Skip to main content

Legal

Privacy Policy

Last updated: 2026-07-25 · Cookie notice version: 2026-07-25-a

This Privacy Policy explains how FLOWMAN LLC ("we," "us," or "our") collects, uses, shares, and protects personal information in connection with TradingFlow and related services. It is designed to meet transparency expectations under the EU General Data Protection Regulation (GDPR) and related laws where they apply.

1. Scope

This Policy covers personal information processed when you:

  • Visit our marketing website at tradingflow.com (including blogs, learn content, glossary, and legal pages);
  • Use the TradingFlow application at app.tradingflow.com (accounts, market data tools, billing);
  • Communicate with us (email, support, sales) about the Services.

Some practices differ between the marketing website and the product app—see Website vs product.

2. Data controller

The controller of personal data described in this Policy is:

FLOWMAN LLC
Product: TradingFlow
Websites: https://tradingflow.com · https://app.tradingflow.com
Privacy: privacy@tradingflow.com
Support: support@tradingflow.com

EU representative (GDPR Art. 27). We are a US-based company without an establishment in the European Economic Area disclosed in this Policy. Whether an EU representative is legally required depends on the nature and scale of our offering to individuals in the EEA. If we appoint a representative, we will update this section. Until then, EEA data subjects may contact us at privacy@tradingflow.com.

3. Website vs product (important split)

TopicMarketing website (tradingflow.com)Product app (app.tradingflow.com)
Primary dataBrowse logs, cookie preferences, optional analytics events, content engagementAccount identity, authentication, billing, product usage, configuration, support tickets
Cookies / SDKBanner + inventory below; analytics only after opt-inAuth/session cookies and product telemetry governed by app flows and vendor contracts (e.g. authentication provider)
Legal basesLegitimate interests / consent (analytics cookies)Contract performance, legitimate interests, legal obligation, consent where required

This static marketing site implements the cookie banner and inventory described here. The authenticated product may use additional processors (hosting, auth, payments) under separate agreements; contact us for an up-to-date processor list for your account region.

4. Categories of personal data

  • Identity & contact — name, email, and similar details when you create an account, subscribe, or contact us.
  • Account & billing — authentication identifiers, plan status, invoices; payment card data is handled by payment processors and not stored in full by us.
  • Usage & device — IP address, user agent, pages viewed, timestamps, referrers, approximate location derived from IP, cookie/device IDs (analytics only with consent on the marketing site).
  • Communications — content of support or sales messages and related metadata.
  • Market / trading configuration — symbols, filters, and other settings you configure in the product (you are responsible for lawful use of any data you upload).

5. Purposes and legal bases (GDPR)

Where GDPR applies, we process personal data only under one or more of the following bases (Art. 6):

PurposeExamplesLegal basis
Provide the ServicesAccount, product features, customer supportContract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) for site security and basic operation
Billing & fraud preventionSubscriptions, abuse detectionContract; legal obligation; legitimate interests
Marketing-site analyticsGoogle Analytics, PostHog (if you opt in)Consent (Art. 6(1)(a)); ePrivacy terminal storage consent
Product improvement & securityLogs, reliability metrics (app context)Legitimate interests; contract where needed to provide service
Marketing communicationsProduct updates you opt intoConsent and/or soft opt-in where permitted; withdraw anytime
Legal complianceTax, law-enforcement requests, disputesLegal obligation (Art. 6(1)(c)); legitimate interests

We do not use marketing-site analytics for automated decisions that produce legal or similarly significant effects (GDPR Art. 22).

6. Cookies and similar technologies (marketing website)

Under the ePrivacy rules (as implemented in EU/EEA Member States) and GDPR, we:

  • Use strictly necessary storage without consent (security, load the site, remember cookie choice, theme, language).
  • Load analytics scripts and initialise analytics SDKs only after you allow analytics in our cookie banner (or later via Cookie settings).
  • Let you reject non-essential cookies with equal prominence and still use the site.
  • Let you withdraw analytics consent via footer Cookie settings; we then stop collection and clear known analytics cookies/storage keys where technically feasible.

Consent records stored in your browser include decision time, policy version (2026-07-25), notice version (2026-07-25-a), locale, and choice (schema v2). You can export that record from Cookie settings. We do not operate a full server-side CMP audit log on this static site; for enterprise audit requirements contact privacy@tradingflow.com.

Name / patternProviderPurposeCategoryTypeDurationConsent
tf_cookie_consentTradingFlow (first-party)Stores your cookie preference (analytics allowed / rejected), policy/notice versions, locale, and timestamp (Art. 7 demonstrability aid).necessaryHTTP cookie + localStorage1 yearNot required
themeTradingFlow (first-party, next-themes)Remembers light / dark / system appearance preference.necessarylocalStorageUntil clearedNot required
tradingflow-languageTradingFlow (first-party)Remembers UI language (en / zh) when multi-language is enabled.necessarylocalStorageUntil clearedNot required
browser-warning-dismissedTradingFlow (first-party)Remembers dismissal of the outdated-browser warning.necessarylocalStorageUntil clearedNot required
tradingflow-recent-searchesTradingFlow (first-party)Recent site-search queries for convenience in the search modal.necessarylocalStorageUntil clearedNot required
_ga, _ga_*, _gid, _gat, _gat_*Google Analytics (Google Ireland / Google LLC)Audience measurement: distinguish visitors, sessions, and traffic sources.analyticsHTTP cookieUp to 2 years (_ga); shorter for _gid / _gat (vendor defaults)Required
ph_*, phc_*, posthog-related keysPostHogProduct analytics: page views, events, and (when enabled) distinct IDs.analyticsHTTP cookie + localStorageVendor default (often up to 1 year for identity keys)Required

7. Recipients and international transfers

We do not sell personal information. We share data with processors and service providers who assist us under contracts, and as needed for legal, safety, or corporate transactions.

7.1 Marketing-site analytics processors (consent-based)

Google LLC / Google Ireland Limited (Google Analytics 4)

Role: processor

Purpose: Website audience measurement and traffic analytics after consent.

Data: Online identifiers (cookie IDs), IP-derived location (when collected), device/browser metadata, page URLs, referrers, approximate engagement metrics.

Location: EEA (Google Ireland) and/or United States (Google LLC) and other Google processing locations.

Transfer tools: EU–US Data Privacy Framework (where vendor certified); EU Standard Contractual Clauses (SCCs)

Google publishes EU–US Data Privacy Framework participation for relevant entities and SCCs/processor terms for Google Ads Data Processing Terms. Confirm active certification and your GA configuration (e.g. IP anonymization, Consent Mode) in Google Admin. We load GA only after analytics consent.

Privacy noticeDPA / processor terms

PostHog Inc. (PostHog product analytics)

Role: processor

Purpose: Product and website event analytics after consent.

Data: Online identifiers, event names, page paths, UTM/referrer, device metadata; may include distinct IDs used for product funnels.

Location: United States (PostHog Cloud US) and/or European Union (PostHog Cloud EU / Frankfurt) depending on project host configuration.

Transfer tools: EU–US Data Privacy Framework (where vendor certified); EU Standard Contractual Clauses (SCCs); EU region hosting (when configured)

PostHog offers Cloud EU (Frankfurt) to keep event data in the EU, and a DPA generator including DPF + SCCs for US processing. Prefer EU hosting for EU traffic where operationally feasible. We initialise PostHog only after analytics consent.

Privacy noticeDPA / processor terms

Where personal data is transferred to the United States or other third countries, we rely on appropriate safeguards under GDPR Chapter V—typically the EU–US Data Privacy Framework (for certified importers) and/or the European Commission's Standard Contractual Clauses (SCCs), as provided in the vendor's DPA. Operators must execute and maintain those vendor DPAs outside this website repository.

Other product processors (cloud hosting, authentication, payments, email) may process account data. Contact privacy@tradingflow.com for a current list relevant to your use of the Services.

8. Retention

  • Cookie consent record — up to 1 year in the browser (then re-prompted), or until you clear site data.
  • Analytics events — retained according to Google Analytics and PostHog project settings (often months to 14+ months; configurable in vendor admin). After withdrawal we stop new collection; historical vendor deletion may require a rights request.
  • Account data — for the life of the account plus a limited period for backups, disputes, and legal obligations.
  • Support communications — as long as needed to resolve issues and maintain business records.

9. Security

We implement technical and organizational measures appropriate to the risk (access controls, encryption in transit, least privilege, vendor diligence). No method of transmission or storage is completely secure.

10. Your rights (including GDPR)

Depending on your location, you may have the right to:

  • Access your personal data and obtain a copy;
  • Rectify inaccurate data;
  • Erase data ("right to be forgotten"), subject to exceptions;
  • Restrict or object to certain processing (including legitimate interests);
  • Data portability (where processing is based on consent or contract and is automated);
  • Withdraw consent at any time (without affecting prior lawful processing);
  • Not be subject to solely automated decisions with legal or similarly significant effects (we do not engage in such decision-making on the marketing site);
  • Lodge a complaint with a supervisory authority—in particular in your EU/EEA Member State of residence, place of work, or place of the alleged infringement. A list of EEA authorities is published by the European Data Protection Board (edpb.europa.eu).

To exercise rights, email privacy@tradingflow.com. We may need to verify your identity. Cookie analytics preferences can also be changed via the site footer Cookie settings control (and you can export your browser consent record from Manage preferences).

11. Children

The Services are directed to adults and business users. We do not knowingly collect personal data from children. Where GDPR information-society consent rules for children apply, the relevant age is generally 16 (or lower if a Member State set 13–15). If you believe a child provided us data, contact privacy@tradingflow.com.

12. Changes

We may update this Policy when our practices or the law change. We will revise the "Last updated" date above. Material changes may also be highlighted on the website or by email where appropriate. Cookie notice version 2026-07-25-a is stored with browser consent records so we can show when preferences were captured against which notice text.

13. Contact

FLOWMAN LLC
Attn: Privacy
Email: privacy@tradingflow.com (preferred for data-subject requests)
Support: support@tradingflow.com