Privacy Policy
How we collect, use, store, share, and protect personal data, including Google user data and data processed by OpenAI.
Effective: 2026-10-03 · Version: 2.0
This Privacy Policy explains how Reseller Flow (“Reseller Flow”, “we”, “us”) collects, uses, stores, shares, and protects information when you visit https://flow.inboxy.one or use the Reseller Flow web application, including when you connect your Google account. If you have questions, contact us at hello@clickcast.net.
1. Who we are and what Reseller Flow does
Reseller Flow is a business messaging platform. Businesses (“workspaces”) use it to manage WhatsApp conversations in a shared inbox, build chatbots, send broadcasts and follow-ups, book appointments, collect form answers, and answer customers with an AI assistant.
For information about the people who sign up for and use Reseller Flow (account holders and their team members) we are the data controller. For the contacts and conversations a workspace manages in Reseller Flow, the workspace is the controller and we act as its data processor, processing that data only on the workspace’s instructions.
2. Information we collect
- Account information: name, email address, password (stored only as a one-way hash), phone number, workspace name, role, language, and two-factor authentication settings.
- Workspace content: contacts (names, phone numbers, WhatsApp IDs, labels, custom fields), WhatsApp messages and media sent and received, chatbot flows, templates, broadcast lists, form and survey answers, appointment details, notes, and knowledge-base documents you upload for the AI assistant.
- Connected services: the data needed to connect a WhatsApp Business account through Meta, and the Google user data described in section 4 when you choose to connect Google.
- Billing information: plan, invoices, and payment status. Card payments are handled by our payment processors on their own hosted pages; we never receive or store full card numbers or card security codes.
- Usage and device information: IP address, browser and device type, pages visited, sign-in history, and security and error logs.
- Cookies: necessary cookies for sign-in, security (CSRF protection), and remembering your cookie choice. Analytics and marketing cookies are used only if you accept them in the cookie banner. See our Cookie Policy.
3. How we use information
- To provide the service: deliver and receive WhatsApp messages, run chatbots and automations, show conversations in the inbox, book appointments, and sync data with the services you connect.
- To provide AI features you turn on (see section 5).
- To create and secure accounts, authenticate users, prevent fraud and abuse, and enforce our Terms of Service.
- To process payments, manage subscriptions, and send service emails such as password resets, security alerts, and billing notices.
- To provide support, fix problems, and keep the service reliable.
- To meet legal obligations.
We do not sell personal information, and we do not use workspace content or Google user data for advertising.
4. Google user data
Connecting a Google account is optional. A workspace member can connect Google from Settings → Integrations to use Google Sheets, Google Calendar, and Google Drive features inside Reseller Flow.
4.1 Data we access and why
- Basic profile (openid, email, profile): your Google account’s email address, name, and profile picture, so we can show which Google account is connected and let you disconnect it.
- Google Sheets (spreadsheets): reads and writes rows only in the spreadsheets you choose in a chatbot step, form, or integration. For example, a chatbot can append a new lead to your sheet or look up an order status in it when your customer asks.
- Google Drive file metadata (drive.metadata.readonly): lists the names and IDs of your spreadsheets so you can pick one from a list. We do not read the contents of other Drive files.
- Google Drive files created or opened with Reseller Flow (drive.file): creates new spreadsheets for you (for example, a sheet to collect form answers) and opens files you select with Reseller Flow.
- Google Calendar (calendar): reads availability on the calendars you choose and creates, updates, or cancels appointment events (with attendee email addresses) when your customers book, reschedule, or cancel through Reseller Flow.
4.2 How we use Google user data
We use Google user data only to provide and improve the user-facing features described above, at your request. We do not use it for advertising, we do not sell it, and we do not use it to build user profiles or to determine creditworthiness or for lending purposes.
We do not use Google user data, including data obtained through Google Workspace APIs, to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models. We do not send Google user data to OpenAI or any other AI provider, unless a workspace owner explicitly builds a chatbot step that passes a spreadsheet value to the AI assistant to answer that workspace’s own customer. Even then, the data is used only to generate that reply, and OpenAI does not use it to train its models (see section 5).
4.3 How we store and protect Google user data
Google OAuth access and refresh tokens are stored encrypted at rest with AES-256 and are never shown in the interface or written to logs. Spreadsheet and calendar data is fetched from Google when a feature needs it. Spreadsheet and calendar lists are cached briefly to keep the interface fast. Values a chatbot reads from a sheet may be saved in the related conversation, like any other chatbot answer. All traffic between Reseller Flow and Google uses HTTPS (TLS).
4.4 How we share Google user data
We do not share, transfer, or disclose Google user data to third parties, except: (a) as needed to provide the features you use, such as writing to your own spreadsheet or calendar; (b) to our infrastructure providers that host Reseller Flow under confidentiality and security obligations; (c) when required by law or to protect the security of the service; or (d) with your explicit consent. Our staff do not read Google user data unless you ask us for support and give consent, it is needed for security or abuse investigations, or the law requires it.
4.5 Retention and deletion of Google user data
You can disconnect Google at any time from Settings → Integrations. When you do, we immediately delete the stored Google tokens and stop accessing your Google account. You can also revoke access at any time at myaccount.google.com/permissions. If your workspace is deleted, all remaining data, including Google connection records, is permanently deleted within 30 days. To ask us to delete Google user data sooner, email hello@clickcast.net.
4.6 Limited Use
Reseller Flow’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. AI features and OpenAI
Reseller Flow uses OpenAI’s GPT large language models (the models that power ChatGPT), accessed through the OpenAI API, as its AI large language model (LLM) provider. OpenAI, L.L.C. acts as our subprocessor for these features.
AI features are optional and are switched on by each workspace. When they are on, we send OpenAI only what is needed for the task:
- AI assistant replies: the customer’s message, recent conversation history, the assistant instructions the workspace wrote, relevant passages from the workspace’s knowledge base, and the contact details the workspace chose to include.
- Knowledge base search: text from documents, web pages, and FAQs the workspace uploads, which is converted into embeddings so the assistant can find relevant answers.
- Voice notes, images, and documents: media a customer sends, when the workspace enables transcription or image and document understanding.
- Agentic flow builder: the instructions a workspace member types to build or edit a chatbot, together with that chatbot’s structure.
Under OpenAI’s API data usage policies, data sent through the OpenAI API is not used to train OpenAI’s models. OpenAI may keep API inputs and outputs for up to 30 days to monitor for abuse, and then deletes them unless the law requires otherwise. See OpenAI’s Privacy Policy. AI-generated replies can be inaccurate, so workspaces should review how their assistant behaves. Requests to the agentic flow builder are screened for misuse before they reach OpenAI, and secrets such as API keys are removed from stored builder chat history.
6. How we share information
We share personal information only with the service providers (subprocessors) that help us run Reseller Flow, under contracts that require them to protect it:
- Meta Platforms (WhatsApp Business Platform): to send and receive WhatsApp messages.
- OpenAI: for the AI features described in section 5.
- Google: only when you connect Google, for the features described in section 4.
- Cloud hosting and storage providers: to run our servers, databases, backups, and file storage.
- Email delivery providers: to send account and notification emails.
- Payment processors (such as Stripe or PayPal): to take payments on their hosted checkout pages.
We may also disclose information if the law requires it, to protect the rights, safety, and security of our users or the service, or as part of a merger or acquisition, in which case this policy continues to apply. Workspaces can also connect their own tools (for example webhooks, HTTP APIs, Shopify, or WooCommerce). Data a workspace sends to those tools is under that workspace’s control.
7. Data retention
- Account and workspace data is kept while the account is active.
- Conversation messages are moved from the live inbox to archive storage after 90 days and are kept until the workspace deletes them or closes its account.
- Completed, cancelled, and no-show appointments are deleted after 730 days, and audit logs after 365 days. Sign-in history and error logs are kept for a few weeks only.
- When a workspace is deleted, its data is permanently deleted within 30 days, apart from records we must keep by law (for example invoices).
8. Security
We protect data with HTTPS (TLS) encryption in transit, encryption at rest for secrets and access tokens, hashed passwords, optional two-factor authentication, role-based permissions, strict separation between workspaces, IP allowlists, rate limiting, audit logs, and regular backups. No system is perfectly secure. If a breach affects your data, we will notify you as required by law.
9. Your rights and choices
Depending on where you live (for example in the EEA, the UK, or California), you may have the right to access, correct, delete, or export your personal information, to restrict or object to certain processing, and to withdraw consent at any time. You can update most account details in the app, disconnect Google or other integrations at any time, and change your cookie choices from the cookie banner. To make a request, email hello@clickcast.net. If you are a contact of a business that uses Reseller Flow, please contact that business first; we will help them respond. You may also complain to your local data protection authority.
Where the GDPR applies, our legal bases are: performing our contract with you; our legitimate interests in securing and improving the service; compliance with legal obligations; and your consent for optional cookies and marketing.
10. International transfers
Our servers and subprocessors may be located in other countries, including the United States. Where required, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
11. Children
Reseller Flow is a business service and is not directed to children under 16. We do not knowingly collect personal information from children.
12. Changes to this policy
We may update this policy from time to time. If we make material changes, especially to how we use Google user data, we will notify account owners by email or in the app before the changes take effect, and update the effective date above.
13. Contact us
For privacy questions, data requests, or to delete Google user data, email hello@clickcast.net or use the contact page.
