs), sync connected integrations, provide support, and prevent abuse. We do not sell personal information.

4. Your customers' data (controller / processor)

When a Shop stores information about its own customers in HyveFlow, the Shop is the data controller and HyveFlow is the data processor acting on the Shop's instructions. The Shop is responsible for having the right to provide that data and for responding to its customers' privacy requests; we assist as reasonably needed. A data processing agreement is available on request.

5. Service providers we use (subprocessors)

We rely on trusted providers to run HyveFlow. They process data only to provide their service to us:

ProviderPurpose
SupabaseDatabase & storage of Shop data
RenderApplication hosting (API)
NetlifyWeb hosting (admin & portal)
Cloudflare R2File storage (proofs, certificates, design files)
ResendTransactional email delivery
ClerkAuthentication / login
AnthropicAI features (order intake, drafting)
Intuit / QuickBooksInvoicing & payment tracking (when connected)
GoogleDrive/Sheets sync (when connected)

6. Security

We use industry-standard measures including encryption in transit, encryption of integration tokens at rest, tenant isolation so one Shop cannot access another's data, private file storage served via short-lived links, and access controls. No system is perfectly secure, but we work to protect your information.

7. Retention & deletion

We keep Shop data for as long as a Shop's account is active and as needed to provide the service. A Shop may request a full export of its data or deletion of its account and data; we will honor reasonable requests, subject to any legal retention obligations.

8. Your rights

Depending on where you live (e.g. California's CCPA or the EU/UK's GDPR), you may have rights to access, correct, export, or delete personal information, and to object to certain processing. Shops can exercise these for their account by contacting us; a Shop's own customers should direct requests to the Shop (the controller), and we will help the Shop respond.

9. Cookies

We use essential cookies and similar technologies needed to keep you logged in and operate the service. We do not use them for third-party advertising.

10. Children

HyveFlow is a business tool and is not directed to children. We do not knowingly collect personal information directly from children; roster data about minors is provided by Shops as controllers for order fulfillment.

11. Changes

We may update this policy as the service evolves. Material changes will be reflected by an updated date and, where appropriate, additional notice.

12. Contact

Privacy questions or requests? Email support@hyveflow.io.