Privacy Policy
Last updated: August 21, 2026
Overview
This Privacy Policy explains how BuyFlow.Dev ("BuyFlow", "we", "us") collects, uses, stores, and discloses information when you use our Slack-based purchase request service (the "Service").
BuyFlow generally acts as a service provider or data processor on behalf of its customers. Our customers remain the controllers or business owners of the data they submit to the Service.
What Data We Process
Account & Workspace Information
- Slack workspace identifiers
- Slack user IDs and display names
- Organization, workspace, and account configuration details
Slack Integration Data
- Slash commands, modal submissions, interactive actions, and direct messages exchanged with the BuyFlow app as part of the workflow
- Purchase request details submitted through BuyFlow workflows
- Approval, rejection, forwarding, and related workflow actions
BuyFlow does not read or monitor public channels, private channels, or conversations except for app interactions and direct messages required to operate the workflow.
QuickBooks Integration Data
- Vendor lists (read-only)
- Purchase order details required to create purchase order records
BuyFlow does not modify or delete existing QuickBooks records except as required to create records initiated by the customer workflow, and does not analyze, mine, or sell customer financial data.
Billing & Usage
- Subscription status and plan details
- Basic usage metrics (e.g. number of requests processed)
BuyFlow does not store payment card details. Payments, if any, are handled by third-party payment processors.
Customers should not submit payment card numbers, bank account details, government identifiers, health information, or other highly sensitive personal data through BuyFlow unless expressly supported in writing by BuyFlow.
How We Use Data
We process data solely to:
- Operate, provide, maintain, and support the Service
- Route purchase requests and approvals
- Create purchase order records in QuickBooks when initiated by the customer workflow
- Maintain security, reliability, fraud prevention, and basic service analytics
- Communicate service, billing, product, legal, or security-related notices
We do not use customer data for advertising, resale, or training AI models.
Cookies & Website Analytics
This section covers our public website only. Customer workflow data is handled as described above and is never used for analytics.
To understand how our website is used, we record which pages are viewed, which buttons are clicked, the domain of the referring website, campaign tags, your country, and your device type. We set three first-party cookies, readable only by our own server:
bf_vid— a random visitor identifier, 13 monthsbf_sid— a random session identifier, 30 minutesbf_ft— the page you arrived on and the site that referred you, 13 months
We do not record your IP address, your browser user-agent string, the contents of any form, or the query string of any page you visit. These cookies work only on this website, are never used to follow you elsewhere, and are never sold, shared, or used for advertising. Records not linked to a BuyFlow account are deleted after 30 days; records linked to an account are deleted after 90 days, or immediately if the account is deleted.
Two third-party tools also run on this website: Vercel Web Analytics, which reports aggregate page views, and Apollo.io, which estimates which company a visitor may work for so we can follow up with interested businesses. Neither receives your account data or anything you submit through the Service.
If your browser sends a Do Not Track signal, we disable our own measurement entirely — no cookies are set and nothing is recorded. Third-party tools can be blocked with your browser's privacy settings or a content blocker. You can also email support@buyflow.dev to have website analytics records associated with you deleted. We rely on our legitimate interest in improving our own website, and you may have the right to object to that processing.
Required Connection Permissions
BuyFlow requires both Slack and QuickBooks connections to operate. During OAuth connection, we request only the scopes needed for the workflow.
Slack Bot Permissions
commandsto receive slash commandschat:writeto send workflow messagesim:writeandim:historyto send and track direct-message approvalsusers:readandusers:read.emailto identify requesters and approvers
QuickBooks Permissions
Accountingscope to read vendors and create purchase order records for approved requests
Data Retention
We retain data only while:
- A customer account is active, or
- Integrations with Slack or QuickBooks remain connected
When a customer disconnects Slack or QuickBooks, closes an account, or requests deletion, we will delete or de-identify customer data within 60 days unless longer retention is required by law or reasonably necessary for security, fraud prevention, billing, or dispute resolution.
Data Sharing
We share data only with:
- Slack and Intuit (QuickBooks), as enabled by the customer
- Trusted service providers that support hosting, analytics, security, customer support, or billing
We do not sell personal information.
Security
We use reasonable administrative, technical, and organizational measures designed to protect data. No system is perfectly secure, and customers are responsible for safeguarding their credentials and maintaining appropriate internal access controls.
International Processing
Data may be processed in countries where we or our service providers operate. Those jurisdictions may have data protection laws that differ from the laws of your jurisdiction.
Children's Privacy
The Service is intended for business use and is not directed to children under 13.
Changes
We may update this Privacy Policy from time to time. If we make material changes, we will post the updated version on this page and revise the "Last updated" date.
Contact
For questions about this Privacy Policy or data requests, contact: support@buyflow.dev
General inquiries: info@buyflow.dev