Legal
Privacy Policy
Last updated: March 19, 2026
1. Introduction
HintFlow (“we,” “us,” or “our”) respects your privacy and is committed to protecting the personal data you share with us. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our services.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, and password when you create an account.
- Profile Data: Optional information you add to your profile, such as a profile picture.
- Payment Information: Billing details processed securely through Stripe. We never store your full credit card number.
- Communications: Information you provide when contacting support or subscribing to our newsletter.
2.2 Information Collected Automatically
- Usage Data: Pages visited, features used, reading history, and interaction patterns.
- Device Information: Browser type, operating system, device type, and screen resolution.
- Analytics: We use Plausible Analytics, a privacy-first analytics tool that does not use cookies and does not collect personal data.
3. How We Use Your Information
- To provide, maintain, and improve our services.
- To personalise your experience and content recommendations.
- To process transactions and manage your subscription.
- To send you our weekly newsletter (with your consent).
- To respond to your enquiries and provide customer support.
- To detect, prevent, and address technical issues or fraud.
- To comply with legal obligations.
4. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information. We may share data with:
- Service Providers: Trusted third parties that help us operate our platform (e.g., Stripe for payments, Resend for emails, MongoDB Atlas for data storage).
- Legal Requirements: When required by law, court order, or governmental authority.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, with notice to affected users.
5. Data Security
We implement industry-standard security measures including encryption in transit (TLS/SSL), secure password hashing (bcrypt), and access controls. While no method of transmission over the Internet is 100% secure, we strive to protect your data using commercially acceptable means.
6. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes described in this policy. Account data is retained while your account is active. You may request deletion at any time by contacting us.
7. Your Rights (GDPR & CCPA)
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data (“right to be forgotten”).
- Portability: Request your data in a machine-readable format.
- Objection: Object to processing of your data for certain purposes.
- Withdraw Consent: Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, please contact us at privacy@hintflow.com. We will respond within 30 days.
8. Children's Privacy
Our services are not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will delete it promptly.
9. International Data Transfers
Your data may be processed in countries other than your own. We ensure appropriate safeguards are in place, including standard contractual clauses, to protect your data in accordance with this policy.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the “Last updated” date. Your continued use of the service after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy, please contact us at privacy@hintflow.com.