Privacy Policy
Last updated: 2 March 2026
1. Introduction
Management Flow ("we", "us", "our") operates the project management platform at managementflow.com. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
2. Data We Collect
We collect information in the following categories:
- Account information — name, email address, and profile picture provided during sign-up via our authentication provider (Clerk).
- Project data — projects, tasks, meetings, team members, time logs, and other content you create within the platform.
- Payment information — billing details are processed securely by Stripe. We do not store credit card numbers on our servers.
- Usage data — page views, feature usage, and performance metrics collected via Vercel Analytics. This data is anonymised and aggregated.
- Technical data — IP address, browser type, device information, and cookies necessary for authentication and session management.
3. How We Use Your Data
- To provide, maintain, and improve the Management Flow platform
- To process payments and manage your subscription
- To send transactional emails (account confirmation, payment receipts, subscription changes)
- To respond to support requests
- To detect and prevent fraud or abuse
- To analyse usage patterns and improve our product (anonymised analytics only)
4. Third-Party Services
We use the following trusted third-party services:
- Clerk — authentication and user management
- Stripe — payment processing and subscription billing
- Supabase — database hosting (EU region, Zurich)
- Vercel — application hosting and analytics
Each provider has their own privacy policy. We encourage you to review them.
5. Data Storage & Security
Your data is stored in Supabase PostgreSQL databases hosted in EU Central (Zurich). All data is encrypted in transit (TLS) and at rest. We implement access controls, regular backups, and monitoring to protect your information.
6. Your Rights (GDPR)
If you are located in the European Economic Area, you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — request correction of inaccurate data
- Erasure — request deletion of your personal data
- Portability — receive your data in a structured, machine-readable format
- Restriction — request restriction of processing
- Objection — object to processing based on legitimate interests
To exercise any of these rights, contact us at privacy@managementflow.com.
7. Cookies
We use essential cookies for authentication and session management. We do not use third-party advertising or tracking cookies. Vercel Analytics uses privacy-friendly, cookie-free analytics.
8. Data Retention
We retain your account and project data for as long as your account is active. If you delete your account, we will remove your personal data within 30 days, except where we are legally required to retain it (e.g. billing records for tax purposes).
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date.
10. Contact Us
If you have questions about this Privacy Policy, contact us at: privacy@managementflow.com