Privacy Policy

Last updated: 5 May 2026 · Effective: 5 May 2026

The short version: Flowticks is a workplace analytics tool. We track only domain names and time spent on websites — never page content, messages, passwords, or anything sensitive. Data is encrypted and stored in the EU. You can pause tracking, view your data, or delete everything at any time.

Contents
  1. Who we are
  2. What data we collect
  3. What we never collect
  4. Legal basis
  5. Employee consent
  6. How we use data
  7. Storage and security
  8. Data sharing
  9. International transfers
  10. Your GDPR rights
  11. Retention
  12. Cookies
  13. Children's privacy
  14. Data breach procedure
  15. Changes
  16. Contact and complaints

1. Who We Are

Flowticks is a workplace analytics service operated by Filip Szlaga, a sole trader registered in Poland ("we", "us", "Flowticks"). We provide automatic website-based time tracking for agencies and small businesses.

For all data protection matters, we act as the data controller for personal data of our direct customers (account holders) and as a data processor for the personal data of their employees who use our extension.

Contact: filip.szlaga@flowticks.io · flowticks.io

2. What Data We Collect

We collect only the minimum data necessary to provide the service:

From the browser extension:

From account creation:

Automatically collected:

3. What We Never Collect

We have built Flowticks specifically to not collect the following:

Under Article 6 of the GDPR, we process personal data based on:

DataLegal basis
Account informationContract performance (Art. 6(1)(b))
Time tracking dataConsent (Art. 6(1)(a)) + Legitimate interest (Art. 6(1)(f))
IP address at signupLegitimate interest — fraud prevention
Communications with usLegitimate interest — customer support

Flowticks operates on a consent-first model. We require:

Important: If you are an employer deploying Flowticks to your team, you are responsible for obtaining valid employee consent under applicable employment and data protection law in your jurisdiction. Flowticks provides the technical means to track time, but the legal responsibility for employee consent and labour law compliance rests with the employer.

6. How We Use Your Data

We never: sell personal data, share data with advertisers, use data for advertising profiling, or train AI models on user data.

7. Storage and Security

8. Data Sharing

We share data only with the following sub-processors who have signed Data Processing Agreements:

ProviderPurposeLocation
Supabase Inc.Database, authenticationEU (Ireland/UK)
Vercel Inc.Web hosting, CDNEU + Global edge
Cloudflare Inc.DNS, securityGlobal edge
Google LLCEmail (Workspace)EU + US

We do not sell, rent, or share personal data with any other third parties.

We may disclose data only when legally required (court order, lawful authority request) and only the minimum necessary. We will notify you of any such request unless legally prohibited.

9. International Data Transfers

Some of our sub-processors may transfer data outside the EEA (e.g. to the United States). All such transfers are protected by:

10. Your Rights Under GDPR

You have the following rights regarding your personal data:

To exercise any of these rights, email filip.szlaga@flowticks.io. We will respond within 30 days (extendable by 60 days for complex requests).

11. Data Retention

Data typeRetention period
Time tracking entries12 months, then auto-deleted
Account dataActive account + 30 days after deletion
Consent records3 years (legal obligation)
Billing records5 years (Polish tax law)
Support communications2 years

You can request immediate deletion at any time by emailing us.

12. Cookies

The Flowticks dashboard uses only essential cookies required for authentication. We do not use:

13. Children's Privacy

Flowticks is intended for workplace use by individuals aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, contact us immediately and we will delete the data within 24 hours.

14. Data Breach Procedure

In the event of a personal data breach that risks the rights and freedoms of data subjects, we will:

15. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to all users via email at least 14 days before they take effect. The "Last updated" date at the top of this policy reflects the most recent change.

Continued use of Flowticks after changes take effect constitutes acceptance of the updated policy.

16. Contact and Complaints

For privacy-related questions or to exercise your rights:

If you are unsatisfied with our response, you have the right to lodge a complaint with your national supervisory authority: