Privacy Policy
Last updated: 3 September 2026
PreviewFlows (“the Service”, “we”) is operated by Flowfly OÜ (registry code 14750934, Ümera tn 42, 13816 Tallinn, Estonia) (“we”, “us”). This policy explains what we collect, why, the legal basis we rely on, and your choices. Questions: georg@beyondwelcome.com.
Our role
We are the data controller for your account, workspace and billing information. For the Klaviyo content you ask us to render — flow and template data pulled from your connected Klaviyo account — we act as a processor on your behalf: we fetch and render it only on your instructions, and only for as long as needed to show you previews.
What we collect
- Account & organization data — your name, email, and organization membership, provided via our auth provider (Clerk).
- Klaviyo connection — the credential that lets us read your flows: either the OAuth access and refresh tokens Klaviyo issues when you connect with your Klaviyo login, or the read-only private API key you create in Klaviyo and give us. Both are stored encrypted at rest, together with your Klaviyo account ID and name. We never receive or store your Klaviyo password. The Figma plugin sends an API key to us once and never keeps it.
- Email content you render — to generate previews we fetch your flow email templates from Klaviyo and render them to images. Rendered images are stored temporarily (see Retention) and scoped to your organization. We also keep a hash (fingerprint) of each template so that later updates only re-render emails that changed.
- Usage & logs — basic operational logs (render jobs, errors) for reliability and abuse prevention.
- Billing records — subscription and payment status. Card details are handled by Stripe and never reach our systems.
How we use it
Solely to provide the Service: authenticate you, connect to Klaviyo on your behalf, render previews, enforce plan limits, and bill your organization. We do not sell your data or use your email content to train models.
Legal bases for processing (GDPR Article 6(1))
Where the GDPR applies, we rely on the following legal bases:
- Performance of a contract — Art. 6(1)(b). Creating and authenticating your account, storing your Klaviyo credentials, fetching and rendering your flow emails, enforcing plan limits, and providing support. Without this processing we cannot supply the Service.
- Legitimate interests — Art. 6(1)(f). Keeping the Service secure, available and free of abuse; operational logging and error monitoring; and defending legal claims. Our interest is running a reliable, secure product; we limit this processing to operational metadata and balance it against your rights. You may object at any time (see Your rights).
- Legal obligation — Art. 6(1)(c). Retaining invoices and accounting records for the periods Estonian accounting and tax law requires, and responding to lawful requests from authorities.
- Consent — Art. 6(1)(a). Only where we ask for it separately, such as optional product-update emails. You can withdraw consent at any time, without affecting processing already carried out.
We do not process special-category data (Art. 9) and do not carry out automated decision-making that produces legal or similarly significant effects.
Sub-processors
We rely on: Clerk (authentication), Neon (database), Vercel (hosting, functions, Blob storage), Inngest (job orchestration), and the billing provider (Clerk Billing / Stripe). Klaviyo is the source you connect.
International transfers
Some of our providers are established in, or process data from, the United States. Where personal data leaves the EEA we rely on the European Commission’s Standard Contractual Clauses, or on the provider’s certification under the EU–US Data Privacy Framework, as incorporated in each provider’s data processing agreement.
Retention
Rendered preview images are deleted automatically after 7 days. Klaviyo credentials are kept until you disconnect or delete the connection. For a connection made with your Klaviyo login, disconnecting also revokes our access at Klaviyo. For a connection made with an API key, disconnecting deletes our copy of the key; to fully revoke access, also delete the key in Klaviyo (Settings → Account → API keys), as the dashboard reminds you. Account data is kept while your account is active; on deletion we remove your organization’s connections and assets within 30 days. Billing and accounting records are kept for the statutory period (7 years under Estonian law).
Security
Klaviyo tokens and API keys are encrypted at rest (AES-256-GCM). Access to your organization’s data is isolated per organization and gated by authentication on every request. Preview image URLs are unguessable and expire. Our internal controls are described in our Information Security Policy, available on request.
Your rights
If you are in the EEA or UK you have the right to access your personal data; to have it corrected or erased; to restrict or object to processing (including processing based on legitimate interests); to data portability; and to withdraw consent where processing is based on it. Exercise any of these by emailing georg@beyondwelcome.com — we respond within one month. You can also disconnect Klaviyo or delete your organization’s data at any time from your dashboard. If you believe we have handled your data improperly you may lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) or your local supervisory authority.
California residents
We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not process it for cross-context behavioural advertising. California residents may request to know, delete, or correct the personal information we hold, and will not be discriminated against for exercising those rights. Send requests to georg@beyondwelcome.com.
Changes
We’ll post updates here and adjust the “last updated” date. For material changes we notify account holders by email or on the dashboard before they take effect.