Flow2FA legal
Cookie and Similar Technologies Policy
- Last Revised:
- 7 August 2026
- Effective Date:
- 7 August 2026
This policy explains how Flowstates Inc, doing business as Flow2FA ("Flow2FA," "we," "us," or "our"), uses cookies and similar technologies that store information on, or gain access to information already stored on, your device when you visit our website at flow2fa.com. We say "cookies and similar technologies" because the rules apply to browser storage such as localStorage and sessionStorage as well, even though those are not cookies. It should be read together with our Privacy Policy, Website Terms of Use, and Ethics Policy.
Flowstates Inc is registered in New York, NY (SR: 20223077628, EIN: 88-3465626), with a registered address at 330 Madison Avenue, 27th Floor, New York, NY 10017, United States.
The short version
- On your first visit you see a banner headed “Your privacy choices” with an equally prominent “Accept optional storage” and “Reject optional storage”, plus “Manage preferences”.
- We use one necessary first-party localStorage entry to remember the choice you make.
- The only optional technology is a persistent identifier that lets the website assistant continue your conversation across pages, reloads and later visits. It is never created or read before you consent, and only once you open or use the assistant.
- If you reject or have not yet chosen, the assistant still works — it uses a temporary identifier held in page memory, so the conversation may reset after a reload or a new visit.
- We use no analytics, advertising or marketing technologies, no social-media pixels and no cross-site tracking.
- You can reopen your choices at any time using “Cookie settings” in the website footer, and withdrawing is as easy as consenting.
1.Scope and who we are
This policy covers the flow2fa.com website operated by Flowstates Inc (doing business as Flow2FA), the data controller for the storage described here. It does not cover the websites, applications or products of our business customers, or any third-party website you may reach from a link on our site.
Flow2FA is a business-to-business one-time passcode (OTP) delivery platform. Delivering an OTP to an end user's phone number or email address does not place cookies or browser storage on that end user's device.
2.What cookies and similar technologies are
A "cookie" is a small text file that a website asks your browser to store, and which is sent back to the server with later requests. "Similar technologies" include localStorage and sessionStorage: browser storage written and read by scripts running on the page, which — unlike cookies — is not automatically transmitted with every request.
Rules on cookies and similar technologies, including the UK Privacy and Electronic Communications Regulations and equivalent EU ePrivacy rules, apply to storing information on, and accessing information stored on, your device however that storage is implemented. Consent is required unless the storage is strictly necessary to provide a service you have requested, or is needed to record the choice you have made.
Storage can be "first-party" (set by the site you are visiting — here, Flow2FA) or "third-party" (set by another domain, typically an advertising, analytics or social-media service). Flow2FA uses no third-party storage on this website.
3.Technologies used on flow2fa.com
We audited the website in a clean browser profile at the date of this policy. No cookies were set at all, before or after a choice was made and after using the assistant and the contact form. The complete inventory of storage written by this website is:
| Name | Party and type | Purpose | Category and legal basis | Duration |
|---|---|---|---|---|
| flow2fa.storageConsent.v1 | First-party localStorage (not a cookie) | Stores your privacy preference, the policy version, the timestamp of your decision, its expiry and the method used (accept, reject or saved preferences) | Necessary to remember the visitor's choice; no optional consent required | 180 days, then renewed |
| flow2fa.chat.sessionId.v1 | First-party localStorage (not a cookie) | Allows the website assistant conversation to continue across page changes, reloads and later visits in the same browser profile | Optional functional storage; only after consent and assistant use | Until consent expires, is withdrawn, site data is cleared, or the value is replaced |
3.1 Navigation scroll position
The website's routing framework also writes one sessionStorage entry, tsr-scroll-restoration-v1_3, when you navigate between pages. It holds scroll coordinates only, contains no identifier, is not sent to our servers, and is discarded automatically when you close the browser tab. It is strictly necessary for the site to return you to your place when you use the browser back button.
3.2 Server request logs are not browser storage
Like any website, flow2fa.com is served by infrastructure that generates server-side request logs — typically IP address, requested URL, timestamp, referrer and user agent — used for reliability, debugging, abuse prevention and security. These are created on our side of the connection, are not cookies or browser storage, and are described in our Privacy Policy.
4.Necessary preference storage
flow2fa.storageConsent.v1 is written when you make a choice on the banner or in the preferences dialog. It records the preference itself, the policy version, when you decided, when that decision expires, and whether you accepted, rejected or saved granular preferences. It is not sent to our servers and contains no identifier or profile.
This entry is necessary: without it the website could not remember and honour your choice, and it would have to ask you again on every page view. It also supports essential website and security operation. For that reason it is always active and no toggle is offered for it. Deleting it means you will be asked again on your next visit.
5.Optional assistant-continuity storage
Our website includes a public AI assistant that answers general questions about Flow2FA's channels, fallback behaviour and API. To let a conversation continue across page changes, reloads and later visits, the assistant needs a persistent identifier stored in your browser: flow2fa.chat.sessionId.v1. It is a random, first-party value; it is not an advertising identifier and is not used to track you across other websites.
We treat this as optional functional storage, not as strictly necessary. Accordingly:
- it is never created or read before you have given consent for it;
- even after consent, it is created only when you actually open or use the assistant — not on page load;
- if you reject it, or have not yet decided, the assistant still works: your browser generates a temporary identifier held in page memory only, which is discarded when you reload or leave, so the conversation may reset after a reload or on a new visit; and
- if you withdraw consent, the persistent entry is removed from your browser immediately and no future identifier is stored.
Whichever identifier is in use, it is sent to our chat API with your message so that the related conversation records can be grouped on our servers. Where the persistent identifier exists, opening the assistant also retrieves the most recent messages of that conversation from our servers so you can carry on where you left off; without it, nothing is retrieved after a reload. Each conversation is deleted from our live database 30 days after its last message, and you can delete the current conversation yourself at any time using "Delete this conversation" in the assistant panel. Those server-side records, the message text you submit and the AI processing involved are described in our Privacy Policy — they are not cookies or browser storage. Please do not submit one-time passcodes, credentials, API keys or other sensitive information to the public assistant.
6.Technologies not currently used
The flow2fa.com website does not currently use:
- analytics cookies or analytics scripts;
- advertising or marketing cookies, retargeting pixels or conversion tags;
- social-media pixels;
- cross-site or cross-context behavioural tracking; or
- third-party embeds that set cookies.
Because none of these are in use, our preferences dialog lists analytics and advertising for information only and offers no toggle for them: we do not create placeholder controls for categories that have no effect. We also do not sell or share personal information collected through the website for cross-context behavioural advertising.
7.How consent works
- No optional technology is used before you make a positive choice. Nothing optional is written or read while you are undecided.
- On your first visit, a banner headed “Your privacy choices” appears. It does not block the page or your navigation.
- “Accept optional storage” and “Reject optional storage” are presented together, with the same size, comparable visual weight and the same single click. Rejecting is not hidden behind a small text link or an extra step.
- “Manage preferences” opens a dialog with granular categories. The optional toggle is switched off for undecided visitors — nothing is pre-ticked.
- Continuing to browse, scrolling or closing the banner is not consent. If you make no choice, the optional storage stays off.
- You can use the whole website, the documentation, the contact form and the assistant after rejecting.
- Your choice is recorded in the necessary preference entry described in Section 4, including its version and timestamp.
8.How to change or withdraw a choice
Select Cookie settings in the footer of any page on this website. The same preferences dialog opens, and you can accept, reject or change the optional category at any time. Withdrawing is exactly as easy as consenting: one control, in the same place, with the same number of clicks. The assistant panel also links to these settings.
When you switch the optional category off, the persistent assistant identifier is deleted from your browser immediately, no new one is stored, and earlier conversations are no longer restored. This does not automatically delete assistant messages already stored on our servers: use "Delete this conversation" in the assistant panel to remove them yourself, or rely on the automatic 30-day deletion. Other requests are handled under our Privacy Policy.
9.Browser controls
You can also inspect, clear and block browser storage for flow2fa.com yourself:
- Chrome, Edge and other Chromium browsers: Settings → Privacy and security → Site settings → Cookies and site data.
- Safari: Settings/Preferences → Privacy → Manage Website Data.
- Firefox: Settings → Privacy & Security → Cookies and Site Data.
- Mobile browsers: check your browser app settings under Privacy or Site settings.
- Developer tools: most browsers let you inspect and clear localStorage and sessionStorage for a specific site from the Application or Storage panel.
- Private/incognito windows generally discard cookies and browser storage when the window is closed.
If you clear site data for flow2fa.com, the preference entry is removed and the banner appears again on your next visit. Blocking storage entirely does not stop you reading the site or using the assistant; the banner will simply reappear and continuity will not be available.
10.Retention and expiry
- flow2fa.storageConsent.v1: 180 days from your decision, then renewed by asking again. If the record has expired, or was written under a superseded policy version, we delete it, delete the optional assistant identifier, and ask you again.
- flow2fa.chat.sessionId.v1: kept until consent expires, is withdrawn, you clear site data, you delete the conversation from the assistant panel, or the value is replaced.
- Temporary in-memory assistant identifier (used without functional consent): discarded when the page is reloaded or closed. It is never written to your device.
- tsr-scroll-restoration-v1_3: discarded automatically when the browser tab is closed.
- Server-side assistant conversation records: deleted automatically 30 days after the last message in that conversation, or immediately when you delete the conversation from the assistant panel. Server request logs are retained as described in our Privacy Policy. This is separate from the browser-storage durations above.
11.Third parties and international processing
All storage listed in Section 3 is first-party. No third party sets or reads storage on this website, and the entries described are not shared with advertising or analytics providers.
Flow2FA is based in the United States. The preference entry stays on your device and is not transmitted to us. Data you actively submit — for example assistant messages, together with whichever session identifier is in use — is processed on infrastructure operated by our hosting and AI providers, which may be located in the United States or other countries. Where applicable law requires safeguards for international transfers of personal data, we implement them as described in our Privacy Policy.
This policy describes our current technical configuration in plain terms. It is not legal advice and is not a guarantee of compliance with the law of any particular jurisdiction.
12.Customers' own websites and apps
Flow2FA provides OTP delivery to businesses over WhatsApp, SMS and email, accessed by our customers via SMPP v3.4 binds or our REST API (see our Website Terms of Use and API documentation). Sending a message to an end user's phone number or email address does not set cookies or browser storage on that end user's device.
If a customer integrates Flow2FA into its own website, app or product, any cookies, browser storage or tracking technologies used on that customer's own digital properties are deployed and controlled by the customer, who is responsible for the notices, consent mechanisms and privacy disclosures required by law for its own end users. This policy covers only flow2fa.com.
13.Changes to the policy
We may update this policy, including to reflect changes in the technologies we use or in applicable law. We will update the "Last Revised" date at the top of this page when we do. Where a change affects what you have consented to, we will change the policy version used by the consent record, which clears any optional storage and asks you to choose again before that technology is used. If we ever introduce analytics, advertising or other non-essential technologies, we will not activate them before obtaining valid consent through the mechanism described in Section 7.
14.Contact
If you have questions about this policy, or you find browser storage on flow2fa.com that is not listed in Section 3, please contact us:
- Privacy questions / Data Protection Officer: dataprotectionofficer@flowstates.net
- Legal questions: legal@flowstates.net
- Or use our contact form
Flowstates Inc, doing business as Flow2FA — 330 Madison Avenue, 27th Floor, New York, NY 10017, United States.