Privacy Policy
Effective: July 9, 2026 · This is a pre-launch draft, finalized after legal review.
MessageFlow (“we”) respects your privacy and processes personal data in accordance with applicable data protection laws, including the EU/UK GDPR where relevant. This policy explains what we collect, why, and your rights.
1. Data We Collect
| Category | Data | Source |
|---|---|---|
| Account | Email address, authentication identifier (Firebase UID) | You / Google sign-in |
| Business | Company name, contact, workspace | Onboarding |
| Service use | Connected device info, send/receive logs (recipient number, message content, time), campaign/entry data | Automatically/manually during use |
| Billing | Payment identifiers, transaction records | Payment processor (e.g., Stripe) |
2. Purposes & Legal Bases
- Providing the Service (account, device management, sending/receiving) — performance of a contract.
- Billing and subscription management — contract / legal obligation.
- Security, fraud prevention, service improvement — legitimate interests.
- Marketing communications, where applicable — consent (withdrawable at any time).
3. Roles (Controller / Processor)
For your account and billing data, we act as a controller. For message content and recipient data you process through the Service, you are the controller and we act as a processor acting on your instructions.
4. Sharing & Sub-processors
We do not sell personal data. We use sub-processors to deliver the Service:
| Sub-processor | Purpose |
|---|---|
| Google Cloud / Firebase | Hosting, authentication, data storage |
| PhoneSender | Message send/receive backbone |
| Stripe | Payment processing |
5. International Transfers
Data may be processed in countries other than yours. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses for transfers outside the EEA/UK.
6. Retention
We retain personal data only as long as necessary for the purposes above or as required by law, then delete or anonymize it. Billing and transaction records may be retained for statutory periods.
7. Your Rights
Subject to applicable law, you may request access, rectification, erasure, restriction, portability, and objection, and may withdraw consent at any time. You may also lodge a complaint with your local supervisory authority.
8. Security
- Encryption of sensitive secrets at rest (AES-256-GCM) and in transit (HTTPS/TLS).
- Least-privilege access controls and regular review.
9. Contact
- Data Protection Contact: (to be designated at launch)
- Email: privacy@messageflow.io
Controller
The Big Shot Co., Ltd. · Business Reg. No. 110-81-92150
Address 402, 20 Hakdong-ro 24-gil, Gangnam-gu, Seoul, Republic of Korea