Privacy notice
Last updated 10 August 2026
Who this covers
QoreFlow is provided by [OWNER TO CONFIRM: legal name], company number [OWNER TO CONFIRM: company number], registered at [OWNER TO CONFIRM: registered address], United Kingdom. This notice explains how we handle personal data under the UK GDPR and the Data Protection Act 2018.
There are two distinct roles. For the people who hold QoreFlow accounts, we are the controller. For the business data an organisation connects and syncs into QoreFlow, we are a processor acting on that organisation's instructions; the organisation is the controller and decides what is connected and why.
Account data we hold as controller
We hold, for each person with an account:
- email address and password credential, held by our authentication provider;
- display name, and the organisation memberships and role that grant access;
- invitations you send or receive, including the invited email address and expiry;
- a record of metric queries run by your organisation, used to enforce plan allowances and, later, to meter billing.
Our lawful basis is performance of the contract to provide the service, and legitimate interests in keeping it secure and within its allowances.
Customer data we process as processor
When an organisation connects a business tool, we read the data the connection permits and store it in that organisation's rows in our database, then derive the customer, order and invoice records the dashboards report on. That data may include the names, email addresses and transaction records of the organisation's own customers.
We process it only to provide the service: syncing, storing, transforming and querying it for that organisation. We do not use it for our own purposes, do not sell it and do not use it to train models.
Isolation and security measures we have built
These are the controls in place today, not aspirations. Every table that holds customer data carries the organisation it belongs to, and row-level security in the database restricts each request to the organisations the signed-in user is a member of. Metrics are structured definitions rather than free-text queries: the query is assembled on our servers and always constrained to the requesting organisation, so there is no interface through which a customer can write their own SQL.
Credentials for connected third-party accounts are encrypted with AES-256-GCM before they are stored, using a key held only in our server environment. They are never sent to the browser and are not written to logs. Access to data in transit is over TLS.
What we store, and what we never store
QoreFlow stores:
- account details: email address, display name, organisation memberships and roles;
- connection metadata: which tool is connected, which account or property it points at, when it last ran and whether it failed;
- business figures synced from a connected tool, on the customer's instruction and only for the entities that tool exposes;
- usage and audit records: metric queries run, AI calls made, invites sent, emails sent, sync runs and platform-administration actions.
QoreFlow never stores:
- card or bank details. Billing is not live, so no payment data is collected or held anywhere in the service.
- passwords for a connected provider. Only the sealed access tokens or API keys the customer supplies are held, encrypted, and they are never shown back to the browser.
Subprocessors
We rely on the following, and no others, to run the service:
- Supabase - the database and authentication behind the service.
- Lovable - application hosting and serverless execution.
- Resend - sending transactional email, such as invitations and password resets.
- Amazon Web Services - the underlying infrastructure on which that database and hosting run.
A connected vendor, such as Xero or Google, processes data only when a customer chooses to connect it.
Each third-party tool an organisation chooses to connect is that organisation's own supplier, not ours. Data may be processed outside the UK by these providers, in which case we rely on the transfer safeguards they offer, including the UK international data transfer addendum.
How long we keep it
Retention is tied to the account. Synced and derived data stays while the connection and the organisation exist. When an owner deletes an organisation, its connections, stored credentials, landed and derived data, metric definitions, dashboards, memberships and invites are deleted permanently and immediately, and cannot be recovered. Removing a single connection removes its stored credentials with it.
Deleted data may persist briefly in encrypted infrastructure backups held by our hosting providers before those backups expire on their normal cycle.
Your rights
If you hold a QoreFlow account, you have the right to access, correct, delete or receive a copy of your personal data, to object to processing based on legitimate interests, and to complain to the Information Commissioner's Office. You can correct your display name in the app, and an owner can delete an entire organisation there.
If your personal data reached QoreFlow because an organisation connected a tool, that organisation is the controller: please raise your request with them and we will support them in answering it.
Cookies and similar storage
We use browser storage only to keep you signed in, to remember which organisation you are viewing and to remember your light or dark theme. We do not run advertising or cross-site tracking.
Contact
For any privacy question, or to exercise a right, email support@qoreflow.co, or write to us at the registered address above.