Privacy Policy
This explains what BznsFlow collects when you use this website, why, who else sees it, and what you can ask us to do about it. It is written to be read, not to be survived.
Who we are
BznsFlow builds and runs AI front-office, website, CRM and automation systems for businesses. This policy covers the website at www.bznsflowai.com and the sign-in, chat and enquiry features on it.
It does not cover systems we build and operate for a client under a separate agreement. In those, the client is responsible for their own customers' data and we act on their instructions.
For anything in this policy, contact ahmed@bznsflowai.com.
What we collect
Three ways, and they are quite different.
What you give us
- When you sign in: your email address. That is all that is needed to create an account.
- When you complete your profile: your name, phone number, country and industry.
- When you request the playbook: your name and email address.
- When you use the chat assistant: whatever you type into it, and the replies.
What we collect automatically
- Your IP address, briefly, as part of limiting how often our sign-in and chat endpoints can be called. It is used as a counter key and expires within days.
- Standard server request logs, held by our hosting provider.
- The page you were on when you submitted an enquiry.
- Anonymous performance measurements about how fast pages load.
What sign-in providers tell us
If you sign in with Google or LinkedIn, we receive your email address, your name, and a permanent identifier that provider uses for you. We store that identifier so we recognise you next time, even if you later change your email with them.
We never receive your password, and we cannot see anything else in your account there.
What we never collect
- We do not ask for or store payment card details anywhere on this website.
- We do not store your one-time sign-in codes. Only a one-way hash is kept, so a copy of our database could not be used to log in as you.
- We do not store your session token either — only a hash of it.
- We do not buy personal data from third parties.
Why we use it, and on what basis
We do not sell your personal data, and we do not share it with anyone for their own marketing.
- To sign you in and keep you signed in — necessary to provide a service you asked for.
- To reply to your enquiry and follow it up — necessary to take steps at your request before entering a contract.
- To send the guide or resource you asked for — your consent, given when you submitted the form.
- To limit abuse of our sign-in and chat endpoints — our legitimate interest in keeping the service working and our costs bounded.
- To measure our advertising — your consent, where required.
Who else sees it
We use a small number of service providers. Each only receives what it needs to do its job.
Two are worth calling out specifically. Messages you type into our chat assistant are sent to OpenAI to generate a reply. And our advertising measurement sends Meta a pseudonymous identifier — not your name, email or phone.
| Who | What they do | Where |
|---|---|---|
| Vercel | Hosts the website and runs its server code. Sees request logs, including IP addresses. | United States / global |
| Supabase | The database holding your account, and chat conversations. | Singapore (ap-southeast-1) |
| Google (Apps Script, Sheets, Gmail) | Sends your sign-in code and our emails, and stores enquiries in our internal sheet. | United States / global |
| OpenAI | Generates the replies in our chat assistant. Receives the messages you type into it. | United States |
| Meta (Facebook) | Measures our advertising. Receives a pseudonymous identifier, not your name. | United States / global |
| Google Fonts | Serves the typefaces. Your browser requests them directly, which exposes your IP address to Google. | United States / global |
| Google / LinkedIn sign-in | Only if you choose one of those buttons. They confirm your identity and email to us. | United States / global |
Where your data is stored
Our database is hosted in Singapore. Our hosting, email and other providers operate in the United States and elsewhere.
If you are in a country that restricts sending personal data abroad, be aware that using this site involves such a transfer. We rely on our providers' standard contractual protections for this.
How long we keep it
- Unused sign-in codes: deleted within about a day.
- Expired sessions: deleted about a week after they expire.
- Rate-limiting counters, which include IP addresses: days, not months.
- Your account and profile: kept while your account exists, so you do not have to re-enter it. Ask us and we will delete it.
- Chat conversations and enquiry records: kept while we may still need them to follow up with you or to show what we agreed.
How we protect it
No system is perfectly secure, and we will not claim otherwise. If we ever discover a breach affecting your data, we will tell you.
- The whole site is served over HTTPS and browsers are instructed never to use an unencrypted connection.
- Sign-in codes and session tokens are only ever stored as one-way hashes, never in a readable form.
- Our database denies all access by default. Only our own server code can read it, using a key that is never sent to your browser.
- Sign-in attempts are rate-limited, and a code is locked after five wrong guesses.
Your rights
Whatever country you are in, you can ask us to:
- Tell you what we hold about you.
- Give you a copy of it.
- Correct anything wrong.
- Delete it.
- Stop using it for marketing.
- Stop using it altogether, where our reason for doing so was our own legitimate interest.
Email ahmed@bznsflowai.com. We will respond within 30 days. There is no charge, and we will not ask why.
If you are in the UK or EU and you are not satisfied with our answer, you may complain to your national data protection authority.
Cookies and similar technologies
A full technical breakdown, kept in step with the code, is in our repository's COOKIES.md. In short:
| Name | Type | Lasts | What it does |
|---|---|---|---|
| bf_locale | Necessary | 1 year | Remembers whether you chose Arabic or English. |
| bf_session | Necessary | 30 days | Keeps you signed in. Holds a random token; the database stores only a hash of it. |
| bf_csrf | Necessary | 30 days | Protects your session from cross-site request forgery. |
| bf_oauth | Necessary | 10 minutes | Holds one in-progress social sign-in. Deleted the moment you return. |
| _fbp, _fbc | Marketing | ~90 days | Set by the Meta pixel to measure our advertising. |
| bznsflow_chat_session, bf_playbook_seen, bf_uid | Browser storage | Until cleared | Keep your chat continuous, stop a pop-up repeating, and identify you to Meta pseudonymously. |
The ones marked Necessary cannot be turned off — the site cannot sign you in or protect that sign-in without them. The marketing ones can be blocked in your browser settings, or with any standard content blocker, without breaking the site.
Children
This site is for businesses and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has given us their details, email us and we will delete them.
Changes to this policy
If we change how we handle your data, we will update this page and the date at the top. If the change is significant and we hold your email address, we will tell you directly rather than relying on you noticing.
Contact us
Email ahmed@bznsflowai.com, or message us on WhatsApp using the button on any page. We read everything.