NS FLOW - Legal

Privacy Policy

Effective July 19, 2026

01

Who we are & scope

This policy explains how NS FLOW (“we”, “us”) handles personal data when you visit our websites, use the NS FLOW platform, or communicate with us. It covers two roles:

  • As a controller - for data about our merchants, their team members, and site visitors.
  • As a processor- for data about a merchant’s end customers, which we process on the merchant’s behalf and instructions to deliver the services (Section 05).

If you are an end customer of a store that uses NS FLOW, the store (the merchant) is responsible for your data; contact the store first, and we will support their response.

02

What we collect

  • Account data - name, business name, email, login credentials, plan and billing records.
  • Store & order data - orders, line items, shipping addresses, tracking events, dispute records, and related customer contact details synced from platforms you connect.
  • Communications - messages sent and received through connected channels (such as WhatsApp, Messenger, Instagram, email) and your correspondence with us.
  • Checkout data - order and contact details entered on hosted checkout pages. Card payments are processed by the payment gateway the merchant connects; full card numbers are entered with, and stored by, that gateway - not by us. Gateway credentials merchants store with us are encrypted.
  • Usage & device data - log data, IP address, browser type, pages viewed, and cookies (Section 10).
03

How we use data

  • provide, secure, and improve the platform and services;
  • run dispute alerts, outreach, and representment - including contacting end customers on the merchant’s behalf and assembling evidence from order and shipment records;
  • purchase shipping labels and sync tracking status;
  • operate the unified inbox and hosted checkout;
  • bill for the services and prevent fraud and abuse;
  • comply with law and enforce our agreements; and
  • with your permission or as permitted by law, send product updates and marketing you can opt out of at any time.

We use aggregated, de-identified data (for example, dispute outcome statistics) to improve the services; it no longer identifies any person.

04

How we share data

We do not sell personal data. We share it only with:

  • Subprocessors that host and power the platform - cloud hosting, database, and email delivery providers;
  • Integrated services you connect - payment gateways, storefront platforms, shipping carriers, messaging platforms (including Meta for WhatsApp, Messenger, and Instagram), and ad platforms - as needed to run the features you use;
  • Financial institutions- processors, acquirers, and card networks, when submitting dispute responses on a merchant’s behalf;
  • Authorities - when required by law, or to protect rights, safety, or the integrity of the platform; and
  • A successor - in a merger, acquisition, or asset sale, with notice.
05

End-customer data (processor terms)

For end-customer personal data we act on the merchant’s documented instructions: we process it only to deliver the services, apply the security measures in Section 08, impose equivalent obligations on subprocessors, assist the merchant with data-subject requests, and delete or return the data when the engagement ends, except where law requires retention. Merchants are responsible for their own privacy notices and for having a lawful basis to share customer data with us - including consent where required for messaging channels.

06

International transfers

We operate globally and may process data in countries other than yours. Where required, we rely on appropriate safeguards for cross-border transfers, such as standard contractual clauses with our subprocessors.

07

Retention

We keep personal data while your account is active and as needed for the purposes above, then delete or de-identify it. Dispute evidence and billing records may be retained longer where card-network rules, tax, or other law requires. Merchants can export their data for 30 days after termination.

08

Security

We use technical and organizational measures appropriate to the risk: encryption in transit, encryption of stored gateway credentials and other sensitive secrets, access controls and least-privilege service roles, and logging. No system is perfectly secure; if a breach affects your data we will notify you as required by law.

09

Your rights

Depending on where you live (including under the GDPR, UK GDPR, and the CCPA/CPRA), you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict processing, to withdraw consent, and to not be discriminated against for exercising these rights. We do not sell or share personal data as those terms are defined by the CCPA. To exercise a right, email privacy@nsflow.to; we will verify the request and respond within the legally required time. End customers should contact their merchant first (Section 01). You may also complain to your local supervisory authority.

10

Cookies

We use strictly necessary cookies for sign-in and session management, and limited analytics to understand how the site is used. We do not run third-party advertising cookies on the platform. Your browser can block or delete cookies; sign-in requires the necessary ones.

11

Children

The services are for businesses and are not directed to anyone under 18. We do not knowingly collect data from children; if you believe a child has provided us data, contact us and we will delete it.

12

Changes & contact

We may update this policy by posting a revised version with a new effective date; material changes will be notified to your account email. Questions or requests: privacy@nsflow.to. See also our Terms of Service.