Privacy Policy

Last updated: July 10, 2026

This Privacy Policy explains how CW Designs, a sole proprietorship based in Ohio, United States (“CW Designs,” “we,” “us,” or “our”), collects, uses, and shares information in connection with the CW Flows platform and related websites and applications (the “Service”). It applies to people who sign in to or interact with the Service.

1. Our Role: Controller and Service Provider

CW Flows is a business-to-business service. We act in two capacities:

  • As a controller for account and identity information we collect directly (for example, the name and email used to sign in) and for operating and securing the Service.
  • As a service provider / processor for the data that our business customers (each a “Customer”) and their authorized users submit to the Service about their own business, employees, and operations (“Customer Data”). We process Customer Data on the Customer’s behalf and under their instructions. If you are an employee of a Customer, that Customer (your employer) controls that data — please direct requests about it to them.

2. Information We Collect

Account and identity information

When you sign in, our authentication provider collects information such as your name, email address, organization membership and role, and authentication events. We do not receive or store your password.

Customer Data

Customers and their authorized users submit data to the Service, which may include client and employee names and emails, tasks and their status, comments and notes, activity and login history, messages, references to third-party records (such as quote identifiers or inspection links), and related operational details.

Payment information

If you pay for the Service, payments are handled by a third-party payment processor. We receive limited billing details (such as plan, amount, and status) but do not store full payment-card numbers.

Usage and device information

We and our providers automatically collect technical and usage data such as IP address, browser and device type, pages and features used, and timestamps, including through cookies and similar technologies (see Section 8).

Communications

If you contact us, we keep your messages and contact details to respond and for our records.

3. How We Use Information

  • provide, operate, maintain, secure, and improve the Service;
  • authenticate users and enforce role-based access and permissions;
  • send transactional and service-related messages and notifications;
  • process billing and payments;
  • provide support and respond to inquiries;
  • monitor, prevent, and investigate fraud, abuse, and security incidents; and
  • comply with legal obligations and enforce our agreements.

4. AI-Assisted Processing

Some features use automated or artificial-intelligence processing (for example, generating summaries, drafts, or task updates). To provide these features, relevant Service data may be processed by us and by our AI service provider. AI output may be inaccurate and should be reviewed before it is relied upon. We do not authorize our AI provider to use your data to train general-purpose models except as permitted by our agreement with them.

5. How We Share Information

We do not sell personal information. We share information only as follows:

  • Service providers (subprocessors) who help us run the Service, under contracts that limit their use of the data (see Section 6);
  • With your organization — data is visible to authorized users within your Customer organization according to their role;
  • At your direction — for example, with a third-party integration you choose to connect;
  • For legal reasons — to comply with law, respond to lawful requests, or protect rights, safety, and security; and
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.

6. Subprocessors

We rely on reputable third parties to provide the Service. Depending on the features in use, these may include:

  • Clerk — authentication and user management;
  • Supabase — database and data storage;
  • Vercel — application hosting and delivery;
  • Stripe — payment processing;
  • DreamHost — transactional email delivery;
  • Anthropic — AI assistant features; and
  • Jobber and similar tools — only when a Customer connects them.

This list may change as the Service evolves; we will keep it current on this page.

7. Data Retention

We retain information for as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. Customer Data is retained according to our agreement with the Customer and may be deleted after a reasonable period following account termination. You are responsible for exporting any data you wish to keep before termination.

8. Cookies and Similar Technologies

We use cookies and similar technologies that are necessary to operate the Service (for example, to keep you signed in) and, where applicable, to understand usage. You can control cookies through your browser settings, but disabling necessary cookies may prevent the Service from working.

9. Security

We take reasonable technical and organizational measures designed to protect information, including role-based access controls and encryption in transit. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.

10. Your Rights and Choices

Depending on where you live, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent.

  • U.S. state privacy laws (e.g., California/CCPA-CPRA): rights to know, access, correct, and delete personal information, and to not be discriminated against for exercising those rights. We do not sell or “share” personal information for cross-context behavioral advertising.
  • EEA/UK (GDPR): the rights described above, plus the right to lodge a complaint with a supervisory authority.
  • Employee data: if your information was provided to the Service by your employer (a Customer), please direct your request to that employer; we will assist them as their service provider.

To exercise a right, email TyPavia@cw-flows.com. We may need to verify your identity before responding.

11. International Users

We operate in the United States, and our providers may process information in the United States and other countries. If you access the Service from outside the United States, you understand that your information may be transferred to and processed in the United States.

12. Children’s Privacy

The Service is intended for business use and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us and we will take appropriate steps to delete it.

13. Changes to This Policy

We may update this Policy from time to time. When we do, we will revise the “Last updated” date above and, for material changes, provide additional notice where appropriate. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.

14. Contact

Questions or requests about this Policy or your information? Contact CW Designs at TyPavia@cw-flows.com.