Kanso Flow, Inc. (“Kanso Flow,” “we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and related services (collectively, the “Service”).
This policy is compliant with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and other applicable privacy laws effective as of 2026.
Contents
1. Information We Collect
Information You Provide
- Account Information: Name, email address, phone number, and business details when you create an account.
- Payment Information: Billing address and payment method details processed through our secure payment processor.
- Customer Data: Information about your customers that you input into the Service, including names, contact details, and order history.
- Communications: Messages, support requests, and feedback you send to us.
Information Collected Automatically
- Device Information: Device type, operating system, unique device identifiers, and mobile network information.
- Usage Data: Features used, time spent on the app, and interaction patterns.
- Log Data: IP address, access times, and pages viewed.
2. Visual Tracking & Garment Photos
Our Visual Tracking feature allows you to photograph garments at intake for order verification and quality assurance. We are committed to transparency about how these images are handled:
3. How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To provide, maintain, and improve our Service.
- Account Management: To create and manage your account, process payments, and send transactional communications.
- Customer Support: To respond to your inquiries and provide technical support.
- Analytics: To understand usage patterns and improve user experience.
- Legal Compliance: To comply with legal obligations and protect our rights.
- Security: To detect, prevent, and address fraud and security issues.
Legal Basis for Processing (GDPR): We process your data based on: (a) performance of our contract with you; (b) our legitimate business interests; (c) your consent where required; and (d) compliance with legal obligations.
4. Data Sharing & Disclosure
We do not sell your personal information. We may share your information with:
- Service Providers: Third parties who perform services on our behalf (payment processing, cloud hosting, analytics).
- Business Transfers: In connection with a merger, acquisition, or sale of assets.
- Legal Requirements: When required by law, court order, or governmental authority.
- Protection of Rights: To protect our rights, privacy, safety, or property.
CCPA Disclosure: In the preceding 12 months, we have not sold personal information. We have disclosed personal information to service providers for business purposes as described above.
5. Data Retention
We retain your information for as long as necessary to:
- Provide our Service to you
- Comply with legal and regulatory requirements
- Resolve disputes and enforce agreements
- Support business operations
Specific retention periods: Account data is retained while your account is active and for 3 years after closure. Garment photos are deleted 90 days after order completion. Transaction records are retained for 7 years for tax and legal purposes.
6. Your Privacy Rights
Rights Under GDPR (EEA Residents)
- Access: Request a copy of your personal data.
- Rectification: Request correction of inaccurate data.
- Erasure: Request deletion of your data (“right to be forgotten”).
- Restriction: Request limited processing of your data.
- Portability: Receive your data in a portable format.
- Objection: Object to processing based on legitimate interests.
- Automated Decision-Making: Right not to be subject to solely automated decisions.
Rights Under CCPA/CPRA (California Residents)
- Know: Right to know what personal information we collect, use, and disclose.
- Delete: Right to request deletion of your personal information.
- Correct: Right to correct inaccurate personal information.
- Opt-Out: Right to opt-out of the sale or sharing of personal information.
- Limit Use: Right to limit use and disclosure of sensitive personal information.
- Non-Discrimination: Right not to be discriminated against for exercising your rights.
To exercise any of these rights, please contact us at privacy@kansoflow.com or use the in-app settings.
7. How to Delete Your Account
You have the right to delete your Kanso Flow account and all associated data at any time. Here's how:
Option 1: In-App Deletion (Recommended)
- Open the Kanso Flow app
- Go to My Flows → Business Settings → My Business
- Tap “Delete My Account”
- Confirm your decision
Option 2: Email Request
Send an email to privacy@kansoflow.com with the subject line “Account Deletion Request” from the email address associated with your account.
What Happens When You Delete Your Account
- Your account will be immediately deactivated
- All personal data will be permanently deleted within 30 days
- All garment photos will be permanently deleted
- Customer data you entered will be removed
- Transaction records may be retained for up to 7 years for legal/tax purposes in anonymized form
This action is irreversible. Please export any data you need before deleting your account.
8. Data Security
We implement industry-standard security measures to protect your data:
- AES-256 encryption for data at rest
- TLS 1.3 encryption for data in transit
- Regular security audits and penetration testing
- Multi-factor authentication available for all accounts
- Role-based access controls
- SOC 2 Type II compliance
While we take comprehensive measures to protect your data, no system is completely secure. We encourage you to use strong, unique passwords and enable two-factor authentication.
9. International Data Transfers
Our servers are located in the United States. If you access our Service from outside the United States, your information may be transferred to, stored, and processed in the U.S. We rely on Standard Contractual Clauses (SCCs) and the EU-U.S. Data Privacy Framework for lawful data transfers from the European Economic Area, United Kingdom, and Switzerland.
10. Children's Privacy
Our Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at privacy@kansoflow.com.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page, updating the “Last Updated” date, and sending you an email notification. We encourage you to review this policy periodically.
12. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us:
Kanso Flow, Inc.
Privacy Team
Email: privacy@kansoflow.com
For GDPR inquiries, our Data Protection Officer can be reached at dpo@kansoflow.com.