Skip to content
Privacy Policy

Privacy Policy

What personal data we collect on falrow.com and in the Falrow app, why we collect it, who else touches it, how long we keep it, and the rights you have over it.

Version 1.0 · Effective 6 October 2026

In plain words
  • Spring Digital Commerce LLC decides how your account, website and access request data is used. For the content your organisation puts in a workspace, your organisation decides, and we follow its instructions.
  • We collect what we need to run Falrow and keep it secure. No advertising, no analytics trackers, no selling or sharing of personal data.
  • Workspace data is stored in the EU (Frankfurt). AI features, when enabled, send the request in progress to model providers in the US. Nothing is used to train models.
  • You can ask to see, correct, export or delete your data at bas@falrow.com. We reply within 30 days.

This summary helps you read the document. It is not part of it: where they differ, the sections below apply.

1.Who we are and what this policy covers

Falrow is operated by Spring Digital Commerce LLC, a Delaware limited liability company, 2810 North Church Street, Wilmington, DE 19802, United States ("we", "us"). For questions about this policy or your data, write to bas@falrow.com.

This policy covers personal data we handle as a controller (the party that decides why and how it is processed): visitors to falrow.com, people who request access, users' account and security data in the Falrow app, and people who correspond with us.

It does not cover Customer Data, the content an organisation puts in its Falrow workspace, such as tickets, client records, meeting notes or imported Slack messages. For that data, the organisation using Falrow is the controller and we are its processor under our Data Processing Addendum. If your personal data is in someone's workspace, for example because you are a client of one of our customers, contact that organisation first; we will help it respond.

2.What we collect, why, and on what legal basis

DataWhat it includesWhy we use itLegal basis (GDPR)
Website visitsIP address, browser and device type, pages requested, time of request, in our hosting provider's request logsTo deliver the website and protect it against abuseLegitimate interests (running and securing the website)
Access requestsName, work email, company, role, website, team size, coding agents used, what you build and why Falrow would helpTo review your request and reply about accessSteps at your request before entering a contract; legitimate interests
Account dataName, email address, password (stored only as a hash by our authentication provider), workspace memberships and roles, optional avatar and capacity, linked Slack user IDTo create your account, sign you in, and give you the access your organisation grantedPerformance of a contract; legitimate interests of your organisation and us
Security and audit dataSign-in attempts keyed by email, a one-way hash of your IP address for rate limiting, session records and revocations, OAuth grants and token metadata, the workspace activity log of who changed whatTo prevent account takeover and abuse, investigate incidents, and show your organisation who did whatLegitimate interests (security); legal obligations
AI usage metadataWhich AI feature was used, by which user, token counts and cost. Never the prompt or the output.To enforce your workspace's AI spend cap and bill it correctlyPerformance of a contract
CorrespondenceWhat you send us by email or in support conversations, and your contact detailsTo answer you and keep a record of what was agreedLegitimate interests; performance of a contract
Business contact and billing dataNames, emails and roles of your organisation's contacts, billing address, VAT or tax number, invoicesTo manage the customer relationship, invoice and meet tax and accounting dutiesPerformance of a contract; legal obligations

We do not ask for, and ask you not to give us, special categories of personal data. We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. AI features in Falrow suggest; a person decides.

3.Where data comes from

Mostly from you. Some comes from your organisation (for example when an admin invites you, sets your role or links your Slack account) and from the integrations your organisation connects, such as your Slack profile name and ID when you link your Slack identity.

4.Who we share it with

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We disclose it only to:

  • Our service providers, under contracts that bind them to process it only on our instructions and to protect it. They are listed with their purpose and location on the Subprocessors page.
  • Your organisation, which can see account and activity information about its own workspace members.
  • Integrations your organisation enables, such as Slack, to the extent needed for them to work.
  • Professional advisers such as lawyers and accountants, under confidentiality duties.
  • Authorities, when the law requires it, as described in our Legal Notices.
  • A successor, if our business or Falrow is sold or merged, under the same protections as this policy, and with notice to you.

5.International transfers

We are a US company, and some of our service providers are in the US. Workspace data is stored and processed in the European Union: the database in Frankfurt, Germany, and the application in the Netherlands. Personal data reaches the US when AI features are used (only the request in progress), when we send transactional email, when you visit our website, and when our team or our providers' support staff access systems.

Where personal data from the European Economic Area, the United Kingdom or Switzerland goes to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum and their Swiss equivalent, together with the security measures described on our Security page. You can ask us for a copy of the relevant safeguards.

6.How long we keep it

DataHow long
Website request logsAs long as our hosting provider's standard log retention, which is days, not months
Access requests not accepted12 months after our last contact with you, then deleted
Account dataWhile you are a member of a workspace. Removed with the workspace, or within 30 days of your request once you are no longer a member, unless we must keep it longer by law
Sign-in attempt and rate-limit recordsShort rolling windows, measured in minutes to days
Workspace activity logFor the life of the workspace, because your organisation relies on it as its audit trail
AI usage metadataFor the life of the workspace, to show monthly usage against the cap
Contracts, invoices and tax recordsAs long as tax and company law require, typically seven years
BackupsOverwritten on a rolling cycle of no more than 35 days

7.How we protect it

Data is encrypted in transit with TLS and at rest by our database provider. Integration secrets and API keys are additionally encrypted in the application with AES-256-GCM, access tokens are stored only as hashes, and every request passes the same role checks. The full list is on our Security page. No system is perfectly secure; if a breach affects your personal data, we will tell you and the authorities as the law requires.

8.Your rights

Depending on where you live, you have some or all of these rights over personal data we hold about you as a controller:

  • Access: to know what we hold and get a copy.
  • Correction of inaccurate data. You can change your name and other profile details in the app.
  • Deletion of your data, unless we need it for a legal obligation or legal claims.
  • Portability: to receive data you gave us in a structured, machine-readable format.
  • Objection to processing based on legitimate interests, and restriction of processing while a dispute is resolved.
  • Withdrawal of consent, where we rely on it, without affecting what we did before.
  • Opt out of the sale or sharing of personal information, and limit the use of sensitive personal information. We do neither, so there is nothing to opt out of, but you can still ask us to confirm it.
  • Non-discrimination: we will not treat you differently for exercising a right.

To exercise a right, email bas@falrow.com from the address linked to your account, or tell us how to reach you. We may need to verify your identity before acting. You may use an authorised agent, who will need your signed permission. We reply within 30 days (45 days where US state law allows, extendable once where the law permits, and we will tell you why). If we decline a request, you can appeal by replying to our decision; we will answer the appeal within the time your state law sets.

If you are in the EEA, the UK or Switzerland, you also have the right to complain to your data protection authority. We would appreciate the chance to resolve your concern first.

Browser signals: we honour Global Privacy Control as a request to opt out of sale and sharing. Because we do neither, it changes nothing about how we process your data.

9.Cookies

We use only cookies and browser storage that are strictly necessary, such as the cookie that keeps you signed in to the app and a setting that remembers light or dark mode. There are no advertising or analytics cookies. The Cookie Notice lists each one.

10.Children

Falrow is a business tool for adults. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, tell us and we will delete it.

11.Changes to this policy

When we change this policy we update the version and effective date above. If a change materially affects how we use personal data we already hold, we will tell account holders by email or in the app before it takes effect.

12.Contact

Spring Digital Commerce LLC, 2810 North Church Street, Wilmington, DE 19802, United States. Email: bas@falrow.com.

Who you contract with
Spring Digital Commerce LLC2810 North Church Street
Wilmington, DE 19802
United States
EIN 35-2886201bas@falrow.com
This versionVersion 1.0, effective 6 October 2026. Earlier versions are available on request from bas@falrow.com.All legal documents