Legal
Privacy Policy
Last updated: 2026-07-25 · Cookie notice version: 2026-07-25-a
This Privacy Policy explains how FLOWMAN LLC ("we," "us," or "our") collects, uses, shares, and protects personal information in connection with TradingFlow and related services. It is designed to meet transparency expectations under the EU General Data Protection Regulation (GDPR) and related laws where they apply.
1. Scope
This Policy covers personal information processed when you:
- Visit our marketing website at tradingflow.com (including blogs, learn content, glossary, and legal pages);
- Use the TradingFlow application at app.tradingflow.com (accounts, market data tools, billing);
- Communicate with us (email, support, sales) about the Services.
Some practices differ between the marketing website and the product app—see Website vs product.
2. Data controller
The controller of personal data described in this Policy is:
FLOWMAN LLC
Product: TradingFlow
Websites: https://tradingflow.com · https://app.tradingflow.com
Privacy: privacy@tradingflow.com
Support: support@tradingflow.com
EU representative (GDPR Art. 27). We are a US-based company without an establishment in the European Economic Area disclosed in this Policy. Whether an EU representative is legally required depends on the nature and scale of our offering to individuals in the EEA. If we appoint a representative, we will update this section. Until then, EEA data subjects may contact us at privacy@tradingflow.com.
3. Website vs product (important split)
| Topic | Marketing website (tradingflow.com) | Product app (app.tradingflow.com) |
|---|---|---|
| Primary data | Browse logs, cookie preferences, optional analytics events, content engagement | Account identity, authentication, billing, product usage, configuration, support tickets |
| Cookies / SDK | Banner + inventory below; analytics only after opt-in | Auth/session cookies and product telemetry governed by app flows and vendor contracts (e.g. authentication provider) |
| Legal bases | Legitimate interests / consent (analytics cookies) | Contract performance, legitimate interests, legal obligation, consent where required |
This static marketing site implements the cookie banner and inventory described here. The authenticated product may use additional processors (hosting, auth, payments) under separate agreements; contact us for an up-to-date processor list for your account region.
4. Categories of personal data
- Identity & contact — name, email, and similar details when you create an account, subscribe, or contact us.
- Account & billing — authentication identifiers, plan status, invoices; payment card data is handled by payment processors and not stored in full by us.
- Usage & device — IP address, user agent, pages viewed, timestamps, referrers, approximate location derived from IP, cookie/device IDs (analytics only with consent on the marketing site).
- Communications — content of support or sales messages and related metadata.
- Market / trading configuration — symbols, filters, and other settings you configure in the product (you are responsible for lawful use of any data you upload).
5. Purposes and legal bases (GDPR)
Where GDPR applies, we process personal data only under one or more of the following bases (Art. 6):
| Purpose | Examples | Legal basis |
|---|---|---|
| Provide the Services | Account, product features, customer support | Contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) for site security and basic operation |
| Billing & fraud prevention | Subscriptions, abuse detection | Contract; legal obligation; legitimate interests |
| Marketing-site analytics | Google Analytics, PostHog (if you opt in) | Consent (Art. 6(1)(a)); ePrivacy terminal storage consent |
| Product improvement & security | Logs, reliability metrics (app context) | Legitimate interests; contract where needed to provide service |
| Marketing communications | Product updates you opt into | Consent and/or soft opt-in where permitted; withdraw anytime |
| Legal compliance | Tax, law-enforcement requests, disputes | Legal obligation (Art. 6(1)(c)); legitimate interests |
We do not use marketing-site analytics for automated decisions that produce legal or similarly significant effects (GDPR Art. 22).
6. Cookies and similar technologies (marketing website)
Under the ePrivacy rules (as implemented in EU/EEA Member States) and GDPR, we:
- Use strictly necessary storage without consent (security, load the site, remember cookie choice, theme, language).
- Load analytics scripts and initialise analytics SDKs only after you allow analytics in our cookie banner (or later via Cookie settings).
- Let you reject non-essential cookies with equal prominence and still use the site.
- Let you withdraw analytics consent via footer Cookie settings; we then stop collection and clear known analytics cookies/storage keys where technically feasible.
Consent records stored in your browser include decision time, policy version (2026-07-25), notice version (2026-07-25-a), locale, and choice (schema v2). You can export that record from Cookie settings. We do not operate a full server-side CMP audit log on this static site; for enterprise audit requirements contact privacy@tradingflow.com.
6.1 Cookie and storage inventory
| Name / pattern | Provider | Purpose | Category | Type | Duration | Consent |
|---|---|---|---|---|---|---|
| tf_cookie_consent | TradingFlow (first-party) | Stores your cookie preference (analytics allowed / rejected), policy/notice versions, locale, and timestamp (Art. 7 demonstrability aid). | necessary | HTTP cookie + localStorage | 1 year | Not required |
| theme | TradingFlow (first-party, next-themes) | Remembers light / dark / system appearance preference. | necessary | localStorage | Until cleared | Not required |
| tradingflow-language | TradingFlow (first-party) | Remembers UI language (en / zh) when multi-language is enabled. | necessary | localStorage | Until cleared | Not required |
| browser-warning-dismissed | TradingFlow (first-party) | Remembers dismissal of the outdated-browser warning. | necessary | localStorage | Until cleared | Not required |
| tradingflow-recent-searches | TradingFlow (first-party) | Recent site-search queries for convenience in the search modal. | necessary | localStorage | Until cleared | Not required |
| _ga, _ga_*, _gid, _gat, _gat_* | Google Analytics (Google Ireland / Google LLC) | Audience measurement: distinguish visitors, sessions, and traffic sources. | analytics | HTTP cookie | Up to 2 years (_ga); shorter for _gid / _gat (vendor defaults) | Required |
| ph_*, phc_*, posthog-related keys | PostHog | Product analytics: page views, events, and (when enabled) distinct IDs. | analytics | HTTP cookie + localStorage | Vendor default (often up to 1 year for identity keys) | Required |
7. Recipients and international transfers
We do not sell personal information. We share data with processors and service providers who assist us under contracts, and as needed for legal, safety, or corporate transactions.
7.1 Marketing-site analytics processors (consent-based)
Google LLC / Google Ireland Limited (Google Analytics 4)
Role: processor
Purpose: Website audience measurement and traffic analytics after consent.
Data: Online identifiers (cookie IDs), IP-derived location (when collected), device/browser metadata, page URLs, referrers, approximate engagement metrics.
Location: EEA (Google Ireland) and/or United States (Google LLC) and other Google processing locations.
Transfer tools: EU–US Data Privacy Framework (where vendor certified); EU Standard Contractual Clauses (SCCs)
Google publishes EU–US Data Privacy Framework participation for relevant entities and SCCs/processor terms for Google Ads Data Processing Terms. Confirm active certification and your GA configuration (e.g. IP anonymization, Consent Mode) in Google Admin. We load GA only after analytics consent.
PostHog Inc. (PostHog product analytics)
Role: processor
Purpose: Product and website event analytics after consent.
Data: Online identifiers, event names, page paths, UTM/referrer, device metadata; may include distinct IDs used for product funnels.
Location: United States (PostHog Cloud US) and/or European Union (PostHog Cloud EU / Frankfurt) depending on project host configuration.
Transfer tools: EU–US Data Privacy Framework (where vendor certified); EU Standard Contractual Clauses (SCCs); EU region hosting (when configured)
PostHog offers Cloud EU (Frankfurt) to keep event data in the EU, and a DPA generator including DPF + SCCs for US processing. Prefer EU hosting for EU traffic where operationally feasible. We initialise PostHog only after analytics consent.
Where personal data is transferred to the United States or other third countries, we rely on appropriate safeguards under GDPR Chapter V—typically the EU–US Data Privacy Framework (for certified importers) and/or the European Commission's Standard Contractual Clauses (SCCs), as provided in the vendor's DPA. Operators must execute and maintain those vendor DPAs outside this website repository.
Other product processors (cloud hosting, authentication, payments, email) may process account data. Contact privacy@tradingflow.com for a current list relevant to your use of the Services.
8. Retention
- Cookie consent record — up to 1 year in the browser (then re-prompted), or until you clear site data.
- Analytics events — retained according to Google Analytics and PostHog project settings (often months to 14+ months; configurable in vendor admin). After withdrawal we stop new collection; historical vendor deletion may require a rights request.
- Account data — for the life of the account plus a limited period for backups, disputes, and legal obligations.
- Support communications — as long as needed to resolve issues and maintain business records.
9. Security
We implement technical and organizational measures appropriate to the risk (access controls, encryption in transit, least privilege, vendor diligence). No method of transmission or storage is completely secure.
10. Your rights (including GDPR)
Depending on your location, you may have the right to:
- Access your personal data and obtain a copy;
- Rectify inaccurate data;
- Erase data ("right to be forgotten"), subject to exceptions;
- Restrict or object to certain processing (including legitimate interests);
- Data portability (where processing is based on consent or contract and is automated);
- Withdraw consent at any time (without affecting prior lawful processing);
- Not be subject to solely automated decisions with legal or similarly significant effects (we do not engage in such decision-making on the marketing site);
- Lodge a complaint with a supervisory authority—in particular in your EU/EEA Member State of residence, place of work, or place of the alleged infringement. A list of EEA authorities is published by the European Data Protection Board (edpb.europa.eu).
To exercise rights, email privacy@tradingflow.com. We may need to verify your identity. Cookie analytics preferences can also be changed via the site footer Cookie settings control (and you can export your browser consent record from Manage preferences).
11. Children
The Services are directed to adults and business users. We do not knowingly collect personal data from children. Where GDPR information-society consent rules for children apply, the relevant age is generally 16 (or lower if a Member State set 13–15). If you believe a child provided us data, contact privacy@tradingflow.com.
12. Changes
We may update this Policy when our practices or the law change. We will revise the "Last updated" date above. Material changes may also be highlighted on the website or by email where appropriate. Cookie notice version 2026-07-25-a is stored with browser consent records so we can show when preferences were captured against which notice text.
13. Contact
FLOWMAN LLC
Attn: Privacy
Email: privacy@tradingflow.com (preferred for data-subject requests)
Support: support@tradingflow.com