Privacy

Privacy Policy

This English version is a convenience translation provided for information purposes only. Solely the German version of this Privacy Policy is legally binding.

1. Controller

The controller responsible for data processing on this website and within the scope of the FlowToo services is:

Markus Marussow (sole proprietorship)
Kornäcker 27
97256 Geroldshausen
Germany
Email: info@flowtoo.de
Phone: +49 1525 1931042

2. No Data Protection Officer Appointed

Pursuant to Art. 37 GDPR in conjunction with § 38 of the German Federal Data Protection Act (BDSG), we are currently not obliged to appoint a company data protection officer, as we do not, as a rule, permanently employ at least 20 persons in the automated processing of personal data. If you have any questions about data protection, please contact the address given above directly.

3. Scope

This Privacy Policy applies to the use of our website flowtoo.de as well as to the use of the FlowToo software (ticket inbox, AI responses, returns management, retention, WISMO tracking, cancellation handling, admin dashboard) by our customers (Shopify store operators) and their end customers, insofar as their data is processed by us in the course of use by our customers.

Note: Insofar as FlowToo processes personal data of end customers on behalf of our customers (processing pursuant to Art. 28 GDPR), our customer (the store operator) is primarily the controller under data protection law. The details of this data processing are governed by the Data Processing Agreement (DPA) concluded with our customers.

4. Origin of the Data

We predominantly do not receive personal data of our customers' end customers directly from the data subjects themselves, but via the connection to the respective Shopify store of our customer (e.g. order, contact and shipping data).

5. Legal Bases of Processing

We process personal data on the basis of the following legal bases:

  • Art. 6 (1) (b) GDPR – performance of a contract (provision of our SaaS service to our customers)
  • Art. 6 (1) (f) GDPR – legitimate interest (including IT security, abuse prevention, product improvement)
  • Art. 6 (1) (c) GDPR – legal obligation (e.g. retention obligations under tax and commercial law)
  • Art. 6 (1) (a) GDPR – consent (e.g. for optional cookies or newsletters)
  • Art. 28 GDPR – data processing on behalf of our customers

6. Categories of Data Processed

  • Master data: name, email address, company name, billing address
  • Usage data: login data, IP address, time of use, usage behaviour within the application
  • Contract data: subscription, plan, payment history
  • Communication data: support inquiries, ticket contents, email correspondence between store and end customer
  • Order and shipping data: order number, tracking number, delivery status, return reasons (within the scope of WISMO tracking and returns management)
  • Payment data: processed exclusively via our payment service provider Stripe; we ourselves do not store complete payment data

7. Purposes of Processing

  • Provision and operation of the FlowToo platform
  • Automated answering and generation of suggestions for customer service inquiries using AI
  • Shipment tracking (WISMO) and returns processing
  • Contract processing and invoicing
  • Communication with our customers (support, onboarding)
  • Ensuring IT security and troubleshooting
  • Compliance with statutory retention obligations

8. Data Sharing / Sub-Processors

To provide our service, we use the following service providers (sub-processors), which are contractually obliged to comply with data protection requirements under data processing agreements:

Service providerPurposeRegistered office / server location
Base44 (Wix.com Ltd.)Hosting and app platform on which FlowToo is operatedIsrael (EU Commission adequacy decision)
OpenAI, L.L.C.AI language model for automated response suggestionsUSA (Data Privacy Framework)
Anthropic, PBCAI language model for automated response suggestionsUSA (Data Privacy Framework)
MongoDB, Inc.Database infrastructure (via Base44)USA (Data Privacy Framework)
Render Services, Inc.Server infrastructure/hosting (via Base44)USA (Data Privacy Framework)
Supabase, Inc.Database/backend infrastructure (via Base44)USA (Data Privacy Framework)
Google Cloud (Google Ireland Ltd.)Cloud infrastructure (via Base44)EU/USA (Data Privacy Framework)
DataDog, Inc.Monitoring/logging of the infrastructure (via Base44)USA (Data Privacy Framework)
Mailgun (Sinch)Sending of transactional emailsUSA/EU
Stripe Payments Europe, Ltd.Payment processingIreland/USA (Data Privacy Framework)
17TRACKShipment tracking (WISMO)China
Shopify Inc. / Shopify International Ltd.E-commerce platform of our customers, data interfaceIreland/Canada (adequacy decision for Canada)

9. International Data Transfers

Insofar as data is transferred to countries outside the EU/EEA, we ensure an adequate level of data protection through:

  • adequacy decisions of the EU Commission (e.g. for Israel, Canada),
  • the respective provider's participation in the EU-US Data Privacy Framework (DPF), where applicable, or
  • the conclusion of EU Standard Contractual Clauses (SCC) together with additional safeguards, in particular for transfers to China (17TRACK), where no adequacy decision exists.

10. Data Security

We employ technical and organisational measures (TOMs) to protect your data against loss, misuse and unauthorised access, including encryption of data transmission (TLS/SSL), access restrictions and regular security reviews. Our hosting partner Base44 is SOC 2 Type II and ISO 27001 certified.

11. Retention Periods

Data categoryRetention period
Contract dataFor the duration of the contract term plus statutory retention periods (generally 6-10 years pursuant to German HGB/AO)
Invoice data10 years (§ 147 of the German Fiscal Code, AO)
Support/communication dataUp to 3 years after end of contract
Usage/log dataUp to 12 months
Order/tracking dataFor the duration of processing, thereafter in accordance with statutory periods

12. Data Subject Rights

You have the following rights:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing (Art. 21 GDPR), in particular to processing for direct marketing purposes – in this case your data will no longer be processed for this purpose
  • Withdrawal of consent given (Art. 7 (3) GDPR)

To exercise these rights, please contact us at info@flowtoo.de.

13. Right to Lodge a Complaint with a Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority. The competent authority is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 27
91522 Ansbach, Germany
www.lda.bayern.de

14. Cookies

Our website uses cookies, some of which are technically necessary and some of which are used for reach measurement. Details and configuration options can be found in our cookie banner.

15. Automated Decision-Making / AI-Powered Processing

FlowToo offers AI-powered functions for answering customer service inquiries. In the default setting, the AI merely creates response suggestions that are reviewed and approved by an employee of our customer – no automated decision with legal or similarly significant effect within the meaning of Art. 22 GDPR takes place.

Optionally, our customers can activate an "autopilot" mode in which AI-generated responses are sent automatically without manual review. The decision to activate this mode and the responsibility under data protection law for doing so lies with our respective customer as the controller under data protection law.

To create response suggestions, inquiry contents are transmitted to the AI providers OpenAI and/or Anthropic (see section 8). Customer data is not used to train the AI models of these providers.

AI disclosure (EU AI Act Art. 50): Pursuant to Art. 50 (2) of the EU AI Act, providers are obliged to inform users that they are interacting with an AI system. FlowToo therefore appends a notice at the end of automatically sent AI responses ("This response was created with AI assistance."). Our customers can deactivate this disclosure in the settings; in this case, responsibility for the legally required disclosure lies with the respective customer as controller.

16. Note for Our Customers (Store Operators)

If you use FlowToo as a store operator and have personal data of your end customers processed via our platform, we conclude a separate Data Processing Agreement (DPA) with you pursuant to Art. 28 GDPR. You can find it at flowtoo.de/AVV.

17. No Offering for Children

Our offering is not directed at children under the age of 16.

18. Changes to this Privacy Policy

We reserve the right to adapt this Privacy Policy in order to bring it in line with changed legal circumstances or changes to our services. The current version published on this page applies.

19. Contact

If you have any questions about data protection, you can reach us at: info@flowtoo.de

Last updated: July 2026