Privacy Policy
This policy explains what ClientFlow collects, why we collect it, and the choices you have — including for text messaging.
Last updated: August 20, 2026
SMS / Text Messaging Privacy
No mobile information is shared with third parties or affiliates for marketing or promotional purposes. All categories of mobile information — including mobile phone numbers and SMS/text messaging consent and opt-in data — are excluded from all third-party sharing. ClientFlow does not sell, rent, lease, trade, or otherwise disclose mobile phone numbers or SMS opt-in data to any third party for that party's own marketing, promotional, or lead-generation purposes, under any circumstances, including in a merger, acquisition, or business transfer. Mobile numbers and SMS consent records are disclosed only to subprocessors that are strictly necessary to transmit the message you asked to receive (for example our telecommunications carrier and hosting provider), which act solely on our written instructions and are contractually barred from using the data for any purpose of their own. Text-message originators are the individual businesses that collected your consent; ClientFlow never uses their contacts, mobile numbers, or SMS consent records to market ClientFlow's own products.
Who we are
ClientFlow is a customer relationship management (CRM) platform for service businesses. Businesses ("Customers") use ClientFlow to manage leads, contacts, jobs and communications with their own customers ("End Users"). This policy covers information ClientFlow processes as a service provider on behalf of Customers, and information we collect directly from visitors and account holders.
Information we collect
- Account information: name, email address, business name, role and authentication identifiers.
- Mobile phone numbers: business phone numbers registered by a Customer, and End User mobile numbers stored in a Customer's workspace.
- SMS and call data: message content, timestamps, delivery status, direction, call events (such as missed or completed calls), and consent or opt-out records.
- CRM records: leads, contacts, companies, opportunities and activity history entered by a Customer.
- Technical data: IP address, browser type, device information and security logs used to operate and protect the service.
Mobile phone numbers and SMS data
Mobile phone numbers and SMS opt-in or consent data are never shared or sold to third parties for their own marketing purposes. No mobile information is shared with third parties or affiliates for marketing or promotional purposes.
Phone numbers and consent records are used solely to deliver the messaging features a Customer has configured and that the End User has agreed to receive. We share this information only with telecommunications and infrastructure providers strictly for the purpose of transmitting messages (for example, our messaging carrier), and only to the extent required to deliver the service. Those providers are contractually prohibited from using the data for their own marketing.
How SMS consent is collected and used
- Consent is collected by the Customer directly from the End User, through a clearly labelled opt-in checkbox, a written agreement, or another documented affirmative action.
- Opt-in is never pre-checked, bundled with unrelated terms, or a condition of purchase.
- Each consent event is recorded with the phone number, the channel, the status (granted or revoked), the source of the opt-in and the time it was recorded.
- Consent is used only to send the message categories disclosed at the time of opt-in, and it is scoped to the specific business that collected it.
- Replying STOP records a revocation immediately and blocks all further non-required messages to that number.
Message frequency, rates, STOP and HELP
- Message frequency varies and depends on your interaction with the business messaging you — for example replies to your enquiry, appointment reminders or job updates. Recurring programs typically send up to a small number of messages per month, and the sending business discloses the expected frequency at opt-in.
- Message and data rates may apply. Your mobile carrier's standard messaging and data charges apply to messages you send and receive.
- To opt out, reply STOP to any message. You will receive a single confirmation, and no further messages will be sent to that number by that business.
- For help, reply HELP to any message, or contact the business directly. You may also email support@clientflow.app.
- Carriers are not liable for delayed or undelivered messages.
How we use information
- To provide, secure and support the ClientFlow service.
- To deliver messages and calls a Customer initiates and an End User has consented to receive.
- To enforce compliance controls such as suppression lists, quiet hours and sending limits.
- To maintain audit logs for security, dispute resolution and legal compliance.
- To communicate with account holders about their account, billing and service changes.
We do not sell personal information, and we do not use End User data for our own advertising.
How we share information
- Service providers: hosting, database, telephony and email providers acting under contract and on our instructions.
- With the Customer whose workspace the data belongs to.
- Legal: where required by law, subpoena or to protect the rights and safety of users and the public.
- Business transfers: in a merger or acquisition, subject to this policy — mobile phone numbers and SMS/text messaging consent and opt-in data are explicitly excluded from any such transfer for marketing or promotional purposes, and any successor remains bound by this policy.
- We do not share mobile numbers or SMS opt-in data with anyone for their own marketing.
Data security
- All data is transmitted over encrypted connections (TLS) and encrypted at rest by our infrastructure provider.
- Every workspace is isolated with row-level security so one business can never read another business's records.
- Provider credentials and API tokens are stored as server-side secrets and are never exposed to the browser.
- Inbound webhooks are signature-verified and processed idempotently to prevent spoofing and replay.
- Access to production data is limited to personnel who need it, and administrative actions are recorded in audit logs.
Data retention
We retain workspace data for as long as the Customer's account is active, and afterwards only as needed for legal, tax or dispute-resolution purposes. Opt-out and suppression records are retained indefinitely so we can continue to honour a revocation.
Your choices and rights
- Opt out of SMS at any time by replying STOP.
- Request access to, correction of, or deletion of your personal information.
- Request that we restrict or object to certain processing, where applicable law provides that right.
- End Users should contact the business they interacted with first; ClientFlow will assist that business in responding.
Children's privacy
ClientFlow is not directed to children under 13 and we do not knowingly collect their information.
International users
Data may be processed in the United States and other countries where our providers operate. Appropriate safeguards are used for cross-border transfers where required.
Changes to this policy
We may update this policy. Material changes will be announced in the product or by email, and the "last updated" date above will change.