OfficeFlow

Privacy Policy

How OfficeFlow handles your workplace data

OfficeFlow is used by organisations to run attendance, task assignment, approvals and leave for their own staff. This policy sets out exactly what the app records, why it records it, and who inside and outside your organisation can see it.

Effective 4 September 2026 Applies to OfficeFlow for Android Contact content84.topperias@gmail.com

01Who controls your data

Throughout this policy, “your organisation” means the employer or institute that invited you to OfficeFlow and administers your account.

OfficeFlow is supplied to organisations, and each organisation controls the records of its own staff. Your organisation decides who is invited, what is recorded, what a manager may see, and when an account is closed. If you are a staff member with a question about your own attendance, leave or task history, speak to your organisation’s OfficeFlow administrator first — they hold those records.

For questions about the app itself — how it works, what it stores, a security concern — write to content84.topperias@gmail.com.

02Information we collect

OfficeFlow collects only what is needed to run your workplace. There are no advertising SDKs and no third-party analytics in the app.

What we never collect: advertising identifiers, device location, contacts, call logs, SMS messages, photos from your gallery, or browsing history.

Collected data, purpose, and visibility
WhatWhy it is collectedWho can see it
Name, phone number, email To sign you in by one-time SMS code and identify you to colleagues You, and admins in your organisation
Designation, department, role To route tasks, approvals and leave to the right people Your organisation
Date of birth Optional profile detail, entered by you or your admin You, and admins in your organisation
Language preference To show the app in English or Kannada You only
Attendance: clock-in and clock-out times, and the date The attendance record your organisation relies on You, your manager, your admins
Tasks: title, description, deadline, priority, status, assignee To run day-to-day work assignment People the task involves
Comments posted on tasks Discussion attached to a piece of work People the task involves
Leave requests: dates, the reason you give, the decision To request leave and record the outcome You and your approvers
Approval requests and decisions To record who approved what, and when You and your approvers
Files you attach to a task, with file name, type and size To share documents alongside the work they belong to Authorised members of your organisation
In-app notifications To tell you when something needs your attention You only
Subscription status and plan To manage your organisation’s billing Your organisation’s administrators

Payments

Subscription payments are processed by Razorpay. Card, UPI and bank details are entered on Razorpay’s own checkout and are never seen by, passed through, or stored in OfficeFlow. We keep only the payment reference and the subscription state that Razorpay reports back to us.

03How we use your information

Your data is used solely to operate the service for your organisation:

  • To sign you in and keep your session active on your device.
  • To show your tasks, attendance and leave, and your team’s where your role allows.
  • To route approvals and leave requests to the right manager or administrator.
  • To notify you when a task, approval or leave decision affects you.
  • To manage your organisation’s subscription and billing state.

We do not sell your data, share it with data brokers, use it for advertising, profile you across other apps, or use it to train machine-learning models.

04Data storage

Your records are held in a managed Supabase PostgreSQL database and file store, hosted on infrastructure located in India. Files you attach to tasks are kept in a private storage bucket that is not publicly readable; they are reachable only through short-lived signed links issued to authorised members of your organisation.

Your signed-in session and your language preference are stored locally on your own device so you are not asked to sign in every time you open the app. Signing out clears them.

05Third-party services

OfficeFlow uses two service providers, and only for the purposes named here:

  • Supabase — database, authentication and file storage hosting. Supabase processes your account and work records on our behalf in order to store them.
  • Razorpay — payment processing for organisation subscriptions. Razorpay collects payment details directly from the administrator making the payment; its own privacy policy governs that transaction.

The one-time code you use to sign in is delivered as an SMS through our messaging provider, which receives your phone number and that code for the sole purpose of delivering the message. There are no other third parties in the app.

06Data sharing

Inside your organisation

Staff see their own records and the tasks assigned to them. Managers and administrators can see records across their department or organisation, according to how your organisation has configured roles and permissions.

Between organisations — never

Each organisation’s data is isolated at the database level by row-level security rules. The server rejects any request for data outside your own organisation rather than relying on the app to hide it, so members of one organisation cannot read another organisation’s records under any circumstances.

Legal

We may disclose data where we are required to by applicable law or valid legal process.

07Children’s privacy

OfficeFlow is a workplace tool intended for employees and staff. It is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child’s data has been entered into OfficeFlow, contact us and we will remove it.

08Data retention and account deletion

Records are kept for as long as your organisation’s account is active, because attendance and task history are the working record the organisation relies on.

When an administrator removes a member, that member’s account is deactivated rather than erased, so the attendance and task history attached to them stays intact and auditable for the organisation. A deactivated member can no longer sign in or access any data. An organisation owner can delete the entire organisation from within the app, which deactivates the organisation and every member in it.

Requesting deletion of your account and data

You can ask us to delete your OfficeFlow account and the personal data held about you without installing the app or signing in:

  1. Email content84.topperias@gmail.com with the subject line “Delete my OfficeFlow account”.
  2. Include the mobile number you sign in with, so we can identify the account.
  3. We will confirm the request with you and action it within 30 days.

What is deleted: your profile — name, phone number, email, designation, date of birth — your notifications, and your sign-in credentials. Your account can no longer be used.

What may be retained: where your employer is the controller of the record, attendance entries, completed tasks, and approval and leave decisions may be kept as the organisation’s own business record, with your name removed where we are able to do so. We will tell you what was kept and why, and refer you to your organisation’s administrator for anything that is theirs to decide.

09Your rights

You may ask to:

  • Access the personal data we hold about you.
  • Correct anything that is inaccurate — you can edit your own profile in the app at any time.
  • Delete your account and personal data, as described in section 8.
  • Object to or restrict a particular use of your data.

Contact your organisation’s administrator, or write to content84.topperias@gmail.com. We respond within 30 days. Where your organisation is the controller of the data, we will refer the request to them, since their workplace records may need to be retained.

10Security

Sign-in is by one-time code sent to your registered mobile number; there is no password to leak or reuse. Access to every record is enforced by row-level security policies in the database, so the server refuses requests for data outside your organisation rather than relying on the app to hide it. Traffic between the app and our servers is encrypted in transit over HTTPS, and file downloads use expiring signed links.

No system is perfectly secure, but these are the measures we use to protect your information. If you find a security problem, please report it to the address below.

11Changes to this policy

If this policy changes materially we will update the effective date at the top of this page and, where appropriate, notify organisation administrators. Continued use of OfficeFlow after a change means you accept the updated policy.

12Contact us

Questions about this policy, a data request, or a security report:

content84.topperias@gmail.com