Privacy Policy
Last updated: June 2026
TeamFlow ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the TeamFlow mobile application and website.
1. Information We Collect
We collect information you provide directly to us, such as:
- Account information: name, email address, and PIN
- Organisation information: company name, industry, and type
- Work data: hours worked, check-in/out times, distance driven, vehicle type, work location, and notes
- Schedule data: shift assignments and schedule information
- Device information: device token for push notifications
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the TeamFlow service
- Process timesheet entries and generate reports
- Send schedule notifications and shift updates
- Process payments through our payment provider (Stripe)
- Communicate with you about your account and our services
- Comply with legal obligations
3. Data Storage and Security
Your data is stored securely using Google Firebase infrastructure in the European Union (europe-west1 region). We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction.
Passwords are stored as hashed credentials through Firebase Authentication. We do not store plain-text passwords.
4. Payment Information
Payment processing is handled by Stripe. We do not store your credit card details on our servers. All payment information is processed and stored securely by Stripe in accordance with PCI DSS standards. Please review Stripe's privacy policy at stripe.com/privacy.
5. Data Sharing
We do not sell, trade, or rent your personal information to third parties. We may share your information with:
- Service providers: Google Firebase (cloud infrastructure), Stripe (payments)
- Within your organisation: Employers can view employee timesheet data for their organisation
- Legal requirements: When required by law or to protect our rights
6. Your Rights (GDPR)
If you are located in the European Economic Area, you have the following rights regarding your personal data:
- Right of access: You may request a copy of your personal data
- Right to rectification: You may request correction of inaccurate data
- Right to erasure: You may request deletion of your account and data via the app's Settings screen
- Right to data portability: You may request your data in a portable format
- Right to object: You may object to processing of your personal data
To exercise these rights, contact us at teamflowwms@gmail.com.
7. Data Retention
We retain your personal data for as long as your account is active or as needed to provide services. When you delete your account through the app, your personal data is removed from our systems within 30 days. Timesheet and work records may be retained for up to 7 years to comply with labour law requirements, unless you request earlier deletion.
8. Push Notifications
We use Firebase Cloud Messaging to send push notifications about schedule updates and shift changes. You can disable push notifications at any time through your device settings.
9. Children's Privacy
TeamFlow is not directed at individuals under the age of 16. We do not knowingly collect personal information from children under 16. If you become aware that a child has provided us with personal information, please contact us.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically.
11. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at: