Legal
Privacy Policy
What Umikflow Billing collects, why, who else touches it, and what you can ask us to do about it. Written for this application rather than copied from a template.
Last updated 14 September 2026
Umikflow Billing holds two quite different kinds of information: the details of your own account, and the client and payment records you enter into your workspace. This policy treats them separately, because the obligations differ.
Short version: we hold what the workspace needs to function, we do not sell anything, we do not contact your clients, and we run no advertising. The detail is below.
1.Who this policy covers
This policy applies to the Umikflow Billing website and the billing workspace at billing.umikflow.com. “We” and “Umikflow” mean the operators of that service; “you” means a visitor to the public site or a merchant with an account.
It describes what this specific application does. Where we have nothing to say about a common practice — selling data or advertising profiles — it is because we do not do it. Website analytics we do run are described below, rather than left implied.
2.Account information
Creating a workspace requires an email address, a password and a name. Authentication is handled by Supabase Auth, which stores the credential; we never receive or store your password in readable form.
A profile record is created alongside the account. It holds your name, your email address, the role and status of the account, and the timestamps for when it was created and last changed.
3.Profile information you add
You can complete your profile with a postal address, a mobile number and a professional qualification. These fields are optional in the sense that the workspace runs without them, but your name, address and mobile number are needed to produce an invoice, because they appear at the top of the document.
This information is used to render your invoices and to sign the reminders you send. It is not published anywhere and is not shared with other merchants.
4.Client and payment data you enter
The substance of the workspace is data you enter about your own clients: a client name, a mobile number, an optional reference describing the work, the fee you agreed, and the payments you record against it with their amounts, dates and notes.
We process this information on your behalf so the workspace can function. We do not analyse it, aggregate it for any purpose beyond your own dashboard, sell it, or use it to contact your clients. We never contact your clients at all.
Your responsibility. Those clients are individuals whose information you are holding. You should have a lawful basis for storing it, should only enter what you actually need in order to bill and follow up, and should honour any request they make to you about it. We give you the tools to edit and remove records so you can do that.
5.The contact form
The form on the contact page sends your name, email address and message to our server so we can email them to support@umikflow.com. We do not write those submissions into the billing database.
We hold the correspondence in the support inbox for as long as it is useful for support, and we use it only to reply to you. We do not add you to a mailing list.
7.Service providers
We rely on a small number of third parties to run the service:
- Supabase — authentication, and the PostgreSQL database holding your profile, clients and payments.
- Vercel — hosting and content delivery for the website and application.
- Google Analytics — website usage measurement, as described above.
- Google Fonts — the typefaces used across the site, served as part of the application build.
These providers process data in order to provide their service to us. We do not sell your data, and we do not share it with anyone for their own marketing.
When you use a WhatsApp reminder or share an invoice, your device hands the message or file to WhatsApp — an application operated by Meta, under its own terms and privacy policy. Umikflow has no connection to the WhatsApp Business API and transmits nothing itself.
8.How the data is protected
Access to client and payment records is enforced by Row Level Security policies inside the database, so a query can only return rows belonging to the account that made it. One merchant cannot reach another merchant's records.
Administrators can moderate accounts and view platform-level counts, and moderation actions are recorded in an activity log. Administrators do not have a route into a merchant's client or payment ledger.
The application in your browser is configured with a public key only; credentials capable of bypassing those database rules are never sent to it. Traffic to the site and the database is served over HTTPS.
The security page sets this out in more detail, including what we do not claim.
9.Retention and deletion
We keep your account, profile, client and payment data for as long as your workspace exists, because the workspace is a record you are relying on.
Removing a client or a payment marks the record as deleted rather than destroying it immediately. That is deliberate: it is what allows an accidental removal to be restored. A removed record is no longer shown in your workspace, and it remains reachable only by your own account.
If you want your account and its data deleted outright, email support@umikflow.com from the address on the account and we will action it.
10.Your rights
Regarding the personal data we hold about you as a merchant, you can:
- Access it — most of it is visible and editable inside your workspace.
- Correct it — your profile and every client and payment record can be edited.
- Request deletion of your account and its data.
- Ask what we hold and what we do with it, and get a straight answer.
- Withdraw from analytics by blocking cookies in your browser.
Where a client of yours asks you to exercise similar rights over data you entered about them, that request is one for you to fulfil, since you control those records. The workspace lets you edit or remove them.
11.Children
Umikflow Billing is a tool for running a business and is not directed at children. We do not knowingly create accounts for anyone under 18. If you believe a child has an account, tell us and we will remove it.
12.Changes to this policy
If the application changes in a way that affects this policy — a new service provider, a new category of data — we will update this page and change the date at the top. Continuing to use the service after a change means you accept the updated policy.
13.Contacting us about privacy
Email support@umikflow.com with any question about this policy, a request about your data, or a correction to something stated here. You can also use the contact page.
