Flow2CRM
RUEN
Request access
← Home

Privacy Policy

Terms of Service Personal Data Processing Policy Payment and Refunds User Data Deletion
Last updated: October 9, 2026

This policy explains what data Flow2CRM processes, why it is needed, who receives it, and how to request deletion. It applies to flow2crm.ru and flow2crm.com, the account dashboard, the website tracker, and connected integrations, including Instagram.

Service: Flow2CRM
Support and personal data requests: support@flow2crm.com

1. Who this policy covers

Flow2CRM processes account holder information to provide the service. When a customer connects a website, messenger, or CRM, that customer determines the purposes of processing their visitors and conversation participants' data; Flow2CRM processes it to perform the functions configured by the customer. This policy also covers people whose messages or enquiries arrive through a connected source, even if they do not have a Flow2CRM account.

2. Data we process

  • Account data: name, organization, website, email, preferred language, password hash, and account usage information.
  • Connection data: source name, account ID, name, username, phone number where available, account type, permissions, tokens or session data, and connection status.
  • Communication data: participant IDs and available names, phone numbers and usernames, message text and timestamps, direction, comments, attachments and their technical properties. For supported sources, we record call events, direction, outcome, and available duration; this feature does not record call audio or video.
  • Connected website data: visitor and session IDs, page and destination URLs, referrers, UTM parameters, advertising identifiers, available Yandex Metrica ClientID, click time and channel, and links to conversations and CRM records.
  • Technical and operational data: IP addresses, browser information, request timestamps, errors and security logs, API and webhook settings, notification delivery results, and CRM synchronization results.

3. How we use data

We use data for registration and sign-in, selected integrations, communication history, matching clicks to enquiries and CRM records, delivery to the CRM and webhooks configured by the customer, connection monitoring, service notifications, support, and prevention of abuse. The scope depends on enabled features and external platform permissions. Customers must have an appropriate legal basis for processing their visitors and conversation participants' data.

4. Instagram and Meta data

When a professional Instagram account is connected through the official Meta OAuth flow, Meta provides permitted account information, participant IDs, available Direct messages, comments, and attachments. Flow2CRM uses this data for the selected communication history and CRM integration functions. In this connection method, the Instagram password is entered with Meta, not shared with Flow2CRM. Meta data is not sold, supplied to data brokers, or used for third-party advertising. Disconnecting Instagram in the dashboard removes the stored OAuth token but does not delete previously received history; you can request its deletion.

5. Who may receive data

Data is sent to the CRM, including Bitrix24, webhook destinations, and other integrations configured by the customer, only for the relevant functions. A configured Yandex Metrica integration may receive attribution and event data. An account owner may also create a protected communication history link and share it with others; access depends on that link's settings. Hosting and email delivery providers may process information needed to perform their services. Disclosure to required recipients may occur in response to a lawful request. External platforms process received data under their own rules, and their infrastructure may be located in other countries.

6. Cookies and local storage

The dashboard uses session cookies for sign-in and security. On a connected website, the tracker stores a visitor ID in a cookie and localStorage, and session information in localStorage, to link visits and enquiries. The visitor cookie is set for up to one year; browser identifiers can be cleared in browser settings. Clearing the browser does not itself delete information already sent to Flow2CRM. Website owners are responsible for required tracker notices and consent. Public pages load Google Fonts; during loading, the browser contacts Google and sends ordinary technical request information.

7. Retention and security

Account information and settings are retained to service the account. Communication history and analytics are kept for configured functions until deletion or until the relevant need ends. If history storage is disabled, CRM-synchronized text and local attachments are cleared after processing; operational links may remain. There is no single automatic deletion period for all data. Account passwords are stored as hashes, and OAuth tokens and supported integration secrets are encrypted; access to the dashboard, sessions, and media is restricted. Backups and logs may also contain data and are considered when handling deletion requests.

8. Access, correction, and deletion

You can contact support at the email above to ask about processing of your data, request access, correction, or deletion, and exercise other rights provided by applicable law. To protect data, we may request proportionate verification of identity or account ownership. Passwords, sign-in codes, and tokens are not required for such a request. Where data was supplied by our customer, we coordinate the necessary actions with them without restricting your right to contact Flow2CRM.

9. Requesting deletion

Detailed instructions are published on the User Data Deletion page, which is accessible without signing in. You may request deletion of your Flow2CRM account, data from a particular connection, including Instagram, or messages and enquiries relating to you. Simply disconnecting a source does not erase saved history. We handle requests without undue delay and within the time limits required by applicable law. If particular information must be retained by law, we explain the reason and duration; deletion in Flow2CRM does not automatically delete copies in a CRM or at an external platform.

10. Policy updates and contact

The current policy is published on this page with its update date. Send privacy, integration, and data deletion enquiries to the Flow2CRM support address above. The Russian version is available at flow2crm.ru and the English version at flow2crm.com.

Flow2CRMEvery conversation. More sales.

One customer. One history. One CRM.

About Flow2CRM Documents Contacts
© 2026 Flow2CRM