1. Scope
This policy applies to the OfficerFlow public website, onboarding and subscription flows, and OfficerFlow workspaces. An organisation using OfficerFlow decides what business information its authorised users enter and who can access it. People should also review any privacy notices provided by their organisation.
2. Information we collect
Account and contact data
This may include names, work email addresses, contact numbers supplied during onboarding, organisation details, job or role information, workspace name requests, sign-in identifiers, invitation details, and support communications.
Workspace and business data
This may include tasks, events, schedules, officer and staff records, approvals, finance records, documents, comments, reports, settings, and other information that authorised users add to the workspace.
Logs, security and device metadata
We may collect IP addresses, browser and device information, timestamps, sign-in and security events, activity and audit records, error diagnostics, request metadata, and information needed to detect misuse or investigate incidents.
Billing references
We may store plan choices, amounts, currency, OfficerFlow order and payment references, a UPI UTR or PayPal transaction ID, payment-review status, timestamps, receipt references, and limited payment metadata. A customer may optionally upload a receipt image or PDF. These attachments are stored privately and are available only through authorised OfficerFlow routes to the submitting organisation where appropriate and the platform payment reviewer.
OfficerFlow does not ask for or store a UPI PIN, OTP, full card number, CVV, bank password, PayPal password, or full online-banking credentials. Receipt images are not used for automatic approval or treated as authoritative proof.
3. Why we use information
We use information to:
- create, configure, operate, and support OfficerFlow accounts and workspaces;
- authenticate users, manage invitations and permissions, and maintain security and audit records;
- process onboarding, subscriptions, verified payment status, service delivery, support, and account communications;
- monitor reliability, diagnose errors, prevent fraud and abuse, and improve usability and performance;
- meet legal, accounting, security, dispute-resolution, and enforcement obligations; and
- protect OfficerFlow, customers, users, and the public.
4. Processors, payment services and other sharing
We may use service providers for hosting, storage, email delivery, monitoring, security, support, and other infrastructure. They receive information only as reasonably needed to perform their services and are expected to handle it under appropriate confidentiality and security obligations.
UPI payments are completed in the customer’s chosen UPI app, and PayPal payments are completed separately with PayPal. OfficerFlow does not use a PayPal payment API in the current manual flow. OfficerFlow receives the transaction reference and any optional receipt supplied by the customer, then an authorised owner compares it with the actual receiving account. Payment is treated as successful only after this manual verification.
We may also disclose information when required by law, to protect rights or safety, to investigate fraud or security events, in connection with a lawful business reorganisation, or with the relevant person’s or organisation’s direction. We do not sell full card or bank credentials because OfficerFlow does not receive or store them.
Cross-border processing
Information may be processed in India and in other jurisdictions where carefully selected service providers operate. Where applicable, we use reasonable contractual, organisational, and technical measures intended to protect information during such processing, subject to local law.
6. Retention and security safeguards
We retain information while an account or workspace is active and for as long as reasonably needed to provide the service, preserve security and payment audit records, resolve duplicate or incorrect payment questions, maintain backups, prevent fraud, and meet legal, tax, accounting, or contractual obligations. Optional receipt attachments follow a documented operational retention target and may be retained longer when reasonably required for an active dispute, accounting, fraud prevention, or law. Backup copies may remain for a limited period before normal deletion cycles complete.
OfficerFlow uses reasonable administrative, technical, and organisational safeguards designed to protect information. These include access controls, authentication protections, separation of operational areas, logging, secure transmission, and restricted handling of sensitive configuration. No online service can guarantee absolute security.
7. Access, correction and deletion requests
You may ask to access, correct, or delete personal information associated with you by emailing info@officerflow.in. We may need to verify your identity and authority, and may direct a workspace-related request to the organisation responsible for that information.
Requests are subject to applicable law and legitimate retention obligations. We may retain limited information when necessary for security, fraud prevention, legal claims, accounting, backups, or compliance, and will explain when a request cannot be completed in full.
8. Updates and contact
We may update this policy as OfficerFlow, its providers, or legal requirements change. The revised policy will be posted on this page with an updated date. Material changes may also be communicated through the service or account contact details.
Email OfficerFlow at info@officerflow.in.