← Back

Privacy Policy

Last updated: June 30, 2026

1. Who we are

OnboardFlow (“we”, “us”), operated by Flow Systems Solution LLC, provides an employee onboarding and training platform. This policy explains what personal data we collect and how we handle it.

2. What we collect

  • Account data: name and email address of admins and employees.
  • Onboarding data: module progress, quiz scores, and completion records.
  • Certification documents: files (PDFs/images) that employees upload to record certifications, and their expiry dates.
  • Billing data: handled by our payment processor; we do not store full card details.

We do not intentionally collect sensitive categories of data (such as government ID numbers, health, or biometric data).

3. How we use it

To provide the Service: create accounts, deliver onboarding, track progress and certifications, send notifications (invites, reminders, completion alerts), and process payments.

4. Where it's stored & who processes it

Data is hosted in the United States. We use the following sub-processors to operate the Service:

  • Supabase — database, authentication, and file storage
  • Netlify — application hosting
  • Resend — transactional email delivery
  • Stripe — subscription billing
  • Anthropic (Claude) — AI generation of quiz questions from lesson content. Anthropic does not train its models on data submitted via its API.

5. Security

Data is encrypted in transit (HTTPS) and access is isolated per company. Passwords are stored hashed. Uploaded files are kept in private storage and served only via short-lived signed links.

6. Your rights

Depending on your location (including under GDPR, LGPD, and CCPA), you may have the right to access, correct, export, or delete your personal data. To make a request, contact us at support@flowsystemssolution.com. Admins can also edit or delete employee records directly in the app.

7. Your U.S. state privacy rights

If you are a resident of California, Virginia, Colorado, Connecticut, Utah, Texas, or another U.S. state with a comprehensive consumer privacy law, you may have some or all of the following rights regarding your personal information:

  • Know / access the personal information we hold about you.
  • Correct inaccurate personal information.
  • Delete your personal information.
  • Obtain a portable copy of your personal information.
  • Opt out of the “sale” or “sharing” of personal information and of targeted advertising and profiling.
  • Non-discrimination for exercising any of these rights.

We do not sell your personal information, and we do not share or process it for cross-context behavioral or targeted advertising.

Most personal data in OnboardFlow about an employee is provided and controlled by their employer (our business customer), for whom we act as a service provider / processor. If you are an employee, please direct privacy requests to your employer; we will assist them in responding. Company admins can also access, edit, export, or delete employee records directly in the app.

To exercise your rights, contact us at support@flowsystemssolution.com. We will verify your identity before responding and will respond within the timeframe required by applicable law. If we deny your request, you may appeal by replying to our response; where required (for example, in Virginia and Colorado) we will also tell you how to raise concerns with your state attorney general.

California (CCPA/CPRA): in the preceding 12 months we collect the categories described in Section 2 (identifiers, professional/employment information, and internet activity such as usage data) for the business purposes described in Section 3. We do not sell or share personal information as those terms are defined under the CCPA.

8. Retention

We keep personal data for as long as an account is active. On account closure, data may be deleted or anonymized on request, subject to legal retention requirements.

9. Contact

Privacy questions or requests: support@flowsystemssolution.com.