Privacy Policy
Last updated: July 13, 2026
Huisman Web3 (KVK 86087053, VAT NL213628211B03), trading as Flow²Market, Amsterdam, Netherlands (“we”) respects your privacy. This policy explains how we handle your personal data in accordance with the GDPR.
1. What We Collect
You provide: Email (via magic link), billing details (processed by Stripe), brand materials (logos, images, PDFs, fonts), prompts, campaign goals, and budget settings.
We collect automatically: IP address, browser user agent, URL parameters (utm_*, gclid, fbclid), anonymous ID (localStorage), session ID (sessionStorage), and usage data. We use self-hosted product analytics (Rybbit) and Meta Pixel to measure advertising performance and conversion events on this site.
2. How We Use Your Data
We use your data to provide the service, process payments, send transactional emails, generate AI-powered marketing content (via OpenRouter), conduct market research, and attribute conversions. Each purpose has a legal basis under GDPR: contract performance, legitimate interest, consent, or legal obligation.
3. Who We Share Data With
We share data only with services necessary to operate: payment processing (Stripe), AI inference (OpenRouter), email delivery, cloud hosting (IONOS, Berlin, Germany), and search engines for research. We do not sell your data. When you connect ad platforms (Google Ads, Meta, TikTok, LinkedIn, X, etc.), data is shared only as necessary to execute your campaigns.
3a. Google User Data
When you connect Google Ads, Flow²Market uses Google OAuth to access your Google account only after you authorize it. We request the minimum scopes needed to manage campaigns and read performance for accounts you own: Google Ads account access and basic profile information (email, name) for sign-in.
We use this data solely to provide the service you request: listing your ad accounts, creating and managing campaigns you approve, and reporting performance in your dashboard. We do not sell Google user data, and do not use it for advertising or unrelated purposes. You can disconnect Google at any time in the app, which revokes our access to new data from that account.
Data protection: OAuth refresh tokens and access tokens are encrypted at rest using AES-256-GCM with a randomly generated initialization vector (IV) per token. The encryption key is derived via scrypt and stored as an environment variable, never in the database. Tokens are decrypted only in-memory at the moment of use and never logged. All API traffic to Google APIs is transmitted over TLS 1.3. Access to decrypted credentials is restricted to the application runtime and is not accessible to support staff or administrators in plaintext.
Flow²Market's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3b. Meta User Data
When you connect Meta (Facebook/Instagram ads), Flow²Market uses Facebook Login for Business to access your Meta account only after you authorize it. We request permissions needed to manage ads on accounts and Pages you own: business_management, ads_read, ads_management, pages_show_list, pages_manage_ads, and public_profile (name and profile for the connected-account display).
We use this data solely to provide the service you request: listing your ad accounts and Facebook Pages, associating a Page with ad creatives, creating and managing campaigns you approve (new campaigns default to paused), and reporting performance in your dashboard. We store OAuth tokens encrypted (AES-256-GCM), do not sell Meta user data, and do not use it for advertising or unrelated purposes.
Meta Platform Data is processed on infrastructure hosted by IONOS SE (Berlin, Germany). Encrypted app traffic is routed via Cloudflare Tunnel; Cloudflare does not store Meta Platform Data at rest. You can disconnect Meta at any time in the app, or revoke access in your Facebook settings. We also honor Meta's deauthorize callback at app.flow2market.cc/api/platforms/meta/deauthorize, which clears stored tokens for your account.
Flow²Market's use of information received from Meta APIs adheres to the Meta Platform Terms and applicable Developer Policies.
3c. Data Protection & Security
Encryption at rest: All OAuth tokens, credentials, and sensitive user data stored in our database are encrypted using AES-256-GCM. Each value is encrypted with a unique random initialization vector (IV) and authentication tag. The encryption key is derived via scrypt with a random salt and stored exclusively as an environment variable — it is never committed to code, stored in the database, or accessible to administrators in plaintext.
Encryption in transit: All API traffic between our application, your browser, and third-party services (Google Ads, Meta, Stripe, OpenRouter, etc.) is transmitted over TLS 1.3. Our infrastructure uses Cloudflare Tunnel for egress, ensuring no public IP exposure and an additional layer of encrypted transport.
Access controls: Decrypted credentials are held in application memory only for the duration of the API call that requires them and are never persisted to logs, error reports, or metrics. No employee or administrator can view plaintext OAuth tokens or user credentials. Database access is restricted to the application runtime service account; direct database access requires production-level authentication and is logged.
Key management: Encryption keys are set via environment variables in production and are rotated as part of our deployment process. We do not use hardcoded or default keys in production — the application refuses to start with a development key when NODE_ENV=production.
Data minimization: We only request the OAuth scopes necessary to provide the specific feature you use. Tokens are revoked and deleted when you disconnect a platform or delete your account. We do not retain raw API responses beyond what is needed for dashboard display and performance reporting.
4. AI & Model Training
Your prompts and brand materials are processed by AI models through OpenRouter. We do not train our own models on your data. Your data is not used to improve third-party AI models unless you explicitly opt in.
5. Data Retention
We retain your data while your account is active and for 30 days after deletion. Billing records are kept for 7 years (Dutch tax law). Usage logs are retained for 12 months.
6. Automated Decision-Making
Flow²Market uses AI to autonomously generate creatives, allocate budgets, and optimize campaigns. You retain control and can review or override decisions. Contact us to contest any automated decision.
7. Your Rights
Under GDPR, you have the right to access, rectify, delete, port, and restrict processing of your data. To exercise these rights, email [email protected]. You may also lodge a complaint with the Autoriteit Persoonsgegevens (ap.nl).
8. Contact
Huisman Web3
Eerste Goudsbloemdwarsstraat 14 3, 1015JW Amsterdam, Netherlands
KVK 86087053 · VAT NL213628211B03
[email protected]