Skip to content

Privacy policy

Last updated 1 Oct 2026

This policy explains what personal data Flowbit Technologies ("Flowbit") handles, why, and the choices you have. It covers our website and the Flowbit app.

1. Who decides what

For data your organisation puts into its workspace (employee records, attendance, payroll, clients, invoices), your organisation decides why and how it is used, and Flowbit processes it on its behalf. For account details and website enquiries, Flowbit decides and is responsible.

2. What we collect

  • Account details: name, email, password (stored only as a one-way hash), profile photo and preferences such as sounds.
  • Workspace content your team adds, which may include employee details such as PAN, UAN, bank account and salary when Muster is used.
  • Billing details: legal name, GSTIN, billing address and payment status. Card and UPI details are handled by Razorpay, not stored by us.
  • Demo requests from our website: name, work email, company, team size, phone if given, and your message.
  • Technical data: IP address, browser user agent and sign-in times, used for security, rate limiting and the audit log.

3. How we use it

We do not sell personal data and we do not use workspace content for advertising.

  • To run the service you signed up for and keep each workspace separate.
  • To send emails the product needs: invites, password resets, payslips, invoices and billing notices.
  • To keep the service secure, including the audit log of sensitive changes.
  • To reply to demo requests and support emails.

4. Cookies

Flowbit sets one essential cookie, fb_session, to keep you signed in. It is httpOnly and lasts up to 30 days. Your sound preference is remembered in your browser. We do not use advertising or tracking cookies.

5. Service providers

We use a small number of providers to run Flowbit, each only for its purpose:

  • Database and file hosting for workspace data.
  • Razorpay for subscription payments.
  • Resend for sending email, when configured.
  • Google for "Sign in with Google", only if you choose it.
  • Anthropic, only when the Arc AI provider is switched on, to draft suggestions from the text of your request.

6. How long we keep it

Workspace data is kept while the workspace exists, including during the read-only period after a trial or subscription ends. Issued invoices, HR letters and released payroll are kept as records and voided rather than deleted. When a workspace owner asks us to delete a workspace, we remove its data except what the law requires us to keep, such as our own GST invoices.

7. Security

Every record belongs to one workspace and every request is checked against it. Passwords are hashed, sessions are stored as hashes, sensitive fields are visible only to roles with explicit permission, and sensitive changes are written to an audit log.

8. Your rights

You can ask to see, correct or erase your personal data, or withdraw consent where we rely on it. If your data sits in an employer’s workspace, ask that organisation first; we will help them respond.

Write to our grievance contact at support@flowbit.app. We will reply within the time the law requires.

9. Changes

If we change this policy in a meaningful way we will update the date above and tell workspace owners by email.