FlowzerFlowzer

Legal

Privacy Policy

Last updated: June 24, 2026

Flowzer ("Flowzer", "we", "us") provides a dashboard for managing advertising accounts on Meta (Facebook) Ads and Google Ads. This policy explains what information we collect, why we collect it, and how it's handled.

Information we collect

  • Account information: the name and email address you register with, and a hashed (not plaintext) version of your password if you use password login.
  • Connected ad account data: when you connect a Facebook Ads or Google Ads account, we store the OAuth access/refresh token needed to act on your behalf, along with the ad account ID, account name, campaign details, and performance metrics (spend, impressions, clicks, conversions) that those platforms return to us.
  • Social login profile data: if you sign in with Google or Facebook, we receive your name and email address from that provider to create or match your Flowzer account. We do not request or store anything beyond basic profile information for sign-in.
  • Usage data: basic session information (e.g. login timestamps) needed to operate the service securely.

How we use this information

  • To authenticate you and maintain your session.
  • To retrieve, display, and let you manage campaigns and performance data from the ad platforms you connect.
  • To send transactional email (e.g. magic links, password resets) - never marketing email without consent.
  • To diagnose and fix problems with the service.

How we protect your data

OAuth tokens and other connection credentials are encrypted at rest before being stored. Passwords are hashed, never stored in plaintext. Session tokens are signed and time-limited. Access to production systems is restricted to the people operating the service.

Third parties we share data with

We use the following services to operate Flowzer. Each only receives the data necessary to perform its function:

  • Meta Graph API / Facebook Marketing API - to read and manage the Facebook Ads accounts you connect.
  • Google Ads API - to read and manage the Google Ads accounts you connect.
  • MongoDB Atlas - database hosting for account and connection data.
  • Microsoft Azure - hosting for our backend API.
  • Vercel - hosting for our web application.
  • Postmark - delivery of transactional email (magic links, password resets).

We do not sell your personal information to anyone.

Cookies

We use a single session cookie to keep you signed in. We do not use third-party advertising or tracking cookies on Flowzer itself.

Data retention and deletion

We retain your account and connection data while your account is active. You can disconnect an ad account at any time from the Configuration page, which stops further access to that account. To request deletion of your account and associated data, contact us using the details below.

Your choices

You can revoke Flowzer's access to your Facebook or Google account at any time from that platform's own security settings, in addition to disconnecting it within Flowzer.

Children's privacy

Flowzer is intended for business use and is not directed at children. We do not knowingly collect data from children.

Changes to this policy

We may update this policy as the product changes. We'll update the "Last updated" date above when we do.

Contact us

Questions about this policy or your data can be sent to support@flowzerai.com.