RGPD / GDPR

Privacy Policy

How Flow-MRR processes personal data related to the FlowMRR website and service.

Last updated: September 14, 2026

1. Controller and scope

Flow-MRR, a French simplified joint-stock company with a sole shareholder (SASU) with a share capital of 1,000 euros, registered with the Paris Trade and Companies Register (RCS Paris) under number 109 145 771, with its registered office at 6 rue d’Armaillé, 75017 Paris, France, is the controller for personal data described in this policy where it determines the purposes and means of processing. Contact: support@flow-mrr.com.

This policy covers website visitors, prospects, authorised service users and people who contact us. When Flow-MRR processes personal data from a connected Stripe account on a customer’s behalf, the customer is controller and Flow-MRR acts as processor under the Data Processing Agreement.

2. Data, purposes and legal bases

Account, service and support

We process account and contact information, authentication data, preferences, support communications and data required to use the service. This processing is based on contract performance, requested pre-contractual steps and our legitimate interest in securing and improving the service.

Connected Stripe data

When a customer connects Stripe, the service processes data needed for enabled features, including account, customer, subscription, invoice, payment, refund, product and activity data. This data is processed on the customer’s instructions to provide analytics, forecasting and recovery features. The access granted through Stripe Connect is read-write in scope (Stripe offers no read-only option for this kind of connection); FlowMRR uses it to read the account and performs a single write, retrying a failed invoice at the customer’s explicit request. Stripe credentials and end-customer personal data are encrypted at rest. What we read, write and protect is detailed on the Security & data use page.

Security, compliance and improvement

We process technical logs, security information and usage data to prevent fraud, maintain security, meet legal obligations and improve the service. We may use irreversibly aggregated and anonymised data for statistics and market analysis; we do not sell personal data or identifying customer data.

3. Recipients and transfers

Data access is limited to authorised personnel and service providers needed to provide, secure and improve the service. When a transfer outside the European Economic Area is necessary, we use a GDPR-valid transfer mechanism and appropriate safeguards.

4. Retention

Account and service data is retained for the contractual relationship, then deleted or anonymised in line with available functionality, customer instructions and applicable legal obligations. Backups are deleted under security and retention cycles. Irreversibly anonymised data may be retained.

5. Your rights

Subject to applicable law, you may request access, rectification, erasure, restriction, objection, portability and withdrawal of consent where processing is based on consent. To exercise your rights, contact us at the address above. You may also lodge a complaint with the CNIL or your competent supervisory authority.

6. Cookies and analytics

The website does not use advertising cookies or audience-measurement cookies stored on your device. Internal measurement uses browser session storage and a daily pseudonymous server-side identifier derived from a truncated IP address and user agent. Raw IP addresses are not retained. We will reassess this policy before adding any third-party or non-essential tracker and obtain consent where required.

Contact us

For privacy questions: support@flow-mrr.com.