Legal

Privacy Policy

Effective date: July 11, 2026

FlowGlance is an analytics product, so we handle data for a living. That makes it doubly important that we are precise about what we collect, why, and who controls it. This policy is written to be read, not skimmed past.

1. Who we are

FlowGlance (flowglance.com) is a data console for site owners: visitor journey analytics, service usage, revenue verification, search insights, and AI-generated recommendations. FlowGlance launched in 2026.

For anything in this policy, you can reach us at [email protected]. We respond within 2 business days.

2. Our two roles: controller and processor

We handle data in two distinct capacities, and the difference matters:

  • As a controller — for data about you when you visit flowglance.com or hold a FlowGlance account. We decide what to collect and why, and this policy governs it directly.
  • As a processor — for visitor data collected on customer sites that embed our analytics script. There, the site owner is the controller: they decide what to enable (described below), and we process it on their behalf and under their instructions.

3. Data we collect on our own site

When you use flowglance.com and a FlowGlance account:

  • Account data. Sign-in is handled by Clerk using email verification codes. We store your email address; we never store passwords — there are none.
  • Billing data. Payments are processed by Stripe. We never see or store your full card number; we receive only what Stripe shares to manage your subscription (e.g. plan, payment status, card brand and last four digits).
  • Usage analytics. Our own site runs our first-party analytics script, fw.js — the same one we offer customers. It uses localStorage identifiers, not third-party cookies, and we use no third-party ad trackers of any kind.
  • Support correspondence. If you email us, we keep the thread so we can actually help you.

4. Data collected on customer sites

Site owners embed our fw.js script on their own sites to collect visitor analytics. In that context, the site owner is responsible for telling their visitors about the analytics and for having a lawful basis to collect it; we process the data solely to provide the analytics service back to that owner.

What is collected is described in the next section. Identifiers on customer sites are stored in the visitor's browser localStorage (_fw_vid and _fw_sid), not in third-party cookies.

5. What is collected on customer sites

What fw.js records is governed by per-ability switches the site owner controls. Always collected while the script runs: pages viewed, clicks (with the content section they happened in), scroll depth, dwell time, business events and payment events the site sends. Each of the following is an individual switch the owner can turn off at any time: sections read; form activity (started/submitted, without field contents); identity (such as an email after sign-in on that site); JavaScript errors; copied text; media plays; upload activity (file name, type and size — never the file itself); the personalised output their site shows a visitor; the text a visitor submits in forms; and a compressed copy of images uploaded into the site's features. Password, hidden and payment-shaped fields are never collected under any switch, and anything whose switch is off is discarded at ingestion, not stored.

Site owners can optionally connect their own database to power the Business board by providing a connection string — we recommend a dedicated read-only role. The credential is stored AES-256-GCM encrypted and used only for read-only aggregate queries: every query runs in a read-only transaction, so the database itself refuses any write we could send. We persist only totals, trends and a handful of recent rows — never a copy of the database. Disconnecting deletes the credential and every stored aggregate immediately.

All of it is processed solely to provide the analytics service back to that owner: per-site isolation, no cross-site profiles, no advertising use, no sale of data. Deleting a site — or the account — permanently deletes the data it collected.

6. Where your data lives

We build on a small set of infrastructure providers, each acting as a subprocessor:

  • Clerk — authentication (email verification codes and session management).
  • Stripe — payment processing.
  • Vercel — application hosting.
  • Neon — database, hosted in the United States.
  • Cloudflare R2 — file storage.
  • Cloudflare — CDN and security.

We do not sell data, and we do not share it with advertisers or data brokers. Data goes to these providers only as needed to run the service.

7. Retention and deletion

  • Delete a site — its collected analytics data is deleted.
  • Delete your account — your account data and all data for your sites is deleted.

We keep data only for as long as it serves the analytics you signed up for, and billing records only as long as required for accounting and legal obligations (held by Stripe).

8. Your rights

Depending on where you live, you may have legal rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. We honor these requests regardless of jurisdiction where we reasonably can:

  • You can delete sites or your entire account yourself, from within the console.
  • For access, correction, or export requests, email [email protected] — we respond within 2 business days.

9. If you visited a site that uses FlowGlance

If your data was collected on someone else's site through our script, that site owner is the controller of your data. Please direct requests about that data to the site owner — we will assist them in fulfilling your request. If you are unsure who to contact, email us and we will point you in the right direction where we can.

10. Changes to this policy

If we change this policy in a way that matters, we will update the effective date at the top and, for significant changes affecting account holders, notify you by email before the change takes effect.

11. Contact

Questions, requests, or concerns: [email protected]. We respond within 2 business days.

Related policies: Cookie Policy · Terms of Service