Workspace
VERSION 2026-08-25

Privacy Notice

Clear, short information about how Flow works and how your data is handled.

Pre-launch legal review

This product-specific draft is operationally accurate. Company identity, official privacy contact and governing-law details must be approved by counsel before public launch.

1. Data we process

We process account identity, business and team details, workflows, orders, and customer data you enter, such as names, phone numbers and order details.

When you use Offers or WhatsApp, we store contacts, consent and opt-out history, WhatsApp connection identifiers, templates and delivery status. Meta secrets are never exposed to the browser.

When you connect an external system, we process sample events and orders it sends so awam can detect fields, map statuses and run your workflow. Raw event records are retained for up to 30 days for troubleshooting and duplicate prevention, then automatically deleted.

We also keep wallet, activity, audit and limited technical security records needed to prevent abuse and operate the service.

2. Why we use it

We use data to run workflows, send notifications you configure, manage teams and balances, provide support, secure accounts, and prevent duplicate or abusive activity.

3. Your customers and your responsibility

You are responsible for the accuracy of customer data and for having a lawful basis or clear consent before sending marketing offers. awam preserves opt-outs and will not silently re-enable them through a bulk import.

4. Sharing and service providers

We do not sell data. Data may be processed by hosting and security providers, Meta and WhatsApp when connected, and integrations you choose later. We share only what is needed for the requested function.

Awam's public and signup pages use Meta Pixel to measure campaign visits and completed account creation. It is not loaded in the workspace or administration dashboard, and no order or customer details are sent to it.

5. Retention and deletion

We retain information while an account is active or as legally and operationally necessary. The business owner can schedule deletion in Settings. A 14-day cooling-off period allows cancellation before deletion executes.

A limited copy may remain in isolated backups until the published backup-retention period expires. Deleted records are not returned to the live service during a restore.

6. Your rights and security

You can review and correct business data, manage marketing consent, and request deletion. We use tenant isolation, permissions, audit records and abuse limits, but no online service can eliminate every risk.

External-system connection tokens are stored as one-way hashes. The full connection URL is shown only when it is created or rotated, and you can pause or delete it from Settings.

Read the TermsBack to Flow