Last updated: March 1, 2026
1. Introduction
Dealsflow ("we," "our," or "us") operates the website dealsflow.ai and the Dealsflow application platform at app.dealsflow.ai (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our Service.
By accessing or using the Service, you agree to this Privacy Policy. If you do not agree with the terms of this policy, please do not access the Service.
2. Information We Collect
2.1 Personal Information You Provide
We collect information that you voluntarily provide when you:
- Create an account (name, email address, password)
- Subscribe to a paid plan (billing address, payment information processed by our payment provider)
- Fill out a contact form or book a demo (name, email, company name, role)
- Communicate with us via email or through the Service
- Use Flow AI and provide business data, client information, or other content
2.2 Information Collected Automatically
When you access the Service, we may automatically collect:
- Device Information: Browser type, operating system, device identifiers, and screen resolution
- Usage Data: Pages visited, features used, time spent on pages, click patterns, and referring URLs
- Log Data: IP address, access times, and server log information
- Cookies and Similar Technologies: We use cookies, local storage, and similar tracking technologies to maintain session state, remember preferences, and analyze usage patterns
2.3 Information from Third-Party Integrations
When you connect third-party services (such as Facebook, Instagram, WhatsApp, Google, or email providers) to Dealsflow, we may receive information from those services in accordance with their privacy policies and your authorization settings. This may include contact lists, message history, advertising data, and analytics.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To provide, operate, and maintain the Dealsflow platform, including Flow AI functionality, CRM features, email campaigns, ad management, and workflow automations
- AI Processing: To power Flow AI's conversational interface, memory system, and proactive suggestions. Your business data is processed to generate relevant responses and take actions on your behalf
- Account Management: To create and manage your account, process transactions, and send service-related communications
- Improvement: To analyze usage patterns, diagnose technical issues, and improve the Service
- Communication: To respond to inquiries, send product updates, and provide customer support
- Security: To detect, prevent, and address fraud, abuse, and security issues
- Legal Compliance: To comply with applicable laws, regulations, and legal processes
4. AI and Data Processing
Dealsflow uses artificial intelligence to provide its core features. Here's how your data interacts with our AI systems:
- Conversation Data: Messages you send to Flow AI are processed in real-time to generate responses and execute actions. Conversation history is stored to provide the persistent memory feature
- Business Data: Client records, deals, tasks, and other business data you input are used by Flow AI to provide context-aware assistance
- Model Training: We do not use your personal business data to train our AI models. Your data is used solely to provide the Service to you
- Third-Party AI Providers: We may use third-party AI infrastructure to process requests. These providers are bound by data processing agreements and do not retain your data beyond what is necessary to complete the request
5. Data Sharing and Disclosure
We do not sell your personal information. We may share your information in the following circumstances:
- Service Providers: With third-party vendors who perform services on our behalf (hosting, payment processing, email delivery, analytics) under contractual obligations to protect your data
- Third-Party Integrations: When you authorize connections to external platforms, data is shared as necessary to provide the integrated functionality
- Legal Requirements: When required by law, regulation, legal process, or governmental request
- Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction
- With Your Consent: When you explicitly authorize us to share your information for a specific purpose
6. Data Security
We implement industry-standard security measures to protect your information, including:
- Encryption of data in transit (TLS 1.3) and at rest (AES-256)
- Regular security audits and penetration testing
- Access controls and authentication requirements for all systems
- Secure infrastructure hosted on SOC 2 Type II compliant providers
- Automated monitoring for unauthorized access attempts
While we strive to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
7. Data Retention
We retain your information for as long as your account is active or as needed to provide you with the Service. Specifically:
- Account Data: Retained for the duration of your account and deleted within 30 days of account closure upon request
- Conversation History: Retained to provide the persistent memory feature. You can delete specific conversations or request full deletion
- Usage Analytics: Aggregated and anonymized data may be retained indefinitely for analytical purposes
- Legal Records: Certain data may be retained longer if required by law or for legitimate business purposes (e.g., billing records)
8. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information, subject to legal exceptions
- Data Portability: Request your data in a structured, machine-readable format
- Restriction: Request that we restrict processing of your data in certain circumstances
- Objection: Object to processing of your data for certain purposes
- Withdraw Consent: Where processing is based on consent, withdraw that consent at any time
To exercise any of these rights, contact us at privacy@dealsflow.ai. We will respond to your request within 30 days.
9. Cookies
We use the following types of cookies:
- Essential Cookies: Required for the Service to function (authentication, security, session management)
- Analytics Cookies: Help us understand how visitors interact with the Service (page views, navigation paths, feature usage)
- Preference Cookies: Remember your settings and preferences for a better experience
You can manage cookie preferences through your browser settings. Disabling essential cookies may impact Service functionality.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place, including standard contractual clauses and data processing agreements, to protect your information in accordance with this Privacy Policy.
11. Children's Privacy
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. For significant changes, we may also send you an email notification. Your continued use of the Service after any changes constitutes acceptance of the updated policy.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at: