Last updated: March 19, 2026
AgenciesFlow ("we," "us," or "our") operates the AgenciesFlow platform, a SaaS tool for agencies to capture and manage leads and client onboarding. Our contact email is support@agenciesflow.com.
We collect data in two ways:
We do not sell your data to third parties, use it for advertising, or share it with anyone except the sub-processors listed below.
Under the General Data Protection Regulation, we rely on the following legal bases:
Where we act as a data processor on your behalf (processing lead and contact data submitted through your intake forms), you are the data controller and are responsible for ensuring a valid legal basis for that processing.
Lead messages submitted through your intake form are sent to OpenAI's API for enrichment (scoring, summarising, generating follow-up questions). OpenAI processes this data as a data processor under their API Data Usage Policy. We do not use your data to train AI models.
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Auth, database hosting | EU / US |
| OpenAI | AI lead enrichment | US |
| Resend | Transactional email | US |
| Paddle | Billing and payments | US |
| Railway | API and worker hosting | US |
| Vercel | Frontend hosting | Global CDN |
| Sentry | Error monitoring (optional) | US |
Your account and lead data is retained for as long as your account is active. If you cancel and request account deletion, we will delete your data within 30 days, except where we are required to retain it for legal or billing purposes.
Depending on your location, you may have the right to:
To exercise any of these rights, email support@agenciesflow.com. We will respond within 30 days.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
To exercise these rights, email support@agenciesflow.com with the subject line "CCPA Request." We will verify your identity and respond within 45 days.
In the preceding 12 months, we have collected the categories of personal information described in Section 2 above. We have not sold personal information to third parties.
AgenciesFlow uses only essential cookies required for authentication (Supabase session token). We do not use tracking cookies, advertising cookies, or third-party analytics cookies. No cookie banner is required.
All data is transmitted over HTTPS. Passwords are managed by Supabase Auth and are never stored by AgenciesFlow. We use HMAC-SHA256 to verify webhook payloads. Access to production systems is restricted to authorised personnel.
AgenciesFlow is a business tool not intended for use by anyone under the age of 18. We do not knowingly collect data from minors.
We may update this policy from time to time. Material changes will be communicated by email or an in-app notice. Continued use of the platform after the effective date constitutes acceptance.
For any privacy questions, email support@agenciesflow.com.