Legal · Privacy

Privacy Policy

How Flowdrive collects, uses, and protects your information — and the choices you have about it.

Last updated: June 17, 2026

Long read? Ask AI to summarize this policy.

1. Information We Collect

1.1 Information You Provide

  • Account information (name, email, password)
  • Billing information
  • Files and content you upload
  • Custom domain information
  • Communication preferences

1.2 Information Automatically Collected

  • Usage data and analytics
  • Device information
  • IP addresses
  • Access logs
  • Cookie data

2. How We Use Your Information

2.1 Service Provision

  • Hosting and serving your files
  • Processing uploads and downloads
  • Managing your account
  • Providing customer support

2.2 Service Improvement

  • Analyzing usage patterns
  • Improving features
  • Debugging issues
  • Preventing abuse

3. Data Storage and Security

3.1 File Storage

  • Files are stored in secure cloud infrastructure
  • Regular security audits
  • Backup systems in place

3.2 Data Protection

  • Industry-standard security measures
  • Access controls and monitoring
  • Regular security updates
  • Employee access restrictions

4. Information Sharing

4.1 Third-Party Service Providers

  • Cloud storage and infrastructure providers (Cloudflare)
  • Payment processors (Stripe)
  • Membership platforms you connect (Memberstack) — see 4.3
  • Analytics services
  • Customer support tools

4.2 Legal Requirements

  • Court orders
  • Legal obligations
  • Government requests
  • Rights protection

4.3 Membership Integrations (Memberstack)

If you enable Flowdrive's secured-files feature, Flowdrive integrates with Memberstack to check whether a site visitor is permitted to view a protected file. This integration is optional and only active when you connect it.

What you provide to us

  • Your Memberstack secret API key(s) — sandbox and/or live. These are encrypted at rest and used only on our servers to verify visitors with Memberstack. They are never sent to a browser or exposed in any published page.

What we process about your site's visitors

When a visitor loads a secured file, their browser sends our signing endpoint the following, solely to authorize that request:

  • Memberstack session token — to identify the visitor to Memberstack.
  • Requested file path(s) — which secured file(s) they are trying to view.
  • Download flag and access mode — whether it is a view or a download, and live vs. sandbox.

Retention and boundaries

  • The visitor's session token is not stored. It is used transiently to verify the visitor with Memberstack and then discarded; only a short-lived, hashed authorization result is cached to speed up repeat requests.
  • Verification happens server-side. Neither your secret key nor a visitor's token is ever returned to the browser.
  • Memberstack acts as an independent controller of member data under its own privacy policy. Flowdrive uses it only to answer "may this visitor see this file?"
  • You can disconnect the integration or rotate your keys at any time from your dashboard; removing it deletes the stored keys.

5. Your Rights and Choices

5.1 Account Information

  • Access your data
  • Update your information
  • Request data deletion
  • Export your data

5.2 Communication Preferences

  • Email preferences
  • Marketing communications
  • Service notifications
  • Account alerts

6. Data Retention

  • Active account data retention
  • Deleted account handling
  • Backup retention periods
  • Log data retention

7. Children's Privacy

  • Age restrictions
  • No intentional collection of children's data
  • Deletion of discovered underage accounts

8. International Data Transfers

  • Cross-border data transfers
  • Data protection measures
  • International compliance

9. Cookies and Tracking Technologies

9.1 Cookies and Local Storage We Use

Strictly necessary (always active — required to run the service and cannot be disabled):

  • auth_token and refresh_token — keep you signed in to the app.
  • fd_consent — remembers your cookie and tracking choices.

Analytics & marketing (optional — set only if you opt in, and not set by default for visitors in the EU, EEA, UK, or Switzerland):

  • PostHog cookies and local-storage keys — product analytics and session recording (see Section 10).
  • Google Ads (gtag) — measures advertising conversions on our marketing site.
  • affiliate_ref — credits the partner who referred you, for our affiliate program.

9.2 Managing Your Choices

You can accept or decline optional cookies using the consent controls on our website (including the “Cookie preferences” link in the footer) and the privacy controls in your account. You can also control cookies through your browser settings. Disabling strictly necessary cookies may affect the functionality of the service.

10. Analytics & Session Recording

10.1 What We Collect

  • Product usage events (pages viewed, clicks, and features used)
  • Device and browser type
  • Approximate location, derived from your IP address
  • Session recordings — replays of how you interact with the app, used to debug issues and improve the product

10.2 Who Processes It

We use PostHog, hosted in the European Union. Your analytics and session-recording data is stored in the EU.

10.3 Lawful Basis & Your Control

We rely on your consent. If you are in the EU, EEA, UK, or Switzerland, analytics and session recording are off by default and run only if you opt in. You can change your choice at any time using the cookie and privacy controls on our website and in your account settings.

10.4 Session Recording

Where enabled, we may record interactions such as page navigation, clicks, and scrolling. Text you type, form inputs, and sensitive fields are masked, so their contents are not captured in the recording.

10.5 Retention

Analytics and session-recording data is retained for up to 12 months, after which it is automatically deleted.

11. Data Breach Notification

10.1 Breach Response

In the event of a data breach that may affect your personal information, we will notify affected users within 72 hours of discovery, as required by applicable laws.

10.2 Notification Methods

  • Email notification to affected users
  • Public disclosure if required by law
  • Regulatory notification to authorities

12. GDPR Compliance

11.1 EU User Rights

  • Right to access your personal data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing

11.2 Legal Basis for Processing

  • Contract performance for service delivery
  • Legitimate interests for service improvement
  • Consent for marketing communications
  • Legal obligation for compliance requirements

13. CCPA Compliance

12.1 California Consumer Rights

  • Right to know what personal information is collected
  • Right to know how personal information is used
  • Right to know how personal information is shared
  • Right to access personal information
  • Right to delete personal information
  • Right to opt-out of sale of personal information

12.2 Non-Discrimination

We will not discriminate against you for exercising your privacy rights under CCPA.

14. Changes to Privacy Policy

13.1 Update Notifications

  • Email notification for material changes
  • In-app notifications for significant updates
  • Website banner for policy changes

13.2 Continued Use

Continued use of our service after policy changes constitutes acceptance of the updated policy.

15. Embedded Upload Widget & Member-Gated Media

When a Flowdrive customer embeds the Flowdrive upload widget on their website, the widget runs on that site's pages and communicates with Flowdrive services. This section describes exactly what the embedded runtime sends and how we handle it.

Duplicate-install detection

If the widget detects that it was loaded more than once on a page, it warns the site owner in the browser console so they can remove the duplicate. This check is entirely local — no data is sent to Flowdrive about it, and no telemetry endpoint is contacted.

Member-gated media (Memberstack)

  • When: only on pages where the site owner has enabled Flowdrive member-gated media, and only if a Memberstack member session is present.
  • Data sent: the visitor's Memberstack session token, over HTTPS, to Flowdrive's media-signing endpoint.
  • Purpose: solely to verify — via Memberstack's own API — that the visitor is entitled to the gated media, and to return a temporary signed link or deny access.
  • Protections: the token is transmitted over HTTPS only; it is never written to logs and never stored — only a one-way hash is used briefly to cache the verification result for a few minutes. An invalid or absent token results in access being denied.
  • Retention: no token is retained; the verification cache entry expires within minutes.

16. Contact Information

For privacy-related inquiries:

Manuel Ogomigo LLC
South Governors Avenue 1111b
Dover, DE 19904 US

Contact Details:

Email: [email protected]
Website: https://tryflowdrive.com

Take control of your file hosting on Webflow.

Ask about Flowdrive on
© 2026 Flowdrive