Privacy Policy
Last updated: 9 April 2026
This Privacy Policy explains how we process personal data in connection with the PIXCRM FLOW cloud platform (marketing automation, CRM, messaging channels, and related features). By using FLOW, you acknowledge the practices described here. If you use FLOW on behalf of an organization, that organization is typically the controller of data about its customers and employees; we act as a processor for that workspace content, while we remain responsible for account, billing and platform operations data as described below.
Data controller and contact
The service is operated by PIXCRM (“we”, “us”). For privacy requests about the platform, email privacy@pixcrm.app. If you are an end user of a customer organization, contact that organization first for questions about how they use FLOW to process your data.
Scope
This policy applies to the FLOW web application, APIs, official browser extensions published by us that connect to FLOW, and related operational communications (e.g. security notices, billing). It does not cover third-party sites or integrations you choose to connect; those services have their own policies.
Categories of data we process
We may process: account and profile data (name, email, role, preferences); authentication and security data (sessions, device/browser metadata, audit logs); workspace content you or your organization stores in FLOW (e.g. contacts, companies, campaigns, messages, files, automation definitions); usage and diagnostics (feature usage, error logs); support interactions; and billing data. Payment card details are handled by our payment provider (e.g. Stripe); we do not store full card numbers on FLOW application servers.
Purposes and legal bases
We use data to provide, secure and improve the service; authenticate users; operate multi-tenant workspaces; prevent abuse and fraud; comply with law; invoice and collect payment; provide support; and communicate important service information. Depending on your jurisdiction, legal bases may include contract, legitimate interests (balanced against your rights), legal obligation, and consent where required (e.g. certain cookies or marketing communications).
Cookies and local storage
We use cookies and similar technologies for session management, language/locale preferences, security (e.g. CSRF protection where applicable), and to remember UI choices. You can control cookies through your browser settings; disabling essential cookies may prevent sign-in or core features from working.
Processors and sharing
We use trusted infrastructure and service providers (e.g. hosting, email delivery, observability, payment processing) under written agreements with confidentiality and data-protection obligations. They may only process data on our instructions. We do not sell your personal data. We may disclose information if required by law or to protect rights, safety, and the integrity of the service.
International transfers
Your data may be processed in countries other than your own where we or our subprocessors operate. Where required, we implement appropriate safeguards (such as standard contractual clauses) in line with applicable regulations.
Retention
We retain data for as long as needed to provide the service, comply with legal obligations, resolve disputes, and enforce agreements. Workspace content is generally retained until your organization deletes it or closes the workspace, subject to backup cycles and legal holds. Technical logs may be kept for shorter rolling periods.
Security
We implement administrative, technical, and organizational measures designed to protect data against unauthorized access, loss, or alteration. No method of transmission or storage is completely secure; please use strong passwords and protect your credentials.
Your rights
Depending on applicable law (including GDPR and LGPD), you may have rights to access, correct, delete, or export personal data; restrict or object to certain processing; withdraw consent where processing is consent-based; and lodge a complaint with a supervisory authority. To exercise rights relating to your FLOW account, contact us at privacy@pixcrm.app. For data your employer or client entered about you as a contact in their workspace, that organization is usually the controller and can assist you.
Children
FLOW is a business-to-business platform and is not directed at children. We do not knowingly collect personal data from children without appropriate parental authority. If you believe we have collected such data, contact us and we will take appropriate steps.
Changes to this policy
We may update this page from time to time. We will adjust the “Last updated” date above and, when appropriate, provide additional notice (e.g. in-product or by email) for material changes.
Contact
Questions about this Privacy Policy: privacy@pixcrm.app
