Skip to content
FFlowwFFloww
Legal

Privacy policy

Last updated : July 17, 2026

What data we collect, why we collect it, where it is hosted, and your rights. This policy applies to the mirrorfloww.com website and the FFloww software.

1. Introduction

This privacy policy describes how FFloww (hereinafter "we", "the Publisher") collects, uses, and protects the personal data of users of the Service available at https://mirrorfloww.com.

It complies with the General Data Protection Regulation (GDPR, EU 2016/679) and the French Data Protection Act (Loi Informatique et Libertés), as amended.

Data controller: the site publisher, identified in the legal notice.

2. Data we collect

We collect only the data strictly necessary for the operation of the Service.

2.1 Data you provide

  • Email address — account identifier, authentication, transactional communications, and linkage with your Stripe subscription.
  • Password — stored as a secure hash by our authentication provider (Supabase). No plaintext password is retained by the Publisher.
  • Figures entered in dashboards — stored primarily locally on your Windows device. Demo data you create belongs to you and is not shared with third parties, unless you export or distribute it yourself.
  • Contact forms — name, email, subject, and message submitted voluntarily.

2.2 Automatically collected data

  • IP address, browser type, operating system, pages viewed, and connection dates and times — for security, abuse prevention, and Service stability.
  • Usage data — site navigation, features accessed, software version — aggregated or anonymized where possible to improve the Service.
  • License and activation data — subscription status, Stripe subscription identifier, validity dates, required to verify access to the software.

2.3 Payment data

Payments are processed exclusively by Stripe. No banking data (card number, security code) is stored by FFloww. Only subscription status (active / inactive), Stripe customer identifier, and subscription identifier are transmitted to us via a secure webhook.

3. Purposes of processing

  • Creating and managing your user account
  • Authentication and Service security
  • Verifying and managing your subscription
  • Providing the Windows software and updates
  • Transactional communications (confirmation, renewal, cancellation)
  • Customer support and responses to contact requests
  • Fraud prevention and detection of uses contrary to the Terms of Use
  • Service improvement through anonymized usage statistics
  • Compliance with legal and accounting obligations

4. Legal bases

  • Performance of a contract (Article 6(1)(b) GDPR) — account management, provision of the Service, billing.
  • Legitimate interest (Article 6(1)(f)) — security, abuse prevention, Service improvement, limited outreach to existing customers where applicable.
  • Consent (Article 6(1)(a)) — non-essential cookies and optional marketing communications, where applicable.
  • Legal obligation (Article 6(1)(c)) — accounting and tax record-keeping.

5. Hosting and subprocessors

The Service relies on the following subprocessors, bound by confidentiality commitments and, where applicable, standard contractual clauses (Article 28 GDPR):

  • Hostinger International Ltd.Hosting of the mirrorfloww.com website. Location: European Union.
  • Supabase, Inc.Authentication, user accounts, and subscription status. Location: European Union (eu-central-1 region, Frankfurt).
  • Stripe, Inc.Payment processing and subscription management. Location: PCI-DSS compliant; processing per Stripe configuration.

No transfer outside the European Union is carried out without appropriate safeguards (European Commission standard contractual clauses or adequacy decision).

6. Retention periods

  • Account data — retained while the account is active, then deleted within 30 days after a deletion request or prolonged inactivity of 3 years.
  • Billing data — retained for 10 years from the last transaction, in accordance with French accounting obligations.
  • Connection logs — 12 months maximum, in accordance with legal recommendations.
  • Contact messages — 24 months maximum, unless a contrary legal obligation applies.
  • Anonymized usage data — retained indefinitely, as it no longer allows identification of an individual.

7. Cookies and trackers

FFloww uses a limited number of cookies and similar technologies:

  • Strictly necessary cookies — authentication session, technical preferences, subscription checkout. No consent required (Article 82 of the French Data Protection Act).
  • Anonymized audience measurement — where applicable, configured in accordance with CNIL recommendations and exempt from consent where applicable.

No third-party advertising or profiling cookies are placed without your prior consent. If non-essential analytics tools are added in the future, a consent banner will be implemented beforehand.

8. Your rights

Under Articles 15 to 22 of the GDPR, you have the following rights regarding your personal data:

  • Right of access — obtain a copy of your data.
  • Right to rectification — correct inaccurate data.
  • Right to erasure ("right to be forgotten").
  • Right to restriction of processing.
  • Right to data portability — receive your data in a structured format.
  • Right to object — in particular to processing based on legitimate interest.
  • Right to withdraw consent at any time, without affecting the lawfulness of prior processing.

To exercise these rights, write to business@mirrorfloww.com attaching a copy of proof of identity if required. We respond within one month.

If disagreement persists, you may lodge a complaint with the CNIL (cnil.fr), the French data protection authority.

9. Security

We implement appropriate technical and organizational measures:

  • HTTPS encryption across the entire site
  • Secure password hashing (via Supabase)
  • Data access limited to what is strictly necessary
  • Access monitoring and security event logging
  • Regular updates of software dependencies

As no security measure is infallible, we encourage you to protect your credentials and report any suspected unauthorized access.

10. Minors

The Service is intended for adults or minors with authorization from their legal representative. We do not knowingly collect data concerning children under 16 without verifiable parental consent.

11. Changes

This policy may evolve. Any material change will be communicated by email or through a notice in your account area. The update date appears at the top of this page.

12. Contact

For any question about this policy or to exercise your rights: business@mirrorfloww.com or via the contact form.