Home How It Works Pricing Login
EN TR AR

Privacy Policy

Last updated: 2026-04-18 | Version 1.0.3

Your privacy is important to us. It is the policy of propflow.tech ("Propflow") to respect your privacy regarding any information we may collect from you across our website and application. In the event of any discrepancy between the English version of this policy and any translated version, the English version shall prevail.

1. Information We Collect

We collect information you provide directly to us, such as when you create an account, connect social media profiles, or contact customer support. This primarily includes:

  • Contact information (email, phone)
  • Profile data (Company name)
  • OAuth Access Tokens for connected platforms

2. How We Use Your Data

We use the information we collect to operate and improve our Services, specifically to:

  • Publish content to your connected social media accounts (Facebook, Instagram, TikTok, YouTube, WhatsApp)
  • Automate interactions and process messaging data for AI auto-replies (e.g., TikTok Business Messaging)
  • Provide customer support
  • Analyze usage trends (anonymized)
  • Process transactions and send related information, including confirmations and invoices

3. Payment Information

Propflow does not store your credit card or payment instrument details on our servers. All payments are securely processed by Paddle.com (our Merchant of Record), who handles all transactions, billing, and refund management on our behalf. We only share necessary transaction data (such as your User ID and selected plan) with Paddle to facilitate your purchase. Please note that as our Merchant of Record, Paddle is legally required to retain financial transaction records for tax compliance and auditing purposes for a minimum of 5 years.

4. OAuth Data & Security

When you connect a third-party account (e.g., via Google/YouTube API Services), we store standard access tokens strictly in secure, restricted database collections ('secrets'). We do NOT share this data with external parties unrelated to the publishing service. We comply with the Google API Services User Data Policy, including Limited Use requirements.

5. Third-Party API Scopes Usage

Propflow uses OAuth-based authorization scopes provided by third-party platforms to perform specific, user-approved actions. These scopes are used strictly within the boundaries defined by each platform:

• Facebook & Instagram: Used to publish content to Facebook Pages and connected Instagram Business accounts, and to retrieve basic post engagement metrics. The application does not access private messages or personal profile data.

• TikTok: Used to publish videos and retrieve basic video performance metrics such as views, likes, comments, and shares. Additionally, handles TikTok Business Messaging to process direct messages for AI-powered automated replies and inbox management. Only data related to the authenticated user's own business account and its direct messages is accessed for these purposes.

• YouTube (Google API Services): Used to upload videos to the user's YouTube channel and to retrieve basic video statistics such as view count, like count, and comment count. Access is limited to the user's own content and complies with the Google API Services User Data Policy.

• WhatsApp (Meta Business API): Used to send media messages and notifications via the WhatsApp Business platform. We access only the phone numbers and message content explicitly provided for distribution, following Meta's Business SDK privacy requirements.

All scopes are requested explicitly during account connection, are limited to the minimum required functionality, and can be revoked by the user at any time.

6. Data Retention & Deletion

We retain your personal information only for as long as necessary to provide you with our services and as described in this policy. Our standard retention practices include:

  • Standard Retention: Personal data is deleted when you explicitly delete your account.
  • Automated Inactivity Purge: Accounts inactive for more than 6 months are subject to automated data scrubbing.
  • TikTok Deauthorization: In accordance with TikTok's Data Security & Privacy Review (DSPR) standards, if you revoke PropFlow's access via your TikTok settings, we automatically delete your TikTok Business Messaging data (messages, threads, and personal metadata) within 24 hours of receiving the deauthorization notification.
  • Merchant Records: Billing data is retained by Paddle for 5 years for tax compliance.

7. Data Sharing

We do not share your personal information with third parties except as necessary to provide our Services (e.g., using the Facebook API to post your photo) or as required by law.

8. Cookies & Local Storage

We use cookies and local storage technologies to maintain your active session, store your preferences, and secure your account. We do not use these technologies for third-party advertising tracking.

9. Your Rights

You have the right to access, correct, or delete your personal information. You can revoke Propflow's access to your social media accounts at any time via the security settings pages of the respective platforms (e.g., Google Security Settings).

10. Contact Us

PropFlow values your privacy and handles all data protection matters directly. If you have any questions about this Privacy Policy, your data rights, or wish to exercise your right to access or deletion, please contact me directly at [email protected]. I am committed to responding to all inquiries promptly.

11. Data Access & Portability

You have the right to request a copy of the personal data we hold about you. You can request a data export by contacting us at [email protected]. We will provide your data in a structured, commonly used, and machine-readable format within 30 days of receiving your request.