Privacy Policy
What personal data we collect on falrow.com and in the Falrow app, why we collect it, who else touches it, how long we keep it, and the rights you have over it.
Version 1.0 · Effective 6 October 2026
- Spring Digital Commerce LLC decides how your account, website and access request data is used. For the content your organisation puts in a workspace, your organisation decides, and we follow its instructions.
- We collect what we need to run Falrow and keep it secure. No advertising, no analytics trackers, no selling or sharing of personal data.
- Workspace data is stored in the EU (Frankfurt). AI features, when enabled, send the request in progress to model providers in the US. Nothing is used to train models.
- You can ask to see, correct, export or delete your data at bas@falrow.com. We reply within 30 days.
This summary helps you read the document. It is not part of it: where they differ, the sections below apply.
1.Who we are and what this policy covers
Falrow is operated by Spring Digital Commerce LLC, a Delaware limited liability company, 2810 North Church Street, Wilmington, DE 19802, United States ("we", "us"). For questions about this policy or your data, write to bas@falrow.com.
This policy covers personal data we handle as a controller (the party that decides why and how it is processed): visitors to falrow.com, people who request access, users' account and security data in the Falrow app, and people who correspond with us.
It does not cover Customer Data, the content an organisation puts in its Falrow workspace, such as tickets, client records, meeting notes or imported Slack messages. For that data, the organisation using Falrow is the controller and we are its processor under our Data Processing Addendum. If your personal data is in someone's workspace, for example because you are a client of one of our customers, contact that organisation first; we will help it respond.
2.What we collect, why, and on what legal basis
| Data | What it includes | Why we use it | Legal basis (GDPR) |
|---|---|---|---|
| Website visits | IP address, browser and device type, pages requested, time of request, in our hosting provider's request logs | To deliver the website and protect it against abuse | Legitimate interests (running and securing the website) |
| Access requests | Name, work email, company, role, website, team size, coding agents used, what you build and why Falrow would help | To review your request and reply about access | Steps at your request before entering a contract; legitimate interests |
| Account data | Name, email address, password (stored only as a hash by our authentication provider), workspace memberships and roles, optional avatar and capacity, linked Slack user ID | To create your account, sign you in, and give you the access your organisation granted | Performance of a contract; legitimate interests of your organisation and us |
| Security and audit data | Sign-in attempts keyed by email, a one-way hash of your IP address for rate limiting, session records and revocations, OAuth grants and token metadata, the workspace activity log of who changed what | To prevent account takeover and abuse, investigate incidents, and show your organisation who did what | Legitimate interests (security); legal obligations |
| AI usage metadata | Which AI feature was used, by which user, token counts and cost. Never the prompt or the output. | To enforce your workspace's AI spend cap and bill it correctly | Performance of a contract |
| Correspondence | What you send us by email or in support conversations, and your contact details | To answer you and keep a record of what was agreed | Legitimate interests; performance of a contract |
| Business contact and billing data | Names, emails and roles of your organisation's contacts, billing address, VAT or tax number, invoices | To manage the customer relationship, invoice and meet tax and accounting duties | Performance of a contract; legal obligations |
We do not ask for, and ask you not to give us, special categories of personal data. We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. AI features in Falrow suggest; a person decides.
3.Where data comes from
Mostly from you. Some comes from your organisation (for example when an admin invites you, sets your role or links your Slack account) and from the integrations your organisation connects, such as your Slack profile name and ID when you link your Slack identity.
5.International transfers
We are a US company, and some of our service providers are in the US. Workspace data is stored and processed in the European Union: the database in Frankfurt, Germany, and the application in the Netherlands. Personal data reaches the US when AI features are used (only the request in progress), when we send transactional email, when you visit our website, and when our team or our providers' support staff access systems.
Where personal data from the European Economic Area, the United Kingdom or Switzerland goes to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum and their Swiss equivalent, together with the security measures described on our Security page. You can ask us for a copy of the relevant safeguards.
6.How long we keep it
| Data | How long |
|---|---|
| Website request logs | As long as our hosting provider's standard log retention, which is days, not months |
| Access requests not accepted | 12 months after our last contact with you, then deleted |
| Account data | While you are a member of a workspace. Removed with the workspace, or within 30 days of your request once you are no longer a member, unless we must keep it longer by law |
| Sign-in attempt and rate-limit records | Short rolling windows, measured in minutes to days |
| Workspace activity log | For the life of the workspace, because your organisation relies on it as its audit trail |
| AI usage metadata | For the life of the workspace, to show monthly usage against the cap |
| Contracts, invoices and tax records | As long as tax and company law require, typically seven years |
| Backups | Overwritten on a rolling cycle of no more than 35 days |
7.How we protect it
Data is encrypted in transit with TLS and at rest by our database provider. Integration secrets and API keys are additionally encrypted in the application with AES-256-GCM, access tokens are stored only as hashes, and every request passes the same role checks. The full list is on our Security page. No system is perfectly secure; if a breach affects your personal data, we will tell you and the authorities as the law requires.
8.Your rights
Depending on where you live, you have some or all of these rights over personal data we hold about you as a controller:
- Access: to know what we hold and get a copy.
- Correction of inaccurate data. You can change your name and other profile details in the app.
- Deletion of your data, unless we need it for a legal obligation or legal claims.
- Portability: to receive data you gave us in a structured, machine-readable format.
- Objection to processing based on legitimate interests, and restriction of processing while a dispute is resolved.
- Withdrawal of consent, where we rely on it, without affecting what we did before.
- Opt out of the sale or sharing of personal information, and limit the use of sensitive personal information. We do neither, so there is nothing to opt out of, but you can still ask us to confirm it.
- Non-discrimination: we will not treat you differently for exercising a right.
To exercise a right, email bas@falrow.com from the address linked to your account, or tell us how to reach you. We may need to verify your identity before acting. You may use an authorised agent, who will need your signed permission. We reply within 30 days (45 days where US state law allows, extendable once where the law permits, and we will tell you why). If we decline a request, you can appeal by replying to our decision; we will answer the appeal within the time your state law sets.
If you are in the EEA, the UK or Switzerland, you also have the right to complain to your data protection authority. We would appreciate the chance to resolve your concern first.
Browser signals: we honour Global Privacy Control as a request to opt out of sale and sharing. Because we do neither, it changes nothing about how we process your data.
10.Children
Falrow is a business tool for adults. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, tell us and we will delete it.
11.Changes to this policy
When we change this policy we update the version and effective date above. If a change materially affects how we use personal data we already hold, we will tell account holders by email or in the app before it takes effect.
12.Contact
Spring Digital Commerce LLC, 2810 North Church Street, Wilmington, DE 19802, United States. Email: bas@falrow.com.
Wilmington, DE 19802
United StatesEIN 35-2886201bas@falrow.com