StasiukFlow
Privacy Policy
Draft: 6 September 2026
1. Data controller
This policy covers StasiukFlow. Contact for personal data matters: info@s-flow.online, phone +48 511 228 619. The operator’s full legal name, address and Polish tax number require confirmation; a brand name does not replace these details.
The operator is responsible for account data, communications and Service billing. For workshop customer and employee data, the workshop is generally the controller and StasiukFlow processes data on its instructions under a data processing agreement.
2. Data categories and sources
Account data: username, email, password hash, profile image, verification status and session identifiers. Google sign-in provides an account identifier, email and available profile image.
Company and team data: name, address, tax number, contacts, roles and membership. Workshop data: customers, phone numbers, emails, vehicles, registration numbers and VINs, appointments, orders, parts, PDF documents and financial records.
Payment data includes the plan, subscription status and dates, and Stripe customer and subscription identifiers. Stripe handles full card details. We also process technical data needed for connections and security and the correspondence sent to us.
Data comes from the User, workshop or authorised team member, and selected integrations. Registration and payment details required for those functions must be provided to use them; other fields are optional depending on the feature.
3. Purposes and legal bases
The bases below concern the operator’s processing as controller. For data entrusted by a workshop, the workshop determines the purposes and legal bases.
| Purpose | Legal basis |
|---|---|
| Account and performance of the contract with the User | Article 6(1)(b) GDPR |
| Company representatives and correspondence; interest: communication and business cooperation | Article 6(1)(f) GDPR |
| Billing and statutory obligations | Article 6(1)(b) and (c) GDPR |
| Security and claims; interest: protecting the Service and operator’s rights | Article 6(1)(f) GDPR |
| Features based on voluntary consent, if offered | Article 6(1)(a) GDPR |
4. Recipients and external services
Necessary data may be received by hosting and email providers, staff supporting the Service, and Stripe (payments), Google (optional sign-in), Cloudflare Turnstile (form protection), Telegram and WhatsApp (configured notifications). The scope depends on the feature used.
Providers may act as processors or independent controllers. The operator must confirm the specific legal entities, locations and contractual arrangements. Disclosure to authorities requires an appropriate legal basis; we do not promise to exclude their statutory powers.
5. Confidentiality and link sharing
The workshop database is not intended for public publication. An active order tracking link nevertheless permits access without signing in, including shared contacts and documents. Anyone holding the link can read its contents.
Files in the server’s public directory are accessible through a direct URL. Expiry of a tracking link does not automatically invalidate a file address. Share links only with intended recipients; requests to restrict access should be addressed to the workshop and operator.
6. Transfers outside the EEA
External services may involve processing outside the European Economic Area. Before such a transfer, the operator must establish the recipient, country and appropriate safeguard, such as an adequacy decision or standard contractual clauses. Information about the safeguards used and how to obtain a copy is available through the contact address.
7. Retention
Account data is needed while the Service is provided; after termination, further retention depends on legal obligations and establishing or defending claims. Billing records are subject to applicable statutory retention periods. Correspondence is retained to handle the matter and any claims.
The data processing agreement and controller’s instructions govern the return and deletion of workshop data. The operator should confirm detailed periods for logs, backups and deletion; cancelling a subscription does not automatically delete the account.
9. Your rights
Within the conditions set by the GDPR, you have rights of access, rectification, erasure, restriction, portability and objection to processing based on legitimate interests. Consent can be withdrawn without affecting the lawfulness of earlier processing.
Send account requests to info@s-flow.online and requests concerning workshop customer data to the workshop. We may request proportionate identity verification. Responses are generally provided within one month, subject to extensions allowed by the GDPR. You may complain to the President of the Polish Personal Data Protection Office (UODO) or the competent supervisory authority.
10. Automation and updates
The application automatically checks payment status, plan limits and feature access. The inspected code did not show advertising profiling or decisions with effects covered by Article 22 GDPR. Questions about access restrictions can be directed to support.
This policy will be updated when data processing changes. The current version is available on this page; material changes should be communicated to Users.
Contact: info@s-flow.online · +48 511 228 619
Legal basis and individual rights: GDPR / RODO · UODO
Terms of Service