Skip to main content

Flow2FA legal

Privacy Policy

Last Revised:
7 August 2026
Effective Date:
7 August 2026

This Privacy Policy describes how Flowstates Inc, doing business as Flow2FA ("Flow2FA," "we," "us," or "our"), located at 330 Madison Avenue, 27th Floor, New York, NY 10017, United States (SR: 20223077628, EIN: 88-3465626), collects, uses, discloses, stores, transfers and protects Personal Data in connection with flow2fa.com and the Flow2FA business-to-business OTP / two-factor-authentication delivery platform (the "Flow2FA Services").

1.Contact Details

Controller / Business:
Flowstates Inc, doing business as Flow2FA
330 Madison Avenue, 27th Floor
New York, NY 10017
United States

Privacy Contact / Data Protection Officer: dataprotectionofficer@flowstates.net

Legal Contact: legal@flowstates.net

For privacy rights requests, data protection questions, complaints, or Colombian consultas or reclamos, please contact us using the privacy email address above, or via our contact page.

2.Scope of This Privacy Policy

This Privacy Policy applies to Personal Data we process when:

  • you visit flow2fa.com;
  • you create or use a Flow2FA account;
  • you communicate with us, including through our contact form or AI assistant;
  • you receive customer support;
  • you interact with our cookies or similar technologies (see our Cookie Policy);
  • you are a business customer, supplier, partner, or representative of one; or
  • your Personal Data is processed through the Flow2FA Services on behalf of one of our Customers, for example as an OTP or verification message recipient.

This Privacy Policy does not replace any Data Processing Agreement, Customer agreement, or platform-specific terms that apply to our Customers. See our Website Terms of Use and Cookie and Browser Storage Policy for related terms.

3.Our Role: Controller, Processor, Service Provider, or Encargado

Flow2FA may process Personal Data in different roles depending on the context.

3.1 Where Flow2FA Acts as Controller

Flow2FA acts as a controller when we determine the purposes and means of processing Personal Data, including account registration information, billing information, website and contact-form data, AI assistant chat data, support records, business contact data, and security logs processed for our own business purposes.

3.2 Where Flow2FA Acts as Processor or Service Provider

Flow2FA acts as a processor, service provider, or contractor when it processes Personal Data on behalf of our Customers through the Flow2FA Services — for example, when routing and delivering OTP and verification messages over WhatsApp, SMS, or email. In that context, the Customer determines the purposes and means of processing, and Flow2FA processes the data only on the Customer's documented instructions, under the applicable Data Processing Agreement, Website Terms of Use, and applicable law.

3.3 Colombian Law Roles

For purposes of Colombian data protection law, Flow2FA may act as a Responsable del Tratamiento when it determines the purposes and means of processing, or as an Encargado del Tratamiento when it processes Personal Data on behalf of a Customer.

4.Key Definitions

  • Customer — a business or organization that registers for or uses the Flow2FA Services to authenticate or verify its own end users.
  • End User — an individual whose phone number, WhatsApp identifier, or email address is used by a Flow2FA Customer to receive an OTP or verification message through the Flow2FA Services.
  • OTP / Verification Message — a one-time passcode, authentication code, or related verification communication sent by or on behalf of a Customer through the Flow2FA Services.
  • Personal Data or Personal Information — information that identifies, relates to, describes, can reasonably be associated with, or could reasonably be linked to an identified or identifiable person, household, or device.
  • Processing — any operation performed on Personal Data, including collection, storage, use, disclosure, transmission, deletion, or analysis.
  • Sensitive Personal Data — Personal Data treated as sensitive under applicable law, which may include health data, biometric data, precise geolocation, government identifiers, account login credentials, racial or ethnic origin, political opinions, religious or philosophical beliefs, union membership, sexual orientation, children's data, or other protected categories.
  • Data Processing Agreement or DPA — the agreement governing Flow2FA's processing of Personal Data on behalf of a Customer.

5.Personal Data We Process as Controller

The table below describes the main categories of Personal Data we process as controller through flow2fa.com and our own business operations. Unlike a marketing platform, our website does not run advertising pixels, analytics cookies, or a payment checkout — the categories below reflect what the site actually collects.

CategoryExamplesSourcePurposeRetention Criteria
Contact-form submissionsName, work email, company, phone, topic, message, page path the form was submitted fromYou, via the contact formRespond to enquiries, qualify leads, provide sales and support informationRetained in our database for as long as needed to respond to and document the enquiry, and thereafter as required for record-keeping or legal purposes
AI assistant chat dataA random session identifier for your assistant conversation — stored persistently in your browser's localStorage only where you have accepted optional assistant-continuity storage, and otherwise a temporary identifier held in page memory only — together with chat messages you send, the page path where the chat session started, and your browser user agentYou, via the AI assistant widget; your browserOperate the assistant, restore your earlier conversation where you have accepted optional assistant-continuity storage, generate relevant replies, and troubleshootConversations and their messages are kept in our live database for 30 days from the last message in that conversation, then deleted automatically. You can delete the current conversation at any time from the assistant panel. We do not retain raw chat text for analytics or for training AI models
AI assistant model processingThe text of your assistant conversation, sent as prompts and conversation contextYou, via the assistant, transmitted through the Lovable AI Gateway to the configured Google Gemini modelGenerate an AI-drafted reply to your messageRetained by the model provider only as needed to process and return the response; see Section 21 (AI Assistant Disclosure)
Account and business contact dataName, work email, company, role, phoneYou, your employer, account administratorsCreate and manage Customer accounts, provision API/SMPP access, communicate about the serviceFor the duration of the business relationship and a defined period after account closure
Hosting, security, and server logsIP address, request metadata, timestamps, error and access logsAutomatically, through hosting and infrastructure providersOperate, secure, and troubleshoot the website and platform; detect and prevent abuseFor a defined period necessary for security, troubleshooting, and abuse prevention, or longer where needed for an investigation or legal claim

6.Personal Data We Process on Behalf of Customers

Customers use the Flow2FA Services to deliver one-time passcodes and verification messages to their own End Users over WhatsApp, SMS, and email, using their own vendors and SMPP binds, Flow2FA-supplied routes, or both. In this context the Customer is generally the controller (or Responsable del Tratamiento), and Flow2FA is generally the processor, service provider, or Encargado del Tratamiento.

Data TypeExamplesProcessing Purpose
End User contact identifiersPhone numbers, WhatsApp identifiers, email addressesDelivering OTP and verification messages to the correct destination
OTP / verification contentOne-time passcodes, verification codes, message templatesGenerating, transmitting, and validating authentication codes
Account, API, and routing configurationCustomer account data, API keys, SMPP bind credentials, routing and fallback rulesProvisioning and operating the Customer's authentication traffic
Request and session identifiersOTP IDs, request IDs, SMPP session dataTracking a request through generation, delivery, and validation
Delivery and verification metadataTimestamps, delivery status, verification outcome, retry and fallback attemptsRouting, fallback logic, delivery monitoring, and troubleshooting
Vendor, route, and carrier logsVendor/route identifiers, mobile-operator or carrier data, billing and traffic logsRouting traffic, billing, reconciliation, and compliance with carrier requirements
Security signalsIP address, device data, or risk indicators, only where supplied by the Customer or generated for service securityFraud prevention, abuse detection, and service integrity

Flow2FA processes End User Personal Data only to provide the Flow2FA Services, comply with Customer instructions, maintain security and service integrity, prevent abuse, comply with law, and perform related activities described in the applicable DPA. Flow2FA is a business-to-business authentication delivery platform — it is not a marketing campaign platform, and Flow2FA does not guarantee delivery of any message.

7.Customer Responsibilities

Because the Flow2FA Services are used to deliver OTP and verification messages, Customers must comply with all applicable privacy, telecommunications, consumer protection, and anti-spam laws. Customers are responsible for:

  • providing lawful notices to End Users regarding authentication messages;
  • obtaining and documenting any legally required consents or authorizations;
  • determining the lawful basis for processing End User Personal Data;
  • ensuring messages sent through the Flow2FA Services are lawful and non-deceptive;
  • maintaining accurate End User contact data;
  • ensuring that End User data submitted to Flow2FA may lawfully be processed; and
  • properly configuring their own vendors, SMPP binds, or Flow2FA-supplied routes.

Flow2FA may suspend, restrict, or terminate access to the Services where we believe it is necessary to protect End Users, prevent abuse, preserve service integrity, comply with law, respond to carrier or regulator requirements, or enforce our Website Terms of Use.

8.Sensitive Personal Data

Flow2FA does not require Customers to submit Sensitive Personal Data through the Flow2FA Services. Customers must not submit Sensitive Personal Data, protected health information, children's data, biometric data, government identifiers, or other regulated data through the Services unless:

  • the Customer has obtained all legally required consent or authorization;
  • such processing is permitted under the applicable agreement with Flow2FA; and
  • Flow2FA has confirmed that the relevant Services are configured to support that processing.

The Flow2FA Services are not intended for the processing of Protected Health Information under HIPAA unless Flow2FA and the Customer have entered into a separate agreement addressing that processing. Where we process Sensitive Personal Data as controller, we do so only where permitted by applicable law and, where required, with explicit consent.

9.Children's Privacy

The Flow2FA Services are intended for business customers and are not directed to children or minors under 18. We do not knowingly collect Personal Data from children under 13 through our website or AI assistant. Customers must not use the Flow2FA Services to deliver messages to children or minors unless they have obtained all legally required consents and authorizations.

If you believe a child has provided Personal Data to us, please contact dataprotectionofficer@flowstates.net.

10.Cookies and Similar Technologies

flow2fa.com does not use analytics, advertising, social-media pixels or cross-site tracking technologies. On your first visit you see a banner headed "Your privacy choices" that lets you accept or reject optional storage with equal prominence, or open granular preferences. Your choice is recorded in a necessary first-party localStorage entry, flow2fa.storageConsent.v1, which holds the preference, policy version, decision timestamp, expiry and method for 180 days and is not sent to our servers.

The only optional technology is a persistent identifier, flow2fa.chat.sessionId.v1, that lets the website assistant continue a conversation across pages, reloads and later visits. It is never created or read before you consent, and only once you open or use the assistant. Without that consent the assistant still works using a temporary identifier held in page memory only. You can reopen or change your choices at any time using "Cookie settings" in the website footer. Full details are set out in our Cookie and Similar Technologies Policy.

If this changes in the future — for example, if we introduce analytics — we will update this Privacy Policy and our Cookie Policy and obtain any consent required by applicable law before the technology is used.

11.How We Share Personal Data

We may disclose Personal Data to the following categories of recipients:

  • Flow2FA staff and authorized personnel, subject to access controls and confidentiality obligations;
  • hosting, cloud infrastructure, and database providers (including Supabase, which stores our contact-form submissions and AI assistant conversations);
  • the AI infrastructure and model providers used to generate assistant replies (the Lovable AI Gateway and the underlying Google Gemini model);
  • vendors, carriers, and mobile operators involved in delivering WhatsApp, SMS, or email messages, whether supplied by the Customer or by Flow2FA;
  • professional advisers, including lawyers, accountants, auditors, and insurers;
  • public authorities, courts, regulators, or law enforcement where required or permitted by law;
  • parties involved in a merger, acquisition, financing, restructuring, sale of assets, bankruptcy, or similar transaction; and
  • Customers, where we process End User data on their behalf as a processor.

We do not sell personal data

Flow2FA does not sell Personal Data for money. The current version of flow2fa.com does not use Personal Data for cross-context behavioral advertising or targeted advertising, and we do not use analytics or advertising cookies. We describe your rights regarding any future "sale" or "sharing" as those terms are defined under U.S. state law in Section 19 below.

12.Subprocessors and Service Providers

We use third-party subprocessors, service providers, and vendors to help provide, secure, maintain, and improve the Flow2FA Services. These currently include our database and backend infrastructure provider (Supabase) and the AI infrastructure used by our assistant (the Lovable AI Gateway and the underlying Google Gemini model). Customers may also route traffic through their own vendors and SMPP binds, which are not Flow2FA subprocessors.

Our subprocessors are required to process Personal Data under contract and only for the purposes authorized by Flow2FA or our Customers, using appropriate confidentiality, security, and privacy safeguards. Where required by our DPA, we provide Customers with notice of new subprocessors and an opportunity to object.

13.International Transfers

Flow2FA is based in the United States, and Personal Data we process — whether as controller or processor — may be processed in the United States and in other countries where our subprocessors operate. Where we transfer Personal Data from the EEA, UK, Switzerland, Colombia, or another jurisdiction that restricts international transfers, we use appropriate safeguards where required, such as:

  • Standard Contractual Clauses;
  • the UK International Data Transfer Agreement or UK Addendum;
  • applicable adequacy decisions;
  • data processing or transmission agreements; or
  • another lawful transfer mechanism recognized under applicable law.

You may contact us at dataprotectionofficer@flowstates.net for more information about the transfer safeguards we use.

14.Data Retention

We retain Personal Data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law. Because exact retention periods depend on the type of record and applicable legal requirements, we describe the criteria we apply below rather than fixed periods.

Data CategoryRetention Criteria
Contact-form submissionsFor as long as needed to respond to and document the enquiry, and thereafter as required for record-keeping
AI assistant chat sessions, messages, page path, and user agent (server-side)Deleted automatically 30 days after the last message in that conversation (a rolling window that restarts each time you send a message). You can also delete the current conversation yourself at any time from the assistant panel, which removes the conversation and all of its messages. We do not retain raw chat text for analytics or AI training
Browser storage on your device (consent record and optional assistant-continuity identifier)The consent record expires after 180 days and is then renewed by asking again; the optional assistant-continuity identifier is kept only until consent expires, is withdrawn, you clear site data, or the value is replaced. Where you have not accepted optional storage, the assistant identifier exists in page memory only and is discarded on reload. See our Cookie and Similar Technologies Policy
Account and business relationship dataFor the duration of the business relationship plus a defined period required for accounting, tax, and legal purposes
End User data processed on behalf of CustomersAs instructed by the Customer and under the applicable DPA, and no longer than needed to provide the Services
Delivery, verification, vendor, route, and carrier logsFor a defined period necessary for billing, reconciliation, compliance, and abuse prevention, or longer where needed for a dispute, investigation, or legal claim
Hosting, security, and server logsFor a defined period necessary for security and troubleshooting, or longer where needed for an investigation or legal claim
Legal and compliance recordsAs long as necessary to demonstrate compliance and support an audit or dispute

15.Security

We use administrative, technical, and organizational safeguards designed to protect Personal Data against unauthorized access, disclosure, alteration, or destruction, including access controls, encryption in transit, and database-level access restrictions on our backend infrastructure. No security measure is perfect, and we cannot guarantee absolute security. If we become aware of a security incident affecting Personal Data, we will take reasonable steps to investigate and notify affected parties as required by applicable law.

16.Your Rights

Depending on your location and the applicable law, you may have rights to access, correct, delete, restrict, or object to our processing of your Personal Data, to receive a copy of your data in a portable format, or to withdraw consent where processing is based on consent. You may exercise these rights by contacting dataprotectionofficer@flowstates.net. Where Flow2FA processes your Personal Data as a processor on behalf of a Customer, we may direct your request to that Customer, who is generally best placed to respond.

17.GDPR, EEA, UK, and Swiss Rights

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the right to:

  • access the Personal Data we hold about you;
  • rectify inaccurate or incomplete Personal Data;
  • erase your Personal Data in certain circumstances;
  • restrict or object to processing in certain circumstances;
  • request data portability; and
  • lodge a complaint with your local data protection supervisory authority.

Where we rely on legitimate interests to process your data as controller, you have the right to object at any time. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

For cookies and similar technologies, you can withdraw consent as easily as you gave it by using "Cookie settings" in the website footer. Changing that setting stops any further persistent storage on your device and removes the optional assistant-continuity identifier immediately, so earlier conversations are no longer restored in your browser. It does not by itself delete assistant messages already stored on our servers. You can delete those yourself using "Delete this conversation" in the assistant panel, which permanently removes that conversation and all of its messages from our live database; in any event, each conversation is deleted automatically 30 days after its last message. Other requests to access or delete server-side data are handled as privacy-rights requests under this Privacy Policy, using the contact details above.

18.U.S. State Privacy Rights

Residents of certain U.S. states — including California, Colorado, Connecticut, Virginia, Utah, and other states with comprehensive privacy laws — may have rights to know what Personal Information we collect about them, to access or delete that information, to correct inaccuracies, to opt out of the sale or sharing of Personal Information or its use for targeted advertising, and to be free from discrimination for exercising these rights.

Flow2FA does not sell Personal Information for money, and the current version of flow2fa.com does not use Personal Information for targeted advertising or cross-context behavioral advertising. You may exercise your state privacy rights by contacting dataprotectionofficer@flowstates.net. The full California Privacy Notice below describes our practices and your rights in more detail; other state residents may exercise comparable rights using the same contact channel.

19.California Privacy Notice

This section supplements the rest of this Privacy Policy and applies to California residents, as required by the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA").

19.1 Notice at Collection

We collect the categories of Personal Information described in Sections 5 and 6 of this Privacy Policy, including identifiers (such as name, email, and phone number), internet or electronic activity information (such as chat messages, session identifiers, and page paths), and commercial information (such as contact-form and account data), for the business and commercial purposes described in this Privacy Policy.

19.2 Sources of Personal Information

  • directly from you, such as through our contact form or AI assistant;
  • automatically, through your use of our website;
  • from your employer or the business you represent, where you are a Customer's representative; and
  • from Customers, where Personal Information is processed on their behalf through the Flow2FA Services.

19.3 Purposes for Collection

  • operating and securing our website and the Flow2FA Services;
  • responding to enquiries and providing customer support;
  • operating the AI assistant and improving its responses;
  • delivering OTP and verification messages on behalf of Customers;
  • billing, account administration, and business relationship management;
  • fraud, abuse, and security incident prevention; and
  • complying with legal obligations.

19.4 Disclosures for a Business Purpose

We disclose the categories of Personal Information described in Section 11 (How We Share Personal Data) to service providers and contractors for the business purposes described in this Privacy Policy, under written contracts that restrict their use of the information.

19.5 Sale or Sharing of Personal Information

Flow2FA does not sell Personal Information for money. The current version of flow2fa.com does not use Personal Information for cross-context behavioral advertising, and we do not use analytics or advertising cookies that would constitute "sharing" under the CCPA. If this changes, we will update this Privacy Policy and provide the required notice and opt-out mechanism.

19.6 Your California Rights

  • Right to know / access the specific pieces and categories of Personal Information we have collected;
  • Right to delete Personal Information we have collected, subject to certain exceptions;
  • Right to correct inaccurate Personal Information;
  • Right to opt out of the sale or sharing of Personal Information (not currently applicable, as described above);
  • Right to limit use of Sensitive Personal Information (not applicable, as we do not collect Sensitive Personal Information through the website); and
  • Right to non-discrimination for exercising any of these rights.

19.7 How to Exercise Your Rights

You may submit a request to know, access, delete, or correct your Personal Information by emailing dataprotectionofficer@flowstates.net or using our contact page. We will need to verify your identity before completing certain requests. Authorized agents may submit requests on your behalf; we may require proof of authorization and may ask you to verify your identity directly with us unless an exception applies.

19.8 Response Timelines

We will respond to California privacy requests within the period required by law. For requests to know, access, delete, or correct, we generally confirm receipt within 10 business days and respond within 45 calendar days, unless an extension is permitted by law.

20.Colombian Privacy Notice

This section applies to Personal Data processing subject to Colombian data protection law, including Law 1581 of 2012 and its implementing regulations.

20.1 Responsible Entity

Responsable del Tratamiento:
Flowstates Inc, doing business as Flow2FA
330 Madison Avenue, 27th Floor
New York, NY 10017
United States
Email: dataprotectionofficer@flowstates.net

20.2 Purposes of Processing

  • providing and operating the Flow2FA Services;
  • managing accounts and business relationships;
  • delivering OTP and verification messages over WhatsApp, SMS, and email;
  • providing customer support, including through our AI assistant;
  • billing, accounting, and tax compliance;
  • fraud, abuse, and security incident prevention;
  • compliance with legal, regulatory, judicial, or contractual obligations; and
  • responding to consultas, reclamos, complaints, and other rights requests.

20.3 Authorization

Where required by Colombian law, we will request prior, express, and informed authorization for the processing of Personal Data. Authorization may be obtained in writing, electronically, orally, by affirmative conduct, or by another mechanism that allows later consultation of the authorization. When requesting authorization, we will inform data subjects of the Personal Data to be collected, the purposes of processing, their rights, our identity and contact details, the optional nature of providing Sensitive Personal Data or children's data where applicable, and how to access this Privacy Policy.

20.4 Sensitive Data

The provision of Sensitive Personal Data is optional unless an exception applies under law. We will not condition any activity on the provision of Sensitive Personal Data unless legally permitted, and we will obtain express consent where required.

20.5 Children and Adolescents

Processing Personal Data of children and adolescents is restricted. Where such processing is permitted, it must respect the superior interests of the child or adolescent and their fundamental rights.

20.6 Colombian Data Subject Rights

  • know, update, and rectify their Personal Data;
  • request proof of the authorization granted for processing, unless an exception applies;
  • be informed, upon request, about how their Personal Data has been used;
  • file complaints with the Superintendencia de Industria y Comercio after completing the applicable consulta or reclamo process with us;
  • revoke authorization and/or request deletion of Personal Data where applicable;
  • access their Personal Data free of charge; and
  • exercise any other right provided under Colombian law.

20.7 Procedure for Consultas and Reclamos

Privacy / Data Protection Office: dataprotectionofficer@flowstates.net

Requests should include:

  • the data subject's full name;
  • identification information sufficient to verify identity;
  • contact details for response;
  • a clear description of the request, consulta, or reclamo;
  • supporting documents, where applicable; and
  • if submitted by a representative, proof of authority to act.

Consultas will be answered within 10 business days from receipt. If we cannot respond within that period, we will explain the reason for the delay and provide a response within the additional period permitted by law. Reclamos will be handled within 15 business days from receipt of a complete claim; if incomplete, we may request additional information, and we will similarly explain any necessary delay. A data subject may file a complaint with the Superintendencia de Industria y Comercio only after first completing the applicable consulta or reclamo process with us.

20.8 International Transfers and Transmissions From Colombia

Personal Data subject to Colombian law may be transferred or transmitted outside Colombia, including to the United States and other countries where Flow2FA or its subprocessors operate. Where required, we will use contractual safeguards, transmission agreements, transfer mechanisms, authorization, or other measures required under Colombian data protection law.

20.9 Effective Date and Database Validity

This Colombian Personal Data processing notice is effective as of the "Effective Date" shown at the top of this page. Our databases will remain valid for as long as necessary to fulfil the purposes described in this Privacy Policy, unless a longer period is required or permitted by law, contract, compliance, dispute resolution, or legitimate business purposes.

21.AI Assistant Disclosure

Please read before using the assistant

The Flow2FA website includes an AI assistant that answers questions about our OTP delivery platform. Replies are generated automatically by an AI model and may be inaccurate, incomplete, or out of date — always verify anything important with our team via /contact.

When you use the assistant, we store your conversation — including the messages you send and receive, a random session identifier for that conversation, the page path where the session started, and your browser's user agent — in our backend database. Storing that identifier persistently in your browser is optional and controlled through your cookie and storage preferences, which you can open at any time from "Cookie settings" in the footer: where you have accepted assistant continuity, it is kept in localStorage so the conversation can resume across pages, reloads and later visits; where you have not, it is held in page memory only and discarded when the page is reloaded or closed. Either way, it is sent with your messages so we can group the server-side conversation records. Your messages, together with the assistant's prior replies, are transmitted through the Lovable AI Gateway to the configured Google Gemini model so that a reply can be generated.

Do not submit OTP codes, passwords, API keys, SMPP credentials, or other secrets, sensitive personal data, or confidential business information through the public assistant. The assistant is intended for general product and documentation questions only.

22.Marketing Communications

We may send account-related, transactional, service, and support communications to our Customers and business contacts as part of operating the Flow2FA Services. Where we send any promotional communications, we will do so only where permitted by law and will provide an opt-out mechanism. You may object to any such communications at any time by contacting dataprotectionofficer@flowstates.net. We may continue to send non-promotional communications, including transactional, account, security, billing, and legal messages.

23.Messaging Opt-Outs

If you receive an OTP or verification message sent by a Flow2FA Customer through the Flow2FA Services, the Customer is generally responsible for that message and for honouring your preferences. If you contact Flow2FA about a message you received, we may forward your request to the relevant Customer or help process the request as required by law, contract, or carrier rules. Because OTP and verification messages are transactional and typically required to complete authentication, an opt-out request may mean the Customer can no longer authenticate you through that channel.

24.Do Not Track and Opt-Out Preference Signals

Some browsers provide "Do Not Track" settings. Because there is no uniform industry standard for responding to Do Not Track signals, and because our website does not currently use advertising or analytics cookies, we do not respond differently to Do Not Track signals at this time. Where required by law, including California law, we will honour recognized opt-out preference signals, such as Global Privacy Control, as a request to opt out of any future sale or sharing of Personal Information for the relevant browser, device, or account.

25.Automated Decision-Making and Profiling

We do not use Personal Data for automated decision-making that produces legal or similarly significant effects without appropriate notice and lawful basis. Our AI assistant generates conversational replies only and does not make decisions about you. Where the Flow2FA Services include risk signals or delivery-monitoring logic used to route, retry, or fall back a message between channels, this operational logic is used to improve delivery reliability and does not constitute profiling that produces legal or similarly significant effects on End Users.

27.Business Transfers

If Flow2FA is involved in a merger, acquisition, financing, restructuring, bankruptcy, sale of assets, or similar transaction, Personal Data may be disclosed or transferred as part of that transaction, subject to appropriate safeguards and applicable law.

28.Third-Party Websites and Services

Our website and Services may link to third-party websites, platforms, or integrations, including channel providers such as WhatsApp, mobile carriers, and Customer-supplied vendors. We are not responsible for the privacy practices of third parties, and their own privacy policies govern their collection and use of Personal Data.

29.Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The "Last Revised" date at the top of this page indicates when it was last updated. Where required by law, we will provide additional notice or obtain consent for material changes. See also our Website Terms of Use and Ethics Policy for related commitments.

30.Contact Us

For questions, privacy rights requests, complaints, Colombian consultas or reclamos, California privacy requests, GDPR requests, or other data protection concerns, please contact:

Flowstates Inc, doing business as Flow2FA
330 Madison Avenue, 27th Floor
New York, NY 10017
United States

Privacy Contact / Data Protection Officer: dataprotectionofficer@flowstates.net
Legal: legal@flowstates.net
Or use our contact page.

This Privacy Policy is governed by the laws of the State of New York, United States.