TalleFlow mark
TalleFlow

Features

Compare

Resources

Privacy Policy

This Privacy Policy explains how TalleFlow, Inc. (“TalleFlow,” “we,” “our,” or “us”) collects, uses, shares, and protects personal information when you access or use our website, platform, and related services (collectively, the “Services”).By using the Services, you agree to the collection and use of information as described in this Privacy Policy.

1. Information We Collect

a. Information You Provide Directly

We collect information you provide when you:

  • Create or manage an account

  • Use the Services

  • Communicate with us

  • Make a payment

This may include:

  • Name

  • Email address

  • Business information

  • Authentication credentials (including via Google Sign-In)

  • Billing and subscription details

  • Content you upload or create (documents, forms, messages, files)

b. Client & End-Client Data

When you use TalleFlow to manage your business, you may collect personal information about your own clients or end clients through client portals, contracts, forms, or other tools.

In these cases:

  • You are the data controller

  • TalleFlow acts as a data processor

End clients must direct data access, correction, or deletion requests to the business that invited them to use TalleFlow.

c. Automatically Collected Information

We automatically collect limited technical and usage information, including:

  • IP address

  • Device and browser type

  • Operating system

  • Log files

  • Feature interactions and usage events

This information is used to operate, secure, and maintain the Services. Some information is collected automatically through cookies and similar technologies. On the marketing website (talleflow.com), non-essential cookies and tags—including Google Tag Manager (analytics and advertising tags) and the Intercom support widget—load only after you opt in via our cookie consent banner (“Manage settings”) or the cookie preferences icon; see our Cookies Policy. In the TalleFlow web application and client portal, product analytics (including Amplitude and session replay when enabled) and optional tools such as Intercom run only after you opt in via the in-product cookie preference controls. You can change your preferences at any time in Account and Security (Cookie preferences) in the web app, or via Cookie preferences in the client portal footer.

2. How We Use Information

We process personal information under one or more lawful bases under applicable law (for example: performance of a contract; legitimate interests that are not overridden by your rights; consent where required; and legal obligation). We maintain an internal record of processing that maps each purpose to its lawful basis; you may request a summary by contacting[email protected]. We use personal information to:

Processing purposes (summary)

The table below summarizes the main purposes for which we process personal information, the categories of data involved, our primary lawful basis under GDPR (where applicable), typical recipients/processors, and retention. This is a summary; details are available on request at[email protected].

PurposeData categoriesLawful basisRecipients / processors (examples)RetentionAccount registration, authentication, and account administrationName, email, auth identifiers, profile settingsContract (Art. 6(1)(b))Clerk; hosting (Railway); database (MongoDB Atlas)For the life of the account, then deleted or anonymized subject to legal holdsProvide CRM / project / document / portal features you configureBusiness and client contact data, project content, files, messagesContract (Art. 6(1)(b)); for end-client data we act as processor for the business customerAWS S3 (files); MongoDB Atlas; RailwayWhile the business relationship / records are needed for the Services, then per customer instructions and legal holdsPayments, subscriptions, and invoicingBilling contact, payment metadata, invoice recordsContract (Art. 6(1)(b)); Legal obligation (Art. 6(1)(c)) for tax/accounting recordsStripeAs required by tax and accounting law (typically multi-year), then securely disposedElectronic signatures and signature audit trailsSigner identity, consent records, signature artifacts, anonymized IP / audit metadataContract (Art. 6(1)(b)); Legal obligation / legitimate interests for retention of evidence (Art. 6(1)(c)/(f))Hosting and storage providers supporting the ServicesTypically retained for compliance/evidence periods (e.g., multi-year), then deleted or archived per policyTransactional / service emailsEmail address, message content needed to deliver the emailContract (Art. 6(1)(b)); Legitimate interests (Art. 6(1)(f)) for service noticesResendAs needed to deliver and troubleshoot delivery; longer if required for security/abuse investigationMarketing emails to contacts (where enabled)Email, name, marketing preference / unsubscribe statusConsent (Art. 6(1)(a)) and/or other lawful basis permitted for B2B marketing under applicable law; withdraw anytimeResendUntil unsubscribe or account/contact deletion, subject to suppression-list retention needed to honor opt-outsProduct analytics and session replay (web app / portal)Usage events, device/browser data, session replay where enabledConsent (Art. 6(1)(a)) via in-product cookie preferences; you may withdraw consent at any timeAmplitudePer analytics retention settings; reduced when consent withdrawn / account deleted where feasibleSecurity, fraud prevention, logging, and abuse detectionIP/device signals, auth logs, security eventsLegitimate interests (Art. 6(1)(f)); Legal obligation where applicableHosting, logging, and monitoring providersFor security and investigation windows, then deleted or aggregatedCustomer supportContact details and information you submit in a requestContract (Art. 6(1)(b)); Legitimate interests (Art. 6(1)(f))Support / feedback tools as configuredFor the support matter and a reasonable follow-up periodComply with law and enforce termsRecords needed for legal claims, compliance, or lawful requestsLegal obligation (Art. 6(1)(c)); Legitimate interests (Art. 6(1)(f))Professional advisers; authorities when requiredAs required by law or until disputes are resolvedInternal de-identified product analytics (not public)De-identified usage and performance metrics from the ServicesLegitimate interests (Art. 6(1)(f)); internal use onlyTalleFlow engineering and operations teamsPer internal retention policies; not published externally

International transfers: Personal data may be processed in the United States and other countries where we or our providers operate. Where GDPR requires it, we use appropriate safeguards (such as SCCs, adequacy, and/or EU–U.S. Data Privacy Framework for certified providers). Ask[email protected]for the mechanism used for a specific provider.

  • Provide, operate, and maintain the Services

  • Authenticate users and secure accounts

  • Process payments and manage subscriptions

  • Send service-related and marketing communications

  • Monitor usage and improve product functionality

  • Provide customer support

  • Comply with legal obligations

Marketing emails are sent only to users who have opted in to receive them. You may opt out at any time using the unsubscribe link included in our communications.

Customer business data (your workspace)

When you use TalleFlow to run your business, data you enter or generate in the Services—such as CRM contacts, projects, documents, bookings, invoices, pricing, packages, and messages—is processed to provide the features you configure. We treat this as your business data.

We do not sell your business data or your clients’ personal information.

We do not use your business data (including booking, pricing, or invoice information) to create public marketing content, industry benchmark reports, pricing guides, or similar publications, unless you explicitly opt in to a separate program that we describe at the time of enrollment.

We may use de-identified and aggregated information derived from use of the Services solely for internal product improvement, security, reliability, and analytics. We design these aggregates so they do not identify you, your business, or your clients in published outputs.

3. AI & Data Usage (Non-Google Data)

TalleFlow may use anonymized and aggregated data to improve internal systems and product functionality, including AI-powered features. Such use is limited to internal operations and is not used to create public industry reports, benchmark publications, pricing guides, or other marketing content unless you explicitly opt in to a separate program as described in Section 2.

We do not use identifiable customer, client, or end-client data to train AI models.

AI features are assistive only and require human review before use.

4. Google User Data & API Services

TalleFlow may access Google user data only when you explicitly choose to connect Google services (such as Google Sign-In or other Google integrations).

How Google User Data Is Used

  • Accessed only as required to provide the specific user-requested feature

  • Used solely within the TalleFlow application

  • Not used for advertising purposes

  • Not sold

  • Not shared, except as strictly necessary to provide the requested functionality

  • Not retained longer than necessary to operate the feature

  • Not used to train AI or machine learning models

Compliance Statement

TalleFlow’s use and handling of Google user data complies with:

  • The Google API Services User Data Policy

  • The Limited Use requirements

  • CASA (Cloud App Security Assessment) standards

If there is any conflict between this section and other parts of this Privacy Policy,this section governs Google user data handling.

5. How We Share Information

We do not sell personal data.

We do not sell personal data. We share information with trusted third-party service providers (processors) only as necessary to operate the Services. Examples include:

  • Payment processors (e.g., Stripe)

  • Authentication providers (e.g., Clerk)

  • Email delivery services (e.g., Resend)

  • Analytics and monitoring tools (e.g., Amplitude; error monitoring providers where configured)

  • Cloud infrastructure and hosting providers (e.g., Railway, Amazon Web Services / S3, MongoDB Atlas)

  • Customer support and product feedback tools (as configured from time to time)

6. Cookies & Analytics

We use cookies and similar technologies to support core functionality, analyze website performance, and measure marketing effectiveness.

  • Essential cookies are required for the Services to function properly and cannot be disabled.

  • Essential cookies are required for the Services to function and cannot be disabled. On the marketing website, analytics and advertising cookies are described in our Cookies Policy and are controlled by the website cookie settings where available. In the TalleFlow web application and client portal, product analytics tools (including Amplitude and session replay when enabled) require your opt-in through the cookie preference banner and Cookie preferences controls. You may withdraw consent at any time using those same controls.

For more detailed information about how we use cookies and similar technologies, please see our Cookie Policy.

7. Data Retention

When an account is deleted:

  • Data may be retained for a limited period in accordance with our Terms of Service

  • Certain records, such as billing or legal records, may be retained as required by law

8. Data Security

We implement reasonable administrative, technical, and organizational safeguards designed to protect personal information.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Your Rights & Choices

Depending on your location (including where GDPR or similar laws apply), you may have the right to:

  • Access your personal information and receive a copy (data portability where applicable)

  • Request correction, deletion, restriction of processing, or objection to certain processing

  • Opt out of marketing communications (and withdraw consent where processing is based on consent)

Requests related to client or end-client data must be made through the business that collected the data. You may also contact us at[email protected]to exercise privacy rights. For cookie and analytics preferences: use Cookie preferences in the TalleFlow web app (Account and Security) or the client portal footer; on the marketing website, use the cookie consent banner (“Manage settings”) or the cookie preferences icon.

Privacy-related requests may be submitted to <a href="mailto:[email protected]“>[email protected]</a>.

10. Children’s Privacy

The Services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children.

11. California Privacy Rights

TalleFlow does not sell personal information.

We may share limited personal information with advertising partners for marketing and measurement purposes only where permitted by law and only with your consent.

California residents have the right to opt out of the sharing of personal information for targeted advertising. You may exercise this right through marketing-website cookie settings (including “Manage settings” in the cookie banner or the cookie preferences icon), by enabling Global Privacy Control (GPC) in your browser where supported (we honor GPC as a request to deny non-essential cookies on our marketing site), or by contacting us at[email protected].

12. International Users

TalleFlow, Inc. is based in the United States. If you access the Services from outside the United States, your information may be processed in the United States and other countries where we or our service providers operate (including providers listed in Section 5). Where required by applicable law (including GDPR Chapter V), we rely on appropriate transfer safeguards such as an adequacy decision, Standard Contractual Clauses (SCCs), and/or the EU-U.S. Data Privacy Framework for certified providers-not on consent to transfer alone. You may request details of the transfer mechanism used for a specific provider by contacting[email protected].

Where GDPR applies, we are committed to complying with applicable data protection laws. If an EU Article 27 representative is required for our activities, we will appoint one and publish their contact details here and in our Privacy Policy contact section. Until then, privacy rights and GDPR inquiries should be sent to[email protected].

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Continued use of the Services after changes become effective constitutes acceptance of the updated policy.

14. Contact Us

If you have questions about this Privacy Policy, our data practices, privacy rights requests, international transfers, or (where applicable) our EU Article 27 representative once appointed, please contact us at:

[email protected]