1. Scope and roles
This policy applies to the AssetsFlow website, accounts, workspaces, projects, project email, assets, public review and delivery pages, billing, and support. AssetsFlow generally decides how account, billing, security, and service-operation data is processed. For client files, contacts, messages, reviewers, and delivery recipients supplied by a workspace, the workspace customer generally decides why that data is used and AssetsFlow processes it to provide the service.
Third-party websites and provider pages, including OAuth and hosted checkout pages, use their own privacy policies.
2. Data collected directly and indirectly
We receive data directly from account holders, workspace administrators, client contacts, reviewers, delivery recipients, support requesters, and people who send or receive project email. We also receive technical and transaction data from sign-in, payment, email, storage, infrastructure, and analytics providers.
- Account and workspace data: name, email, avatar, locale, invitations, roles, permissions, sessions, and security events.
- Project and client data: client contacts, project names and settings, messages, email addresses, files, attachments, comments, review decisions, delivery acceptance, and confirmed project context.
- Asset and AI data: uploaded content, filenames, metadata, prompts, instructions, inputs, outputs, versions, processing status, and error information.
- Billing data: customer, checkout, subscription, invoice, payment, tax, credit-ledger, refund, and dispute identifiers and status. Full card numbers are handled by the payment provider rather than stored by AssetsFlow.
- Technical and link data: IP address or derived IP hash, user agent, timestamps, referrer, approximate country/region/city, link events, bandwidth, request status, and diagnostic logs.
3. Purposes and legal bases
We use data to create accounts; provide projects, email, storage, previews, reviews, delivery, memory, AI and billing; authenticate users; enforce permissions and plan limits; prevent abuse; diagnose failures; support customers; maintain accounting and legal records; and improve product reliability.
When a customer requests troubleshooting, authorized AssetsFlow personnel may use a time-limited, read-only support session to view the selected workspace as the affected user would. Support sessions are restricted to that workspace; block changes, messages, downloads, generation, and payment actions; record their start and expiry in the workspace; and add an end record when the session is explicitly exited. The internal troubleshooting reason is retained only in the platform administration audit.
Necessary reliability monitoring may receive a pseudonymous internal user and workspace identifier, deployment environment, release, sanitized route template, support reference, request identifier, browser runtime details, and a scrubbed exception stack. We do not intentionally send project or customer content, filenames, prompts, messages, email addresses, access tokens, page views, clicks, or session recordings through this error-diagnostic path.
Depending on location and context, processing is based on performance of a contract, steps requested before a contract, consent, compliance with law, protection of legal rights, or legitimate interests such as security and reliable operation. Optional analytics is used only after consent where the consent banner is available.
4. Taiwan personal data notice
For purposes of Taiwan's Personal Data Protection Act, the collecting entity is the operator of AssetsFlow. Collection purposes include account and membership administration, contracts and customer management, information and database management, payment and accounting, security, support, product operation, marketing measurement with consent, and legal compliance.
Data categories include identifying information, contact information, online identifiers, account and transaction data, employment or organization relationship supplied by users, project communications, files, opinions and decisions, and technical usage records. Data may be used for the service period and afterwards as needed for legal, accounting, dispute, security, backup, and operational purposes; in locations where AssetsFlow and its processors operate; by AssetsFlow, authorized workspace members and recipients, and the processors described in this policy.
You may request inquiry, review, a copy, supplementation, correction, cessation of collection/processing/use, or deletion as allowed by law. Refusing required account, security, billing, or project data may prevent us from providing the relevant service. Optional analytics can be refused without losing core service access.
5. Sharing and processors
Data is shared only as needed with authorized workspace members and invited recipients; sign-in, payment, infrastructure, database, storage, file-delivery, email, AI, monitoring, and support providers; professional advisers; authorities when legally required; and a successor in a legitimate business transaction subject to appropriate protections.
The Third-party Data Processing page describes the service categories in which providers may process data. A current named list is available to customers and prospective business customers through an applicable DPA, procurement review, or legitimate privacy request. We do not sell personal data. We do not share personal data for cross-context behavioral advertising.
6. International transfers
AssetsFlow and its providers may process data outside your country, including in the United States and other locations where providers operate. Those locations may have different privacy laws. We use provider contracts, access controls, and other available safeguards appropriate to the service and transfer context.
7. Retention and deletion reality
Account and workspace data is kept while the service is active and may remain afterwards for account recovery, security, disputes, legal obligations, billing reconciliation, backups, and reliable operation. Payment and accounting records may be kept for statutory periods. Public-link analytics may be displayed using plan-specific reporting windows, but a display window is not an automatic deletion schedule.
AssetsFlow does not currently promise automatic hard deletion after a fixed number of days or zero-data-retention processing. Deletion requests are reviewed manually. Data can remain in backups, logs, derived security records, or records we must retain, and will be removed or isolated according to operational cycles and applicable law.
8. Security, choices, and requests
We use authentication, scoped authorization, private object storage, controlled public links, secret management, audit records, and operational monitoring appropriate to the current service. No internet service is completely secure.
Use the cookie settings to change optional analytics consent. For access, correction, deletion, restriction, export, or objection requests, email [email protected]. We may verify identity, authority, workspace ownership, and legal constraints before acting.
9. Children, changes, and contact
AssetsFlow is intended for business users and is not directed to children. Do not provide children's personal data unless you have a lawful business purpose and all required authority.
We may update this policy and will show the new version and effective date. Privacy questions and complaints can be sent to [email protected].