SETROASFLOW — PRIVACY POLICY
Version: Draft — 25 August 2026
1. WHO WE ARE
SetRoasFlow is currently operated by Matteo De Giuseppe, an individual established in Italy. The Service is currently in private beta and free of charge. Paid operation is planned only after transition to the appropriate company/business structure.
Contact: [email protected]
2. ROLES
SetRoasFlow acts as controller for personal data relating to its own website, waitlist, accounts, dashboard users, support and operational activities. For customer/visitor data processed through a Merchant's implementation of the Service, SetRoasFlow generally acts as processor on the Merchant's documented instructions.
3. DATA WE COLLECT AS CONTROLLER
Depending on how you interact with SetRoasFlow, we may process account information, contact information, authentication and account records, support communications, usage and security information, and information you voluntarily provide.
4. PURPOSES
We use controller-side data to provide and secure the Service, operate accounts, communicate with users, provide support, prevent abuse, maintain reliability, improve the Service and comply with legal obligations.
Aggregated, non-personal operational statistics may be used to improve the Service. Merchant and end-customer personal data is not used to train AI models.
5. MERCHANT DATA
When a Merchant deploys SetRoasFlow, event data and customer profile information may be processed on the Merchant's behalf. The Merchant determines the purposes and lawful basis. Categories include email, phone, external IDs, names, location fields, IP address, user-agent, advertising click IDs, event information, attribution information, country/region, device type and derived analytics.
The Service is not intended for special categories of personal data or criminal-offence data.
6. CONSENT AND GEO-AWARE PROCESSING
The Service uses consent signals supplied by the Merchant's CMP or privacy mechanisms. EU/EEA/UK/Switzerland traffic is configured for opt-in handling; US and other traffic uses applicable opt-out mechanisms, including GPC where applicable.
7. COOKIES AND LOCAL STORAGE
The Service may use first-party cookies such as _srf and _srf_aud_<token> and localStorage keys _srf_ft and _srf_lt. Their purposes and consent treatment are described in the Cookie & Tracking Policy.
The legal treatment of attribution localStorage without a consent gate is subject to legal review under applicable ePrivacy rules.
8. RECIPIENTS
Recipients may include infrastructure providers, advertising platforms, analytics providers, CRM providers, AI providers and other destinations configured by the Merchant.
A recipient's inclusion in the Service does not itself establish its legal role. The applicable role and transfer mechanism are assessed separately.
9. INTERNATIONAL TRANSFERS
Some providers may process data outside the EEA. The applicable transfer mechanism is assessed vendor-by-vendor, including adequacy decisions, applicable certification frameworks and/or contractual safeguards.
10. RETENTION
CDP profiles are retained for the lifetime of the applicable Merchant account/project unless deletion is requested earlier. Event records are retained for a rolling period of 24 months.
Project deletion triggers live-data deletion within 24 hours. Residual disaster-recovery copies may persist for limited provider-specific periods.
11. ACCESS BY SETROASFLOW
Authorized SetRoasFlow personnel may have technically possible administrative access to production data stores when necessary for operations, debugging or support. Such access is subject to organizational and contractual restrictions and is not routine.
12. RIGHTS
Where applicable, individuals may have rights of access, correction, deletion, restriction, objection, portability and withdrawal of consent. Requests concerning Merchant-controlled data should generally be directed to the relevant Merchant.
13. SECURITY
We use TLS, signed cookies, HMAC verification, server-side secrets, backend-only database access, identity hashing before egress and PII redaction in logs, among other measures.
14. CHILDREN
The Service is intended for business customers and professionals who have or manage websites and is not offered as a consumer service.
[LAWYER REVIEW REQUIRED: confirm age/children policy.]
15. CUSTOMER REFERENCES
SetRoasFlow may publicly identify business customers and use their logos unless the customer opts out by contacting [email protected].
16. CHANGES
We may update this Policy as the Service or legal requirements change.