Privacy & data

Privacy Policy

This Policy explains what data FlamePages processes, why it is used, how leads, tracking, newsletters, integrations and billing affect privacy, and what controls are available.

Last updated: August 11, 2026Terms of ServiceRefund Policy
Account data

Registration, authentication, preferences, security and administrative activity.

Operational data

Pages, leads, forms, newsletters, analytics, support and integrations.

Billing & third parties

Stripe and configured providers process data needed to deliver their services.

01

Scope and privacy roles

This Policy applies to FlamePages accounts, workspaces and related services. On customer-created pages, the customer generally determines what visitor data is collected and why; in that context, FlamePages processes data to provide the contracted infrastructure.

Page owners are responsible for publishing their own privacy notices and obtaining consent where required.

02

Account and authentication data

We may process name, email, protected password data, locale, workspace memberships, roles and permissions, email verification, notification preferences and information related to 2FA.

We also maintain sessions, security tokens and records needed for fraud prevention and account protection.

03

Billing and payments

Stripe processes payment data used for checkout and subscriptions. FlamePages records operational billing identifiers and metadata such as Stripe customer, subscription, invoice, payment intent, charge, associated payment method, currency, amounts, status, trial dates, billing periods, refunds and disputes.

FlamePages does not need to receive full card numbers to operate the billing flow described above.

04

Content, leads and forms

We store builder content and configuration, pages, sites, domains and media. Published forms can create leads containing name, email, phone, source, UTM parameters and other fields configured by the customer.

Form submissions and lead data remain within the customer workspace context and are controlled by authorized workspace users.

05

Analytics, tracking and technical data

The platform may record page views, referrer, UTM parameters, user-agent classification, consent state and technical events for analytics, reliability and operations.

Customers can configure Google Analytics, Google Tag Manager, Meta Pixel and custom tracking code. Those services may use their own cookies or technologies according to customer configuration and visitor consent.

06

Newsletters, consent and communications

Newsletter features may process email, name, tags, custom fields, subscription status, double opt-in confirmation, consent timestamp, consent IP, user agent and a snapshot of the consent text.

Delivery, open and click events may record technical information such as URL, user agent and identifiers or hashes used for metrics and unsubscribe flows.

07

Support, attachments and audit records

Support tickets may store subject, category, priority, messages, attachments, workspace, page or site references and conversation history.

Audit logs may record administrative, security, billing, integration and other important actions to investigate incidents and protect the platform.

08

Integrations, OAuth and providers

When you connect an integration, we may store settings, identifiers, tokens or encrypted credentials needed for the connection. Google integrations may use OAuth; other integrations may use API keys, webhooks or credentials you provide.

Data sent to third parties is also subject to their privacy policies.

09

AI and media generation features

When generation features are used, we may process prompts, instructions, files, generated results, credit consumption and technical metadata required to perform and record the operation.

Configured external providers may process this data to generate the requested result.

10

How we use data

  • provide, authenticate and secure accounts and workspaces;
  • publish pages, deliver forms and operate leads;
  • process subscriptions, payments, invoices, refunds and disputes;
  • run integrations, analytics, newsletters and automations;
  • provide support, investigate incidents and maintain audit records;
  • improve reliability, performance and security;
  • comply with contractual and legal obligations.
12

Data sharing

We do not sell personal data. We may share data with providers required to operate the service, including billing, hosting, infrastructure, email, domain/DNS, analytics and integrations selected by customers.

We may also disclose information when required by law, to protect rights and safety, or as part of a corporate transaction subject to applicable safeguards.

13

Retention and deletion

We retain data for as long as needed to provide the service, maintain security, fulfill contracts and legal obligations, resolve disputes, and preserve billing and audit records.

Some data may remain longer in backups, financial records or security logs. Deletion requests are evaluated in light of those obligations.

14

Your rights

Depending on your location, you may have rights to access, correct, export, delete, restrict or object to processing, and to withdraw consent where processing relies on consent.

We may verify identity and workspace information before fulfilling a request.

15

Security

We use technical and organizational controls including authentication, optional 2FA, encryption of sensitive secrets, role-based permissions, audit logs, webhook validation and session protections.

No system is perfectly secure, so we recommend unique credentials, 2FA and periodic access reviews.

16

International processing

Infrastructure, billing and integration providers may process data in countries different from yours. Where applicable, contractual or other safeguards are used as required by relevant law.

17

Changes to this Policy

We may update this Policy to reflect new features, integrations, security requirements or legal changes. The date at the top identifies the current version.

18

Privacy contact

Send privacy requests to [email protected] with the subject “Privacy Request”.

Privacy request

To request access, correction, export or deletion, contact us and include the account email and related workspace.

Send request